VLDB 2026 Research / reviewers in the wild / expert
Jan Jürjens
dblp:j/JanJurjens
· DBLP profile ↗
105ranked-venue papers
26as first author
21since 2021 · last 2026
0000-0002-8938-0470ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 76 · 21 first-author · 15 since 2021Security and privacy · 16 · 3 first-author · 2 since 2021Databases, data management, data science and information retrieval · 7 · 3 since 2021Artificial intelligence and machine learning · 6 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5Theory of computation · 3 · 3 first-authorComputer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Too Many Issues: Automatically Prioritizing Analyzer Findings by Tracing Security ImportanceabstractCode-based analyzers often find too many potentially security-related issues to address them all. Therefore, issues likely to lead to vulnerabilities should be fixed first. Such prioritization requires project-specific knowledge, such as quality requirements, security-related decisions, and design, which is not accessible to code analyzers. We present TraceSEC, an automated technique for prioritizing issues according to their security-related importance to the project. Its core concept is to incorporate available design artifacts and trace links between them, thus considering the project context that the code lacks. We reduce the problem of issue prioritization to a maximum flow problem and quantify the importance of each issue by the flow from user-defined quality aspects to the issue, i.e., quantifying its impact on project-specific security preferences. Our evaluation shows that TraceSEC effectively provides automated prioritization and can be tailored to project-specific quality goals. Its prioritization correlates stronger with manual expert prioritization than SonarQube rule severities, which are commonly used in practice. In particular, TraceSEC has a higher similarity for identifying high-priority issues. TraceSEC scales reasonably well for codebases up to four million lines of code, and the initial setup overhead is likely to be recouped after the first automated prioritization. Sven Peldszus, Katharina Großer, Marco Konersmann, Wasja Brunotte, Maike Ahrens, Kurt Schneider, Jan Jürjens |
ACM Trans. Softw. Eng. Methodol. | 7 |
| 2025 | An Evaluation of Open Source Data Anonymisation Tools for Medical DataabstractMedical data is inherently multimedia in nature. A single patient record typically contains diverse data types, including multimodal medical images, sensor signals, and Electronic Health Records (EHRs). Anjali Pullattukunnel, Ibraheem Al-Dhamari, Jan Jürjens |
MMAsia | 3 |
| 2025 | From missile warhead to smart fridge: Interviews with industry experts on tracing safety- and security-relevant artifactsabstractEnsuring traceability of safety- and security-related artifacts is vital in software development to comply with standards and mitigate risks. Despite its importance, the practical implementation of defining and tracing safety- and security-relevant artifacts remains ambiguous. Based on eight semi-structured interviews with industry experts, this work explores the definitions, methods, processes, and challenges of tracing safety- and security-related artifacts. The interviews revealed that definitions of safety- and security-relevant artifacts are highly context-dependent, shaped by regulatory standards, internal processes, technical characteristics, and practitioner judgment. Rather than signaling a deficiency, this variability reflects the inherently multifaceted nature of safety and security work, where artifact classification emerges from practical reasoning rather than strict or universal criteria. Tools play a key role in supporting traceability, and cross-team alignment remains a concern in practice. Our findings provide actionable insights for organizations seeking to strengthen traceability. The recommendations encourage the development of internal classification criteria, support effective collaboration with external partners, support guidance, onboarding, and training, and help align practices with across teams, fostering more reliable and transparent management of safety- and security-relevant artifacts. Marc Herrmann, Alexander Specht, Abdurrahman Sekerci, Martin Obaidi, Marco Ehl, Duaa Adel Ali Elsofi, Katharina Großer, Jil Klünder, Jan Jürjens, Kurt Schneider |
J. Syst. Softw. | 9 |
| 2025 | MBFair: a model-based verification methodology for detecting violations of individual fairnessabstractAbstract Decision-making systems are prone to discrimination against individuals with regard to protected characteristics such as gender and ethnicity. Detecting and explaining the discriminatory behavior of implemented software is difficult. To avoid the possibility of discrimination from the onset of software development, we propose a model-based methodology called MBFair that allows for verifying UML-based software designs with regard to individual fairness. The verification in MBFair is performed by generating temporal logic clauses, whose verification results enable reporting on the individual fairness of the targeted software. We study the applicability of MBFair using three case studies in real-world settings including a bank services system, a delivery system, and a loan system. We empirically evaluate the necessity of MBFair in a user study and compare it against a baseline scenario in which no modeling and tool support is offered. Our empirical evaluation indicates that analyzing the UML models manually produces unreliable results with a high chance of 46% that analysts overlook true-positive discrimination. We conclude that analysts require support for fairness-related analysis, such as our MBFair methodology. Qusai Ramadan, Marco Konersmann, Amir Shayan Ahmadian, Jan Jürjens, Steffen Staab |
Softw. Syst. Model. | 4 |
| 2025 | Correction: MBFair: a model-based verification methodology for detecting violations of individual fairnessabstract137 Qusai Ramadan, Marco Konersmann, Amir Shayan Ahmadian, Jan Jürjens, Steffen Staab |
Softw. Syst. Model. | 4 |
| 2024 | Fast, Favorable, and Fair Blockchain-based Exchange of Digital Goods using State ChannelsabstractWhen exchanging data with an untrusted counterpart, there is a risk that the counterpart will not behave honestly. Fair exchange protocols provide fairness guarantees to involved parties, e.g., by employing blockchains as trusted third parties. However, blockchain transaction fees and block creation times render such protocols expensive and slow. Furthermore, grieving attacks impose the risk of significant unilateral costs. To improve on all three, we propose a state channel-based fair exchange protocol with a mechanism to prevent grieving attacks. Our protocol lowers the cost of repeating exchanges and increases performance while preserving security guarantees of state-of-the-art fair exchange protocols. Using the Ethereum blockchain and the Perun state channel framework, we evaluate our protocol with regard to cost and performance showing significant improvements in comparison to the state-of-the-art. Matthias Lohr, Sven Peldszus, Jan Jürjens, Steffen Staab |
ICBC | 3 |
| 2024 | 5G-Enabled Flexible Security Framework for Industrial ApplicationsabstractWireless networks have made great strides in recent years in supporting the Industrial Internet of Things (IIoT). However, industrial network security remains a major challenge in the context of wireless access. Notably, many industrial communication services that enable factory floor applications are still based on proprietary and industry-specific protocols that lack essential security features. As a solution to this challenge, in this paper, we propose an application function (AF) based security framework (AERO). This framework enables the 5G security function to meet the security requirements of industrial networks when wireless access is used without implementing redundant mechanisms. The basic idea is that the 5G system implements the user plane cryptographic mechanism over the air, based on industry requirements, without affecting existing industry protocols. We propose ($i$) static configuration and (ii) dynamic configuration mechanisms that facilitate providing the 5G core network security policy used to determine user plane cryptographic requirements. Furthermore, we demonstrate the advantages of our AERO approach by applying it to two specific use cases: Automated Guided Vehicles (AGVs) and Electrified Mono-rail Systems (EMSs). Through our analysis, we establish that our proposal significantly reduces data transmission time when compared to the current 5G mechanism. Malla Reddy Sama, Eike Lyczkowski, Michael Petry, Wolfgang Kiess, Jan Jürjens |
ICC | 5 |
| 2024 | Benchmarking requirement template systems: comparing appropriateness, usability, and expressivenessabstractAbstract Various semi-formal syntax templates for natural language requirements foster to reduce ambiguity while preserving human readability. Existing studies on their effectiveness focus on individual notations only and do not allow to systematically investigate quality benefits. We strive for a comparative benchmark and evaluation of template systems to assist practitioners in selecting appropriate ones and enable researchers to work on pinpoint improvements and domain-specific adaptions. We conduct comparative experiments with five popular template systems—EARS, Adv-EARS, Boilerplates, MASTeR , and SPIDER. First, we compare a control group of free-text requirements and treatment groups of their variants following the different templates. Second, we compare MASTeR and EARS in user experiments for reading and writing. Third, we analyse all five meta-models’ formality and ontological expressiveness based on the Bunge-Wand-Weber reference ontology. The comparison of the requirement phrasings across seven relevant quality characteristics and a dataset of 1764 requirements indicates that, except SPIDER, all template systems have positive effects on all characteristics. In a user experiment with 43 participants, mostly students, we learned that templates are a method that requires substantial prior training and that profound domain knowledge and experience is necessary to understand and write requirements in general. The evaluation of templates systems’ meta-models suggests different levels of formality, modularity, and expressiveness. MASTeR and Boilerplates provide high numbers of variants to express requirements and achieve the best results with respect to completeness. Templates can generally improve various quality factors compared to free text. Although MASTeR leads the field, there is no conclusive favourite choice, as most effect sizes are relatively similar. Katharina Großer, Amir Shayan Ahmadian, Marina Rukavitsyna, Qusai Ramadan, Jan Jürjens |
Requir. Eng. | 5 |
| 2024 | UMLsecRT: Reactive Security Monitoring of Java Applications With Round-Trip EngineeringabstractToday’s software systems tend to be long-living and often process security-critical data, so keeping up with ever-changing security measures, attacks, and mitigations is critical to maintaining their security. While it has become common practice to consider security aspects during the design of a system, OWASP still identifies insecure design as one of the top 10 threats to security. Furthermore, even if the planned design is secure, verifying that the planned security assumptions hold at run-time and investigating any violations that may have occurred is cumbersome. In particular, the configuration of run-time monitors such as the Java Security Manager, which could enforce design-time security assumptions, is non-trivial and therefore used in practice rarely. To address these challenges, we present UMLsecRT for automatically supporting model-based security engineering with run-time monitoring of design-time security specifications and round-trip engineering for propagating run-time observations to the design level. Following the established security-by-design approach UMLsec, security experts annotate system models with security properties that UMLsecRT automatically synchronizes with corresponding source code annotations for the automatic configuration of UMLsecRT’s run-time monitor. To this end, UMLecRT monitors these security properties at run-time without additional effort to specify monitoring policies. Developers can define mitigations for attacks detected at run-time in advance by adjusting the automatically synchronized annotations at implementation time. Triggered by a security violation, UMLsecRT can adapt the design-time models based on run-time findings to facilitate the investigation of security violations. We evaluated UMLsecRT concerning its effectiveness and applicability to security violations extracted from real-world attacks and the DaCapo benchmark, conducted user studies on the usability of the adapted models and the feasibility of UMLsecRT in practice, especially concerning countermeasures, and investigated the scalability of UMLsecRT. To study the applicability of the whole development process, we applied UMLsecRT in two case studies to the Eclipse Secure Storage and the electronic health record system iTrust. Sven Peldszus, Jens Bürger 0001, Jan Jürjens |
IEEE Trans. Software Eng. | 3 |
| 2023 | Beyond Trading Data: The Hidden Influence of Public Awareness and Interest on Cryptocurrency VolatilityabstractSince Bitcoin first appeared on the scene in 2009, cryptocurrencies have become a worldwide phenomenon as important decentralized financial assets. Their decentralized nature, however, leads to notable volatility against traditional fiat currencies, making the task of accurately forecasting the crypto-fiat exchange rate complex. In this study, we examine the various independent factors that affect the Bitcoin-Dollar exchange rate's volatility. To this end, we propose CoMForE, a multimodal AdaBoost-LSTM ensemble model, which not only utilizes historical trading data but also incorporates public sentiments from related tweets, public interest demonstrated by search volumes, and blockchain hash-rate data. Our developed model goes a step further by predicting fluctuations in the overall cryptocurrency value distribution, thus increasing its value for investment decision-making. We have subjected this method to extensive testing via comprehensive experiments, thereby validating the importance of multimodal combination over exclusive reliance on trading data. Further experiments show that our method significantly surpasses existing forecasting tools and methodologies, demonstrating a 19.29% improvement. This result underscores the influence of external independent factors on cryptocurrency volatility. Zeyd Boukhers, Azeddine Bouabdallah, Jan Jürjens |
CIKM | 4 |
| 2023 | A Comparative Evaluation of Requirement Template SystemsabstractContext: Multiple semi-formal syntax templates for natural language requirements foster to reduce ambiguity while preserving readability. Yet, existing studies on their effectiveness do not allow to systematically investigate quality benefits and compare different notations. Objectives: We strive for a comparative benchmark and evaluation of template systems to support practitioners in selecting template systems and enable researchers to work on pinpoint improvements and domain-specific adaptions. Methods: We conduct a comparative experiment with a control group of free-text requirements and treatment groups of their variants following different templates. We compare effects on metrics systematically derived from quality guidelines. Results: We present a benchmark consisting of a systematically derived metric suite over seven relevant quality categories and a dataset of 1764 requirements, comprising 249 free-text forms from five projects and variants in five template systems. We evaluate effects in comparison to free text. Except for one template system, all have solely positive effects in all categories. Conclusions: The proposed benchmark enables the identification of the relative strengths and weaknesses of different template systems. Results show that templates can generally improve quality compared to free text. Although MASTER leads the field, there is no conclusive favourite choice, as overall effect sizes are relatively similar. Katharina Großer, Marina Rukavitsyna, Jan Jürjens |
RE | 3 |
| 2023 | ILLOD Replication Package: An Open-Source Framework for Abbreviation-Expansion Pair Detection and Term Consolidation in RequirementsabstractILLOD is a tool for detecting abbreviation-expansion pairs (AEPs) in requirement sets. It utilizes syntactic features such as Initial Letters, term Lengths, Order, and Distribution of characters to determine if a term is a potential long form to a given abbreviation. The artifact bundles all source code and data resources to replicate evaluation results presented for ILLOD in two research papers published at the REFSQ2022 Conference and in the Information and Software Technology (IST) journal. In addition, ILLOD can be used to detect AEPs, perform abbreviation detection, and the input data-set can be used for further research in requirements engineering or other related fields. The repository is organized into different directories containing data, Python sources, and notebooks for experiments and evaluations. Detailed instructions are provided to load and use the tool on a local system, and the results generated by ILLOD are stored in output files. The tool demonstrates its effectiveness in detecting AEPs and consolidating glossary terms, and the evaluation results provide insights into the performance of different classifiers. The artifact repository is a valuable resource for researchers and practitioners in the field of requirements engineering and related areas. Hussein Hasso, Katharina Großer, Iliass Aymaz, Hanna Geppert, Jan Jürjens |
RE | 5 |
| 2023 | Enhanced abbreviation-expansion pair detection for glossary term extraction
Hussein Hasso, Katharina Großer, Iliass Aymaz, Hanna Geppert, Jan Jürjens |
Inf. Softw. Technol. | 5 |
| 2023 | Knowledge guided multi-filter residual convolutional neural network for ICD coding from clinical textabstractAbstract A common challenge encountered when using Deep Neural Network models for automatic ICD coding is their potential inability to effectively handle unseen clinical texts, especially when these models are only trained on a limited number of examples. This is because these models rely solely on the patterns and relationships present in the training data, and may not be able to effectively incorporate additional knowledge about the relationships between medical entities. To address this issue, we introduce KG-MultiResCNN—KnowledgeGuidedMulti-filterResidualConvolutionalNeuralNetwork model, which combines training examples with external knowledge from the Wikidata Knowledge Graph (KG) in order to better capture the relationships between medical entities. The KG is a structured database that contains a wealth of information about various entities, including medical concepts and their relationships with one another. By incorporating this external knowledge into our model, we are able to improve its ability to predict ICD codes for new clinical texts. In our experiments with the MIMIC-III dataset, we found that the KG-MultiResCNN model significantly outperformed the baseline approaches. This demonstrates the effectiveness of using external knowledge, in addition to training examples, to improve the performance of deep learning models for automatic ICD coding. Zeyd Boukhers, Prantik Goswami, Jan Jürjens |
Neural Comput. Appl. | 3 |
| 2023 | Checking security compliance between models and codeabstractAbstract It is challenging to verify that the planned security mechanisms are actually implemented in the software. In the context of model-based development, the implemented security mechanisms must capture all intended security properties that were considered in the design models. Assuring this compliance manually is labor intensive and can be error-prone. This work introduces the first semi-automatic technique for secure data flow compliance checks between design models and code. We develop heuristic-based automated mappings between a design-level model (SecDFD, provided by humans) and a code-level representation (Program Model, automatically extracted from the implementation) in order to guide users in discovering compliance violations, and hence, potential security flaws in the code. These mappings enable an automated, and project-specific static analysis of the implementation with respect to the desired security properties of the design model. We developed two types of security compliance checks and evaluated the entire approach on open source Java projects. Katja Tuma, Sven Peldszus, Daniel Strüber 0001, Riccardo Scandariato, Jan Jürjens |
Softw. Syst. Model. | 5 |
| 2022 | Formalizing Cost Fairness for Two-Party Exchange Protocols using Game Theory and Applications to BlockchainabstractExisting fair exchange protocols usually neglect consideration of cost when assessing their fairness. However, in an environment with non-negligible transaction cost, e.g., public blockchains, high or unexpected transaction cost might be an obstacle for wide-spread adoption of fair exchange protocols in business applications. For example, as of 2021-12-17, the initialization of the FairSwap protocol on the Ethereum blockchain requires the selling party to pay a fee of approx. 349.20 USD per exchange. We address this issue by defining cost fairness, which can be used to assess two-party exchange protocols including implied transaction cost. We show that in an environment with non-negligible transaction cost where one party has to initialize the exchange protocol and the other party can leave the exchange at any time cost fairness cannot be achieved. Matthias Lohr, Kenneth Skiba, Marco Konersmann, Jan Jürjens, Steffen Staab |
ICBC | 4 |
| 2022 | Evaluation Methods and Replicability of Software Architecture Research ObjectsabstractContext: Software architecture (SA) as research area experienced an increase in empirical research, as identified by Galster and Weyns in 2016 [1]. Empirical research builds a sound foundation for the validity and comparability of the research. A current overview on the evaluation and replicability of SA research objects could help to discuss our empirical standards as a community. However, no such current overview exists.Objective: We aim at assessing the current state of practice of evaluating SA research objects and replication artifact provision in full technical conference papers from 2017 to 2021.Method: We first create a categorization of papers regarding their evaluation and provision of replication artifacts. In a systematic literature review (SLR) with 153 papers we then investigate how SA research objects are evaluated and how artifacts are made available.Results: We found that technical experiments (28%) and case studies (29%) are the most frequently used evaluation methods over all research objects. Functional suitability (46% of evaluated properties) and performance (29%) are the most evaluated properties. 17 papers (11%) provide replication packages and 97 papers (63%) explicitly state threats to validity. 17% of papers reference guidelines for evaluations and 14% of papers reference guidelines for threats to validity.Conclusions: Our results indicate that the generalizability and repeatability of evaluations could be improved to enhance the maturity of the field; although, there are valid reasons for contributions to not publish their data. We derive from our findings a set of four proposals for improving the state of practice in evaluating software architecture research objects. Researchers can use our results to find recommendations on relevant properties to evaluate and evaluation methods to use and to identify reusable evaluation artifacts to compare their novel ideas with other research. Reviewers can use our results to compare the evaluation and replicability of submissions with the state of the practice. Marco Konersmann, Angelika Kaplan, Thomas Kühn 0001, Robert Heinrich, Anne Koziolek, Ralf Reussner, Jan Jürjens, Mahmood al-Doori, Nicolas Boltz, Marco Ehl, Dominik Fuchß, Katharina Großer, Sebastian Hahner, Jan Keim, Matthias Lohr, Timur Saglam, Sophie Corallo, Jan-Philipp Töberg |
ICSA | 7 |
| 2022 | Redefining the Trust Model for the Internet of Everything in the 6G eraabstractDespite decades of evolution, the fundamental trust model of mobile networks remains unchanged. As a result, each mobile device has its own identity chip with network access credentials to be able to use mobile services such as voice telephony or Internet access. The upcoming Internet of Everything (IoE) revolution leads to a massive increase in connected devices and challenges the scalability of this approach. We propose to simplify trust establishment and show how the identity chips storing the credentials can be eliminated for most devices. The key idea is a new trust model in which an authorized subscriber securely delegates trust to other devices such that these other devices can claim legitimacy to connect to the mobile network. Our analysis shows that this proposal significantly reduces costs compared to the 5G trust model. Malla Reddy Sama, Wolfgang Kiess, Riccardo Guerzoni, Srisakul Thakolsri, Jan Jürjens |
PIMRC | 5 |
| 2022 | Abbreviation-Expansion Pair Detection for Glossary Term Extraction
Hussein Hasso, Katharina Großer, Iliass Aymaz, Hanna Geppert, Jan Jürjens |
REFSQ | 5 |
| 2022 | Requirements document relationsabstractAbstract Relations between requirements are part of nearly every requirements engineering approach. Yet, relations of views, such as requirements documents, are scarcely considered. This is remarkable as requirements documents and their structure are a key factor in requirements reuse, which is still challenging. Explicit formalized relations between documents can help to ensure consistency, improve completeness, and facilitate review activities in general. For example, this is relevant in space engineering, where many challenges related to complex document dependencies occur: 1. Several contractors contribute to a project. 2. Requirements from standards have to be applied in several projects. 3. Requirements from previous phases have to be reused. We exploit the concept of “layered traceability”, explicitly considering documents as views on sets of individual requirements and specific traceability relations on and between all of these representation layers. Different types of relations and their dependencies are investigated with a special focus on requirement reuse through standards and formalized in an Object-Role Modelling (ORM) conceptual model. Automated analyses of requirement graphs based on this model are able to reveal document inconsistencies. We show examples of such queries in Neo4J/Cypher for the EagleEye case study. This work aims to be a step toward a better support to handle highly complex requirement document dependencies in large projects with a special focus on requirements reuse and to enable automated quality checks on dependent documents to facilitate requirements reviews. Katharina Großer, Volker Riediger, Jan Jürjens |
Softw. Syst. Model. | 3 |
| 2021 | Ontology-driven evolution of software security
Sven Peldszus, Jens Bürger 0001, Timo Kehrer, Jan Jürjens |
Data Knowl. Eng. | 4 |
| 2020 | Ontology Evolution in the Context of Model-Based Secure Software Engineering
Jens Bürger 0001, Timo Kehrer, Jan Jürjens |
RCIS | 3 |
| 2020 | A semi-automated BPMN-based framework for detecting conflicts between security, data-minimization, and fairness requirementsabstractAbstract Requirements are inherently prone to conflicts. Security, data-minimization, and fairness requirements are no exception. Importantly, undetected conflicts between such requirements can lead to severe effects, including privacy infringement and legal sanctions. Detecting conflicts between security, data-minimization, and fairness requirements is a challenging task, as such conflicts are context-specific and their detection requires a thorough understanding of the underlying business processes. For example, a process may require anonymous execution of a task that writes data into a secure data storage, where the identity of the writer is needed for the purpose of accountability. Moreover, conflicts not arise from trade-offs between requirements elicited from the stakeholders, but also from misinterpretation of elicited requirements while implementing them in business processes, leading to a non-alignment between the data subjects’ requirements and their specifications. Both types of conflicts are substantial challenges for conflict detection. To address these challenges, we propose a BPMN-based framework that supports: (i) the design of business processes considering security, data-minimization and fairness requirements, (ii) the encoding of such requirements as reusable, domain-specific patterns, (iii) the checking of alignment between the encoded requirements and annotated BPMN models based on these patterns, and (iv) the detection of conflicts between the specified requirements in the BPMN models based on a catalog of domain-independent anti-patterns. The security requirements were reused from SecBPMN2, a security-oriented BPMN 2.0 extension, while the fairness and data-minimization parts are new. For formulating our patterns and anti-patterns, we extended a graphical query language called SecBPMN2-Q. We report on the feasibility and the usability of our approach based on a case study featuring a healthcare management system, and an experimental user study. Qusai Ramadan, Daniel Strüber 0001, Mattia Salnitri, Jan Jürjens, Volker Riediger, Steffen Staab |
Softw. Syst. Model. | 4 |
| 2019 | Secure Data-Flow Compliance Checks between Models and Code Based on Automated MappingsabstractDuring the development of security-critical software, the system implementation must capture the security properties postulated by the architectural design. This paper presents an approach to support secure data-flow compliance checks between design models and code. To iteratively guide the developer in discovering such compliance violations we introduce automated mappings. These mappings are created by searching for correspondences between a design-level model (Security Data Flow Diagram) and an implementation-level model (Program Model). We limit the search space by considering name similarities between model elements and code elements as well as by the use of heuristic rules for matching data-flow structures. The main contributions of this paper are three-fold. First, the automated mappings support the designer in an early discovery of implementation absence, convergence, and divergence with respect to the planned software design. Second, the mappings also support the discovery of secure data-flow compliance violations in terms of illegal asset flows in the software implementation. Third, we present our implementation of the approach as a publicly available Eclipse plugin and its evaluation on five open source Java projects (including Eclipse secure storage). Sven Peldszus, Katja Tuma, Daniel Strüber 0001, Jan Jürjens, Riccardo Scandariato |
MoDELS | 4 |
| 2018 | Detecting Conflicts Between Data-Minimization and Security Requirements in Business Process Models
Qusai Ramadan, Daniel Strüber 0001, Mattia Salnitri, Volker Riediger, Jan Jürjens |
ECMFA | 5 |
| 2018 | Taming Multi-Variability of Software Product Line TransformationsabstractSoftware product lines continuously undergo model transformations, such as refactorings, refinements, and translations. In product line transformations, the dedicated management of variability can help to control complexity and to benefit maintenance and performance. However, since no existing approach is geared for situations in which both the product line and the transformation specification are affected by variability, substantial maintenance and performance obstacles remain. In this paper, we introduce a methodology that addresses such multi-variability situations. We propose to manage variability in product lines and rule-based transformations consistently by using annotative variability mechanisms. We present a staged rule application technique for applying a variability-intensive transformation to a product line. This technique enables considerable performance benefits, as it avoids enumerating products or rules upfront. We prove the correctness of our technique and show its ability to improve performance in a software engineering scenario. Daniel Strüber 0001, Sven Peldszus, Jan Jürjens |
FASE | 3 |
| 2018 | Model-based security analysis of feature-oriented software product linesabstractToday's software systems are too complex to ensure security after the fact – security has to be built into systems by design. To this end, model-based techniques such as UMLsec support the design-time specification and analysis of security requirements by providing custom model annotations and checks. Yet, a particularly challenging type of complexity arises from the variability of software product lines. Analyzing the security of all products separately is generally infeasible. In this work, we propose SecPL, a methodology for ensuring security in a software product line. SecPL allows developers to annotate the system design model with product-line variability and security requirements. To keep the exponentially large configuration space tractable during security checks, SecPL provides a family-based security analysis. In our experiments, this analysis outperforms the naive strategy of checking all products individually. Finally, we present the results of a user study that indicates the usability of our overall methodology. Sven Peldszus, Daniel Strüber 0001, Jan Jürjens |
GPCE | 3 |
| 2018 | Data security and consumer trust in FinTech innovation in GermanyabstractPurpose The purpose of this study is to empirically analyse the key factors that influence the adoption of financial technology innovation in the country Germany. The advancement of mobile devices and their usage have increased the uptake of financial technology (FinTech) innovation. Financial sectors and startups see FinTech as a gateway to increase business opportunities, but mobile applications and other technology platforms must be launched to explore such opportunities. Mobile application security threats have increased tremendously and have become a challenge for both users and FinTech innovators. In this paper, the authors empirically inspect the components that influence the expectations of both users and organizations to adopt FinTech, such as customer trust, data security, value added, user interface design and FinTech promotion. The empirical results definitely confirm that data security, customer trust and the user design interface affect the adoption of FinTech. Existing studies have used the Technology Acceptance Model (TAM) to address this issue. The outcomes of this study can be used to improve the performance of FinTech strategies and enable banks to achieve economies of scale for global intensity. Design/methodology/approach In this paper, the authors empirically consider factors that influence the expectations of both users and organizations in adopting FinTech, such as customer trust, data security, value added, the user design interface and FinTech promotion. The results confirm that customer trust, data security and the user design interface affect the adoption of FinTech. This research proposes a model called “Intention to adopt FinTech in Germany,” constructs of which were developed based on the TAM and five additional components, as identified. The outcomes of this study can be used to improve the performance of FinTech strategies and enable banks to achieve economies of scale for global intensity. Findings The authors demonstrated that the number of mobile users in Germany is rapidly increasing; yet the adoption of FinTech is extremely sluggish. It is intriguing to reckon that 99 per cent of respondents had mobile devices, but only 10 per cent recognized FinTech. Further, it is significantly discouraging to perceive that only 10 of the 209 respondents had ever used FinTech services, representing under 1 per cent of the surveyed respondents. It is obvious that the FinTech incubators and banks offering FinTech services need to persuade their customers regarding the usefulness and value added advantages of FinTech. This study has been carried out to determine the key factors that influence and provoke FinTech adoption. Research limitations/implications There are a few limitations in this study. Initially, this study focuses on FinTech implementation in Germany and not the whole of Europe. In addition, demographic and regional factors could be consolidated to inspect their particular impact on the intention to use FinTech services, particularly among younger users with a high interest in technology. Without these constraints, the authors could have gathered additional data for a more robust result and obtained new knowledge to further upgrade polices to enhance the FinTech adoption process. Future analysts can assist exploration of this topic by altering determinants in the unified theory of acceptance and use of technology model. Additionally, because the cluster sampling technique was used, the reported outcomes are not 100 per cent generalized to the German population. To accomplish a complete generalization, a basic random sampling strategy for the whole population is essential. The authors could also alleviate some limitations by examining how online vendors are performing with regard to FinTech to satisfy the needs of customers via case studies. Practical implications This study was conducted in Germany and might have produced different results if held in other countries, as technology acceptance is different in a different environment. For instance, the authors suspect that the results would be somewhat different, were the research to be conducted in the United Kingdom, where take-up of FinTech appears to be far greater than in Germany. Therefore, the authors’ results are only generalized for the country of Germany and not other geographical areas. Furthermore, respondents may have been influenced by past experiences about FinTech usage which might have led them to neglect to answer some questions. In spite of this, this study did not consider the influence of moderating variables such as age, education and FinTech services experience. The authors also neglected social impact and control factors, as their corresponding items disregarded the instrument dependability. Accordingly, the authors could not quantify social impact and control factors on FinTech use. Social implications The outcomes of this study can be used to improve the performance of FinTech strategies and enable banks to accomplish economies of scale for global intensity. The authors do hope that this paper will serve to encourage FinTech innovators in their approach to FinTech and enable FinTech researchers to use past work with more prominent certainty, resulting in rigid hypothesis improvement in the future. Originality/value A considerable amount of revenue has been invested in the information technology (IT) infrastructure of banks to enhance their performance, but investment in IT remains a substantial risk regarding the return on investment (Carlson, 2015). Most banks and financial organizations around the globe are engaging in an extreme pressure from their customers and competitors to enhance IT. Harrison Stewart, Jan Jürjens |
Inf. Comput. Secur. | 2 |
| 2018 | A framework for semi-automated co-evolution of security knowledge and system models
Jens Bürger 0001, Daniel Strüber 0001, Stefan Gärtner 0001, Thomas Ruhroth, Jan Jürjens, Kurt Schneider |
J. Syst. Softw. | 5 |
| 2017 | Model-Based Privacy Analysis in Industrial Ecosystems
Amir Shayan Ahmadian, Daniel Strüber 0001, Volker Riediger, Jan Jürjens |
ECMFA | 4 |
| 2017 | From Secure Business Process Modeling to Design-Level Security VerificationabstractTracing and integrating security requirements throughout the development process is a key challenge in security engineering. In socio-technical systems, security requirements for the organizational and technical aspects of a system are currently dealt with separately, giving rise to substantial misconceptions and errors. In this paper, we present a model-based security engineering framework for supporting the system design on the organizational and technical level. The key idea is to allow the involved experts to specify security requirements in the languages they are familiar with: business analysts use BPMN for procedural system descriptions; system developers use UML to design and implement the system architecture. Security requirements are captured via the language extensions SecBPMN2 and UMLsec. We provide a model transformation to bridge the conceptual gap between SecBPMN2 and UMLsec. Using UMLsec policies, various security properties of the resulting architecture can be verified. In a case study featuring an air traffic management system, we show how our framework can be practically applied. Qusai Ramadan, Mattia Salnitri, Daniel Strüber 0001, Jan Jürjens, Paolo Giorgini |
MoDELS | 4 |
| 2017 | Model-based privacy and security analysis with CARiSMAabstractWe present CARiSMA, a tool that is originally designed to support model-based security analysis of IT systems. In our recent work, we added several new functionalities to CARiSMA to support the privacy of personal data. Moreover, we introduced a mechanism to assist the system designers to perform a CARiSMA analysis by automatically initializing an appropriate CARiSMA analysis concerning security and privacy requirements. The motivation for our work is Article 25 of Regulation (EU) 2016/679, which requires appropriate technical and organizational controls must be implemented for ensuring that, by default, the processing of personal data complies with the principles on processing of personal data. This implies that initially IT systems must be analyzed to verify if such principles are respected. System models allow the system developers to handle the complexity of systems and to focus on key aspects such as privacy and security. CARiSMA is available at http://carisma.umlsec.de and our screen cast at https://youtu.be/b5zeHig3ARw. Amir Shayan Ahmadian, Sven Peldszus, Qusai Ramadan, Jan Jürjens |
ESEC/SIGSOFT FSE | 4 |
| 2017 | Information security management and the human aspect in organizationsabstractPurpose The aim of this study is to encourage management boards to recognize that employees play a major role in the management of information security. Thus, these issues need to be addressed efficiently, especially in organizations in which data are a valuable asset. Design/methodology/approach Before developing the instrument for the survey, first, effective measurement built upon existing literature review was identified and developed and the survey questionnaires were set according to past studies and the findings based on qualitative analyses. Data were collected by using cross-sectional questionnaire and a Likert scale, whereby each question was related to an item as in the work of Witherspoon et al. (2013). Data analysis was done using the SPSS.3B. Findings Based on the results from three surveys and findings, a principle of information security compliance practices was proposed based on the authors’ proposed nine-five-circle (NFC) principle that enhances information security management by identifying human conduct and IT security-related issues regarding the aspect of information security management. Furthermore, the authors’ principle has enabled closing the gap between technology and humans in this study by proving that the factors in the present study’s finding are interrelated and work together, rather than on their own. Research limitations/implications The main objective of this study was to address the lack of research evidence on what mobilizes and influences information security management development and implementation. This objective has been fulfilled by surveying, collecting and analyzing data and by giving an account of the attributes that hinder information security management. Accordingly, a major practical contribution of the present research is the empirical data it provides that enable obtaining a bigger picture and precise information about the real issues that cause information security management shortcomings. Practical implications In this sense, despite the fact that this study has limitations concerning the development of a diagnostic tool, it is obviously the main procedure for the measurements of a framework to assess information security compliance policies in the organizations surveyed. Social implications The present study’s discoveries recommend in actuality that using flexible tools that can be scoped to meet individual organizational needs have positive effects on the implementation of information security management policies within an organization. Accordingly, the research proposes that organizations should forsake the oversimplified generalized guidelines that neglect the verification of the difference in information security requirements in various organizations. Instead, they should focus on the issue of how to sustain and enhance their organization’s compliance through a dynamic compliance process that involves awareness of the compliance regulation, controlling integration and closing gaps. Originality/value The rapid growth of information technology (IT) has created numerous business opportunities. At the same time, this growth has increased information security risk. IT security risk is an important issue in industrial sectors, and in organizations that are innovating owing to globalization or changes in organizational culture. Previously, technology-associated risk assessments focused on various technology factors, but as of the early twenty-first century, the most important issue identified in technology risk studies is the human factor. Harrison Stewart, Jan Jürjens |
Inf. Comput. Secur. | 2 |
| 2016 | Supporting Model-Based Privacy Analysis by Exploiting Privacy Level AgreementsabstractSecurity and privacy are increasing concerns for both IT service customers and providers. According to cloud security alliance (CSA), privacy level agreements (PLAs) are intended to be used as appendixes to service level agreements and are likely to become as an industry standardized way for cloud service providers to describe the level of privacy and data protection. In this paper, we introduce an approach to verify whether the system design of a service provider supports the service customer's privacy and security preferences, by exploiting PLAs. In the first step, we formalize the PLAs. To this end, a metamodel for the PLAs is provided. This metamodel is based on the PLA outline provided by CSA, which is originally based on Directive 95/46/EC. In our research, we first investigate if an adaptation of the PLA outline with respect to the Regulation 2016/679 (repealing of Directive 95/46/EC) on the protection of natural persons with respect to the processing of personal data, is required. Afterwards, we describe how the PLAs are used to support model-based privacy and security analyses. Moreover, we explain how the analyses results can be used to refine PLAs. Our approach is supported by the CARiSMA tool. To evaluate the approach, we applied it to a real industry case study. Amir Shayan Ahmadian, Jan Jürjens |
CloudCom | 2 |
| 2015 | Preserving Validity of Batch-Job Nets under Change at Run-TimeabstractIn this paper, we develop an approach to preserve validity of executable batch-job specifications during changes at run-time based on Petri-nets. The approach in particular supports changing batch-job specifications while they are being executed, which makes it particularly important to ensure that the change preserves the critical properties. The approach supports verification of the batch-job specifications that are subject to change against these properties and correction of those batch-job specifications that become invalid by the change. The developed approach was implemented and validated in an industrial application context. Chris Apfelbeck, Martin Fritz, Jan Jürjens, Johannes Zweihoff |
COMPSAC | 3 |
| 2015 | Restoring Security of Long-Living Systems by Co-evolutionabstractSecurity is an important quality aspect for modern information systems. Security properties may however be violated if the information system operates in an evolving environment. Environmental changes then trigger reactions which lead to co-evolution of the security design and the corresponding system model. However, updating the security design manually is time-consuming and error-prone. We present an approach to support semi-automatic system co-evolution which responds to environmental knowledge evolution, using the UML security extension UMLsec and graph transformation. The aim is to enable software engineers to react more reliably and effectively to environmental changes and to ensure lifelong compliance of information systems. To evaluate our approach, we conducted a case study on the open-source project iTrust. Jens Bürger 0001, Stefan Gärtner 0001, Thomas Ruhroth, Johannes Zweihoff, Jan Jürjens, Kurt Schneider |
COMPSAC | 5 |
| 2015 | Model-based Security Analysis and Applications to Security Economics
Jan Jürjens, Amir Shayan Ahmadian |
MODELSWARD | 1 |
| 2015 | A Platform for Empirical Research on Information System EvolutionabstractSoftware-intensive systems are subject to continuous change due to modification of the systems themselves and their environment.Methods for supporting evolution are a competitive edge in software engineering as software is operated over decades.Empirical research is useful to validate the effectiveness of these methods.However, empirical studies on software evolution are rarely comprehensive and hardly replicable.Collaboration in empirical studies may prevent these shortcomings.We analyzed the support for such collaboration and examined existing studies in a literature review.Based on our findings, we designed CoCoMEP-a platform for supporting collaboration in empirical research on software evolution by shared knowledge.We report lessons learned from the application of the platform in a large research programme. Robert Heinrich, Stefan Gärtner 0001, Tom-Michael Hesse, Thomas Ruhroth, Ralf Reussner, Kurt Schneider, Barbara Paech, Jan Jürjens |
SEKE | 8 |
| 2015 | Special Issue on Secure Information Systems EngineeringabstractThe development of secure software and systems presents many challenges, as demonstrated by the high number of security weaknesses that are discovered in practice on a continuous basis. This has motivated a significant amount of work in the fields of security engineering and security software engineering, with corresponding technical, experimental and methodological contributions, as well as applications of the results in practice. Topics of particular current interest include work on security engineering, security models, security governance, standards, and controls, security ontology, security metrics, security in data warehouses, security and trust in service oriented architecture (SOA) and cloud computing [also in the context of service level agreements (SLAs)], privacy and security requirements, and information systems engineering security. A further important topic is data privacy and how to enforce it within the processing of information, for example, within a cloud environment. Also, the topic of model-based security analysis using the unified modelling language (UML) remains a topic of high current interest, as well as techniques for domain-specific security modelling and meta-modelling. This special issue of The Computer Journal therefore includes papers received from the public Call for Papers and extended and improved versions of those papers that were selected from the best of the International Workshop on Security in Information Systems (WOSIS, 2013) and International Workshop on Information Systems Security Engineering (WISSE, 2013). It aims to serve as a forum in which to unite academics, researchers, practitioners and students in the field of security engineering and security software engineering, by presenting technical, experimental, methodological and/or applicative contributions, and to promote the exchange of ideas, discussion and development in these areas. This special issue includes 10 papers of interest within the wide spectrum of research into the area of information systems security. Six of them have been selected as the best papers presented in the two workshops, and the remaining papers are from the public call. There is a predominance of theoretical papers, which are principally focused on security engineering, security models, security ontology, security metrics, security in data warehouses, security in SOA and cloud computing, privacy and security requirements, but there is also an important sample of papers which contribute to the area of information systems engineering security. A brief introduction to each of the papers selected is presented in the following paragraphs. The first contribution, ‘Privacy-Preserving Query Processing by Multi-Party Computation’, by M. Sepehri et al., addresses the problem of Privacy-Preserving Querying Partitioned (P3Q) databases. It first proposes a novel protocol called B-SMEQ to privately compute queries and then offers three techniques for selection, range and equi-join queries. These techniques are based on B-SMEQ. The demonstration of the protocol efficiency in term of computational and communication complexity has been performed through experimental tests executed on randomly generated large size databases. The second paper, entitled ‘Privacy as an Integral Part for the Implementation of Cloud Solutions’, by E. Kavakli et al., contributes to the existing literature through the identification of cloud-specific privacy properties and it advances the state of the art in privacy engineering for cloud computing. The authors introduce a number of implementation techniques that assure privacy properties in a cloud environment. The third contribution, ‘A Trust Evaluation Model for Cloud Computing using SLA’, by M. Dhanraj et al., presents a trust mining model to identify trusted cloud services while negotiating an SLA. The proposed trust model helps both the service provider and cloud user, where the user can make a decision on whether to continue or discontinue the service with the service provider. The fourth contribution, ‘ISGcloud: A Security Governance Framework for Cloud Computing’, by O. Rebollo et al., has the objective of introducing a comprehensive security governance framework (ISGcloud) with its focus on the cloud computing environment. Its four main processes are based on the ISO/IEC 38500 governance standard, and it also proposes a cloud service lifecycle based on the ISO/IEC 27036 security for supplier relationships standard. This proposal offers an overall methodology which guides organizations in the process of deploying a security governance structure during the entire cloud service lifecycle. The fifth paper, ‘A Discussion of Communication Schemes for Process Execution. Histories to Enforce Entailment Constraints in Process-Driven SOAs’, by T. Quirchmayr et al., investigates about different communication schemes for orchestration engines and for choreography engines and extends the informal discussion on the enforcement of entailment constraints in process-driven SOAs. The authors examine the efficiency of these schemes in case of omission failures occur. The sixth contribution, entitled ‘The Robust Measurement Method for Security Metrics Generation’, by K. Mazur et al., is focused on a new security measurement model that extends that presented in the ISO/IEC 27004 with the measurement validation methods. Through the verification of the gathered results, developed information security performance metrics provide a means for the monitoring, reporting, improving and assessing the effectiveness of the implemented security controls. The authors also present a case study of using the new proposed model for cryptographic modules and an implementation of the Crypto-Metrics Tool that is a benchmarking and results validation tool used for testing the performance of the cryptographic primitives. The seventh paper, entitled ‘Reference Ontology for Cybersecurity Operational Information’, by T. Takahashi et al., proposes a reference ontology for cybersecurity operational information in order to build a basis for cybersecurity information exchange on a global scale. The ontology structures cybersecurity information, orchestrates and collaborates with industry specifications, and thus facilitates the exchange of an assortment of cybersecurity information in different schemata. The authors also review existing industry specifications of cybersecurity information schemata by mapping the specifications for each of the information types defined by the ontology. The eighth contribution, ‘Modelling Security of Critical Infrastructures: A Survivability Assessment’, by R.J. Rodríguez et al., presents standard modelling techniques using UML profiling (namely, SecAM profile) plus formal models (namely, Generalized Stochastic Petri nets) are used to assess the security and survivability of critical infrastructures, normally targeted by malicious intended attacks. Thus, security properties specification and assessment are carried out during early phases (requirements, design) of system development life cycle. As case study, the survivability of the Saudi Arabia crude-oil network is evaluated under two different attack scenarios where the minimization of attack damages is quantitatively estimated. The ninth paper, entitled ‘An Integrated Security and Systems Engineering Process and Modelling Framework’, by J. Ruiz et al., studies the Integrated Security and System Engineering Process supports system engineers in integrating security in the development of their systems since the beginning of the design phase. The definition of the security knowledge is done in artefacts called Domain Security Metamodels, which specify the information and solutions of a specific domain (e.g. cloud, metering systems, etc.). The process is supported by a tool for MagicDraw that covers all the system's life cycle and helps system engineers in selecting and applying the security solutions that better fit their requirements. Finally, the 10th contribution, entitled ‘Modernizing Secure OLAP Applications with a Model Driven Approach’, by C. Blanco et al., is focused on the evolution problem of on-line analytical processing (OLAP) applications. It offers a reverse engineering approach that enables an automatic deduction of a conceptual model corresponding to a legacy OLAP application. This approach exhibits security aspects embedded in an OLAP application. It is built using an model-driven, architecture in order to facilitate the evolution of the resulting conceptual model. We would like to thank Prof. Fionn Murtagh (Editor-in-Chief), Dr Jutta Mackwell (Journal Manager) and Prof. Chris Mitchell (Section Editor) from The Computer Journal for their invaluable help and support, and for giving us the opportunity to edit this special issue. We are also extremely grateful for the hard work and kindness of all the members of our international program committee when performing their timely, complete and professional reviews. Last, but by no means least, we would like to thank the authors for their contributions. David Garcia Rosado, Nadira Lammari, Jan Jürjens |
Comput. J. | 3 |
| 2015 | The CoCoME Platform: A Research Note on Empirical Studies in Information System EvolutionabstractMethods for supporting evolution of software-intensive systems are a competitive edge in software engineering as software is often operated over decades. Empirical research is useful to validate the effectiveness of these methods. However, empirical studies on software evolution are rarely comprehensive and hardly replicable. Collaboration may prevent these shortcomings. We designed CoCoMEP — a platform for supporting collaboration in empirical research on software evolution by shared knowledge. We report lessons learned from the application of the platform in a large research programme. Robert Heinrich, Stefan Gärtner 0001, Tom-Michael Hesse, Thomas Ruhroth, Ralf Reussner, Kurt Schneider, Barbara Paech, Jan Jürjens |
Int. J. Softw. Eng. Knowl. Eng. | 8 |
| 2015 | Restoring security of evolving software models using graph transformation
Jens Bürger 0001, Jan Jürjens, Sven Wenzel |
Int. J. Softw. Tools Technol. Transf. | 2 |
| 2014 | Towards Adaptation and Evolution of Domain-Specific Knowledge for Maintaining Secure Systems
Thomas Ruhroth, Stefan Gärtner 0001, Jens Bürger 0001, Jan Jürjens, Kurt Schneider |
PROFES | 4 |
| 2014 | Maintaining requirements for long-living software systems by incorporating security knowledgeabstractSecurity is an increasingly important quality facet in modern information systems and needs to be retained. Due to a constantly changing environment, long-living software systems “age” not by wearing out, but by failing to keep up-to-date with their environment. The problem is that requirements engineers usually do not have a complete overview of the security-related knowledge necessary to retain security of long-living software systems. This includes security standards, principles and guidelines as well as reported security incidents. In this paper, we focus on the identification of known vulnerabilities (and their variations) in natural-language requirements by leveraging security knowledge. For this purpose, we present an integrative security knowledge model and a heuristic method to detect vulnerabilities in requirements based on reported security incidents. To support knowledge evolution, we further propose a method based on natural language analysis to refine and to adapt security knowledge. Our evaluation indicates that the proposed assessment approach detects vulnerable requirements more reliable than other methods (Bayes, SVM, k-NN). Thus, requirements engineers can react faster and more effectively to a changing environment that has an impact on the desired security level of the information system. Stefan Gärtner 0001, Thomas Ruhroth, Jens Bürger 0001, Kurt Schneider, Jan Jürjens |
RE | 5 |
| 2014 | Guiding a general-purpose C verifier to prove cryptographic protocolsabstractWe describe how to verify security properties of C code for cryptographic protocols by using a general-purpose verifier. We prove security theorems in the symbolic model of cryptography. Our techniques include: use of ghost state to attach formal algebraic terms to concrete byte arrays and to detec t collisions when two distinct terms map to the same byte array; decoration of a crypto API with contracts based on symbolic terms; and expression of the attacker model in terms of C programs. We rely on the general-purpose verifier VCC; we guide VCC to prove security simply by writing suitable header files and annotations in implementation files, rather than by changing VCC itself. We formalize the symbolic model in Coq in order to justify the addition of axioms to VCC. François Dupressoir, Andrew D. Gordon 0001, Jan Jürjens, David A. Naumann |
J. Comput. Secur. | 3 |
| 2013 | Ontology-based Analysis of Compliance and Regulatory Requirements of Business Processes
Thorsten Humberg, Christian Wessel, Daniel Poggenpohl, Sven Wenzel, Thomas Ruhroth, Jan Jürjens |
CLOSER | 6 |
| 2013 | Resolving vulnerability identification errors using security requirements on business process modelsabstractPurpose In any information security risk assessment, vulnerabilities are usually identified by information‐gathering techniques. However, vulnerability identification errors – wrongly identified or unidentified vulnerabilities – can occur as uncertain data are used. Furthermore, businesses' security needs are not considered sufficiently. Hence, security functions may not protect business assets sufficiently and cost‐effectively. This paper aims to resolve vulnerability errors by analysing the security requirements of information assets in business process models. Design/methodology/approach Business process models have been selected for use, because there is a close relationship between business process objectives and risks. Security functions are evaluated in terms of the information flow of business processes regarding their security requirements. The claim that vulnerability errors can be resolved was validated by comparing the results of a current risk assessment approach with the proposed approach. The comparison is conducted both at three entities of an insurance company, as well as through a controlled experiment within a survey among security professionals. Findings Vulnerability identification errors can be resolved by explicitly evaluating security requirements in the course of business; this is not considered in current assessment methods. Originality/value It is shown that vulnerability identification errors occur in practice. With the explicit evaluation of security requirements, identification errors can be resolved. Risk assessment methods should consider the explicit evaluation of security requirements. Stefan Taubenberger, Jan Jürjens, Yijun Yu 0001, Bashar Nuseibeh |
Inf. Manag. Comput. Secur. | 2 |
| 2012 | Computational verification of C protocol implementations by symbolic executionabstractWe verify cryptographic protocols coded in C for correspondence properties with respect to the computational model of cryptography. The first step uses symbolic execution to extract a process calculus model from a C implementation of the protocol. The new contribution is the second step in which we translate the extracted model to a CryptoVerif protocol description, such that successful verification with CryptoVerif implies the security of the original C implementation. We implement our method and apply it to verify several protocols out of reach of previous work in the symbolic model (using ProVerif), either due to the use of XOR and Diffie-Hellman commitments, or due to the lack of an appropriate computational soundness result. We analyse only a single execution path, so our tool is limited to code following a fixed protocol narration. This is the first security analysis of C code to target a verifier for the computational model. We successfully verify over 3000 LOC. One example (about 1000 LOC) is independently written and currently in testing phase for industrial deployment; during its analysis we uncovered a vulnerability now fixed by its author. Mihhail Aizatulin, Andrew D. Gordon 0001, Jan Jürjens |
CCS | 3 |
| 2012 | Securing Processes for Outsourcing into the Cloud
Sven Wenzel, Christian Wessel, Thorsten Humberg, Jan Jürjens |
CLOSER | 4 |
| 2012 | Enhancing security requirements engineering by organizational learning
Kurt Schneider, Eric Knauss, Siv Hilde Houmb, Shareeful Islam, Jan Jürjens |
Requir. Eng. | 5 |
| 2011 | Model-Based Security Verification and Testing for Smart-cardsabstractModel-Based Testing (MBT) is a widely used methodology for generating tests aiming to ensure that the system behaviour conforms to its specification. Recently, it has been successfully applied for testing certain security properties. However, for the success of this approach, it is an important prerequisite to consider the correctness of test models with respect to the given security property. In this paper we present an approach for smart-card specific security properties that permits to validate the system with MBT from test schemas. We combine this MBT approach with UMLsec security verification technique, by using UMLsec stereotypes to verify the model w.r.t. given security properties and gain more confidence in the model. We then define an automatic procedure to generate security test from the UMLsec model via so-called "test schemas". We validate this approach on a fragment of the Global Platform specification and report on available tool support. Elizabeta Fourneret, Martín Ochoa, Fabrice Bouquet, Julien Botella, Jan Jürjens, Parvaneh Yousefi |
ARES | 5 |
| 2011 | Connecting Security Requirements Analysis and Secure Design Using Patterns and UMLsec
Holger Schmidt 0001, Jan Jürjens |
CAiSE | 2 |
| 2011 | Extracting and verifying cryptographic models from C protocol code by symbolic executionabstractConsider the problem of verifying security properties of a cryptographic protocol coded in C. We propose an automatic solution that needs neither a pre-existing protocol description nor manual annotation of source code. First, symbolically execute the C program to obtain symbolic descriptions for the network messages sent by the protocol. Second, apply algebraic rewriting to obtain a process calculus description. Third, run an existing protocol analyser (ProVerif) to prove security properties or find attacks. We formalise our algorithm and appeal to existing results for ProVerif to establish computational soundness under suitable circumstances. We analyse only a single execution path, so our results are limited to protocols with no significant branching. The results in this paper provide the first computationally sound verification of weak secrecy and authentication for (single execution paths of) C code. Mihhail Aizatulin, Andrew D. Gordon 0001, Jan Jürjens |
CCS | 3 |
| 2011 | Guiding a General-Purpose C Verifier to Prove Cryptographic ProtocolsabstractWe describe how to verify security properties of C code for cryptographic protocols by using a general-purpose verifier. We prove security theorems in the symbolic model of cryptography. Our techniques include: use of ghost state to attach formal algebraic terms to concrete byte arrays and to detect collisions when two distinct terms map to the same byte array, decoration of a crypto API with contracts based on symbolic terms, and expression of the attacker model in terms of C programs. We rely on the general-purpose verifier VCC, we guide VCC to prove security simply by writing suitable header files and annotations in implementation files, rather than by changing VCC itself. We formalize the symbolic model in Coq in order to justify the addition of axioms to VCC. François Dupressoir, Andrew D. Gordon 0001, Jan Jürjens, David A. Naumann |
CSF | 3 |
| 2011 | Incremental Security Verification for Evolving UMLsec models
Jan Jürjens, Loïc Marchal, Martín Ochoa, Holger Schmidt 0001 |
ECMFA | 1 |
| 2011 | Systematic Development of UMLsec Design Models Based on Security Requirements
Denis Hatebur, Maritta Heisel, Jan Jürjens, Holger Schmidt 0001 |
FASE | 3 |
| 2011 | Automated security hardening for evolving UML modelsabstractDeveloping security-critical software correctly and securely is difficult. To address this problem, there has been a significant amount of work over the last 10 years on providing model-based development approaches based on the Unified Modeling Language which aim to raise the trustworthiness of security-critical systems, some of them including tools allowing the user to check whether a UML model satisfies the relevant security requirements. However, when the requirements are not satisfied by a given model, it can be challenging for the user to determine which changes to do to the model so that it will indeed satisfy the security requirements. Also, the fact that software continues to evolve on an ongoing basis, even after the implementation has been shipped to the customer, increases the challenge since in principle, the software has to be re-verified after each modification, requiring significant efforts. We present work on automated tool-support that exploits recent work on secure software evolution in the Secure Change project in order to support the security hardening of evolving UML models (within the context of the UML security extension UMLsec). Jan Jürjens |
ICSE | 1 |
| 2011 | Seventh international workshop on software engineering for secure systems: (SESS 2011)abstractThe 7th edition of the SESS workshop aims at providing a venue for software engineers and security researchers to exchange ideas and techniques. In fact, software is at core of most of the business transactions and its smart integration in an industrial setting may be the competitive advantage even when the core competence is outside the ICT field. As a result, the revenues of a firm depend directly on several complex software-based systems. Thus, stakeholders and users should be able to trust these systems to provide data and elaborations with a degree of confidentiality, integrity, and availability compatible with their needs. Moreover, the pervasiveness of software products in the creation of critical infrastructures has raised the value of trustworthiness and new efforts should be dedicated to achieve it. However, nowadays almost every application has some kind of security requirement even if its use is not to be considered critical. Seok-Won Lee, Mattia Monga, Jan Jürjens |
ICSE | 3 |
| 2011 | Supporting Requirements Engineers in Recognising Security Issues
Eric Knauss, Siv Hilde Houmb, Kurt Schneider, Shareeful Islam, Jan Jürjens |
REFSQ | 5 |
| 2011 | Problem Analysis of Traditional IT-Security Risk Assessment Methods - An Experience Report from the Insurance and Auditing Domain
Stefan Taubenberger, Jan Jürjens, Yijun Yu 0001, Bashar Nuseibeh |
SEC | 2 |
| 2011 | Run-Time Security Traceability for Evolving SystemsabstractSecurity-critical systems are challenging to design and implement correctly and securely. A lot of vulnerabilities have been found in current software systems both at the specification and the implementation levels. This paper presents a comprehensive approach for model-based security assurance. Initially, it allows one to formally verify the design models against high-level security requirements such as secrecy and authentication on the specification level, and helps to ensure that their implementation adheres to these properties, if they express a system's run-time behaviour. As such, it provides a traceability link from the design model to its implementation by which the actual system can then be verified against the model while it executes. This part of our approach relies on a technique also known as run-time verification. The extra effort for it is small as most of the computation is automated; however, additional resources at run-time may be required. If during run-time verification a security weakness is uncovered, it can be removed using aspect-oriented security hardening transformations. Therefore, this approach also supports the evolution of software since the traceability mapping is updated when refactoring operations are regressively performed using our tool-supported refactoring technique. The proposed method has been applied to the Java-based implementation Jessie of the Internet security protocol SSL, in which a security weakness was detected and fixed using our approach. We also explain how the traceability link can be transformed to the official implementation of the Java secure sockets extension that was recently made open source by Sun. Andreas Bauer 0002, Jan Jürjens, Yijun Yu 0001 |
Comput. J. | 2 |
| 2011 | A framework to support alignment of secure software engineering with legal regulations
Shareeful Islam, Haralambos Mouratidis, Jan Jürjens |
Softw. Syst. Model. | 3 |
| 2010 | The 6th International Workshop on Software Engineering for Secure Systems (SESS'10)
Seok-Won Lee, Mattia Monga, Jan Jürjens |
ICSE (2) | 3 |
| 2010 | Tool support for code generation from a UMLsec propertyabstractS.357-358 Lionel Montrieux, Jan Jürjens, Charles B. Haley, Yijun Yu 0001, Pierre-Yves Schobbens, Hubert Toussaint |
ASE | 2 |
| 2010 | Model-Based Security Engineering with UML: The Last Decade and towards the Future (Keynote)abstractThe current state of the art in developing security-critical software and systems in practice is far from satisfactory: New security vulnerabilities are discovered on an almost daily basis. To address this problem, there has been a significant amount of work over the last 10 years on providing model-based development approaches based on the Unified Modeling Language which aim to raise the trustworthiness of security-critical systems. Recently, model-based security has even managed to gain entry into Gartner's ”hype cycle”. This keynote talk gives an overview over some developments in this field over the last 10 years, discusses the current state of affairs with respect to foundations, tool-support and industrial applications, and considers what might be particularly promising current and future developments. Jan Jürjens |
VL/HCC | 1 |
| 2010 | Runtime verification of cryptographic protocols
Andreas Bauer 0002, Jan Jürjens |
Comput. Secur. | 2 |
| 2010 | From goal-driven security requirements engineering to secure designabstractSecurity of intelligent software systems is an important area of research. Although security is traditionally considered a technical issue; security is, in fact, a two-dimensional problem, which involves technical as well as social challenges. Goal-driven requirements engineering (GDRE) has been proposed in the literature as a suitable paradigm for the analysis of security issues and elicitation of security requirements at both the social and technical level. Nevertheless, there is lack of approaches, which would support the successful transformation of the elicited, using GDRE approaches, security requirements to design. This paper presents work that fills this gap. The presented approach, which is based on the integration of a goal-driven security requirements engineering (GDSRE) methodology and a model-based security engineering (MBSE) method, has some important features: (1) It provides a structured process to translate the results of the GDSRE method to a design, which satisfies these requirements; (2) it allows the simultaneous elicitation and analysis of the security requirements and the functional requirements of the system; (3) it allows consideration of both the social and the technical dimensions of the system's security; (4) it guides software engineers toward a design that is amenable to formal verification with the aid of automated tools. We demonstrate the applicability of the proposed approach at the hand of an application to the electronic purse standard common electronic purse specifications (released by Visa International and others). © 2010 Wiley Periodicals, Inc. Haralambos Mouratidis, Jan Jürjens |
Int. J. Intell. Syst. | 2 |
| 2010 | Eliciting security requirements and tracing them to design: an integration of Common Criteria, heuristics, and UMLsec
Siv Hilde Houmb, Shareeful Islam, Eric Knauss, Jan Jürjens, Kurt Schneider |
Requir. Eng. | 4 |
| 2009 | Secure Information Systems Engineering: Experiences and Lessons Learned from Two Health Care Projects
Haralambos Mouratidis, Ali Sunyaev, Jan Jürjens |
CAiSE | 3 |
| 2009 | Security Analysis of a Biometric Authentication System Using UMLsec and JML
John Lloyd, Jan Jürjens |
MoDELS | 2 |
| 2009 | Model-Driven Development for secure information systems
Eduardo Fernández-Medina, Jan Jürjens, Juan Trujillo 0001, Sushil Jajodia |
Inf. Softw. Technol. | 2 |
| 2009 | Performance analysis of security aspects by weaving scenarios extracted from UML models
C. Murray Woodside, Dorina C. Petriu, Dorin Bogdan Petriu, Jing Xu 0024, Tauseef A. Israr, Geri Georg, Robert B. France, James M. Bieman, Siv Hilde Houmb, Jan Jürjens |
J. Syst. Softw. | 10 |
| 2008 | Automated Analysis of Permission-Based Security Using UMLsec
Jan Jürjens, Jörg Schreck, Yijun Yu 0001 |
FASE | 1 |
| 2008 | Rubacon: automated support for model-based compliance engineeringabstractCompliance frameworks, laws and regulations such as Sarbanes Oxley, Basel II, Solvency II, HIPAA etc. demand from companies in a more and more rigorous way to demonstrate that their organisation, processes and supporting IT landscape implement and follow a set of guidelines at differing levels of abstraction. The work presented in this paper aims to contribute to a software engineering process which is driven by security, risk and compliance management considerations. Sebastian Höhn, Jan Jürjens |
ICSE | 2 |
| 2008 | Model-based security analysis for mobile communicationsabstractMobile communication systems are increasingly used in companies. In order to make these applications secure, the security analysis has to be an integral part of the system design and IT management process for such mobile communication systems. This work presents the experiences and results from the security analysis of a mobile system architecture at a large German telecommunications company, by making use of an approach to Model-based Security Engineering that is based on the UML extension UMLsec. The focus lies on the security mechanisms and security policies of the mobile applications which were analyzed using the UMLsec method and tools. Main results of the paper include a field report on the employment of the UMLsec method in an industrial telecommunications context as well as indications of its benefits and limitations. Jan Jürjens, Jörg Schreck, Peter Bartmann |
ICSE | 1 |
| 2008 | Traceability for the maintenance of secure softwareabstractTraceability links among different software engineering artifacts make explicit how a software system was implemented to accommodate its requirements. For secure and dependable software system development, one must ensure the linked entities are truly traceable to each other and the links are updated to reflect true traceability among changed entities. However, traditional traceability relationships link recovery techniques are not accurate enough. To address this problem, we propose a traceability technique based on refactoring, which is then continuously integrated with other software maintenance activities. Applying our traceability technique to the proven SSL protocol design, we found a significant vulnerability bug in its open-source implementation. The results also demonstrate the level of accuracy and change resilience of our technique that enable reuse of the traceability-related analysis on different implementations. Yijun Yu 0001, Jan Jürjens, John Mylopoulos |
ICSM | 2 |
| 2008 | Evaluating the Reference and Representation of Domain Concepts in APIsabstractAs libraries are the most widespread form of software reuse, the usability of their APIs substantially influences the productivity of programmers in all software development phases. In this paper we develop a framework to characterize domain-specific APIs along two directions: 1) how can the API users reference the domain concepts implemented by the API; 2) how are the domain concepts internally represented in the API. We define metrics that allow the API developer for example to assess the conceptual complexity of his API and the non-uniformity and ambiguities introduced by the API's internal representations of domain concepts, which makes developing and maintaining software that uses the library difficult and error-prone. The aim is to be able to predict these difficulties already during the development of the API, and based on this feedback be able to develop better APIs up front, which will reduce the risks of these difficulties later. Daniel Ratiu, Jan Jürjens |
ICPC | 2 |
| 2008 | Tools for Traceability in Secure Software DevelopmentabstractFor secure and dependable software system development, one must ensure that security requirements are truly traceable to design and implementation, and the traceability links can be updated accordingly to changed entities. To address this, we present a suite of security requirements analysis and traceability assurance tools and demonstrate how they are effectively integrated. Yijun Yu 0001, Jan Jürjens, Jörg Schreck |
ASE | 2 |
| 2008 | Model-Based Quality Assurance of Automotive Software
Jan Jürjens, Daniel Reiß, David Trachtenherz |
MoDELS | 1 |
| 2008 | Model-Based Run-Time Checking of Security Permissions Using Guarded Objects
Jan Jürjens |
RV | 1 |
| 2007 | Model-Based Security Engineering of Distributed Information Systems Using UMLsecabstractGiven the explosive growth of digitally stored information in modern enterprises, distributed information systems together with search engines are increasingly used in companies. By enabling the user to search all relevant information sources with one single query, however, crucial risks concerning information security arise. In order to make these applications secure, it is not sufficient to penetrate- and-patch past system development, but security analysis has to be an integral part of the system design process for such distributed information systems. This work presents the experiences and results of the security analysis of a search engine in the intranet of a German car manufacturer, by making use of an approach to model-based security engineering that is based on the UML extension UMLsec. The focus lies on the application's single-sign-on-mechanism, which was analyzed using the UMLsec method and tools. Main results of the paper include afield report on the employment of the UMLsec method in an industrial context as well as indications on its benefits and limitations. Bastian Best, Jan Jürjens, Bashar Nuseibeh |
ICSE | 2 |
| 2007 | Tools for model-based security engineering: models vs. codeabstractWe present tools to support model-based security engineering at both the model and the code level. In the approach supported by these tools, one firstly specifies the security-critical part of the system (e.g. a crypto protocol) using the UML security extension UMLsec. The models are automatically verified for security properties using automated theorem provers. These are implemented within a framework that supports implementing verification routines, based on XMI output of the diagrams from UML CASE tools. Advanced users can use this open-source framework to implement verification routines for the constraints of self-defined security requirement Jan Jürjens, Yijun Yu 0001 |
ASE | 1 |
| 2007 | Tools for secure systems development with UML
Jan Jürjens, Pasha Shabalin |
Int. J. Softw. Tools Technol. Transf. | 1 |
| 2006 | Towards a Comprehensive Framework for Secure Systems Development
Haralambos Mouratidis, Jan Jürjens, Jorge Fox |
CAiSE | 2 |
| 2006 | Model-Based Security Engineering for Real
Jan Jürjens |
FM | 1 |
| 2006 | Tools for model-based security engineeringabstractWe present tool-support for checking UML models and C code against security requirements. A framework supports implementing verification routines, based on XMI output of the diagrams from UML CASE tools, and on control flow generated from the C code. The tool also supports weaving security aspects into the code generated from the models. Advanced users can use this open-source framework to implement verification routines for the constraints of self-defined security requirements. We focus on a verification routine that automatically verifies crypto-based software for security requirements by using automated theorem provers. Jan Jürjens, Jorge Fox |
ICSE | 1 |
| 2006 | Security Analysis of Crypto-based Java Programs using Automated Theorem ProversabstractDetermining the security properties satisfied by software using cryptography is difficult: Security requirements such as secrecy, integrity and authenticity of data are notoriously hard to establish, especially in the context of cryptographic interactions. Nevertheless, little attention has been paid so far to the verification of such implementations with respect to the secure use of cryptography. We propose an approach to use automated theorem provers for first-order logic to formally verify crypto-based Java implementations, based on control flow graphs. It supports an abstract and modular security analysis by using assertions in the source code. Thus large software systems can be divided into small parts for which a formal security analysis can be performed more easily and the results composed. The assertions are validated against the program behavior in a run-time analysis. Our approach is supported by the tool JavaSec available as open-source and validated in an application to a Java Card implementation of the Common Electronic Purse Specifications and the Java implementation Jessie of SSL Jan Jürjens |
ASE | 1 |
| 2006 | Model-Based Security Engineering
Jan Jürjens |
SECRYPT | 1 |
| 2005 | Code Security Analysis of a Biometric Authentication System Using Automated Theorem ProversabstractUnderstanding the security goals provided by cryptographic protocol implementations is known to be difficult, since security requirements such as secrecy, integrity and authenticity of data are notoriously hard to establish, especially in the context of cryptographic interactions. A lot of research has been devoted to developing formal techniques to analyze abstract specifications of cryptographic protocols. Less attention has been paid to the analysis of cryptoprotocol implementations, for which a formal link to specifications is often not available. In this paper, we apply an approach to determine security goals provided by a C implementation to an industrially-strength biometric authentication system. Our approach is based on control flow graphs and automated theorem provers for first-order logic Jan Jürjens |
ACSAC | 1 |
| 2005 | Tools for Secure Systems Development with UML: Security Analysis with ATPs
Jan Jürjens, Pasha Shabalin |
FASE | 1 |
| 2005 | Cost-Benefit Trade-Off Analysis Using BBN for Aspect-Oriented Risk-Driven DevelopmentabstractSecurity critical systems must perform at the required security level, make effective use of available resources, and meet end-users expectations. Balancing these needs, and at the same time fulfilling budget and time-to-market constraints, requires developers to design and evaluate alternative security treatment strategies. In this paper, the authors presented a development framework that utilizes Bayesian belief networks (BBN) and aspect-oriented modeling (AOM) for a cost-benefit trade-off analysis of treatment strategies. AOM allows developers to model pervasive security treatments separately from other system functionality. This eases the trade-off by making it possible to swap treatment strategies in and out when computing return on security investments (RoSI). The trade-off analysis is implemented using BBN, and RoSI is computed by estimating a set of variables describing properties of a treatment strategy. RoSI for each treatment strategy is then used as input to choice of design. Siv Hilde Houmb, Geri Georg, Robert B. France, James M. Bieman, Jan Jürjens |
ICECCS | 5 |
| 2005 | Model-Based Design and Analysis of Permission-Based SecurityabstractTo guarantee the security of computer systems, it is necessary to define security permissions to restrict the access to the systems' resources. These permissions rely on certain restrictions based on the workflows the system is designed for. It is not always easy to see if workflows and the design of the security permissions for the system fit together. We address this problem using an approach which embeds security permissions in UML models and supports model-based security analysis by providing consistency checks. The presented formal framework also prepares the ground for an automated analysis of underlying protocols for managing security-critical permissions, for example with the help of first-order logic theorem proving. We explain how the models can be securely implemented in a language such as Java. Jan Jürjens, Markus Lehrhuber, Guido Wimmel |
ICECCS | 1 |
| 2005 | Sound methods and effective tools for model-based security engineering with UMLabstractDeveloping security-critical systems is difficult and there are many well-known examples of security weaknesses exploited in practice. Thus a sound methodology supporting secure systems development is urgently needed.We present an extensible verification framework for verifying UML models for security requirements. In particular, it includes various plugins performing different security analyses on models of the security extension UMLsec of UML. Here, we concentrate on an automated theorem prover binding to verify security properties of UMLsec models which make use of cryptography (such as cryptographic protocols). The work aims to contribute towards usage of UML for secure systems development in practice by offering automated analysis routines connected to popular CASE tools. We present an example of such an application where our approach found and corrected several serious design flaws in an industrial biometric authentication system. Jan Jürjens |
ICSE | 1 |
| 2005 | Understanding Security Goals Provided by Crypto-Protocol ImplementationsabstractUnderstanding the security goals provided by cryptographic protocol implementations is known to be difficult, since security requirements such as secrecy, integrity and authenticity of data are notoriously hard to establish, especially in the presence of cryptographic interactions. A lot of research has been devoted to develop formal techniques to analyze abstract specifications of cryptographic protocols. Less attention has been paid to the source code analysis of legacy crypto-protocol implementations, for which specifications are often not available. This is an important challenge since it is non-trivial to determine from a given protocol implementation exactly which security goals are achieved, which is necessary for a reliable maintenance of security-critical systems. In this paper, we propose an approach to determine security goals provided by an implemented protocol based on control flow graphs and automated theorem provers for first-order logic. Jan Jürjens |
ICSM | 1 |
| 2005 | Code security analysis with assertionsabstractDesigning and implementing cryptographic protocols is known to be difficult. A lot of research has been devoted to develop formal techniques to analyze abstract designs of cryptographic protocols. Less attention has been paid to the verification of implementation-relevant aspects of cryptographic protocols. This is an important challenge since it is non-trivial to securely implement secure designs, because a specification by its nature is more abstract than the corresponding implementation, and the additional information may introduce attacks not present on the design level. We propose an approach to determine security goals provided by a protocol implementation based on control flow graphs and automated theorem provers for first-order logic. More specifically, here we explain how to make use of assertions in the source code for a practical and efficient security analysis. Jan Jürjens, Mark Yampolskiy |
ASE | 1 |
| 2005 | Verification of low-level crypto-protocol implementations using automated theorem provingabstractDesigning and implementing cryptographic protocols is known to be difficult. A lot of research has been devoted to developing formal techniques to analyze abstract designs of cryptographic protocols. Less attention has been paid to the verification of implementation-relevant aspects of cryptographic protocols. This is an important challenge since it is non-trivial to securely implement secure designs, because a specification by its nature is more abstract than the corresponding implementation, and the additional information may introduce attacks not present on the design level. In this paper, we address aspects of crypto protocol implementations close to the hardware level. More concretely, we consider the industrial cryptographic token interface standard PKCS 11 which defines how software on untrustworthy hardware can make use of tamper-proof hardware such as smart-cards to perform cryptographic operations on sensitive data. We propose an approach for automated security analysis with first-order logic theorem provers of crypto protocol implementations making use of this standard. Jan Jürjens |
MEMOCODE | 1 |
| 2004 | Sound development of secure service-based systemsabstractService-based software systems are a useful concept recently developed to support the development of systems offering functions (the so-called services) which may be interrelated or may mutually depend on each other. Although appealing from a practical point of view, the development of service-based software for security-critical systems is, unfortunately, not well understood. Services may easily interact with each other in a way which may have unforeseen consequences on the various security properties provided. In this work, we propose a method for facilitating the development of security-critical service-based software systems using the computer-aided systems engineering tool AutoFocus based on the formal method Focus. We explain our method at the example of a service-based system from the automotive domain. Martin R. Deubler, Johannes Grünbauer, Jan Jürjens, Guido Wimmel |
ICSOC | 3 |
| 2003 | Developing Secure Networked Web-Based Systems Using Model-based Risk Assessment and UMLsecabstractDespite a growing awareness of security issues in networked computing systems, most development processes used today still do not take security aspects into account. To address this problem, we designed a process for developing secure networked systems based on the extension of the Unified Modeling Language (UML) for secure systems development UMLsec and on the concept of model-based risk assessment (MBRA). Enterprise information such as security policies, business goals, policies and processes are supported through activities in the model-based integrated development process. These are then refined to security requirements at a more technical level, which can be expressed using UMLsec, and which can be analysed mechanically using the tool-support for UMLsec. Siv Hilde Houmb, Jan Jürjens |
APSEC | 2 |
| 2003 | Security-Critical System Development with Extended Use CasesabstractDue to increasing interconnection, IT systems are confronted with more and more attacks. To address this problem, we have to consider security requirements from the beginning of the system development. In early phases of system development, it is common to use a hybrid system view which is based on an object oriented modeling of the application core and the specification of use cases. We present an extension of this process for security-critical systems. We show a methodical approach for the development of security-critical systems and the modeling of security aspects in the application core with an extension of the Unified Modeling Language for secure systems development, UMLsec. Furthermore, we introduce security use cases for the development of security aspects in conjunction with behavioral modeling. Gerhard Popp, Jan Jürjens, Guido Wimmel, Ruth Breu |
APSEC | 2 |
| 2003 | Modelling and Verification of Layered Security Protocols: A Bank Application
Johannes Grünbauer, Helia Hollmann, Jan Jürjens, Guido Wimmel |
SAFECOMP | 3 |
| 2003 | Critical Systems Development with UML: Overview with Automatic Case Study
Jan Jürjens, Johannes Grünbauer |
SNPD | 1 |
| 2002 | Specification-Based Test Generation for Security-Critical Systems Using Mutations
Guido Wimmel, Jan Jürjens |
ICFEM | 2 |
| 2001 | Towards Development of Secure Systems Using UMLsec
Jan Jürjens |
FASE | 1 |
| 2001 | Formally Testing Fail-Safety of Electronic Purse ProtocolsabstractDesigning and implementing security-critical systems correctly is difficult. In practice, most vulnerabilities arise from bugs in implementations. We present work towards systematic specification-based testing of security-critical systems using the CASE tool AutoFocus. Cryptographic systems are formally specified with state transition diagrams, a notation for state machines in the AutoFocus system., We show how to systematically generate test sequences for security properties based on the model that can be used to test the implementation for vulnerabilities. In particular we focus on the principle of fail-safety. We explain our method at the example of a part of the Common Electronic Purse Specifications (CEPS). Most commonly, attacks address vulnerabilities in the way security mechanisms are used, rather than the mechanisms themselves. Being able to treat security aspects with a general CASE tool within the context of system development enables detection of such vulnerabilities. Jan Jürjens, Guido Wimmel |
ASE | 1 |
| 2001 | Modelling Audit Security for Smart-Cart Payment Schemes with UML-SEC
Jan Jürjens |
SEC | 1 |
| 2000 | Secure Information Flow for Concurrent Processes
Jan Jürjens |
CONCUR | 1 |