Tiago Gasiba

dblp:81/6719 · also Tiago Espinha Gasiba, Tiago José Espinha de Mendonça Gasiba · DBLP profile ↗
← Back
15ranked-venue papers
5as first author
6since 2021 · last 2024
0000-0003-1462-6701ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 4 · 3 since 2021Security and privacy · 3 · 3 first-author · 1 since 2021Computer networks · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Serious Game for Industrial Cybersecurity: Experiential Learning Through Code Review
abstract
Every stage of the industrial software development process is crucial for ensuring high-quality results in a time of increasing digitalization and complexity. Code review is a method to enhance software quality and also promote knowledge exchange among teams. It is generally accepted that the earlier that software bugs and vulnerabilities are caught during product development, the more costs can be saved. As such, code review can play an important role in industrial software development. However, industry experience showcases that code review can be resource-intensive, and the direct impact on code quality can be hard to quantify. Related work shows that practitioners performing code reviews do not focus specifically on security, partly due to a gap in awareness of the topic. Our research focuses on improving the efficiency and effectiveness of code review practices, particularly in identifying and addressing security issues in an industrial context. The present work showcases results from using a serious game as a means to empower developers, by exhibiting code review best practices and raising awareness of security concerns. We collect results over a series of 11 experiments conducted in an industrial setting together with a total of 175 industrial practitioners, serving as a pilot stage, based on which we discuss and conclude on important aspects of the design of the game.
Andrei-Cristian Iosif, Ulrike Lechner, Maria Pinto-Albuquerque, Tiago Gasiba
CSEE&T4
2024 Thriving in the era of Hybrid Work: Raising Cybersecurity Awareness using Serious Games in Industry Trainings
abstract
Modern software engineering education aims to prepare software engineers for hybrid work environments. The shift to work-from-home (WFH) or work-from-anywhere (WFA) has increased the importance of cybersecurity. An industrial case study revealed that raising awareness is crucial. We developed two serious games, CyberSecurity Challenges (CSC) and Cloud of Assets and Threats (CATS) to enhance cybersecurity training. These games empower practitioners to address hybrid work challenges while ensuring secure software development and cloud security. Empirical evidence supports the effectiveness of serious games in raising awareness among software professionals.
Tiange Zhao, Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque
CSEE&T2
2024 A Deep Dive Into CATS Evaluator Algorithm: Quantification Of The Probability in Serious Game Cloud Security Defense Scenarios
abstract
Cloud deployment has become increasingly common due to its flexibility and business value. However, cloud assets face cybersecurity challenges and need to be configured securely. Industry practitioners must be trained to understand key con-cepts in cloud security, including ‘defense & attack’ and ‘roles & responsibilities.’ A serious game provides an engaging and helpful way to convey such messages. This work introduces the core evaluator algorithm developed for Cloud of Asset and Threats (CATS), a serious game designed to enhance cloud security awareness. This work builds upon our previous efforts, focusing on refining the Evaluator algorithm that quantifies the probabilities of the defender strategies as defined by the players to prevent a given attack vector from being successful. We present the results collected from industry training events where the refined algorithm was incorporated into CATS and compare them to the initial implementation. The promising results indicate that with the refinement of the evaluator algorithm, more elements derived from reality are addressed, and the game maintains a similar difficulty level for participants.
Tiange Zhao, Didem Ongu, Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque
CSEE&T3
2024 COPYCAT: Applying Serious Games in Industry for Defending Supply Chain Attack
Tiange Zhao, Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque, Didem Ongu
I4CS2
2024 Thriving in the era of hybrid work: Raising cybersecurity awareness using serious games in industry trainings
Tiange Zhao, Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque
J. Syst. Softw.2
2021 Raising Security Awareness of Cloud Deployments using Infrastructure as Code through CyberSecurity Challenges
abstract
Improper deployment of software can have serious consequences, ranging from simple downtime to permanent data loss and data breaches. Infrastructure as Code tools serve to streamline delivery by promising consistency and speed, by abstracting away from the underlying actions. However, this simplicity may distract from architectural or configuration faults, potentially compromising the secure development lifecycle. One way to address this issue involves awareness training. Sifu is a platform that provides education on security through serious games, developed in the industry, for the industry. The presented work extends the Sifu platform with challenges addressing Terraform-aided cloud deployment on Amazon Web Services. This paper proposes an evaluation pipeline behind the challenges, and provides details of the vulnerability detection and feedback mechanisms, as well as a novel technique for detecting undesired differences between a given architecture and a target result. Furthermore, this paper quantifies the challenges’ perceived usefulness and impact, by evaluating the challenges among a total of twelve participants. Our preliminary results show that the challenges are suitable for education and the industry, with potential usage in internal training. A key finding is that, although the participants understand the importance of secure coding, their answers indicate that universities leave them unprepared in this area. Finally, our results are compared with related industry works, to extract and provide good practices and advice for practitioners.
Tiago Gasiba, Andrei-Cristian Iosif, Ulrike Lechner, Maria Pinto-Albuquerque
ARES1
2020 Awareness of Secure Coding Guidelines in the Industry - A first data analysis
abstract
Software needs to be secure, in particular, when deployed to critical infrastructures. Secure coding guidelines capture practices in industrial software engineering to ensure the security of code. This study aims to assess the level of awareness of secure coding in industrial software engineering, the skills of software developers to spot weaknesses in software code, avoid them, and the organizational support to adhere to coding guidelines. The approach draws on well-established theories of policy compliance, neutralization theory, and security-related stress and the authors' many years of experience in industrial software engineering and on lessons identified from training secure coding in the industry. The paper presents the questionnaire design for the online survey and the first analysis of data from the pilot study.
Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque, Daniel Méndez 0001
TrustCom1
2020 Sifu - a cybersecurity awareness platform with challenge assessment and intelligent coach
abstract
Abstract Software vulnerabilities, when actively exploited by malicious parties, can lead to catastrophic consequences. Proper handling of software vulnerabilities is essential in the industrial context, particularly when the software is deployed in critical infrastructures. Therefore, several industrial standards mandate secure coding guidelines and industrial software developers’ training, as software quality is a significant contributor to secure software. CyberSecurity Challenges (CSC) form a method that combines serious game techniques with cybersecurity and secure coding guidelines to raise secure coding awareness of software developers in the industry. These cybersecurity awareness events have been used with success in industrial environments. However, until now, these coached events took place on-site. In the present work, we briefly introduce cybersecurity challenges and propose a novel platform that allows these events to take place online. The introduced cybersecurity awareness platform, which the authors call Sifu, performs automatic assessment of challenges in compliance to secure coding guidelines, and uses an artificial intelligence method to provide players with solution-guiding hints. Furthermore, due to its characteristics, the Sifu platform allows for remote (online) learning, in times of social distancing. The CyberSecurity Challenges events based on the Sifu platform were evaluated during four online real-life CSC events. We report on three surveys showing that the Sifu platform’s CSC events are adequate to raise industry software developers awareness on secure coding.
Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque
Cybersecur.1
2019 On the Requirements for Serious Games Geared Towards Software Developers in the Industry
abstract
Teaching industry staff on cybersecurity issues is a fundamental activity that must be undertaken in order to guarantee the delivery of successful and robust products to market. Much research attention has been devoted to this topic over the last years. However, the research which has been done has not focused on developing secure code in industrial environments. In this paper we take a look at the constraints and requirements for delivering a training, by means of cybersecurity challenges, that covers secure coding topics from an industry perspective. Using requirements engineering, we aim at understanding the design requirements for such challenges. Along the way, we give details on our experience of delivering cybersecurity challenges in an industrial setting and show the outcome and lessons learned. The proposed requirements for cybersecurity challenges geared towards software developers in an industrial environment are based on systematic literature review, interviews with security experts from the industry and semi-structured evaluation of participant feedback.
Tiago Gasiba, Kristian Beckers, Santiago Suppan, Filip Rezabek
RE1
2007 Nested harmonic broadcasting for scalable video over mobile datacast channels
abstract
Abstract The integration of reliable Video‐on‐Demand (VoD) broadcasting schemes in mobile datacast systems, specifically in DVB‐H, is studied and enhanced. Sophisticated VoD broadcasting schemes such as Harmonic Broadcasting (HB) allows receivers to tune into the ongoing transmission of a video stream at arbitrary time, while still being able to receive the multimedia sequence from beginning to end, after short initial playout latency. In addition, we address service enhancements by using scalable video coding (SVC) to support heterogeneous receiver capabilities and receiving conditions as well as the reception of the signal from more than on transmission site. We present and discuss options for the integration of VoD broadcasting schemes in combination with fountain codes. Optimizations in parameter selection are discussed. A realistic protocol environment is only slightly modified to support our system concept. Simulation results show the benefits of the discussed VoD scheme compared to existing approaches if integrated in DVB‐H. Copyright © 2007 John Wiley & Sons, Ltd.
Thomas Stockhammer, Tiago Gasiba, Wissam Abdel Samad, Thomas Schierl, Hrvoje Jenkac, Thomas Wiegand 0001, Wen Xu 0001
Wirel. Commun. Mob. Comput.2
2006 System design options for video broadcasting over wireless networks
abstract
Abstract — 3GPP has specified Multimedia Broadcast/Multicast Services (MBMS) addressing the increasing demands of multimedia download and streaming applications in mobile scenarios. Thereby, video coding is an essential component and H.264 is the only recommended video codec in MBMS mainly due to its high compression efficiency and easy network integration. In this paper we introduce the main system design parameters that influence the performance of MBMS video streaming over EG-PRS and UMTS using H.264 encoded streaming. Effective design methodology that includes robustness against packet losses and efficient use of the scarce radio resources is presented. Thereby, care is taken also about the limited processing power of mobile terminals, service delay constraints, and heterogeneous receiving conditions. We also investigate an advanced receiver concept, the so called permeable–layer receiver. Selected simulation results show the suitability of certain parameter settings as well as the benefits provided by the advanced receiver concept. I.
Junaid Afzal, Thomas Stockhammer, Tiago Gasiba, Wen Xu 0001
CCNC3
2006 Raptor codes for reliable download delivery in wireless broadcast systems
abstract
In this work we address reliablefile delivery over mobile broadcast networks, concentrating on the Raptor codes as specified for Multimedia Broadcast/Multicast Services (MBMS) within 3GPP. We start by describing Luby-Transform (LT) codes, which are the first practical fountain codes. Then, using a natural and easy to understand linear algebra notation, we describe Raptor codes as a powerful extension of LT codes. We provide some insight into the Raptor code structure and some guidelines for implementation of encoders and decoders. Finally, some selected simulations verify the good performance of file distribution with Raptor codes as specified in 3GPP. References to a complete set of simulation results are also provided. I. INTRODUCTION
Michael Luby, Mark Watson, Tiago Gasiba, Thomas Stockhammer, Wen Xu 0001
CCNC3
2006 System Design and Advanced Receiver Techniques for MBMS Broadcast Services
abstract
Raptor codes have been recently standardized by 3GPP to be used in the application layer. These codes are very efficient and perform sufficiently close to the so-called ideal fountain code on the block-erasure channel. However, for real applications, a simple receiver enhancement called permeable layer receiver can be done, which provides huge performance gains. Standard Raptor decoding algorithms have to be revised and new efficient decoding algorithms need to be introduced. In this work we present a practical and efficient implementation of the Raptor decoder for permeable layer receiver. We show that, not only we achieve huge performance gains, but we achieve them at an affordable (low) decoding complexity. Complexity and decoding performance simulation results are presented for the download delivery and video broadcasting.
Tiago Gasiba, Thomas Stockhammer, Junaid Afzal, Wen Xu 0001
ICC1
2006 Mobile data broadcasting over MBMS tradeoffs in forward error correction
abstract
Third Generation Partnership Project (3GPP) and Digital Video Broadcasting (DVB) have just recently specified the use Raptor codes in their mobile broadcast file delivery engine. Until today, investigations of the applicability of these codes to the mentioned systems have been carried out by assuming almost exclusively quite simple loss models such as statistically independent radio packet losses. Furthermore, the combination and tradeoffs between physical layer parameters such as transmit power or physical layer for-ward error correction code rates in system design has been completely ignored. In this work we investigate the end-to-end system performance by analyzing the trade-off between physical layer parameters and application layer code. In particular we are interested in determining the optimal system operating points for optimized broadcast file delivery. Parameters such as power allocation, mobility model, physical layer Turbo code rate, raptor code expansion ratio are investigated and a single performance criteria is defined, namely the required energy to deliver a file to at least some high percentage of users. It is shown that typically considered system configurations with high transmit power and low physical layer code rates - resulting in low radio block loss rates - are in general suboptimal for efficient delivery. A careful tradeoff the system parameters can reduce the required resources in the order of a magnitude.
Michael Luby, Mark Watson, Tiago Gasiba, Thomas Stockhammer
MUM3
2005 Iterative decoding for GERAN MBMS
abstract
Various advanced methods have been proposed to achieve sufficiently high throughput as well as reliability for multimedia broadcast multicast services (MBMS) within 3GPP RAN and GERAN. One of the methods which yield promising results with only marginal system modifications is based on outer Reed-Solomon (RS) coding on the radio link control (RLC) layer. For initial studies standard decoding algorithms based on erasure-only decoders have been employed. In order to further improve the performance, the system can be viewed as a serially concatenated code such that iterative decoding can be performed. Then, advanced receivers for MBMS over GERAN would incorporate soft-in soft-cut (SISO) decoders for both the inner convolutional code, as well as the outer RS code. Whereas for the convolutional code, standard SISO algorithms are applied, for the outer RS code a standard Berlekamp-Massey algorithm is modified to accept soft-input and to provide soft-output. With this modified iterative decoding strategy, simulations have shown gains of up to 14% in throughput on typical mobile radio channels.
Wen Xu 0001, Tiago Gasiba, Thomas Stockhammer, Hrvoje Jenkac, Günther Liebl
PIMRC2