Maria Pinto-Albuquerque

dblp:85/4416 · DBLP profile ↗
← Back
14ranked-venue papers
1as first author
7since 2021 · last 2025
0000-0002-2725-7629ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 since 2021Security and privacy · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
YearPublicationVenuePosition
2025 Bring Your Own Bug: Enabling User-Generated Content in Serious Games for Industrial Cybersecurity and AppSec Education
Andrei-Cristian Iosif, Ulrike Lechner, Maria Pinto-Albuquerque
I4CS3
2024 Serious Game for Industrial Cybersecurity: Experiential Learning Through Code Review
abstract
Every stage of the industrial software development process is crucial for ensuring high-quality results in a time of increasing digitalization and complexity. Code review is a method to enhance software quality and also promote knowledge exchange among teams. It is generally accepted that the earlier that software bugs and vulnerabilities are caught during product development, the more costs can be saved. As such, code review can play an important role in industrial software development. However, industry experience showcases that code review can be resource-intensive, and the direct impact on code quality can be hard to quantify. Related work shows that practitioners performing code reviews do not focus specifically on security, partly due to a gap in awareness of the topic. Our research focuses on improving the efficiency and effectiveness of code review practices, particularly in identifying and addressing security issues in an industrial context. The present work showcases results from using a serious game as a means to empower developers, by exhibiting code review best practices and raising awareness of security concerns. We collect results over a series of 11 experiments conducted in an industrial setting together with a total of 175 industrial practitioners, serving as a pilot stage, based on which we discuss and conclude on important aspects of the design of the game.
Andrei-Cristian Iosif, Ulrike Lechner, Maria Pinto-Albuquerque, Tiago Gasiba
CSEE&T3
2024 Thriving in the era of Hybrid Work: Raising Cybersecurity Awareness using Serious Games in Industry Trainings
abstract
Modern software engineering education aims to prepare software engineers for hybrid work environments. The shift to work-from-home (WFH) or work-from-anywhere (WFA) has increased the importance of cybersecurity. An industrial case study revealed that raising awareness is crucial. We developed two serious games, CyberSecurity Challenges (CSC) and Cloud of Assets and Threats (CATS) to enhance cybersecurity training. These games empower practitioners to address hybrid work challenges while ensuring secure software development and cloud security. Empirical evidence supports the effectiveness of serious games in raising awareness among software professionals.
Tiange Zhao, Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque
CSEE&T4
2024 A Deep Dive Into CATS Evaluator Algorithm: Quantification Of The Probability in Serious Game Cloud Security Defense Scenarios
abstract
Cloud deployment has become increasingly common due to its flexibility and business value. However, cloud assets face cybersecurity challenges and need to be configured securely. Industry practitioners must be trained to understand key con-cepts in cloud security, including ‘defense & attack’ and ‘roles & responsibilities.’ A serious game provides an engaging and helpful way to convey such messages. This work introduces the core evaluator algorithm developed for Cloud of Asset and Threats (CATS), a serious game designed to enhance cloud security awareness. This work builds upon our previous efforts, focusing on refining the Evaluator algorithm that quantifies the probabilities of the defender strategies as defined by the players to prevent a given attack vector from being successful. We present the results collected from industry training events where the refined algorithm was incorporated into CATS and compare them to the initial implementation. The promising results indicate that with the refinement of the evaluator algorithm, more elements derived from reality are addressed, and the game maintains a similar difficulty level for participants.
Tiange Zhao, Didem Ongu, Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque
CSEE&T5
2024 COPYCAT: Applying Serious Games in Industry for Defending Supply Chain Attack
Tiange Zhao, Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque, Didem Ongu
I4CS4
2024 Thriving in the era of hybrid work: Raising cybersecurity awareness using serious games in industry trainings
Tiange Zhao, Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque
J. Syst. Softw.4
2021 Raising Security Awareness of Cloud Deployments using Infrastructure as Code through CyberSecurity Challenges
abstract
Improper deployment of software can have serious consequences, ranging from simple downtime to permanent data loss and data breaches. Infrastructure as Code tools serve to streamline delivery by promising consistency and speed, by abstracting away from the underlying actions. However, this simplicity may distract from architectural or configuration faults, potentially compromising the secure development lifecycle. One way to address this issue involves awareness training. Sifu is a platform that provides education on security through serious games, developed in the industry, for the industry. The presented work extends the Sifu platform with challenges addressing Terraform-aided cloud deployment on Amazon Web Services. This paper proposes an evaluation pipeline behind the challenges, and provides details of the vulnerability detection and feedback mechanisms, as well as a novel technique for detecting undesired differences between a given architecture and a target result. Furthermore, this paper quantifies the challenges’ perceived usefulness and impact, by evaluating the challenges among a total of twelve participants. Our preliminary results show that the challenges are suitable for education and the industry, with potential usage in internal training. A key finding is that, although the participants understand the importance of secure coding, their answers indicate that universities leave them unprepared in this area. Finally, our results are compared with related industry works, to extract and provide good practices and advice for practitioners.
Tiago Gasiba, Andrei-Cristian Iosif, Ulrike Lechner, Maria Pinto-Albuquerque
ARES4
2020 Integration of Security Standards in DevOps Pipelines: An Industry Case Study
Fabiola Moyón, Rafael Soares, Maria Pinto-Albuquerque, Daniel Méndez 0001, Kristian Beckers
PROFES3
2020 Awareness of Secure Coding Guidelines in the Industry - A first data analysis
abstract
Software needs to be secure, in particular, when deployed to critical infrastructures. Secure coding guidelines capture practices in industrial software engineering to ensure the security of code. This study aims to assess the level of awareness of secure coding in industrial software engineering, the skills of software developers to spot weaknesses in software code, avoid them, and the organizational support to adhere to coding guidelines. The approach draws on well-established theories of policy compliance, neutralization theory, and security-related stress and the authors' many years of experience in industrial software engineering and on lessons identified from training secure coding in the industry. The paper presents the questionnaire design for the online survey and the first analysis of data from the pilot study.
Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque, Daniel Méndez 0001
TrustCom3
2020 Sifu - a cybersecurity awareness platform with challenge assessment and intelligent coach
abstract
Abstract Software vulnerabilities, when actively exploited by malicious parties, can lead to catastrophic consequences. Proper handling of software vulnerabilities is essential in the industrial context, particularly when the software is deployed in critical infrastructures. Therefore, several industrial standards mandate secure coding guidelines and industrial software developers’ training, as software quality is a significant contributor to secure software. CyberSecurity Challenges (CSC) form a method that combines serious game techniques with cybersecurity and secure coding guidelines to raise secure coding awareness of software developers in the industry. These cybersecurity awareness events have been used with success in industrial environments. However, until now, these coached events took place on-site. In the present work, we briefly introduce cybersecurity challenges and propose a novel platform that allows these events to take place online. The introduced cybersecurity awareness platform, which the authors call Sifu, performs automatic assessment of challenges in compliance to secure coding guidelines, and uses an artificial intelligence method to provide players with solution-guiding hints. Furthermore, due to its characteristics, the Sifu platform allows for remote (online) learning, in times of social distancing. The CyberSecurity Challenges events based on the Sifu platform were evaluated during four online real-life CSC events. We report on three surveys showing that the Sifu platform’s CSC events are adequate to raise industry software developers awareness on secure coding.
Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque
Cybersecur.3
2019 The Good, the Bad and the Ugly: A Study of Security Decisions in a Cyber-Physical Systems Game
abstract
Stakeholders' security decisions play a fundamental role in determining security requirements, yet, little is currently understood about how different stakeholder groups within an organisation approach security and the drivers and tacit biases underpinning their decisions. We studied and contrasted the security decisions of three demographics-security experts, computer scientists and managers-when playing a tabletop game that we designed and developed. The game tasks players with managing the security of a cyber-physical environment while facing various threats. Analysis of 12 groups of players (4 groups in each of our demographics) reveals strategies that repeat in particular demographics, e.g., managers and security experts generally favoring technological solutions over personnel training, which computer scientists preferred. Surprisingly, security experts were not ipso facto better players-in some cases, they made very questionable decisions-yet they showed a higher level of confidence in themselves. We classified players' decision-making processes, i.e., procedure-, experience-, scenario- or intuition-driven. We identified decision patterns, both good practices and typical errors and pitfalls. Our game provides a requirements sandbox in which players can experiment with security risks, learn about decision-making and its consequences, and reflect on their own perception of security.
Sylvain Frey, Awais Rashid, Pauline Anthonysamy, Maria Pinto-Albuquerque, Syed Asad Naqvi
IEEE Trans. Software Eng.4
2018 The good, the bad and the ugly: a study of security decisions in a cyber-physical systems game
abstract
Motivation: The security of any system is a direct consequence of stakeholders' decisions regarding security requirements. Such decisions are taken with varying degrees of expertise, and little is currently understood about how various demographics - security experts, general computer scientists, managers - approach security decisions and the strategies that underpin those decisions. What are the typical decision patterns, the consequences of such patterns and their impact on the security of the system in question? Nor is there any substantial understanding of how the strategies and decision patterns of these different groups contrast. Is security expertise necessarily an advantage when making security decisions in a given context? Answers to these questions are key to understanding the "how" and "why" behind security decision processes.
Sylvain Frey, Awais Rashid, Pauline Anthonysamy, Maria Pinto-Albuquerque, Syed Asad Naqvi
ICSE4
2014 Tackling the requirements jigsaw puzzle
abstract
A key challenge during stakeholder meetings is that of presenting the requirements and conflicts to stakeholders in a way that fosters co-responsibility and co-ownership regarding the conflicts and their resolution. In this paper, we propose a jigsaw puzzle metaphor to make identified conflicts explicit as well as an associated method to utilise this metaphor during stakeholder meetings. The metaphor provides an easy to understand language for stakeholders from otherwise diverse backgrounds. It enables stakeholders to work with a well-understood concept - that of building a system from misshapen pieces. These characteristics foster communication and team work, which improve commitment of stakeholders in co-authoring of requirements and co-responsibility in conflict handling. The gamification of conflict resolution also promotes a relaxed environment, which in turn improves team cooperation and creativity. Our experience in three user studies demonstrates that the jigsaw puzzle indeed improves such co-responsibility and co-ownership when compared with typical text-based representations of requirements.
Maria Pinto-Albuquerque, Awais Rashid
RE1
2005 A platform for the generation of virtual environments inhabited by intelligent virtual humans
abstract
We describe a platform to build virtual environments inhabited by autonomous virtual humans. We propose an architecture comprising several software components assembled to define a platform. The architecture includes a 3D-modelling software, a rendering engine, a library for simulating rigid body dynamics and an agent development framework.
Miguel Silvestre, Maria Pinto-Albuquerque, Maria Beatriz Carmo, Ana Paula Cláudio, João Duarte Cunha, Helder Coelho
ITiCSE2