VLDB 2026 Research / reviewers in the wild / expert
Sascha Kern
dblp:300/9294
· DBLP profile ↗
5ranked-venue papers
3as first author
5since 2021 · last 2025
0000-0002-7082-000XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Transaction Logs in Access Control: Leveraging an Under-Utilized Data Source
Sascha Kern, Thomas Baumer, Raphael Neudert, Günther Pernul |
DBSec | 1 |
| 2024 | A Framework for Managing Separation of Duty PoliciesabstractSeparation of Duty (SoD) is a fundamental principle in information security. Especially large and highly regulated companies have to manage a huge number of SoD policies. These policies need to be maintained in an ongoing effort in order to remain accurate and compliant with regulatory requirements. In this work we develop a framework for managing SoD policies that pays particular attention to policy comprehensibility. We conducted seven semi-structured interviews with SoD practitioners from large organizations in order to understand the requirements for managing and maintaining SoD policies. Drawing from the obtained insights, we developed a framework, which includes the relevant stakeholders and tasks, as well as a policy structure that aims to simplify policy maintenance. We anchor the proposed policy structure in a generic IAM data model to ensure compatibility and flexibility with other IAM models. We then show exemplary how our approach can be enforced within Role-Based Access Control. Finally, we evaluate the proposed framework with a real-world IAM data set provided by a large finance company. Sebastian Groll, Sascha Kern, Ludwig Fuchs, Günther Pernul |
ARES | 2 |
| 2023 | Maintain High-Quality Access Control Policies: An Academic and Practice-Driven Approach
Sascha Kern, Thomas Baumer, Ludwig Fuchs, Günther Pernul |
DBSec | 1 |
| 2022 | Optimization of Access Control PoliciesabstractOrganizations undertake complex and costly projects to model high-quality Access Control Policies (ACPs). Once built, these policies must be maintained and managed in an ongoing process to keep their quality high. Insufficient maintenance leads to inaccurate authorization decisions and increases the policies’ administrative effort and susceptibility to errors. While the initial modeling of ACPs has received significant research interest, their optimization is not yet covered as broadly. This work provides a theoretical foundation for ACP quality and its optimization. Furthermore, it analyzes how existing research addresses optimization of ACPs with regard to six crucial optimization dimensions. It presents a structured literature survey tracing these optimization dimensions, the contributed research artifact and data requirements. Building on this literature catalogue, this work elaborates on inaccuracies for user permission assignments, data availability, minimal perturbation and recommendation-based optimization. Sascha Kern, Thomas Baumer, Sebastian Groll, Ludwig Fuchs, Günther Pernul |
J. Inf. Secur. Appl. | 1 |
| 2021 | Monitoring Access Reviews by Crowd Labelling
Sebastian Groll, Sascha Kern, Ludwig Fuchs, Günther Pernul |
TrustBus | 2 |