VLDB 2026 Research / reviewers in the wild / expert
Koen Yskout
dblp:54/5694
· DBLP profile ↗
13ranked-venue papers
4as first author
4since 2021 · last 2026
0000-0002-9192-9100ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 10 · 3 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Multivocal Literature Review on the Effectiveness of Security Threat ModelingabstractThe growing need for integrating security through out the software development lifecycle leads to the adoption of various security activities. Threat modeling is widely recognized as a process that helps assess security issues, especially architectural flaws, due to insecure design, thereby supporting the security-by-design mindset. While many research and industry sources advocate for threat modeling, others highlight issues such as the lack of motivation, its time-consuming nature, and practical difficulties, leading to questions about its overall effectiveness.In this study, we conduct a comprehensive multivocal literature review to systematically examine the empirical evidence for the effectiveness of threat modeling. In short, by analyzing 109 sources from both white and gray literature, we did not encounter any direct, causal evidence (e.g., a controlled experiment) for the effectiveness of threat modeling as a technique to improve the security of a software application. This absence of causal evidence should not be interpreted as evidence that threat modeling is ineffective, though. The existing literature does describe several benefits and challenges related to threat modeling, as well as suggestions for improving the effectiveness of threat modeling activities. Studies on threat modeling often concentrate on benefits such as improved performance, effectiveness, efficiency, and usability of specific tools and methods. Recurring challenges, on the other hand, include a perceived lack of benefits, tool limitations, usability issues, and difficulties integrating threat modeling into the secure software development lifecycle. Suggestions for improvements include providing clear checklists or guidance, defining a clear scope, and involving different stakeholders during threat modeling activities.Based on this review of the literature, researchers are invited to conduct rigorous empirical studies to address the underexplored aspects of threat modeling, thereby strengthening its evidence base and increasing its impact in the real world. Anh-Duy Tran, Stef Verreydt, Koen Yskout, Wouter Joosen |
IEEE Trans. Software Eng. | 3 |
| 2025 | TerrARA: Automated Security Threat Modeling for Infrastructure as CodeabstractThe emergence of DevOps is accompanied by an increased use of Infrastructure as Code (IaC) to specify and manage deployment configurations, infrastructure, and associated resources. Terraform is one such IaC solution. However, improper configurations can lead to serious security threats. This paper introduces an approach, implemented as TerrARA, that provides a systematic and structured way for automatically eliciting security threats based on Terraform configuration files. Specifically, TerrARA: (1) automates the construction of an abstract model-an enriched Data Flow Diagram (DFD)-from Terraform configuration files for Amazon Web Services (AWS), and it can be extended to other resources and cloud providers via profiles; (2) encodes cloud computing threat patterns, which are utilized by the SPARTA threat modeling engine to automatically identify security threats; and (3) demonstrates its capability in accurately extracting DFDs from Terraform projects and eliciting relevant cloud computing security threats, achieving high accuracy and reasonable performance compared to existing tools and approaches like StartLeft and GPT-4o. By integrating it into CI/CD pipelines, the automated reconstruction and analysis enable continuous security assessments that systematically incorporate cloud infrastructure artifacts into the threat modeling process. Anh-Duy Tran, Laurens Sion, Koen Yskout, Wouter Joosen |
CODASPY | 3 |
| 2023 | AndrAS: Automated Attack Surface Extraction for Android ApplicationsabstractThe attack surface of an Android application captures the set of ways in which attackers can penetrate and compromise the application. Determining the attack surface serves multiple purposes, including assessing the security of the application, identifying weak points, and prioritizing mitigation efforts. In practice, determining the attack surface of an application is still a manual effort, and can be time-consuming and error-prone. This paper introduces AndrAS, a tool for automatically extracting the attack surface of an Android app by using static analysis to identify the entry and exit points associated with five different Android artifact types. To illustrate a potential usage scenario, this study shows how an automated threat modeling technique can be driven by the obtained attack surface to generate a threat model for an Android application. The performance of AndrAS is evaluated on 390 popular apps, and its accuracy and effectiveness using two benchmarks and a real-world case study. Anh-Duy Tran, Koen Yskout, Wouter Joosen |
QRS | 2 |
| 2021 | Security and Privacy Requirements for Electronic Consent: A Systematic Literature ReviewabstractElectronic consent (e-consent) has the potential to solve many paper-based consent approaches. Existing approaches, however, face challenges regarding privacy and security. This literature review aims to provide an overview of privacy and security challenges and requirements proposed by papers discussing e-consent implementations, as well as the manner in which state-of-the-art solutions address them. We conducted a systematic literature search using ACM Digital Library, IEEE Xplore, and PubMed Central. We included papers providing comprehensive discussions of one or more technical aspects of e-consent systems. Thirty-one papers met our inclusion criteria. Two distinct topics were identified, the first being discussions of e-consent representations and the second being implementations of e-consent in data sharing systems. The main challenge for e-consent representations is gathering the requirements for a “valid” consent. For the implementation papers, many provided some requirements but none provided a comprehensive overview. Blockchain is identified as a solution to transparency and trust issues in traditional client-server systems, but several challenges hinder it from being applied in practice. E-consent has the potential to grant data subjects control over their data. However, there is no agreed-upon set of security and privacy requirements that must be addressed by an e-consent platform. Therefore, security- and privacy-by-design techniques should be an essential part of the development lifecycle for such a platform. Stef Verreydt, Koen Yskout, Wouter Joosen |
ACM Trans. Comput. Heal. | 2 |
| 2020 | Automating the early detection of security design flawsabstractSecurity by design is a key principle for realizing secure software systems and it is advised to hunt for security flaws from the very early stages of development. At design-time, security analysis is often performed manually by means of either threat modeling or expert-based design inspections. However, when leveraging the wide range of established knowledge bases on security design flaws (e.g., CWE, CAWE), these manual assessments become too time consuming, error-prone, and infeasible in the context of contemporary development practices with frequent iterations. This paper focuses on design inspection and explores the potential for automating the application of inspection rules to speed up the security analysis. Katja Tuma, Laurens Sion, Riccardo Scandariato, Koen Yskout |
MoDELS | 4 |
| 2017 | Design notations for secure software: a systematic literature review
Alexander van Den Berghe, Riccardo Scandariato, Koen Yskout, Wouter Joosen |
Softw. Syst. Model. | 3 |
| 2016 | Towards systematically addressing security variability in software product linesabstractWith the increasingly pervasive role of software in society, security is becoming an important quality concern, emphasizing security by design, but it requires intensive specialization. Laurens Sion, Dimitri Van Landuyt, Koen Yskout, Wouter Joosen |
SPLC | 3 |
| 2015 | MASC: Modelling Architectural Security ConcernsabstractSecurity decisions are an important part of software architecture design, and thus deserve to be explicitly represented in the design documentation. While UML is the best-known language for creating such documentation, it lacks security specific notations, which makes it difficult to represent the effect of the security decisions. Several security extensions for UML exist in the literature, but they represent security concerns at a lower level of abstraction, or only support a limited subset of security concerns. We propose a new notation, MASC, to model security concerns at the architectural level. It has been designed as an extension of UML, and is based on recurring security concepts that have been distilled from well-known security principles, goals, and patterns. By using our notation, a designer obtains a technique to express security concerns more explicitly in the architectural design documentation. Laurens Sion, Koen Yskout, Alexander van Den Berghe, Riccardo Scandariato, Wouter Joosen |
MiSE@ICSE | 2 |
| 2015 | Do Security Patterns Really Help Designers?abstractSecurity patterns are well-known solutions to security-specific problems. They are often claimed to benefit designers without much security expertise. We have performed an empirical study to investigate whether the usage of security patterns by such an audience leads to a more secure design, or to an increased productivity of the designers. Our study involved 32 teams of master students enrolled in a course on software architecture, working on the design of a realistically-sized banking system. Irrespective of whether the teams were using security patterns, we have not been able to detect a difference between the two treatment groups. However, the teams prefer to work with the support of security patterns. Koen Yskout, Riccardo Scandariato, Wouter Joosen |
ICSE (1) | 1 |
| 2015 | SoSPa: A system of Security design Patterns for systematically engineering secure systemsabstractModel-Driven Security (MDS) for secure systems development still has limitations to be more applicable in practice. A recent systematic review of MDS shows that current MDS approaches have not dealt with multiple security concerns systematically. Besides, catalogs of security patterns which can address multiple security concerns have not been applied efficiently. This paper presents an MDS approach based on a unified System of Security design Patterns (SoSPa). In SoSPa, security design patterns are collected, specified as reusable aspect models to form a coherent system of them that guides developers in systematically addressing multiple security concerns. SoSPa consists of not only interrelated security design patterns but also a refinement process towards their application. We applied SoSPa to design the security of crisis management systems. The result shows that multiple security concerns in the case study have been addressed by systematically integrating different security solutions. Phu Hong Nguyen, Koen Yskout, Thomas Heyman, Jacques Klein, Riccardo Scandariato, Yves Le Traon |
MoDELS | 2 |
| 2014 | Change patterns - Co-evolving requirements and architecture
Koen Yskout, Riccardo Scandariato, Wouter Joosen |
Softw. Syst. Model. | 1 |
| 2012 | Does organizing security patterns focus architectural choices?abstractSecurity patterns can be a valuable vehicle to design secure software. Several proposals have been advanced to improve the usability of security patterns. They often describe extra annotations to be included in the pattern documentation. This paper presents an empirical study that validates whether those proposals provide any real benefit for software architects. A controlled experiment has been executed with 90 master students, who have performed several design tasks involving the hardening of a software architecture via security patterns. The results show that annotations produce benefits in terms of a reduced number of alternatives that need to be considered during the selection of a suitable pattern. However, they do not reduce the time spent in the selection process. Koen Yskout, Riccardo Scandariato, Wouter Joosen |
ICSE | 1 |
| 2008 | Transforming Security Requirements into ArchitectureabstractAutomation is a very promising technique to reduce the chances of flaws happening downstream the software production line. In this context, a very challenging problem is the transformation of requirements to software architectures. The challenge is even more crucial for quality requirements, as they represent the main driver of an architecture. This paper is an initial attempt to provide an approach that supports the transition from requirements to architecture for software security: a quality of ever growing importance in today's world. Koen Yskout, Riccardo Scandariato, Bart De Win, Wouter Joosen |
ARES | 1 |