VLDB 2026 Research / reviewers in the wild / expert
Basel Katt
dblp:37/1402
· DBLP profile ↗
23ranked-venue papers
3as first author
12since 2021 · last 2026
0000-0002-0177-9496ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 1 first-author · 10 since 2021Software engineering, systems software and programming languages · 3Human-computer interaction and ubiquitous computing · 2 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Securing large language models: A quantitative assurance framework approachabstractLarge Language Models (LLMs) are increasingly integrated into sensitive domains such as healthcare and autonomous systems, yet adoption is constrained by security risks that conventional assurance methods do not capture. Traditional software assurance techniques are inadequate for LLM-specific vulnerabilities, including prompt injection, insecure output handling, and training data poisoning. We introduce a quantitative security assurance framework for LLM applications that translates security requirements and vulnerabilities into measurable scores. The framework computes an Assurance Metric (AM) as A M = R M − V M , where VM is weighted using CVSS v4.0, and maps results to five security assurance levels, making security posture comparable, auditable, and actionable. Requirements span input/output validation, training data, development and deployment, access control, third-party services, and security procedures; vulnerability tests align with the OWASP Top 10 for LLMs (prompt injection, insecure output handling, training data poisoning, denial of service, sensitive information disclosure, overreliance, and model theft). Case study results show uncensored models (e.g., Llama2-uncensored) exhibit significantly higher exposure, especially to prompt injection and output-handling attacks–while censored and fine-tuned models attain higher assurance levels. Significance and impact: the framework provides transparent, quantitative scoring to compare systems, prioritize mitigations, and support evidence-based deployment and governance in high-takes environments, with continuous human oversight emphasized. Sander Stamnes Karlsen, Muhammad Mudassar Yamin, Ehtesham Hashmi, Basel Katt, Mohib Ullah |
J. Inf. Secur. Appl. | 4 |
| 2025 | The Privacy Impact of Dash Mixing Fee Payments
Michael H. Ziegler, Mariusz Nowostawski, Basel Katt |
DBSec | 3 |
| 2025 | Severity-based triage of cybersecurity incidents using kill chain attack graphs
Lukás Sadlek, Muhammad Mudassar Yamin, Pavel Celeda, Basel Katt |
J. Inf. Secur. Appl. | 4 |
| 2024 | Combining Uncensored and Censored LLMs for Ransomware Generation
Muhammad Mudassar Yamin, Ehtesham Hashmi, Basel Katt |
WISE (4) | 3 |
| 2024 | All flags are not created equal: A deep look into CTF Scoring AlgorithmsabstractCapture the Flag (CTF) competitions are popular in the cybersecurity field to train and evaluate the skills of students and professionals alike. Each CTF competition has a scoring system that is fundamental in evaluating a participant’s skills by awarding scores for correct behavior and penalizing for incorrect behavior. Even though this topic gets discussed in the CTF community, it has mostly been ignored in previously published research material. The purpose of this research is: (1) to evaluate and understand how scoring algorithms affect the outcome of the two most commonly used CTF formats, i.e., Jeopardy and Attack-Defense. (2) To identify the desired requirements and properties of a CTF scoring algorithm by following a three-step process consisting of conducting a survey targeting experts from the European Cybersecurity Challenge (ECSC), identifying the currently available CTF algorithms using a literature review, and then simulating the identified scoring algorithms using data obtained from real CTFs. Finally, (3) scoring algorithms for both CTF formats are proposed based on the findings of the literature review, survey, and simulation results that fulfill the identified requirements. Abdullah Zafar, Muhammad Mudassar Yamin, Basel Katt, Espen Torseth |
Expert Syst. Appl. | 3 |
| 2024 | Exploring the role of assurance context in system security assurance evaluation: a conceptual modelabstractPurpose Security assurance evaluation (SAE) is a well-established approach for assessing the effectiveness of security measures in systems. However, one aspect that is often overlooked in these evaluations is the assurance context in which they are conducted. This paper aims to explore the role of assurance context in system SAEs and proposes a conceptual model to integrate the assurance context into the evaluation process. Design/methodology/approach The conceptual model highlights the interrelationships between the various elements of the assurance context, including system boundaries, stakeholders, security concerns, regulatory compliance and assurance assumptions and regulatory compliance. Findings By introducing the proposed conceptual model, this research provides a framework for incorporating the assurance context into SAEs and offers insights into how it can influence the evaluation outcomes. Originality/value By delving into the concept of assurance context, this research seeks to shed light on how it influences the scope, methodologies and outcomes of assurance evaluations, ultimately enabling organizations to strengthen their system security postures and mitigate risks effectively. Shao-Fang Wen, Basel Katt |
Inf. Comput. Secur. | 2 |
| 2023 | Insecurity Refactoring: Automated Injection of Vulnerabilities in Source CodeabstractInsecurity Refactoring is a change to the internal structure of software to inject a vulnerability without changing the observable behavior in a normal use case scenario. An implementation of Insecurity Refactoring is formally explained to inject vulnerabilities in source code projects by using static code analysis. It creates learning examples with source code patterns from known vulnerabilities. Insecurity Refactoring is achieved by creating an Adversary Controlled Input Dataflow tree based on a Code Property Graph. The tree is used to find possible injection paths. Transformation of the possible injection paths allows to inject vulnerabilities. Insertion of data flow patterns introduces different code patterns from related Common Vulnerabilities and Exposures (CVE) reports. The approach is evaluated on 307 open source projects. Additionally, insecurity-refactored projects are deployed in virtual machines to be used as learning examples. Different static code analysis tools, dynamic tools and manual inspections are used with modified projects to confirm the presence of vulnerabilities. The results show that in 8.1% of the open source projects it is possible to inject vulnerabilities. Different inspected code patterns from CVE reports can be inserted using corresponding data flow patterns. Furthermore the results reveal that the injected vulnerabilities are useful for a small sample size of attendees (n=16). Insecurity Refactoring is useful to automatically generate learning examples to improve software security training. It uses real projects as base whereas the injected vulnerabilities stem from real CVE reports. This makes the injected vulnerabilities unique and realistic. Felix Schuckert, Basel Katt, Hanno Langweg |
Comput. Secur. | 2 |
| 2023 | A quantitative security evaluation and analysis model for web applications based on OWASP application security verification standardabstractIn today's digital world, web applications are popular tools used by businesses. As more and more applications are deployed on the web, they are seen as increasingly attractive targets by malicious actors eager to exploit any security gaps present. Organizations are always at risk for potential vulnerabilities in their web-based software systems, which can lead to data loss, service interruption, and lack of trust. Therefore, organizations need to have an effective and efficient method for assessing and analyzing the security of acquired web-based software to ensure adequate confidence in its use. Quantitative security evaluation employs mathematical and computational techniques to express the security level that a system reaches. This research focuses on improving the quantitative analysis of web application security evaluation. We strive to unite the Open Web Application Security Project's (OWASP) Application Security Verification Standard (ASVS) into a structural and analyzable model, which aims to efficiently evaluate web application security levels while providing meaningful insights into their strengths and weaknesses. Shao-Fang Wen, Basel Katt |
Comput. Secur. | 2 |
| 2022 | Modeling and executing cyber security exercise scenarios in cyber ranges
Muhammad Mudassar Yamin, Basel Katt |
Comput. Secur. | 2 |
| 2022 | Use of cyber attack and defense agents in cyber ranges: A case study
Muhammad Mudassar Yamin, Basel Katt |
Comput. Secur. | 2 |
| 2021 | Serious games as a tool to model attack and defense scenarios for cyber-security exercises
Muhammad Mudassar Yamin, Basel Katt, Mariusz Nowostawski |
Comput. Secur. | 2 |
| 2021 | Weaponized AI for cyber attacks
Muhammad Mudassar Yamin, Mohib Ullah, Basel Katt |
J. Inf. Secur. Appl. | 4 |
| 2020 | Maturity Modelling to Prepare for Cyber Crisis Escalation and Management
Grethe Østby, Basel Katt |
ICISSP | 2 |
| 2020 | Cyber ranges and security testbeds: Scenarios, functions, tools and architecture
Muhammad Mudassar Yamin, Basel Katt, Vasileios Gkioulos |
Comput. Secur. | 2 |
| 2019 | Learning Software Security in Context: An Evaluation in Open Source Software Development EnvironmentabstractLearning software security has become a complex and difficult task today than it was even a decade ago. With the increased complexity of computer systems and a variety of applications, it is hard for software developers to master the expertise required to deal with the variety of security concepts, methods, and technologies that are required in software projects. Although a large number of security learning materials are widely available in books, open literature or on the Internet, they are difficult for learners to understand the rationale of security topics and correlate the concepts with real software scenarios. We argue that the traditional approach, which usually organizes knowledge content topically, with security-centric, is not suitable to motivate learners and stimulate learners' interest. To tackle this learning issue, our research is focused on forging a contextualized learning environment for software security where learners can explore security knowledge and relate it to the context that they are familiar with. This learning system is developed base on our proposed context-based learning approach and based on ontological technologies. In this paper, we present our evaluation study in the open source software (OSS) development environment. Our results demonstrate that contextualized learning can help OSS developers identify their necessary security information, improve learning efficiency and make security knowledge more meaningful for their software development tasks Shao-Fang Wen, Basel Katt |
ARES | 2 |
| 2019 | Cyber Security Skill Set Analysis for Common Curricula DevelopmentabstractThe field of cyber security is getting diversified day by day, with new specialist responsibilities and roles at different levels of competence being required by the industry. The competencies can be mapped with required skills set in multiple cyber security certification programs. However, different certification programs use different curricula and terminology, which makes the offerings overlap in some aspect and be distinct in others. This makes it hard for new institutes and cyber ranges to decide upon their training offerings. The aim of this study is to identify commonalities in skill set requirements for multiple cyber security roles like penetration tester, security operation center analysts, digital forensic and incident responders and information security managers. The identified commonalities will be used for the development of a standard common curricula to set skill set requirements for the achievement of specific competence levels in a specific cyber security field. Muhammad Mudassar Yamin, Basel Katt |
ARES | 2 |
| 2019 | Preliminary Evaluation of an Ontology-Based Contextualized Learning System for Software SecurityabstractLearning software security is a big challenging task in the information technology sector due to the vast amount of security knowledge and the difficulties in understanding the practical applications. The traditional teaching and learning materials, which are usually organized topically and security-centric, have fewer linkages with learners' experience and prior knowledge that they bring to the learning sessions. Learners often do not associate vulnerabilities or coding practices with programs similar to what they were writing in their previous time. Consequently, their motivation for learning is not touched by conventional methods. The aim of this paper is the presentation of an ontology-based learning system for software security with contextualized learning approaches, and of the results of an initial evaluation using a controlled quasi-experiment in a university learning environment. This system facilitates the contextual learning process by providing contextualized access to security knowledge via real software application scenarios, in which learners can explore and relate the security knowledge to the context they are already familiar with. The experiment results show that the prototyped system with the proposed learning approach not only yields significant knowledge gain compared to the conventional learning approach but also gains better learning satisfaction of students. Shao-Fang Wen, Basel Katt |
EASE | 2 |
| 2017 | Source Code Patterns of SQL Injection VulnerabilitiesabstractMany secure software development methods and tools are well-known and understood. Still, the same software security vulnerabilities keep occurring. To find out if new source code patterns evolved or the same patterns are reoccurring, we investigate SQL injections in PHP open source projects. SQL injections are well-known and a core part of software security education. For each common part of SQL injections, the source code patterns are analysed. Examples are pointed out showing that developers had software security in mind, but nevertheless created vulnerabilities. A comparison to earlier work shows that some categories are not found as often as expected. Our main contribution is the categorization of source code patterns. Felix Schuckert, Basel Katt, Hanno Langweg |
ARES | 2 |
| 2015 | A process for mastering security evolution in the development lifecycle
Michael Felderer, Basel Katt |
Int. J. Softw. Tools Technol. Transf. | 2 |
| 2009 | Building a stateful reference monitor with coloured petri netsabstractThe need for collaboration and information sharing has been recently growing dramatically with the convergence of outsourcing and off shoring, the increasing need to cut costs through cooperative agreements between partners as well as competitors, and the rise in the demand for a high-quality health Basel Katt, Michael Hafner, Xinwen Zhang |
CollaborateCom | 1 |
| 2009 | A usage control policy specification with Petri netsabstractIn this paper we propose a novel usage control policy specification based on Coloured Petri Nets formalism. Recently, usage control has been proposed in order to overcome the shortcomings of transitional access control that fails to meet new security requirements of today's highly dynamic and distri Basel Katt, Michael Hafner, Xinwen Zhang |
CollaborateCom | 1 |
| 2008 | Workflow Testing
Ruth Breu, Alexander Lechner, Mathias Willburger, Basel Katt |
ISoLA | 4 |
| 2008 | A general obligation model and continuity: enhanced policy enforcement engine for usage controlabstractThe usage control model (UCON) has been proposed to augment traditional access control models by integrating authorizations, obligations, and conditions and providing the properties of decision continuity and attribute mutability. Several recent work have applied UCON to support security requirements in different computing environments such as resource sharing in collaborative computing systems and data control in remote platforms. In this paper we identify two individual but interrelated problems of the original UCON model and recent implementations: oversimplifying the concept of usage session of the model, and the lack of comprehensive ongoing enforcement mechanism of implementations. We extend the core UCON model with continuous usage sessions thus extensively augment the expressiveness of obligations in UCON, and then propose a general, continuity-enhanced and configurable usage control enforcement engine. Finally we explain how our approach can satisfy flexible security requirements with an implemented prototype for a healthcare information system. Basel Katt, Xinwen Zhang, Ruth Breu, Michael Hafner, Jean-Pierre Seifert |
SACMAT | 1 |