Bernhard J. Berger

dblp:60/5189 · also Bernhard Johannes Berger · DBLP profile ↗
← Back
17ranked-venue papers
6as first author
10since 2021 · last 2025
0000-0001-6093-9229ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 8 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 5 · 1 first-author · 5 since 2021Security and privacy · 4 · 2 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Leveraging the Benefits of Information Flow Tracking for Detecting Hardware Design Flaws
abstract
Hardware design weaknesses, when overlooked, can lead to security vulnerabilities. Their cost of fixing is higher the later they are found in the development life cycle. The challenges of detecting these issues in the early stages of hardware design, compared to software design, can be attributed to limited research or poorly defined design guidelines. Using the existing hardware design weakness classification by the MITRE Corporation, we evaluated how Information Flow Tracking (IFT) can be utilized to identify security weaknesses in hardware designs. First, we provide a classification of design weaknesses tailored to detection using IFT. Second, we present a case study to identify one of such weaknesses using an open-source IFT tool. Additionally, we discuss the challenges of using IFT to detect information-flow-based hardware design weaknesses.
Srinidhi Rathnakar Ganiga, Bernhard J. Berger, Görschwin Fey
FDL2
2025 Automatic security-flaw detection - towards a fair evaluation and comparison
abstract
Abstract Threat Modeling is an essential step in secure software system development. It is a (so far) manual, attacker-centric approach for identifying architecture-level security flaws during the planning phase of software systems. In recent years, academia has presented ideas to automate threat detection that do not focus on a particular class of security flaws but offer means of pattern-based security flaw descriptions. However, comparing presented ideas (tools) for automated threat detection contains the potential for unwilling bias or restricted information content. In this work, we investigate the process of comparing automatic security flaw detection tools, clarify common pitfalls during this process, and propose a fair, reproducible, and informative comparison approach to be used as a community standard. We additionally discuss the necessary steps for the community to effectively implement this approach and support improved comparisons and evaluations in the future. We use a previously published case study to determine problems with current comparison techniques and classify different levels of comparison to be used for future reference as our main contribution. As a consequence, we propose using a model-based approach for specifying security flaws and apply an existing natural language-based catalogue to this model-based approach. Furthermore, we introduce an inspection process model (for providing a standard to specify findings of a threat detection process) to streamline the evaluation and comparisons of automatic security flaw detection tools. We provide an exemplary evaluation of this detection guideline and inspection process model along the lines of both automatic approaches from the original case study. All artefacts of the work are publicly available to support the research community and to create a common baseline for future tool comparisons.
Bernhard J. Berger, Christina Plump
Softw. Syst. Model.1
2024 Finding the perfect MRI sequence for your patient - Towards an optimisation workflow for MRI-sequences
abstract
Magnetic Resonance Imaging (MRI) is an essential tool for medical diagnosis. At the same time, its usage requires profound expert knowledge to determine the ideal MR sequence and protocol to be run. Until now, the contrast and quality of the resulting image have relied mainly on the radiologist's expertise. When confronted with clinical requirements and patient information, the radiologist chooses suitable sequence protocols for the examination. We propose a workflow that supports medical personnel in finding the optimal sequence for a given diagnostic task. To that end, we combine evolutionary algorithms for the optimisation, machine learning techniques for training a surrogate optimisation function from simulated MRI data, and domain-specific languages to allow non-programmers to formulate their requirements and constraints semi-formally. In this paper, we focus on the efficient usage of real-world application-motivated adaptions of the used evolutionary algorithm and evaluate their effects on four real-life sequence examples. We show that it is essential to use an adaption for the surrogate model to obtain realistic solutions and use correlation information about the search space to stay in feasible areas of the search space and thus improve optimisation quality. These findings are a first step in automating the entire MRI-sequence optimisation flow, which is necessary to allow a more widespread usage of this essential medical diagnostic technique.
Christina Plump, Daniel Christopher Hoinkiss, Jörn Huber, Bernhard J. Berger, Matthias Günther, Christoph Lüth, Rolf Drechsler
CEC4
2023 EVOAL: A Domain-Specific Language-Based Approach to Optimisation
abstract
Adapting optimisation algorithms, such as evolutionary algorithms, to a problem is a necessity. The required collection and exchange of domain information is an important but tedious task in real-world projects involving several experts from different areas of expertise (e.g. the domain and the optimisation area). This paper presents a structured approach that allows the experts to systematically provide their knowledge using domain-specific languages. The presented approach defines a different language for the involved experts that enables them to add their knowledge and use the information provided by other experts. The languages are extensible, allowing the addition of new optimisation aspects without changing the actual language. These languages are the front-end to a versatile open-source optimisation tool, that we built, enabling the actual execution of the optimisation. It additionally provides features for surrogate models as well as data generation and different benchmarks for evaluation. Conducting a user study, we show that the language is suitable to express the domain knowledge and domain experts can use the language to describe their domain knowledge after a short introduction. This way, the approach reduces the effort for domain experts in providing their information. As a side effect, the complete configuration of the optimisation execution through these languages allows an easy and reliable reproduction.
Bernhard J. Berger, Christina Plump, Rolf Drechsler
CEC1
2023 Machine Learning for SAST: A Lightweight and Adaptable Approach
Lorenz Hüther, Karsten Sohr, Bernhard J. Berger, Hendrik Rothe, Stefan Edelkamp
ESORICS (4)3
2023 Hybrid PTX Analysis for GPU accelerated CNN inferencing aiding Computer Architecture Design
abstract
General-Purpose Computation on Graphics Processing Units (GPGPUs) are becoming crucial in accelerating computing capacity. Due to the massive parallelism capabilities of GPUs, they can achieve impressive speedups of up to 32 times compared to common CPUs. However, writing highly parallel code and utilizing a GPU is challenging for programmers. Developers are facing new challenges since GPUs handle threads and parallelism differently from CPUs. Academia and industry proposed several profilers to support developers in terms of code optimization. These profilers often require an actual device (e.g., GPU) and take a long time for the profiling process. We propose HyPA, a hybrid Parallel Thread Execution (PTX) Analyzer that inspects PTX code statically and dynamically. HyPA implements a partly functional emulator that executes instructions that rely on runtime dependencies to count the number of executed PTX instructions and divergent branches. HyPa executes compiled kernels—the programs that run on GPUs—generated by the CUDA compiler and supports the full PTX 7.7 specification. Our functional emulator allows significantly faster analysis of PTX code compared to standard profilers. In our evaluation, we quantify this increase in performance through benchmark runs. HyPA achieved speedups of up to 536% compared to the nvprof profiler. Moreover, our approach can gather performance metrics beyond static analysis (e.g., branch efficiency) by a faster execution time than by profiling the application on an actual device. Finally, we provide an open-source implementation of HyPA to help developers and system designers in further research and development.
Christopher A. Metz, Christina Plump, Bernhard J. Berger, Rolf Drechsler
FDL3
2022 Using density of training data to improve evolutionary algorithms with approximative fitness functions
abstract
Evolutionary algorithms are a well-known optimisation technique, especially for non-convex, multi-modal optimisation problems. Their capability of adjusting to different search spaces and tasks by choosing the suitable encoding and operators has led to their widespread use in various application domains. However, application domains sometimes come with difficulties like fitness functions that can not be evaluated or not more than a few times. In these situations, surrogate functions or approximative fitness functions allow the evolutionary algorithm to work despite this complication. Still, using approximative fitness functions comes with a price: The fitness value is no longer correct for every individual, and the algorithm can not know which value to trust. However, statistical methods yield knowledge about the preciseness of the approximation. We propose using this knowledge to adapt the fitness value to ease the effects of the approximative nature. We choose to use the information given in the density of the training data, which has computational merits over the use of other techniques like cross-validation or prediction intervals. We evaluate our method on four well-known benchmark functions and achieve good optimisation success and computation time results.
Christina Plump, Bernhard J. Berger, Rolf Drechsler
CEC2
2021 Improving Evolutionary Algorithms by Enhancing an Approximative Fitness Function through Prediction Intervals
abstract
Evolutionary algorithms are a successful application of bio-inspired behaviour in the field of Artificial Intelligence. Transferring mechanisms such as selection, mutation, and recombination, evolutionary algorithms are capable of surmounting the disadvantages of traditional methods. Adjusting an evolutionary algorithm to a specific problem requires both, a good understanding of the problem and deep knowledge of the effects of choosing one or another operator in the algorithm. This becomes an especially difficult task when the fitness function is not analytically given - that is, exists only as an approximation, that is highly dependent on the present training data. We propose using prediction intervals to modify the fitness function such, that worse fitness values are less penalized if they occur in a poorly fitted area. We evaluate this with an example from material sciences as well as four standard benchmark algorithms for evolutionary algorithms using a Support Vector Regression for training the approximative fitness function and find that our approach outperforms the naive approximative function.
Christina Plump, Bernhard J. Berger, Rolf Drechsler
CEC2
2021 Domain-driven Correlation-aware Recombination and Mutation Operators for Complex Real-world Applications
abstract
Evolutionary algorithms are a very general method for optimization problems that allow adaption to many different use cases. Application to real-world problems usually comes with features as constraints, dependencies and approximations. When a multidimensional search space comes with strings attached- namely dependencies between its dimensions- an expression in two ways is possible: Restrictive-as equalities or inequalities- or vague-as correlations between dimensions, for example. Correlations between dimensions are not as easy to grasp as constraints. Therefore, well-known techniques as death penalty or penalty functions do not apply directly. We propose new mutation and recombination operators that incorporate domain knowledge to increase the offspring fraction that adheres to these correlations. We evaluate our approach with several benchmark functions and different assumptions on the dependencies of the search space. We compare the likelihood of valid (in terms of adhering correlations) outcomes of algorithms using standard mutation and recombination operators to those with the proposed operators. We find that the correlation-aware operators preserve population's features in terms of dependencies.
Christina Plump, Bernhard J. Berger, Rolf Drechsler
CEC2
2021 [Engineering] eNYPD - Entry Points Detector Jakarta Server Faces Use Case
abstract
Which parts of a software system can be accessed by an attacker is a common question in software security. The answer to this question defines where to look for input validation vulnerabilities, which parts of a system to respect during Microsoft’s Threat Modeling, or how to calculate security metrics. Identifying entry points of an application is, therefore, a frequently occurring problem. Additionally, identifying entry points is relevant when analysing many framework-based applications since they no longer have a simple main method.While different analyses implement entry point detection, the presented tool eNYPD explicitly focuses on answering this question for Java-based systems in an analysis-independent manner. It extracts information on entry points statically and persists this information to a separate file. Therefore, it allows reusing the information in different analyses, and researchers do not need to implement a custom entry point detection for each analysis.The presented tool is explained using Jakarta Server Faces, a user-interface technology for Web-based business applications implemented using Java. The paper presents the implemented extraction approach, the internal data model, and the results stored. Finally, in an evaluation, the statically assessed results of eNYPD are compared to a dynamically determined set of entry points. This comparison allows us to demonstrate the correctness of the extracted information.
Rodrigue Wete Nguempnang, Bernhard J. Berger, Karsten Sohr
SCAM2
2020 Static Extraction of Enforced Authorization Policies SeeAuthz
abstract
Authorization is an intrinsic part of a software's security. Determining whether a user is allowed to access a resource or not is crucial, not only in safety-critical applications but also in everyday applications to prevent misuse of data or software. There is plenty of research dealing with validating and verifying authorization policies in the security community. Still, an implemented authorization policy does not necessarily match the planned authorization policy, i.e., even a validated and verified authorization policy can pose security issues when implemented incorrectly. This gap between planned and implemented authorization policy poses the risk of unauthorized access to sensitive resources due to insufficient authorization checks. Therefore, it is essential to ensure a system's security to validate the implemented authorization policy against the planned one. We, therefore, describe the authorization pattern and present an algorithm to extract authorization graphs from implemented authorization policies, which can then be used to compare against the planned authorization policy. To that end, we developed a configurable context-sensitive analysis tailored to Java-based software systems, where the context is the authorization facts that hold on each point. Using a configuration for Apache Shiro, a security library that supports authorization, we evaluated our implementation using an open-source repository system for the management and dissemination of digital content and a closed-source manufacturing execution system. We discuss additional usage scenarios of the analysis results and describe how to transfer the approach to other authorization policies and programming languages.
Bernhard J. Berger, Rodrigue Wete Nguempnang, Karsten Sohr, Rainer Koschke
SCAM1
2019 Towards Effective Verification of Multi-Model Access Control Properties
abstract
Many existing software systems like logistics systems or enterprise applications employ data security in a more or less ad hoc fashion. Our approach focuses on access control such as permission-based discretionary access control (DAC), variants of role-based access control (RBAC) with delegation, and attribute-based access control (ABAC). Typically, software systems implement hybrid access control making an effective security analysis and assessment rather difficult.
Bernhard J. Berger, Christian Maeder, Rodrigue Wete Nguempnang, Karsten Sohr, Carlos E. Rubio-Medrano
SACMAT1
2019 The Architectural Security Tool Suite - ARCHSEC
abstract
Architectural risk analysis is a risk management process for identifying security flaws at the level of software architectures and is used by large software vendors, to secure their products. We present our architectural security environ- ment (ARCHSEC) that has been developed at our institute during the past eight years in several research projects. ARCHSEC aims to simplify architectural risk analysis, making it easier for small and mid-sized companies to get started. With ARCHSEC, it is possible to graphically model or to reverse engineer software security architectures. The regained software architectures can then be inspected manually or au- tomatically analyzed w.r.t. security flaws, resulting in a threat model, which serves as a base for discussion between software and security experts to improve the overall security of the software system in question, beyond the level of implementation bugs. In the evaluation part of this paper, we demonstrate how we use ARCHSEC in two of our current research projects to analyze business applications. In the first project we use ARCHSEC to identify security flaws in business process diagrams. In the second project, ARCHSEC is integrated into an audit environment for software security certification. ARCHSEC is used to identify security flaws and to visualize software systems to improve the effectiveness and efficiency of the certification process.
Bernhard J. Berger, Karsten Sohr, Rainer Koschke
SCAM1
2018 [Engineering Paper] Built-in Clone Detection in Meta Languages
abstract
Developers often practice re-use by copying and pasting code. Copied and pasted code is also known as clones. Clones may be found in all programming languages. Automated clone detection may help to detect clones in order to support software maintenance and language design. Syntax-based clone detectors find similar syntax subtrees and, hence, are guaranteed to yield only syntactic clones. They are also known to have high precision and good recall. Developing a syntax-based clone detector for each language from scratch may be an expensive task. In this paper, we explore the idea to integrate syntax-based clone detection into workbenches for language engineering. Such workbenches allow developers to create their own domain-specific language or to create parsers for existing languages. With the integration of clone detection into these workbenches, a clone detector comes as a free byproduct of the grammar specification. The effort is spent only once for the workbench and not multiple times for every language built with the workbench. We report our lessons learned in applying this idea for three language workbenches: the popular parser generator ANTLR and two language workbenches for domain-specific languages, namely, MPS, developed by JetBrains, and Xtext, which is based on the Eclipse Modeling Framework.
Rainer Koschke, Urs-Bjorn Schmidt, Bernhard J. Berger
SCAM3
2015 Taint analysis of manual service compositions using Cross-Application Call Graphs
abstract
We propose an extension over the traditional call graph to incorporate edges representing control flow between web services, named the Cross-Application Call Graph (CACG). We introduce a construction algorithm for applications built on the Jax-WS standard and validate its effectiveness on sample applications from Apache CXF and JBossWS. Then, we demonstrate its applicability for taint analysis over a sample application of our making. Our CACG construction algorithm accurately identifies service call targets 81.07% of the time on average. Our taint analysis obtains a F-Measure of 95.60% over a benchmark. The use of a CACG, compared to a naive approach, improves the F-Measure of a taint analysis from 66.67% to 100.00% for our sample application.
Marc-André Laverdière, Bernhard J. Berger, Ettore Merlo
SANER2
2013 The Transitivity-of-Trust Problem in Android Application Interaction
abstract
Mobile phones have developed into complex platforms with large numbers of installed applications and a wide range of sensitive data. Application security policies limit the permissions of each installed application. As applications may interact, restricting single applications may create a false sense of security for end users, while data may still leave the mobile phone through other applications. Instead, the information flow needs to be policed for the composite system of applications in a transparent manner. In this paper, we propose to employ static analysis, based on the software architecture and focused on data-flow analysis, to detect information flows between components. Specifically, we aim to reveal transitivity-of-trust problems in multi-component mobile platforms. We demonstrate the feasibility of our approach with two Android applications.
Steffen Bartsch, Bernhard J. Berger, Michaela Bunke, Karsten Sohr
ARES2
2012 An Approach to Detecting Inter-Session Data Flow Induced by Object Pooling
Bernhard J. Berger, Karsten Sohr
SEC1