Stef Verreydt

dblp:252/6373 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0001-5570-4097ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 A comparative benchmark study of LLM-based threat elicitation tools
Dimitri Van Landuyt, Majid Mollaeefar, Mario Raciti, Stef Verreydt, Abdulaziz Kalash, Andrea Bissoli, Davy Preuveneers, Giampaolo Bella, Silvio Ranise
Future Gener. Comput. Syst.4
2026 A Multivocal Literature Review on the Effectiveness of Security Threat Modeling
abstract
The growing need for integrating security through out the software development lifecycle leads to the adoption of various security activities. Threat modeling is widely recognized as a process that helps assess security issues, especially architectural flaws, due to insecure design, thereby supporting the security-by-design mindset. While many research and industry sources advocate for threat modeling, others highlight issues such as the lack of motivation, its time-consuming nature, and practical difficulties, leading to questions about its overall effectiveness.In this study, we conduct a comprehensive multivocal literature review to systematically examine the empirical evidence for the effectiveness of threat modeling. In short, by analyzing 109 sources from both white and gray literature, we did not encounter any direct, causal evidence (e.g., a controlled experiment) for the effectiveness of threat modeling as a technique to improve the security of a software application. This absence of causal evidence should not be interpreted as evidence that threat modeling is ineffective, though. The existing literature does describe several benefits and challenges related to threat modeling, as well as suggestions for improving the effectiveness of threat modeling activities. Studies on threat modeling often concentrate on benefits such as improved performance, effectiveness, efficiency, and usability of specific tools and methods. Recurring challenges, on the other hand, include a perceived lack of benefits, tool limitations, usability issues, and difficulties integrating threat modeling into the secure software development lifecycle. Suggestions for improvements include providing clear checklists or guidance, defining a clear scope, and involving different stakeholders during threat modeling activities.Based on this review of the literature, researchers are invited to conduct rigorous empirical studies to address the underexplored aspects of threat modeling, thereby strengthening its evidence base and increasing its impact in the real world.
Anh-Duy Tran, Stef Verreydt, Koen Yskout, Wouter Joosen
IEEE Trans. Software Eng.2
2025 Enhanced Threat Modeling and Attack Scenario Generation for OAuth 2.0 Implementations: Data/Toolset paper
abstract
OAuth 2.0 is a widely adopted authorization framework enabling secure, delegated access to resources on behalf of a user. While the protocol is robust when implemented correctly, real-world deployments often exhibit vulnerabilities due to misconfigurations, incomplete mitigations, or misunderstandings of its intricacies. (Semi-)automated testing is therefore essential to identify and address these security flaws. Among available tools, OAuch offers the most comprehensive benchmark for assessing OAuth IdP implementations by identifying potential threats based on the OAuth threat model and related standards. However, OAuch has notable limitations, including an incomplete threat model, ambiguous threat classifications, and a lack of support for multi-vulnerability attack scenarios. This paper presents enhancements to OAuch that improve the tool's usability, including enriched metadata, the introduction of attack scenarios for multi-threat analyses, and a likelihood assessment to prioritize mitigation efforts.
Pieter Philippaerts, Stef Verreydt, Wouter Joosen
CODASPY2
2025 Run-time threat models for systematic and continuous risk assessment
Stef Verreydt, Dimitri Van Landuyt, Wouter Joosen
Softw. Syst. Model.1
2021 Security and Privacy Requirements for Electronic Consent: A Systematic Literature Review
abstract
Electronic consent (e-consent) has the potential to solve many paper-based consent approaches. Existing approaches, however, face challenges regarding privacy and security. This literature review aims to provide an overview of privacy and security challenges and requirements proposed by papers discussing e-consent implementations, as well as the manner in which state-of-the-art solutions address them. We conducted a systematic literature search using ACM Digital Library, IEEE Xplore, and PubMed Central. We included papers providing comprehensive discussions of one or more technical aspects of e-consent systems. Thirty-one papers met our inclusion criteria. Two distinct topics were identified, the first being discussions of e-consent representations and the second being implementations of e-consent in data sharing systems. The main challenge for e-consent representations is gathering the requirements for a “valid” consent. For the implementation papers, many provided some requirements but none provided a comprehensive overview. Blockchain is identified as a solution to transparency and trust issues in traditional client-server systems, but several challenges hinder it from being applied in practice. E-consent has the potential to grant data subjects control over their data. However, there is no agreed-upon set of security and privacy requirements that must be addressed by an e-consent platform. Therefore, security- and privacy-by-design techniques should be an essential part of the development lifecycle for such a platform.
Stef Verreydt, Koen Yskout, Wouter Joosen
ACM Trans. Comput. Heal.1