Jason Jaskolka

dblp:43/164 · DBLP profile ↗
← Back
34ranked-venue papers
4as first author
24since 2021 · last 2026
0000-0001-6316-3040ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 16 · 1 first-author · 13 since 2021Security and privacy · 5 · 2 since 2021Databases, data management, data science and information retrieval · 5 · 4 since 2021Theory of computation · 5 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 since 2021Computer networks · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 SecMLOps: A comprehensive framework for integrating security throughout the machine learning operations lifecycle
abstract
Machine Learning (ML) has emerged as a pivotal technology in the operation of large and complex systems, driving advancements in fields such as autonomous vehicles, healthcare diagnostics, and financial fraud detection. Despite its benefits, the deployment of ML models brings significant security challenges, such as adversarial attacks, which can compromise the integrity and reliability of these systems. To address these challenges, this paper builds upon the concept of Secure Machine Learning Operations (SecMLOps), providing a comprehensive framework designed to integrate robust security measures throughout the entire ML operations (MLOps) lifecycle. SecMLOps builds on the principles of MLOps by embedding security considerations from the initial design phase through to deployment and continuous monitoring. This framework is particularly focused on safeguarding against sophisticated attacks that target various stages of the MLOps lifecycle, thereby enhancing the resilience and trustworthiness of ML applications. A detailed advanced pedestrian detection system (PDS) use case demonstrates the practical application of SecMLOps in securing critical MLOps. Through extensive empirical evaluations, we highlight the trade-offs between security measures and system performance, providing critical insights into optimizing security without unduly impacting operational efficiency. Our findings underscore the importance of a balanced approach, offering valuable guidance for practitioners on how to achieve an optimal balance between security and performance in ML deployments across various domains.
Xinrui Zhang 0009, Pincan Zhao, Jason Jaskolka, Heng Li 0007, Rongxing Lu
Empir. Softw. Eng.3
2026 Enabling Private Cooperative Sensing Sharing in Vehicular Networks via Encrypted Spatial Matching
abstract
Connected and Autonomous Vehicles (CAVs) equipped with diverse sensors can enhance environmental perception through cooperative sensing, overcoming individual sensor limitations such as restricted range and occlusion. However, privacy concerns regarding location exposure and data leakage significantly hinder widespread adoption. This paper presents a comprehensive privacy-preserving cooperative sensing framework that enables secure data sharing among CAVs without compromising performance. We introduce two key innovations: the Vehicular Spatial Index Tree (VSITree), which provides efficient spatial indexing while preventing location leakage through cryptographic encoding, and the Vehicular Attribute Matching Protocol (VAMP), which enables oblivious membership testing between encrypted sensing data and queries. Our framework leverages arithmetic secret sharing and predicate encryption to protect both sensing providers and requesters throughout the data lifecycle. The system is designed to operate through roadside units (RSUs) that facilitate secure matching and aggregation without learning sensitive information. Theoretical analysis and extensive simulations demonstrate the security and efficiency properties of our approach, confirming its resilience against various attack vectors while maintaining real-time performance suitable for safety-critical vehicular applications.
Xinrui Zhang 0009, Pincan Zhao, Rongxing Lu, Jason Jaskolka, Suprio Ray
IEEE Internet Things J.4
2026 A Scalable Game-Theoretic Approach for Selecting Security Controls from Standardized Catalogues
abstract
Selecting the combination of security controls that will most effectively protect a system's assets is a difficult task. If the wrong controls are selected, the system may be left vulnerable to cyber-attacks that can impact the confidentiality, integrity, and availability of critical data and services. In practical settings, as standardized control catalogues can be quite large, it is not possible to select and implement every control possible. Instead, considerations, such as budget, effectiveness, and dependencies among various controls, must be considered to choose a combination of security controls that best achieve a set of system security objectives. In this paper, we present a game-theoretic approach for selecting effective combinations of security controls based on expected attacker profiles and a set budget. The control selection problem is set up as a two-person zero-sum one-shot game. Valid control combinations for selection are generated using an algebraic formalism to account for dependencies among selected controls. Using a software tool, we apply the approach on a fictional Canadian military system with Canada's standardized control catalogue, ITSG-33. Through this case study, we demonstrate the approach's scalability to assist in selecting an effective set of security controls for large systems. The results illustrate how a security analyst can use the proposed approach and supporting tool to guide and support decision-making in the control selection activity when developing secure systems of all sizes.
Dylan Léveillé, Jason Jaskolka
Log. Methods Comput. Sci.2
2025 A model-driven formal methods approach to software architectural security vulnerabilities specification and verification
Quentin Rouland, Brahim Hamid, Jason Jaskolka
J. Syst. Softw.3
2025 Navigating the DevOps landscape
abstract
DevOps, with its increasing prevalence in both industry and academia, has evolved into various DevOps variants (namely XOps) to address emerging technological and operational challenges. However, this proliferation has created confusion and a lack of clarity about the systematic understanding of these XOps and their interrelationship in the DevOps landscape, leading to fragmented knowledge and application. This research seeks to construct a comprehensive picture of the existing DevOps landscape, clarifying the nature and nuances of various XOps, to guide effective future studies and implementations. Utilizing Multivocal Literature Review (MLR), 80 gathered documents are thoroughly examined from throughout the whole community, encompassing both white and grey literature, to map the DevOps landscape. Our review systematically discovered 38 XOps terms and 13 well-studied XOps including AIOps, BizDevOps, CloudOps, DataOps, DevSecOps, FinOps, GitOps, MLOps, ModelOps, NetDevOps, NoOps, SecDevOps and TwinOps. We provided dictionary-like resource that elucidates the core concepts and main ideas associated with each XOps. An in-depth understanding of intricate evolution from DevOps to XOps is delved into, supplemented by the research of relationships between XOps and various technological enablers as well as relationships between XOps and organizational teams, contributing to the ongoing dialogue surrounding their application and evolution. This paper provides a foundational understanding of the DevOps landscape including open issues and challenges, current and future trends, assisting both researchers and practitioners in navigating this complex field. It establishes a platform for further research and practical applications in the evolving field of DevOps and XOps.
Xinrui Zhang 0009, Pincan Zhao, Jason Jaskolka
J. Syst. Softw.3
2024 Uncovering the DevOps Landscape: A Scoping Review and Conceptualization Framework
abstract
The rapid proliferation of DevOps variants, collectively known as XOps, reflects the growing complexity and specialization within software development and operations. However, the diversity of these practices has led to inconsistencies and confusion, which complicates the development and standardization of the field. While there has been significant research on individual XOps, there is a lack of systematic, horizontal analysis across all XOps practices. This paper addresses this gap by conducting a scoping review of XOps literature, focusing on three fundamental research questions: the definition and categorization of XOps, the methodologies used to study their adoption, and the common challenges identified in their implementation. As the first study to systematically address these questions, we propose the XOps conceptualization framework, offering a structured approach to understanding and studying XOps. This framework serves as an initial step toward bringing clarity to the DevOps landscape, providing guidance in uncovering its complexities and laying the foundation for future research and the emergence of new XOps.
Xinrui Zhang 0009, Jason Jaskolka
APSEC2
2024 Reusable Formal Model Libraries for Specifying and Analyzing Security Objectives in Event-B
Loïc Thierry, Brahim Hamid, Jason Jaskolka
MEDI3
2024 A Tool Support Methodology for Creating Security Cases Using Argument Patterns
Marwa Zeroual, Brahim Hamid, Morayo Adedjouma, Jason Jaskolka
MEDI4
2024 Requirements for Applying SCIA: A Structured Cyberattack Impact Analysis Approach for ICS
abstract
Modern industrial control systems (ICS) are increasingly integrating cyber-physical components to automate industrial processes. Such integration requires a rigorous exploration of how cyberattack impact propagates through an ICS. However, impact analysis approaches for ICS usually assume the use of specific modeling formalisms and tools, limiting their adoption by analysts familiar with potential alternatives. This work clarifies the rationale behind 20 requirements for applying SCIA: a Structured Cyberattack Impact Analysis approach with different modeling and simulation platforms. Based on a manufacturing ICS case study, we demonstrate two distinct applications of SCIA: (1) Application A, based on formal modeling and verification in UPPAAL-SMC, and (2) Application B, based on simulations in MATLAB/Simulink. We show how both applications are effective at visualizing the evolution of attacks and analyzing temporary and sustained impacts on ICS reliability and availability. In doing so, we detail the methodological differences, the extent of requirement satisfaction, and the associated trade-offs.
Alvi Jawad, Zoe Arnott, Jason Jaskolka
QRS3
2024 Enhancing Security and Efficiency in Vehicle-to-Sensor Authentication: A Multi-Factor Approach with Cloud Assistance
abstract
Connected and Autonomous Vehicles (CAVs) can improve their perception by integrating data from roadside sensors. However, ensuring secure authentication between CAVs and sensors is challenging due to the limited capabilities of sensors and the growing number of vehicles. This paper introduces a secure authentication protocol that enables direct communication between CAVs and roadside sensors, addressing a critical gap in existing research focused on vehicle-to-cloud authentication. The proposed multi-factor authentication scheme combines password, biometric, and device-specific factors with Elliptic Curve Cryptography (ECC) and efficient key agreement protocols. A comprehensive adversary model tailored for vehicular networks is presented, along with an in-depth security analysis demonstrating the scheme’s resilience against various threats. The cloud-assisted authentication framework offloads computationally intensive tasks to the cloud server, reducing the burden on resource-constrained Roadside Units (RSUs) and ensuring scalability. Extensive performance evaluations showcase the scheme’s computational efficiency, low communication overhead, and storage costs compared to state-of-the-art solutions, highlighting its practical feasibility and potential for real-world deployment in intelligent transportation systems.
Xinrui Zhang 0009, Pincan Zhao, Jason Jaskolka
TrustCom3
2024 A Formal Approach for Verifying and Validating Security Objectives in Software Architecture
Loïc Thierry, Brahim Hamid, Jason Jaskolka
VECoS3
2024 Formal Security Analysis of Deep Neural Network Architecture
Marwa Zeroual, Brahim Hamid, Morayo Adedjouma, Jason Jaskolka
VECoS4
2023 Specification and Verification of Communication Paradigms for CBSE in Event B
abstract
The development of distributed computing systems and of their usage in domains such as the Internet of Things, Big Data, etc., raises numerous questions on the tools available to model the complexity of such systems. Non-formal modeling methods fail to create a rigorous way to describe and analyze these systems. In this paper, we propose an approach to model and analyze the structural and behavioural aspect of these systems using formal techniques. As a prerequisite, we build reusable model libraries to specify and verify communication paradigms for modeling software architectures of distributed systems in a component-based system engineering (CBSE) context. First, we describe high-level concepts for system architecture in a component-port-connector fashion as a metamodel. Then, we develop an Event-B interpretation of the metamodel adding communication characteristics such as buffering, FIFO and synchronicity. To validate our work, we studied the two well-known communication paradigms, namely message passing and remote procedure call.
Loïc Thierry, Jason Jaskolka, Brahim Hamid, Jean-Paul Bodeveix
ICECCS2
2023 A Formal Metamodel for Software Architectures with Composite Components
James Baak, Quentin Rouland, Jason Jaskolka
MEDI3
2023 Understanding the Role of Human-Related Factors in Security Requirements Elicitation
Sanaa A. Alwidian, Jason Jaskolka
REFSQ2
2022 A Formal Analysis of the Efficacy of Rebooting as a Countermeasure Against IoT Botnets
abstract
The Mirai botnet revolutionized the idea of IoT botnets by infecting numerous vulnerable IoT devices in 2016, leading to the rise of many Mirai variants and imitators that plague the current IoT ecosystem. Studying the botnet infection process can greatly aid us in understanding IoT botnet capabilities and the efficacy of currently available countermeasures. However, analyzing IoT botnets is difficult due to their massive scale and the numerous existing heterogeneous IoT devices that can be targeted for infection. In this paper, we model and simulate the dynamic behavior of a Mirai-like botnet infrastructure and various IoT device categories as a network of timed automata in UPPAAL-SMC. To determine the feasibility of rebooting as a countermeasure against botnets, we examine the effectiveness of rebooting on various IoT device networks. The resulting analysis provides a solid understanding of the efficacy and feasibility of rebooting on active and dormant botnet propagation processes.
Alvi Jawad, Luke Newton, Ashraf Matrawy, Jason Jaskolka
ICC4
2022 Towards the Integration of Human Factors in Collaborative Decision Making for Secure Architecture Design
abstract
Designing a large and complex software system depends not only on the nature of the system itself, but also on human-centric characteristics of the team of architects, developers, and managers involved in the design activity. Each of these team members often comes with varying levels of knowledge, experience, attitudes, and behaviors (i.e., human factors) towards securing systems that impact the decision-making process of the individual team members and of the team as a whole. Thus, these human factors can influence architectural design decisions impacting many different system qualities including security. In this paper, we propose a framework for considering human factors in collaborative decision-making for secure architecture design. At the core of the proposed framework, are conceptual models for security human factors and architectural design decisions. We describe the steps and our preliminary results towards creating the proposed framework using a combination of model-driven engineering techniques and human science approaches. We also provide a simple design scenario to illustrate the envisioned design workflow of the proposed framework. With the proposed framework, we aim to improve our understanding of how decisions are made by a team of diverse members, and to provide better traceability of decisions impacting system security.
Jason Jaskolka, Brahim Hamid
ASE1
2022 Conceptualizing the Secure Machine Learning Operations (SecMLOps) Paradigm
abstract
Due to the proliferation of machine learning in various domains and applications, Machine Learning Operations (MLOps) was created to improve efficiency and adaptability by automating and operationalizing ML products. Because many machine learning application domains demand high levels of assurance, security has become a top priority and necessity to be involved at the beginning of ML system design. To provide theoretical guidance, we first introduce the Secure Machine Learning Operations (SecMLOps) paradigm, which extends MLOps with security considerations. We use the People, Processes, Technology, Governance and Compliance (PPTGC) framework to conceptualize SecMLOps, and to discuss challenges in adopting SecMLOps in practice. Since ML systems are often multi-concerned, analysis on how the adoption of SecMLOps impacts other system qualities, such as fairness, explainability, reliability, safety, and sustainability are provided. This paper aims to provide guidance and a research roadmap for ML researchers and organizational-level practitioners towards secure, reliable, and trustworthy MLOps.
Xinrui Zhang 0009, Jason Jaskolka
QRS2
2022 Towards logical specification of adversarial examples in machine learning
abstract
The use of Artificial Intelligence (AI)-based systems, using particularly Machine Learning (ML) classifiers, is growing rapidly and finding uses in many industries. Most of these industries have critical safety, security, and dependability requirements. Despite this rapid growth, interest in the security of these systems has only arisen in the last few years and it is not yet well-studied. There is a want for a formal notion of security for ML systems, similar to that used in classical information security. We took this statement toward security threat modeling and analysis in ML-based systems, focusing on the adversarial example threat. An adversarial example threat is an input of the classifier that was maliciously modified to induce a misclassification. Identifying this threat at the architecture design stage before proceeding with system development is a critical milestone in the development process of secure ML systems. In this paper, we propose an approach to adversarial example threat specification and detection in component-based software architecture models. We use first-order and modal logic as an abstract and technology-independent formalism. The general idea of the approach is to specify the threat as property of a modeled system such that the violation of the specified property indicates the presence of the threat. We demonstrate the applicability of the method through a classifier used in a recommendation system.
Marwa Zeroual, Brahim Hamid, Morayo Adedjouma, Jason Jaskolka
TrustCom4
2022 A Threat Model and Security Recommendations for IoT Sensors in Connected Vehicle Networks
abstract
Intelligent transportation systems, such as connected vehicles, are able to establish real-time, optimized and collision-free communication with the surrounding ecosystem. Introducing the internet of things (IoT) in connected vehicles relies on deployment of massive scale sensors, actuators, electronic control units (ECUs) and antennas with embedded software and communication technologies. Combined with the lack of designed-in security for sensors and ECUs, this creates challenges for security engineers and architects to identify, understand and analyze threats so that actions can be taken to protect the system assets. This paper proposes a novel STRIDE-based threat model for IoT sensors in connected vehicle networks aimed at addressing these challenges. Using a reference architecture of a connected vehicle, we identify system assets in connected vehicle sub-systems such as devices and peripherals that mostly involve sensors. Moreover, we provide a prioritized set of security recommendations, with consideration to the feasibility and deployment challenges, which enables practical applicability of the developed threat model to help specify security requirements to protect critical assets within the sensor network.
Sajib Kumar Kuri, Tarim Islam, Jason Jaskolka, Mohamed Ibnkahla
VTC Spring3
2022 Architecture for ontology-supported multi-context reasoning systems
Andrew LeClair, Jason Jaskolka, Wendy MacCaull, Ridha Khédri
Data Knowl. Eng.2
2021 Analyzing the Impact of Cyberattacks on Industrial Control Systems using Timed Automata
abstract
Many of today's critical infrastructures, including industrial control systems (ICS), are evolving with the integration of numerous connected cyber components with legacy systems. This evolution has exposed ICSs to a new range of security vulnerabilities and threats, making cybersecurity considerations ever more critical. Understanding how severely malicious cy-berattacks can exploit such system vulnerabilities to disrupt or delay system operations is paramount for developing targeted and effective defenses. In this paper, a timed formal modelbased approach is presented to observe and analyze the manifold impact of various cyberattacks on ICS operations. The analysis is automated using UPPAAL on timed automata models of a target system and potential attackers. Representative tampering and spoofing attacks demonstrated on an illustrative manufacturing cell control system show how classical and statistical model checking, respectively, are effective at analyzing the existence and quantifying the severity of cyberattack impact on ICS mission objectives.
Alvi Jawad, Jason Jaskolka
QRS2
2021 Analyzing Structural Security Posture to Evaluate System Design Decisions
abstract
Software systems are increasing in complexity, with attendant increases in the number of vulnerabilities they contain. Remediating these vulnerabilities, ideally during the early requirements and design phases, has been highly resource-intensive, and is often omitted due to lack of knowledge, time, and/or funds. We propose an approach, applied in these early phases, to address the following issues: 1) to enhance the developer's security knowledge of the system, we introduce the notion of structural security posture, which uses a collection of metrics to assess a system's security based on its structural view, 2) to guide the identification of vulnerabilities, we leverage external security data sources, and 3) to address the issue of resource intensiveness, we offer a tool for evaluating and analyzing a system's structural security posture. We illustrate how our approach facilitates the evaluation of design decisions to improve security using an example.
Joe Samuel, Jason Jaskolka, George Yee
QRS2
2021 Specification, detection, and treatment of STRIDE threats for software components: Modeling, formal methods, and tool support
Quentin Rouland, Brahim Hamid, Jason Jaskolka
J. Syst. Archit.3
2020 Reusable Formal Models for Threat Specification, Detection, and Treatment
Quentin Rouland, Brahim Hamid, Jason Jaskolka
ICSR3
2020 Evaluation of Statistical Tests for Detecting Storage-Based Covert Channels
Thomas A. V. Sattolo, Jason Jaskolka
SEC2
2020 Evaluating the Soundness of Security Metrics from Vulnerability Scoring Frameworks
abstract
Over the years, a number of vulnerability scoring frameworks have been proposed to characterize the severity of known vulnerabilities in software-dependent systems. These frameworks provide security metrics to support decision-making in system development and security evaluation and assurance activities. When used in this context, it is imperative that these security metrics be sound, meaning that they can be consistently measured in a reproducible, objective, and unbiased fashion while providing contextually relevant, actionable information for decision makers. In this paper, we evaluate the soundness of the security metrics obtained via several vulnerability scoring frameworks. The evaluation is based on the Method for Designing Sound Security Metrics (MDSSM). We also present several recommendations to improve vulnerability scoring frameworks to yield more sound security metrics to support the development of secure software-dependent systems.
Joe Samuel, Khalil Aalab, Jason Jaskolka
TrustCom3
2020 Formal specification and verification of reusable communication models for distributed systems architecture
Quentin Rouland, Brahim Hamid, Jason Jaskolka
Future Gener. Comput. Syst.3
2019 Distributed Maintenance of a Spanning Tree of k-Connected Graphs
abstract
This work is devoted to the problem of spanning trees maintenance in the presence of crash failures in a distributed environment using only local knowledge. Using a pre-constructed spanning tree of a k-connected graph, we present a protocol to maintain a spanning tree in the presence of k-1 consecutive failures. The contribution of this paper is threefold. First, the problem is formalized as an occurrence of Menger's theorem in a distributed setting. The second result shows an implementation of the protocol which is composed of a set of modules encoded using a graph relabeling systems model. The last contribution is the implementation of this protocol in the asynchronous message passing model. For a given graph G =(V,E), where M is the number of its edges, N is the number of its nodes, and Δ is its degree; After each failure occurrence, our algorithms need the following requirements: The first one uses O(Δ × N) steps and O(Δ) bits per node. The second one uses O(N+M) messages and O(N) time and O(Δ) bits per node. In addition, we investigate the possible specification and verification of the presented algorithm using Alloy as a tooled formal language.
Brahim Hamid, Quentin Rouland, Jason Jaskolka
PRDC3
2018 Formalizing Reusable Communication Models for Distributed Systems Architecture
Quentin Rouland, Brahim Hamid, Jason Jaskolka
MEDI3
2017 An Approach for Identifying and Analyzing Implicit Interactions in Distributed Systems
abstract
Safety-critical system domains such as critical infrastructures, aerospace, automotive, and industrial manufacturing and control are becoming increasingly dependent on the use of distributed systems to achieve their functionality. These distributed systems can contain many complex interactions among their constituent components. Despite extensive testing and verification of individual components, security vulnerabilities resulting from unintended and unforeseen component interactions (so-called implicit interactions) often remain undetected and can have an impact on the safety, security, and reliability of a system. This paper presents an approach for identifying and analyzing the existence and severity of implicit interactions in distributed systems. The approach is based on the modeling framework known as communicating concurrent Kleene algebra (C2KA). Experimental results confirm that this approach can successfully identify and analyze dependencies in system designs that would otherwise be very hard to find. More broadly, the methods presented in this paper can help address the growing need for rigorous and practical methods and techniques for assuring the safe, secure, and reliable operation of distributed systems in critical domains.
Jason Jaskolka, John D. Villasenor
IEEE Trans. Reliab.1
2016 Mitigating covert channels based on analysis of the potential for communication
Jason Jaskolka, Ridha Khédri
Theor. Comput. Sci.1
2014 Endowing Concurrent Kleene Algebra with Communication Actions
Jason Jaskolka, Ridha Khédri, Qinglei Zhang
RAMiCS1
2012 Verification of Aspectual Composition in Feature-Modeling
Qinglei Zhang, Ridha Khédri, Jason Jaskolka
SEFM3