Gerald Quirchmayr

dblp:41/3170 · DBLP profile ↗
← Back
51ranked-venue papers
5as first author
11since 2021 · last 2025
0000-0003-2998-742XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 22 · 3 first-author · 5 since 2021Databases, data management, data science and information retrieval · 17 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 12 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 11 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 5 · 3 since 2021Human-computer interaction and ubiquitous computing · 1
YearPublicationVenuePosition
2025 A Simulation-Oriented Approach to Securing Logistics Processes Based on the NIST CSF and OODA Loop
Larissa Schachenhofer, Gregor Langner, Gerald Quirchmayr, Philipp Wolf 0001, Patrick Hirsch, Stefan Schauer, Ulrike Lechner, Günter Fahrnberger
I4CS3
2025 Privacy Patterns and Objectives for Legally Compliant Software Based on the Indonesia's PDP Law
Guntur Budi Herwanto, Arif Nurwidyantoro, Annisa Maulida Ningtyas, Muhammad Oriza Nurfajri, Gerald Quirchmayr, A Min Tjoa
iiWAS5
2024 Integrating Contextual Integrity in Privacy Requirements Engineering: A Study Case in Personal E-Health Applications
Guntur Budi Herwanto, Diyah Utami Kusumaning Putri, Annisa Maulida Ningtyas, Anis Fuad, Gerald Quirchmayr, A Min Tjoa
I4CS5
2024 Learning to Rank Privacy Design Patterns: A Semantic Approach to Meeting Privacy Requirements
Guntur Budi Herwanto, Gerald Quirchmayr, A Min Tjoa
REFSQ2
2022 Cyber Exercises in Computer Science Education
Melisa Gafic, Simon Tjoa, Peter Kieseberg, Otto Hellwig, Gerald Quirchmayr
ICISSP5
2022 A Tailored Model for Cyber Security Education Utilizing a Cyber Range
Gregor Langner, Florian Skopik, Steven Furnell, Gerald Quirchmayr
ICISSP4
2022 PrivacyStory: Tool Support for Extracting Privacy Requirements from User Stories
abstract
Privacy by design requires that developers address privacy concerns from the early stage of software development life cycle. It encourages them to take a proactive approach to privacy engineering by identifying personal data, creating conceptual data flow diagrams, and identifying privacy threats. We argue that by providing a tool that automates some of the steps can reduce the burden on development teams. We develop a tool called PrivacyStory, including an end-to-end privacy requirement generation from a set of user stories. The tool provides some automation, utilizing a current state-of-the art natural language processing model. The core aim of our tool is to assist development teams in becoming more agile in their approach to privacy requirements engineering.
Guntur Budi Herwanto, Gerald Quirchmayr, A Min Tjoa
RE2
2022 From User Stories to Data Flow Diagrams for Privacy Awareness: A Research Preview
Guntur Budi Herwanto, Gerald Quirchmayr, A Min Tjoa
REFSQ2
2022 KRYSTAL: Knowledge graph-based framework for tactical attack discovery in audit data
abstract
Attack graph-based methods are a promising approach towards discovering attacks and various techniques have been proposed recently. A key limitation, however, is that approaches developed so far are monolithic in their architecture and heterogeneous in their internal models. The inflexible custom data models of existing prototypes and the implementation of rules in code rather than declarative languages on the one hand make it difficult to combine, extend, and reuse techniques, and on the other hand hinder reuse of security knowledge – including detection rules and threat intelligence. KRYSTAL tackles these challenges by providing a knowledge graph-based, modular framework for threat detection, attack graph and scenario reconstruction, and analysis based on RDF as a standard model for knowledge representation. This approach provides query options that facilitate contextualization over internal and external background knowledge, as well as the integration of multiple detection techniques, including tag propagation, attack signatures, and graph queries. We implemented our framework in an openly available prototype and demonstrate its applicability on multiple scenarios of the DARPA Transparent Computing dataset. Our evaluation shows that the combination of different threat detection techniques within our framework improved detection capabilities. Furthermore, we find that RDF provenance graphs are scalable and can efficiently support a variety of threat detection techniques.
Kabul Kurniawan, Andreas Ekelhart, Elmar Kiesling, Gerald Quirchmayr, A Min Tjoa
Comput. Secur.4
2021 Virtual Knowledge Graphs for Federated Log Analysis
abstract
Security professionals rely extensively on log data to monitor IT infrastructures and investigate potentially malicious activities. Existing systems support these tasks by collecting log messages in a database, from where log events can be queried and correlated. Such centralized approaches are typically based on a relational model and store log messages as plain text, which offers limited flexibility for the representation of heterogeneous log events and the connections between them. A knowledge graph representation can overcome such limitations and enable graph pattern-based log analysis, leveraging semantic relationships between objects that appear in heterogeneous log streams. In this paper, we present a method to dynamically construct such log knowledge graphs at query time, i.e., without a priori parsing, aggregation, processing, and materialization of log data. Specifically, we propose a method that – for a given query formulated in SPARQL – dynamically constructs a virtual log knowledge graph directly from heterogeneous raw log files across multiple hosts and contextualizes the result with internal and external background knowledge. We evaluate the approach across multiple heterogeneous log sources and machines and see encouraging results that indicate that the approach is viable and facilitates ad-hoc graph-analytic queries in federated settings.
Kabul Kurniawan, Andreas Ekelhart, Elmar Kiesling, Dietmar Winkler 0001, Gerald Quirchmayr, A Min Tjoa
ARES5
2021 Poster: The Need for a Collaborative Approach to Cyber Security Education
abstract
Traditional forms of cyber security education mainly focus on knowledge transmission, which means that knowledge is perceived as a tangible object being transferred from an expert (i.e., the teacher) to a beginner. When practiced well, the learner may acquire such knowledge, but not the resilience to apply it in various contexts [1], [2]. This is especially troubling for the cyber security domain, given the dynamic and constantly changing nature of the field and the environments in which it is required. We therefore need forms of education that aim at understanding the interdisciplinary nature of the field of cyber security as well as at the development of joint action in context: being able to quickly analyse and understand evolving and possibly previously unseen situations and take collaborative action to prevent, detect and recover from incidents.
Gregor Langner, Jerry Andriessen, Gerald Quirchmayr, Steven Furnell, Vittorio Scarano, Teemu Tokola
EuroS&P3
2019 Enhancing credibility of digital evidence through provenance-based incident response handling
abstract
Digital forensics are becoming increasingly important for the investigation of computer-related crimes, white-collar crimes and massive hacker attacks. After an incident has been detected an appropriate incident response is usually initiated with the aim to mitigate the attack and ensure the recovery of the IT systems. Digital Forensics pursues the goal of acquiring evidence that will stand up in court for sentencing and sometimes opposes contradicting objectives of incident response approaches. The concept presented here provides a solution to strengthen the credibility of digital evidence during actions related to incident response. It adapts an approach for data provenance to accurately track the transformation of digital evidence. For this purpose, the affected system and the incident response systems are equipped with a whole system data provenance capturing mechanism and then data provenance is captured simultaneously during an incident response. Context information about the incident response is also documented. An adapted algorithm for sub-graph detection is used to identify similarities between two provenance graphs. By applying the proposed concept to a use case, the advantages are demonstrated and possibilities for further development are presented.
Ludwig Englbrecht, Gregor Langner, Günther Pernul, Gerald Quirchmayr
ARES4
2019 A Quantitative Evaluation of Trust in the Quality of Cyber Threat Intelligence Sources
abstract
Threat intelligence sharing has become a cornerstone of cooperative and collaborative cybersecurity. Sources providing such data have become more widespread in recent years, ranging from public entities (driven by legislatorial changes) to commercial companies and open communities that provide threat intelligence in order to help organisations and individuals to better understand and assess the cyber threat landscape putting their systems at risk. Tool support to automatically process this information is emerging concurrently. It has been observed that the quality of information received by the sources varies significantly and that in order to assess the quality of a threat intelligence source it is not sufficient to only consider qualitative indications of the source itself, but it is necessary to monitor the data provided by the source continuously to be able to draw conclusions about the quality of information provided by a source. In this paper, we propose a methodology for evaluating cyber threat information sources based on quantitative parameters. The methodology aims to facilitate trust establishment to threat intelligence sources, based on a weighted evaluation method that allows each entity to adapt it to its own needs and priorities. The approach facilitates automated tools utilising threat intelligence, since information to be considered can be prioritised based on which source is trusted the most at the time the intelligence arrives.
Thomas Schaberreiter, Veronika Kupfersberger, Konstantinos Rantos, Arnolnt Spyros, Alexandros Papanikolaou, Christos Ilioudis, Gerald Quirchmayr
ARES7
2019 Challenges of GDPR and the NIS Directive
Gerald Quirchmayr
ICISSP1
2019 Toward the Ontology-Based Security Verification and Validation Model for the Vehicular Domain
Abdelkader Magdy Shaaban, Christoph Schmittner, Gerald Quirchmayr, A. Baith Mohamed, Thomas Gruber 0004, Erich Schikuta
ICONIP (4)3
2019 Ontology-Based Model for Automotive Security Verification and Validation
abstract
Modern automobiles are considered semi-autonomous vehicles regarding new adaptive technologies. New cars consist of a vast number of electronic units for managing and controlling the functional safety in a vehicle. In the vehicular industry, safety and security are considered two sides for the same coin. Therefore, improving functional safety in the vehicular industry is essential to protect the vehicle from different attack scenarios. This work introduces an ontology-based model for security verification and validation in the vehicular domain. The model performs a series of logical quires and inference rules to ensure that the security requirements are fulfilled. It endeavors to enhance the current security state of a vehicle by selecting additional security requirements that can handle existence security weaknesses and meet the actual security goal.
Abdelkader Magdy Shaaban, Christoph Schmittner, Thomas Gruber 0004, A. Baith Mohamed, Gerald Quirchmayr, Erich Schikuta
iiWAS5
2019 An Improved Quick Artificial Bee Colony Algorithm for Portfolio Selection
abstract
Computation Intelligence has inspired many researchers to develop the capability of computers to learn and solve a complex task in real-world problems. In this work, we propose an Artificial Bee Colony (ABC) to deal with the Stock Selection problem. We apply a Sigmoid-based Discrete-Continuous model with ABC to select appropriate features for stock scoring. The empirical study tests the performance of ABC compared with Genetic Algorithm (GA) and Differential Evolution (DE) algorithm by using data from the Stock Exchange Thailand. The empirical results show that the novel model stock selection significantly outperforms in terms of both investment return, diversity and model robustness.
Dit Suthiwong, Maleerat Sodanil, Gerald Quirchmayr
Int. J. Comput. Intell. Appl.3
2018 A GDPR compliance module for supporting the exchange of information between CERTs
abstract
The goal of the project described in this paper is to describe a GDPR compliance checking model and tool for supporting the information exchange between CERTs. The paper first motivates the project, and then briefly discusses major aspects of GDPR, before presenting the developed model and the implemented prototype. A discussion and an outlook conclude the paper.
Otto Hellwig, Gerald Quirchmayr, Walter Hötzendorfer, Christof Tschohl, Edith Huber, Franz Vock, Florian Nentwich, Bettina Pospisil, Matthias Gusenbauer, Gregor Langner
ARES2
2018 CloudWoT - A Reference Model for Knowledge-based IoT Solutions
abstract
Internet technology has changed how people work, live, communicate, learn and entertain. The internet adoption is rising rapidly, thus creating a new industrial revolution named "Industry 4.0". Industry 4.0 is the use of automation and data transfer in manufacturing technologies. It fosters several technological concepts, one of these is the Internet of Things (IoT). IoT technology is based on a big network of machines, objects, or people called "things" interacting together to achieve a common goal. These things are continuously generating vast amounts of data. Data understanding, processing, securing and storing are significant challenges in the IoT technology which restricts its development. This paper presents a new reference IoT model for future smart IoT solutions called Cloud Web of Things (CloudWoT). CloudWoT aims to overcome these limitations by combining IoT with edge computing, semantic web, and cloud computing. Additionally, this work is concerned with the security issues which threatens data in IoT application domains.
Abdelkader Magdy Shaaban, Christoph Schmittner, Thomas Gruber 0004, A. Baith Mohamed, Gerald Quirchmayr, Erich Schikuta
iiWAS5
2017 Towards a security and privacy protection model for semantic query engines
abstract
The semantic web aims to describe information in terms of well-defined vocabularies and comprehends both data and knowledge to cope with meaning of data. Advanced search engines are used to retrieve precise information out of these knowledge resources. The main challenge is not only retrieving data but also how to keep data safe and protected against any form of attacks.
Abdelkader Magdy, A. Baith Mohamed, Gerald Quirchmayr, Erich Schikuta
iiWAS3
2016 Major Challenges in Structuring and Institutionalizing CERT-Communication
abstract
This paper describes an approach to the definition of requirements for CERT-Communication in a changing environment. CERTs play an outstanding role for the detection, analysis and mitigation of vulnerabilities, threats and cyber-attacks in a multistakeholder cyberspace on which society relies more and more. Furthermore CERTs are a very valuable backbone for national and regional (e.g. European Union) cyber strategies and their role is partly defined in national and European legislation. It can be difficult to bring these obligations in line with the current primarily informal communication channels of CERTs that rely on person to person trust. This paper is devoted to the question of which kind of communication requirements have to be fulfilled to best use and support the work of CERTs in this complex environment.
Otto Hellwig, Gerald Quirchmayr, Edith Huber, Gernot Goluch, Franz Vock, Bettina Pospisil
ARES2
2016 Towards a Complex Systems Approach to Legal and Economic Impact Analysis of Critical Infrastructures
abstract
Information security has become interdependent, global and critical - it has become cybersecurity. In this complex environment, legal consideration and economic incentives are as integral to ensuring the security of information systems as the technological realization. In this paper, we argue that comprehensive cybersecurity requires that these three disciplines are considered together. To this end, we propose a legal analysis framework, which can can be used to study legal and economic requirements for cybersecurity in relation to technological realities. The framework yields concrete recommendations, which complex system and critical infrastructure stakeholders can utilize to improve security within their networks. The analysis framework aims to offer key stakeholders a better understanding of the legal and economic requirements for cybersecurity and provide them with recommendations that are in line with modern cybersecurity strategies, including the enhancement of cooperation and collaboration capabilities and the implementation of other state-of-the-art security mechanisms.
Thomas Schaberreiter, Gerald Quirchmayr, Anna-Maija Juuso, Moussa Ouedraogo, Juha Röning
ARES2
2015 Towards a CERT-Communication Model as Basis to Software Assurance
abstract
This paper describes an approach towards modelling the communication in and between CERTs, of CERTs with their constituents, and of CERTs with other stakeholders and partners. As achieving their sometimes diverging goals is essential for CERTs, an extended goal-scenario model is suggested.
Otto Hellwig, Gerald Quirchmayr, Edith Huber, Timo Mischitz, Markus Huber 0001
ARES2
2013 A Knowledge Transfer Framework for Supporting the Transition to Agile Development of Web Application in the Thai Telecommunications Industry
abstract
Agile software development methods are often applied in volatile software development environments typically perceived as being difficult to tackle by traditional methods. Yet, only a minority of organizations is able to transfer to agile development effectively. This paper proposes a knowledge transfer framework supporting the transition to agile development with guidance on how to put knowledge transfer into action. In this framework, a knowledge transfer process consists of six components (i.e., problems, antecedents, knowledge, mechanisms, knowledge application, and outcomes) and flows through four distinct stages (i.e., Initiation, Implementation, Ramp-up, and Integration). In each stage, components interact with each other multi-directionally and play an important role depending on the stage's functionality. A set of knowledge transfer activities in each stage is also specified which aligns with agile ways, especially Scrum. The description of the application of the developed framework and lessons learned conclude the paper.
Nalinpat Porrawatpreyakorn, Wichian Chutimaskul, Gerald Quirchmayr, Maleerat Sodanil
iiWAS3
2012 A Privacy preserving Approach to Call Detail Records Analysis in VoIP Systems
abstract
Attacks on Voice-over-IP calls happen frequently. A specific type of these attacks are toll-fraud attacks. The prevention of these attacks depends on understanding the attack patterns. These can be derived from communication records. However, these records contain privacy relevant information of the call participants. These records are also protected by a number of laws and regulations. To make an analysis privacy compliant, relevant laws and regulations need to be considered. We propose a method for changing communication records in such a way that the forensic analysis in VoIP attacks is possible and the privacy of the call participants is preserved. We define privacy requirements for communication records from laws, regulations and concerns of call participants. We also present patterns of communication records based upon real world examples. We further show a framework for privacy attack identification and privacy data minimisation for a structured analysis of communication records. Moreover, an analysis pattern for toll-fraud attacks states which relations in the communication records have to survive the data minimisation.
Stefan Hofbauer, Kristian Beckers, Gerald Quirchmayr
ARES3
2012 A Lightweight Privacy Preserving Approach for Analyzing Communication Records to Prevent VoIP Attacks Using Toll Fraud as an Example
abstract
Voice-over-IP systems are quite frequently attacked with the intent of service theft. While VoIP security has been intensively researched in the past, devised solutions often demand significant changes to the VoIP systems. In addition, several solutions propose the filtering of telephone calls, but these solutions only have a limited focus on the privacy rights of the call participants. We propose a method for analyzing communication records with the primary purpose to prevent VoIP attacks. Moreover, our approach integrates with little effort into common VoIP usage scenarios. As an example we use the prevention of toll-fraud attacks as a running example. The analysis of the communication records, however, requires investigating personal information in the communication records, e.g., call habits and phone numbers. Consequently we give an overview of major US and EU laws and regulations to elicit privacy requirements. We also demonstrate how these requirements can be implemented using Comercial-Off-The-Shelf VoIP systems.
Stefan Hofbauer, Kristian Beckers, Gerald Quirchmayr, Christoph Sorge
TrustCom3
2011 CDRAS: An Approach to Dealing with Man-in-the-Middle Attacks in the Context of Voice over IP
abstract
This paper describes the CDRAS (Call Detail Records Analysis System) system, the motivation behind it, its approach and its background. The system aims at dealing with the notorious Man-in-the-Middle attack in the context of VoIP. As the use of such a system constitutes leads to an interference with the privacy of users, the most relevant legal aspects related to this work are also briefly discussed.
Stefan Hofbauer, Gerald Quirchmayr, Christopher C. Wills
ARES2
2011 A Formal Approach Enabling Risk-Aware Business Process Modeling and Simulation
abstract
The effective, efficient and continuous execution of business processes is crucial for meeting entrepreneurial goals. Business process modeling and simulation are used to enable desired business process optimizations. However, current approaches mainly focus on economic aspects while security aspects are dealt with in separate initiatives. This missing interconnection may lead to significant differences in improvement suggestions, such as the differing valuation of security investments (e.g., redundancy of systems). The major contribution of this paper is the introduction of a formal model that is capable of expressing the relations between threats, detection mechanisms, safeguards, recovery measures and their effects on business processes. This novel business process simulation capability paves the way for the evaluation of security investments at process design stage by allowing the consideration of stochastic influences of the occurrence of threats on process activities and resources in a unified way. A stylized business case outlines how our method can be applied to real world scenarios.
Simon Tjoa, Stefan Jakoubi, Gernot Goluch, Gerhard Kitzler, Sigrun Roat, Gerald Quirchmayr
IEEE Trans. Serv. Comput.6
2010 A Prototype for Support of Computer Forensic Analysis Combined with the Expected Knowledge Level of an Attacker to More Efficiently Achieve Investigation Results
abstract
This paper describes a novel approach to combine the strengths of an automated presentation and argumentation support system with a classification of cybercriminals similar to the ones used in law enforcement work. The discussed concept is still in an early stage of development with no substantiated scientific results. The beginning of the paper is dedicated to the description of a prototype based on an automated forensic support system called ¿CFAA¿ (¿Computer Forensic Analyzer and Advisor¿). This description is followed by a short classification of current cybercriminals and their knowledge levels. This classification is a slight modification of the one described in "Scene of the Cybercrime" by Debra Littlejohn Shinder. The paper then continues with the presentation of an envisaged approach towards combining the software tool with the determined classification to increase the efficiency of the forensic analysis. The core aim of this paper is to demonstrate the possible increase of efficiency with adjusting the appropriate cybercriminal levels according to the forensic investigation.
Maximilian Bielecki, Gerald Quirchmayr
ARES2
2010 Natural language processing technologies for developing a language learning environment
abstract
So far, Computer-Assisted Language Learning (CALL) comes in many different flavors. Our research work focuses on developing an integrated e-learning environment that allows improving language skills in specific contexts. Integrated e-learning environment means that it is a Web-based solution that performs language learning tasks using common working environments like, for instance, Web browsers or Email clients. It should be accessible on different platforms, even on mobile devices. Natural Language Processing (NLP) forms the technological basis for developing such a learning framework. The paper gives an overview of the state-of-the-art in this area. Therefore, on the one hand, it explains creation processes for NLP resources and gives an overview of corpora. On the other hand, it describes existing NLP standards. Based on our requirements, the paper gives special attention to the evaluation and comparison of toolkits that can suitably support the planned implementation. An outlook at the end points out necessary developments in e-learning to keep in mind.
Harald Wahl, Werner Winiwarter, Gerald Quirchmayr
iiWAS3
2008 Enhancing Business Impact Analysis and Risk Assessment Applying a Risk-Aware Business Process Modeling and Simulation Methodology
abstract
Driven by the steadily growing number of natural disasters, the threat of terrorist and other criminal attacks as well as changed legislation and regulations, companies are increasingly forced to prepare against threats that endanger the survivability of crucial business activities. As a consequence, management has to pay more attention to business continuity issues including serious management commitment and more appropriate funding. Business impact analysis and risk assessment concepts enable adequate business continuity planning as they deliver essential information about the impact of resources' disruption on business. In this paper we present how these concepts can be enhanced through the application of the ROPE (Risk-Oriented Process Evaluation) methodology enabling risk-aware business process management and simulation. Moreover, we present essential extensions of the ROPE simulation capabilities leading to a more efficient and effective business continuity planning.
Simon Tjoa, Stefan Jakoubi, Gerald Quirchmayr
ARES3
2008 Extension of a Methodology for Risk-Aware Business Process Modeling and Simulation Enabling Process-Oriented Incident Handling Support
abstract
Increasingly, companies face the challenges to perform their business processes effectively as well as efficiently and to simultaneously assure the continuity of these processes. As the majority of companies rely on IT, it is essential to establish effective incident handling. In this paper, we introduce new extensions of the risk-aware business process management framework ROPE (risk-oriented process evaluation) in order to support the improvement of the management and execution of business processes. We further discuss the advantages of those extensions and how they can support the implementation of standards and best-practices such as the NIST SP800-61 (Computer Security Incident Handling Guide).
Simon Tjoa, Stefan Jakoubi, Gernot Goluch, Gerald Quirchmayr
AINA4
2008 A middleware for location-based mobile applications with privacy protection
abstract
Network operators gradually open their interfaces to formerly hidden services. This fosters the development of a new class of mobile applications that take into account context information such as the location of users. However, the development of location-based services also raises the issue of users location-privacy.
Oliver Jorns, Gerald Quirchmayr
iiWAS2
2007 A Privacy Enhancing Service Architecture for Ticket-based Mobile Applications
abstract
Network operators gradually open their interfaces to formerly hidden services. This fosters the development of a new class of mobile applications that take into account user's location and presence information. However, this development also raises problems especially the lack of protection of privacy in location-based services. This paper proposes a service architecture that is aimed at overcoming some of the shortages of currently existing context-aware applications that make use of network providers services as well as existing mobile payment systems. We therefore introduce the combination of tickets together with a novel privacy enhancing mechanism that is based on the notion of pseudonyms. Compared to other privacy enhancing solutions our pseudonym mechanism can also be implemented on mobile devices that have some restrictions regarding resources like memory or processing power. Due to their flexibility tickets can be used for many different kinds of applications. One important aspect in this respect is the highly postulated pay-as-you-go model. We give an example of a transport ticket application and explain the message interaction patterns for the basic functionalities of the systems, regarding aspects like data and privacy protection. This example further shows how 3rd party application providers can build meaningful mobile applications that are accepted by users
Oliver Jorns, Oliver Jung, Gerald Quirchmayr
ARES3
2007 Blended Learning Technology in Information Security Management Courses
abstract
In this paper the author describes the approaches to blending learning he has pursued at the University of Vienna's Institute of Distributed and Multimedia Systems and at the University of South Australia's School of Computer and Information Science in an attempt to supply online students and on campus students with enhanced teaching and learning materials in an Information Security Management course
Gerald Quirchmayr
ARES1
2007 Data Protection and Privacy Laws in the Light of RFID and Emerging Technologies
Gerald Quirchmayr, Christopher C. Wills
TrustBus1
2006 A framework for outsourcing IS/IT security services
abstract
Purpose This paper seeks to provide an overview of the major technical, organizational and legal issues pertaining to the outsourcing of IS/IT security services. Design/methodology/approach The paper uses a combined socio‐technical approach to explore the different aspects of IS/IT security outsourcing and suggests a framework for accommodating security and privacy requirements that arise in outsourcing arrangements. Findings Data protection requirements are a decisive factor for IS/IT security outsourcing, not only because they pose restrictions to management, but also because security and privacy concerns are commonly cited among the most important concerns prohibiting organizations from IS/IT outsourcing. New emerging trends such as outsourcing in third countries, pose significant new issues, with regard to meeting data protection requirements. Originality/value The paper illustrates the reasons for which the outsourcing of IS/IT security needs to be examined under a different perspective from traditional IS/IT outsourcing. It focuses on the specific issue of personal data protection requirements that must be accommodated, according to the European Union directive.
Maria Karyda 0001, Evangelia Mitrou, Gerald Quirchmayr
Inf. Manag. Comput. Secur.3
2003 Through-Walls Communication for Medical Emergency Services
abstract
The authors present a model for bringing the coordination power of workflow management systems to outdoor wearable augmented reality (AR) systems. They portray how mobile equipment may be integrated with adaptive, context-aware work environments. A scenario of a medical emergency task is described to illustrate the functionality of this form of collaboration system. Appropriate information stickers are introduced to support data collection in medical emergency scenarios in a sophisticated form through a hands-free user interface for medical personnel. They propose the use of new user interface technology, including multimedia, AR information stickers, and the allocation of patient medical records to identified locations of the human body. A key feature is the access to relevant information for users in the mobile environment as well as for those in the advanced control room. An additional advantage is the automatic recording of on-site data, which helps to build the medical record of a patient without interfering with the work of the emergency team.
Bruce H. Thomas, Gerald Quirchmayr, Wayne Piekarski
Int. J. Hum. Comput. Interact.2
2002 Establishment of Virtual Enterprise Contracts
Gerald Quirchmayr, Zoran Milosevic, Roger Tagg, James B. Cole, Sachin Kulkarni
DEXA1
2000 Assigning Tasks to Resource Pools: A Fuzzy Set Approach
André de Korvin, Shohreh Hashemi, Gerald Quirchmayr, Robert M. Kleyle
DEXA3
1998 Rule Extraction Using Rough Sets When Membership Values Are Intervals
André de Korvin, Gerald Quirchmayr, Shohreh Hashemi, Robert M. Kleyle
DEXA2
1997 A Meta Message Approach for Electronic Data Interchange (EDI)
Christian Huemer, Gerald Quirchmayr, A Min Tjoa
DEXA2
1996 Process Model Reuse to Promote Organizational Learning in Software Development
abstract
Software development often suffers from well-known problems such as wrong schedules and cost estimations, low productivity, and low product quality. In order to overcome these problems we suggest adapting the concepts of "organizational memory" and "organizational learning" and we argue in favor of establishing a reuse culture of software process models. We introduce an approach based on the process definition/instantiation/enaction paradigm and on the reuse of explicit software process descriptions (process models). The key features of our approach are the division of process descriptions into a goal-oriented process definition document and a formal implementation-oriented process model on the one hand and the use of an artificial neural network, more precisely a self-organizing map, for classification and retrieval purposes on the other. We present an exposition of our approach and discuss the promising results of an experiment in structuring a software process library and retrieving reuse candidates for upcoming projects.
Ernst Ellmer, Dieter Merkl, Gerald Quirchmayr, A Min Tjoa
COMPSAC3
1995 A Fuzzy Model of Managerial Decision Making Incorporating Risk and Ambiguity Aversion
André de Korvin, Gerald Quirchmayr, Shohreh Hashemi
DEXA2
1994 Organizing MLS databases from a data modelling point of view
abstract
The conceptual and logical design of multilevel secure (MLS) database applications are treated in an integrated way. For the conceptual design, a powerful semantic data model is suggested in order to represent the data and security semantics of the application domain. For the logical design, a two-phase approach is developed. Phase one consists of the transformation of the database conceptualization into multilevel relational concepts, while phase two is concerned with integrity management. Enforcing the integrity in MLS databases is known to be a difficult task. Careful data modelling is a necessary prerequisite in order to arrive at consistent and secure MLS applications.>
Günther Pernul, Gerald Quirchmayr
ACSAC2
1994 Managing Structured Documents in Distributed Publishing Environments
Franz Burger, Gerald Quirchmayr, Siegfried Reich, A Min Tjoa
DEXA2
1994 Identifying Precedents under Uncertainty
André de Korvin, Gerald Quirchmayr, Shohreh Hashemi
DEXA2
1994 Tis/mm
Gerald Quirchmayr, Reinhold Schimak
ENTER1
1993 The Application of Kripke-Type Structures to Regional Development Programs
Matthias Baaz, Fernando Galindo, Gerald Quirchmayr, Manuel Vázqez
DEXA3
1991 Making C++ Object Persistent by Using a Standard Relational Database System
Paul Andlinger, Christian Gierlinger, Gerald Quirchmayr
DEXA3
1991 A Formal Model for the Support of Analogical Reasoning in Legal Expert Systems
Matthias Baaz, Gerald Quirchmayr
DEXA2