VLDB 2026 Research / reviewers in the wild / expert
Johannes Sametinger
dblp:40/1112
· DBLP profile ↗
20ranked-venue papers
2as first author
5since 2021 · last 2025
0000-0002-0637-6602ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 13 · 2 first-author · 5 since 2021Security and privacy · 3Artificial intelligence and machine learning · 2Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SAFER-D: A Self-adaptive Security Framework for Distributed Computing Architectures
Marco Stadler, Michael Vierhauser, Michael Riegler 0002, Daniel Waghubinger, Johannes Sametinger |
ECSA | 5 |
| 2023 | A Distributed MAPE-K Framework for Self-Protective IoT DevicesabstractInternet of Things (IoT) devices have become ubiquitous in our everyday life, with security becoming an ever-growing issue as more and more cyber-attack incidents being reported, primarily due to deficiencies in existing security mechanisms. However, while, for example, cloud-based applications, or industrial automation systems of systems possess significant resources for monitoring health, and determining their status and correct behavior at runtime, IoT devices operate with limited hardware capabilities and under tight resource constraints, making monitoring, analysis, and response activities a challenging endeavor. Following the NIST Cybersecurity Framework, IoT devices need to identify, protect, detect, respond, and recover from cyber-attacks, unauthorized access, and other security threats. A common way to provide self-adaptation to changing conditions is the MAPE-K loop with four pivotal phases: Monitor, Analyze, Plan, and Execute. This paper presents DSec4IoT, a “Distributed MAPE-K Framework for Self-Protective IoT Devices”. Our framework leverages the idea of distributed MAPE-K patterns and establishes a model for managing and controlling Self-Protective IoT Devices. We evaluate our approach by simulating port scans and performing adaptation activities. Results have confirmed that DSec4IoT can be easily applied to detect and mitigate them. Michael Riegler 0002, Johannes Sametinger, Michael Vierhauser |
SEAMS | 2 |
| 2023 | A model-based mode-switching framework based on security vulnerability scoresabstractSoftware vulnerabilities can affect critical systems within an organization impacting processes, workflows, privacy, and safety. When a software vulnerability becomes known, affected systems are at risk until appropriate updates become available and eventually deployed. This period can last from a few days to several months, during which attackers can develop exploits and take advantage of the vulnerability. It is tedious and time-consuming to keep track of vulnerabilities manually and perform necessary actions to shut down, update, or modify systems. Vulnerabilities affect system components, such as a web server, but sometimes only target specific versions or component combinations. In this paper, we propose a novel approach for automated mode switching of software systems to support system administrators in dealing with vulnerabilities and reducing the risk of exposure. We rely on model-driven techniques and use a multi-modal architecture to react to discovered vulnerabilities and provide automated contingency support. We have developed a dedicated domain-specific language to describe potential mitigation as mode switches. We have evaluated our approach with a web server case study, analyzing historical vulnerability data. Based on the vulnerabilities scores sum, we demonstrated that switching to less vulnerable modes reduced the attack surface in 98.9% of the analyzed time. Editor’s note: Open Science material was validated by the Journal of Systems and Software Open Science Board. Michael Riegler 0002, Johannes Sametinger, Michael Vierhauser, Manuel Wimmer |
J. Syst. Softw. | 2 |
| 2023 | Safety and security of cyber-physical systemsabstractCyber-physical systems (CPSs) interact with their physical environment by both monitoring and manipulating objects and processes from the real world. The range of applications for CPSs encompasses agriculture, aeronautics, energy, healthcare, manufacturing, robotics, and transportation, to name just a few. Often, CPSs are part of what we consider critical infrastructure, for example, electric power and water treatment. CPSs communicating with the outside world are security-critical. They open an attack vector through their communication channels. CPSs are safety-critical if they potentially harm their environment. Conventional protection mechanisms like secure design principles are insufficient. We need to guarantee our CPSs' resilience (cf. Segovia et al.1), that is, the ability of a system to withstand adverse events while maintaining an acceptable functionality.2 Communication and coordination features of CPSs demand a combined approach to consider both safety and security concerns. We have published several special issues on the topic of the safety and security of CPSs in previous years.3-6 Similarly, for the current special issue, a general call for articles was announced and also the authors of the best papers of the International Workshop on Cyber-Security and Functional Safety in Cyber-Physical Systems—IWCFS 20207 and IWCFS 20218 —were invited to submit extended versions of their workshop papers. After thorough and stringent reviews, we selected ten articles that provide relevant contributions to the field of safety and security for CPSs. In the article, Identifying Safety Issues from Energy Conservation Requirements by Madala by Do and Tenbergen, the authors propose an approach for identifying safety issues caused by energy conservation recommendations of CPSs. The authors then empirically study four robotic systems to evaluate the approach's effectiveness. The authors find that the energy conservation recommendations compromise safety at the concept phase. In the article, Context Modeling for Cyber-Physical Systems by Daun and Tenbergen, the authors propose a comprehensive, ontologically grounded context modeling framework to systematically explore the problem space in which a CPS under development will operate. This allows for the systematic elicitation of requirements for the CPS, early validation and verification of its properties, and safety assessment of its context interactions at runtime. In the article, Enhancing and Securing Cyber-physical Systems and Industry 4.0 through Digital Twins: A Critical Review by Lampropoulos and Siakas, the authors present an overview regarding the use of digital twins as a means to reinforce and secure CPSs and Industry 4.0 in general. The authors argue that based on the provided literature review, digital twins can constitute an essential tool for the realization, reinforcement, and security of CPSs and Industry 4.0. In the article, F3FLUID: A Formal Framework for Developing Safety-Critical Interactive Systems in FLUID by Singh, Ait-Ameur, Mendil, Méry, Navarre, Palanque, and Pantel, the authors propose a unified formal framework, F3FLUID (Formal Framework For FLUID), for the development of safety-critical interactive systems. This framework is based on the FLUID (Formal Language of User Interface Design) pivot modeling language that enables the specification of high-level system requirements for interactive systems. This modeling language is designed to handle safety-critical interactive systems concepts, including domain knowledge. An industrial case study complying with the ARINC 661 standard for avionics systems is used to illustrate the effectiveness of the F3FLUID framework for the development of safety-critical interactive systems. In the article, Modeling and Verifying NLSR Protocol of NDN for CPS Using UPPAAL by Fei, Zhu, and Yin, the authors attempt to formally model and verify some fundamental properties of the NLSR protocol using model checker UPPAAL. First, the authors validate the NLSR protocol modeled into timed automata with a simulator in UPPAAL. Then, they verify the model with four fundamental properties (termination, reachability of Sync Interest, reachability of Sync Data, and digest synchronization). The first synchronization problem is found in a scenario with two node topology. The authors then give the improved model, which owns a valid result in digest synchronization verification. To capture more problems, the authors make the model to support the simulation of a temporary network crash. The second synchronization problem is also exposed in two comparative scenarios. Finally, the authors also propose a mechanism implemented in the model, which validates digest synchronization verification results. In the article, An Automated Evaluation of MQTT Broker Compatibility by Sochor, Ferrarotti, and Ramler, the authors develop an automated framework for compatibility evaluation of Message Queuing Telemetry Transport (MQTT) brokers, which can be easily generalized to other similar IoT components. They apply this framework to perform a comprehensive experiment conducted with 16 different versions of six popular MQTT brokers. In this work, the authors report inconsistencies in the behavior of varying MQTT brokers and broker versions. Based on the experiment results, the authors calculate and provide a visualization of compatibility among the evaluated brokers regarding their distance, indicating the risk of incompatibilities when replacing a broker with another. The calculation of distance measures can be adjusted by giving higher weights to essential features. The authors use this method to show security-related differences between the brokers. In the article, Safety And Security Risks Management Process for Cyber-Physical Systems: A Case Study by Inayat, Farooq, and Inayat, the authors present an integrated safety-security risk management process. To demonstrate the efficacy of the proposed process, they used a tetra packaging case study to (i) examine the vulnerabilities of CPS by running the risk management process, (ii) identify safety-security requirements, and (iii) align retrieved safety-security requirements with the relevant standards. The results show (i) safety hazards and security risks along with their severity and priority, (ii) mitigation guidelines in accordance with IEC 61508, and (iii) 15 safety-security requirements that were identified and are aligned with ISO 9001 packaging and labeling machine standard. In the article, Uncertainty Handling in Cyber-Physical Systems: State-of-the-Art Approaches, Tools, Causes, and Future Directions by Asmat, Khan, and Hussain, the authors identify current state-of-the-art approaches, tools, root causes, and metrics for uncertainty in the domain of CPSs. In addition, they performed a systematic literature review. The core contributions of this study are: (i) to categorize the tools used for uncertainty mitigation and existing root causes of uncertainty in the CPSs domain, (ii) to categorize the tools used for uncertainty mitigation and existing root causes of uncertainty in the CPSs domain, and (iii) to identify the state-of-the-art methods which cannot elaborate the metrics to measure the uncertainty in CPSs. The results of the proposed study are beneficial in guiding future research on devising new approaches or tools to mitigate the causes of uncertainty in CPSs. In the article, Internet-of-Things Architectures for Secure Cyber-Physical Spaces: the VISOR Experience Report by Pascale, Cascavilla, Sangiovanni, Tamburri, and Heuvel, the authors conduct a field study in a Dutch Easter music festival in a national interest project called VISOR to select the most appropriate device configuration in terms of performance and results. They iteratively architect solutions for the security of cyber-physical spaces using IoT devices. They test the performance of multiple federated devices encompassing drones, closed-circuit television, smartphone cameras, and smart glasses to detect real-case scenarios of potentially malicious activities such as mosh-pits and pick-pocketing. The results pave the way to select optimal IoT architecture configurations, that is, a mix of CCTV, drones, smart glasses, and camera phones, to make safer cyber-physical spaces a reality. Finally, in the article, Model-Driven Engineering of Safety and Security Software Systems: A Systematic Mapping Study and Future Research Directions by Mashkoor, Egyed, Wille, and Stock, the authors present a systematic mapping study on the model-driven engineering of safety and security concerns in software systems. Combined modeling and development of safety and security concerns is an emerging field of research. The mapping study provides an overview of the current state-of-the-art in this field. This study carefully selected 143 publications out of 27,259 relevant papers through a rigorous and systematic process. This study then proposes and answers questions such as frequently used methods and tools and development stages where these concerns are typically investigated in application domains. Additionally, the authors identify the community's preference for publication venues and trends. The discussion on obtained results also features the gained insights and future research directions. The editors of this special issue would like to thank the production team of Wiley for supporting the creation of this special issue. Special mention is also due to our reviewers, who processed all our submissions. Many thanks! This work is partially supported by the Austrian Science Fund (FWF) (grant # I 4744-N) and the LIT Secure and Correct Systems Lab funded by the State of Upper Austria. Miklós Biró, Atif Mashkoor, Johannes Sametinger |
J. Softw. Evol. Process. | 3 |
| 2021 | Safe and secure cyber-physical systemsabstractAbstract Cyber‐Physical Systems (CPSs) differ from traditional Information Technology (IT) systems in such a way that they interact with the physical environment, i.e., they can monitor and manipulate real objects and processes. For this special issue, the authors of the best papers of IWCFS 2019 were invited to submit extended versions of their workshop papers. Additionally, we received eight submissions from around the globe as a result of an open call. After thorough and stringent reviews, we selected six articles that provide relevant contributions to the field of safety and security for CPSs. Miklós Biró, Atif Mashkoor, Johannes Sametinger |
J. Softw. Evol. Process. | 3 |
| 2020 | Security- and safety-critical cyber-physical systemsabstractSecurity-and safety-critical cyber-physical systemsCyber-physical systems (CPSs) are physical embedded systems with enhanced operations for monitoring, coordination, control, and integration by a computing and communication core. 1 Examples of CPSs include transportations systems, 2 medical systems, 3 and manufacturing systems.4 A CPS can be security-critical, safety-critical, or both.A CPS communicating with the outside world and thus opening an attack vector through the communication channel is considered to be a security-critical CPS.On the other hand, a CPS is considered to be safety-critical if it can harm its environment, eg, a malfunctioning autonomous vehicle might harm its passengers.5 A CPS dealing with both security and safety concerns is considered to be a security-and safety-critical CPS.Contemporary systems and software engineering methods often prove inadequate for the trustworthy and reliable design and engineering of CPSs.Traditional engineering deals with security and safety issues as separate problems.However, given the coordination and communication features of CPSs, such a ''separation-of-concerns'' approach is no longer adequate.We need integrated methods to deal with security and safety concerns within CPSs. Atif Mashkoor, Johannes Sametinger, Miklós Biró, Alexander Egyed |
J. Softw. Evol. Process. | 2 |
| 2019 | COOL: Cooperative Open Learning for Beginning ProgrammersabstractCOOL Informatics (COOL stands for Cooperative Open Learning) is a teaching concept for beginning programmers that is based on brain-supporting teaching methods and materials. It includes several forms of cooperative learning like peer tutoring, pair programming, and talents exchange. We introduced the concept in a Java programming course of our Business Informatics bachelor program in 2018 and have been able to improve the learning outcomes (exam results) and to reduce drop-out rates compared to previous years and to reference groups of 2018. Barbara Sabitzer, Iris Groher, Johannes Sametinger |
ITiCSE | 3 |
| 2014 | Using the Juliet Test Suite to Compare Static Security ScannersabstractSecurity issues arise permanently in different software products. Making software secure is a challenging endeavour. Static analysis of the source code can help eliminate various security bugs. The better a scanner is, the more bugs can be found and eliminated. The quality of security scanners can be determined by letting them scan code with known vulnerabilities. Thus, it is easy to see how much they have (not) found. We have used the Juliet Test Suite to test various scanners. This test suite contains test cases with a set of security bugs that should be found by security scanners. We have automated the process of scanning the test suite and of comparing the generated results. With one exception, we have only used freely available source code scanners. These scanners were not primarily targeted at security, yielding disappointing results at first sight. We will report on the findings, on the barriers for automatic scanning and comparing, as well as on the detailed results. Johannes Sametinger |
SECRYPT | 2 |
| 2013 | Profiles for Convenient Front-end Privacy
Ronald Maier, Johannes Sametinger |
SEKE | 2 |
| 2012 | Secure and usable authentication on mobile devicesabstractMobile devices contain a multitude of sensitive data and provide access to even more data as well as services somewhere on the Internet. Even if only temporarily in the hands of non-entitled persons, privacy is at stake. Authentication protects against unauthorized usage. Today's operating systems of mobile devices offer authentication mechanisms. However, they are either vulnerable in some situations or not user friendly enough to be widely adopted. In this paper we suggest a novel authentication system which meets both the requirements of security and usability. For that purpose, we have analyzed existing authentication methods as well as targeting attacks. The resulting Android application SecureLock is a generic authentication system, which offers PIN and password, but also a property-based authentication method by means of NFC tags, and a novel image-based method called GesturePuzzle. The application has been evaluated and compared with other approaches for security and usability. Roland Schlöglhofer, Johannes Sametinger |
MoMM | 2 |
| 2011 | Software security for small development teams: a case studyabstractMicrosoft is developing wide-spread software solutions like the Windows operating system and the Office suite. In order to improve security of their products, they have introduced the Microsoft Security Development Lifecycle (MS-SDL). Ample documentation about the MS-SDL is available, thus, allowing other companies to adopt the lifecycle as well. We were wondering whether an adoption of the lifecycle is possible and useful for real small development teams, e.g., for a single developing person. In order to find out, we have done a practical test, i.e., we have used the MS-SDL for the development of a small, but real-world software project. The findings will be presented in this paper. Michael Kainerstorfer, Johannes Sametinger, Andreas Wiesauer |
iiWAS | 2 |
| 2009 | A Security Design Pattern Taxonomy based on Attack Patterns - Findings of a Systematic Literature Review
Andreas Wiesauer, Johannes Sametinger |
SECRYPT | 2 |
| 2008 | Case study: Using digital signatures for the archival of medical records in hospitalsabstractEven in medium-sized hospitals, thousands of medical records are created every day. These documents have to be archived over many years. This is important for having access to information for later treatments of patients and for potential legal disputes. The latter makes signing of medical records important. The process of getting rid of paper in hospitals is quite challenging for many reasons. Using digital signatures is definitely one of these challenges. This article will report on this process and on experiences made in an Austrian medium-sized hospital. Sebastian Sageder, Johannes Sametinger, Andreas Wiesauer |
CRiSIS | 2 |
| 2004 | Peer-To-Peer Information Workspaces In InfotopabstractKnowledge workers collaborate in teams, networks and communities in order to accomplish knowledge processes. They have to be supported with adequate organizational as well as information and communication technological (ICT) infrastructures. From an ICT perspective, requirements have changed when compared to more traditional (office) work due to the considerably higher complexity of data, the focus on communication across the boundaries of corporate ICT infrastructures and the mobility of knowledge workers. This requires the systematic handling of context and substantially extended functionality for collaboration in the knowledge workers' personal workspaces. In this paper, we outline typical knowledge processes and discuss ICT support for the personal management of information, of web content, of collaboration and of knowledge. We present Infotop, a tool that supports the creation and management of shared-context information workspaces and organizes knowledge resources in a peer-to-peer (p2p) architecture. We show how Infotop can be used to support typical knowledge work processes and discuss its dimensions, its user interface, its shared context workspaces, its architecture, and some thoughts on a prototype implementation currently under development. Ronald Maier, Johannes Sametinger |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2003 | Infotop - A Shared-context Information Workspace
Ronald Maier, Johannes Sametinger |
SEKE | 2 |
| 2001 | Concepts and architecture of a simulation framework based on the JavaBeans component model
Herbert Prähofer, Johannes Sametinger, Alois Stritzinger |
Future Gener. Comput. Syst. | 2 |
| 1996 | Literate programming and documentation reuseabstractObject-oriented programming has brought many advantages to the software engineering community. The reuse of existing software components and application frameworks can improve the productivity in software development considerably. The same object-oriented techniques, i.e., inheritance and information hiding, that ease reusing software, can be applied to documentation and thus, enable its reuse. One can document each software component-regardless of what a component is-from scratch. This leads to multiple documentation of features that are multiply reused. One can also describe a component's differences to other components. This seems logical for the systems documentation of object-oriented software. However, as is shown, this kind of reuse can not only be applied to source-code related documentation, but also to documentation, where there is no source code involved at all, e.g., user documentation. We describe the concepts for documentation reuse, how these concepts can be realized with a literate programming tool, and the application of documentation reuse. Bart Childs, Johannes Sametinger |
ICSR | 2 |
| 1995 | Design and Implementation Aspects of an Experimental C++ Programming EnvironmentabstractAbstract A good programming language alone is not sufficient for economic software production. The programming environment has a significant influence on the productivity of software engineers. Providing a programmer with information about an object‐oriented software system requires extracting information from the source code, e.g. class, method and variable names. We use separate structure files for holding this information and take advantage of proven tools such as make and the C preprocessor for keeping the structure files up to date and for processing software systems that heavily use macros. In this paper we describe the concepts used for comfortable processing of C++ software systems, and discuss interesting design and implementation aspects, including structure files, the applied make mechanism and the exploitation of the C preprocessor. Johannes Sametinger, Stefan Schiffer 0001 |
Softw. Pract. Exp. | 1 |
| 1990 | A tool for the maintenance of C++ programsabstractThe author describes a software tool that helps programmers understand object-oriented software systems written in C++. This task is accomplished by providing information about the set of classes and files of which the system is comprised and the relationships among them. The tool described enables its users to browse easily through the system on the basis of the relations among its classes, files, and even identifiers. In addition, the flexible use of global text styles enhances the readability of the source code. The implementation of the tool is described. In particular, problems are mentioned that arise when performing static analysis of C++ programs.> Johannes Sametinger |
ICSM | 1 |
| 1989 | User-adaptable PrettyprintingabstractAbstract This paper presents a prettyprinter for high‐level languages that can be adapted to the personal preferences of an individual user or to particular project conventions. The customization of the prettyprinter is done by means of a user profile with a set of parameters. The available parameters have been chosen with respect to minimality of the user interface and reasonable flexibility. The paper includes a complete list of all parameters with examples. The prettyprinter is fairly portable; it consists of a language‐independent back end and a front end that is created by a compiler generator from a formal description of the language to be processed. Currently, Modula‐2 and Pascal versions of the prettyprinter have been implemented. Günther Blaschek, Johannes Sametinger |
Softw. Pract. Exp. | 2 |