EDBT 2026 Demo / reviewers in the wild / expert
Ulrike Lechner
dblp:01/4857
· DBLP profile ↗
34ranked-venue papers
2as first author
23since 2021 · last 2025
0000-0002-4286-3184ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 14 · 14 since 2021Security and privacy · 11 · 5 since 2021Software engineering, systems software and programming languages · 6 · 2 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The Blockchain Governance Laboratory: Demonstrating an Environment for Hands-on Blockchain Governance Research
Jan Biermann, Maximilian Greiner, Karl Seidenfad, Tobias Fertig, Ulrike Lechner |
ICBC | 5 |
| 2025 | Cybersecurity Awareness Education by Making Ransomware Tangible Securely - The Beginning
Günter Fahrnberger, Maximilian Greiner, Stefan Hofbauer, Ulrike Lechner, Andreas Seiler, Judith Strussenberg, Philipp Wolf 0001 |
I4CS | 4 |
| 2025 | The Digital Product Supply Chain: Demonstrating Digital Sovereignty in Real-World Scenarios
Razvan Hrestic, Manfred Hofmeier, Ulrike Lechner |
I4CS | 3 |
| 2025 | Bring Your Own Bug: Enabling User-Generated Content in Serious Games for Industrial Cybersecurity and AppSec Education
Andrei-Cristian Iosif, Ulrike Lechner, Maria Pinto-Albuquerque |
I4CS | 2 |
| 2025 | Designing and Implementing an Educational Game for Cyber Planning Building on Cyberspace's Layers
Andreas Kornmaier, Marko A. Hofmann, Ulrike Lechner |
I4CS | 3 |
| 2025 | A Simulation-Oriented Approach to Securing Logistics Processes Based on the NIST CSF and OODA Loop
Larissa Schachenhofer, Gregor Langner, Gerald Quirchmayr, Philipp Wolf 0001, Patrick Hirsch, Stefan Schauer, Ulrike Lechner, Günter Fahrnberger |
I4CS | 7 |
| 2025 | From Paper to Pixel: The Digitalization of a Serious Game
Judith Strussenberg, Karl Seidenfad, Maximilian Greiner, Kevin Riesel, Jan Biermann, Ulrike Lechner |
I4CS | 6 |
| 2024 | NEWSROOM: Towards Automating Cyber Situational Awareness Processes and Tools for Cyber DefenceabstractCyber Situational Awareness (CSA) is an important element in both cyber security and cyber defence to inform processes and activities on strategic, tactical, and operational level. Furthermore, CSA enables informed decision making. The ongoing digitization and interconnection of previously unconnected components and sectors equally affects the civilian and military sector. In defence, this means that the cyber domain is both a separate military domain as well as a cross-domain and connecting element for the other military domains comprising land, air, sea, and space. Therefore, CSA must support perception, comprehension, and projection of events in the cyber space for persons with different roles and expertise. This paper introduces NEWSROOM, a research initiative to improve technologies, methods, and processes specifically related to CSA in cyber defence. For this purpose, NEWSROOM aims to improve methods for attacker behavior classification, cyber threat intelligence (CTI) collection and interaction, secure information access and sharing, as well as human computer interfaces (HCI) and visualizations to provide persons with different roles and expertise with accurate and easy to comprehend mission- and situation-specific CSA. Eventually, NEWSROOM’s core objective is to enable informed and fast decision-making in stressful situations of military operations. The paper outlines the concept of NEWSROOM and explains how its components can be applied in relevant application scenarios. Markus Wurzenberger, Stephan Krenn, Max Landauer, Florian Skopik, Cora Lisa Perner, Jarno Lötjönen, Jani Päijänen, Georgios Gardikis, Nikos Alabasis, Liisa Sakerman, Kristiina Omri, Juha Röning, Kimmo Halunen, Vincent Thouvenot, Martin Weise, Andreas Rauber, Vasileios Gkioulos, Sokratis K. Katsikas, Luigi Sabetta, Jacopo Bonato, Rocío Ortíz, Daniel Navarro, Nikolaos Stamatelatos, Ioannis Avdoulas, Rudolf Mayer, Andreas Ekelhart, Ioannis Giannoulakis, Emmanouil Kafetzakis, Antonello Corsi, Ulrike Lechner, Corinna Schmitt |
ARES | 30 |
| 2024 | Serious Game for Industrial Cybersecurity: Experiential Learning Through Code ReviewabstractEvery stage of the industrial software development process is crucial for ensuring high-quality results in a time of increasing digitalization and complexity. Code review is a method to enhance software quality and also promote knowledge exchange among teams. It is generally accepted that the earlier that software bugs and vulnerabilities are caught during product development, the more costs can be saved. As such, code review can play an important role in industrial software development. However, industry experience showcases that code review can be resource-intensive, and the direct impact on code quality can be hard to quantify. Related work shows that practitioners performing code reviews do not focus specifically on security, partly due to a gap in awareness of the topic. Our research focuses on improving the efficiency and effectiveness of code review practices, particularly in identifying and addressing security issues in an industrial context. The present work showcases results from using a serious game as a means to empower developers, by exhibiting code review best practices and raising awareness of security concerns. We collect results over a series of 11 experiments conducted in an industrial setting together with a total of 175 industrial practitioners, serving as a pilot stage, based on which we discuss and conclude on important aspects of the design of the game. Andrei-Cristian Iosif, Ulrike Lechner, Maria Pinto-Albuquerque, Tiago Gasiba |
CSEE&T | 2 |
| 2024 | Thriving in the era of Hybrid Work: Raising Cybersecurity Awareness using Serious Games in Industry TrainingsabstractModern software engineering education aims to prepare software engineers for hybrid work environments. The shift to work-from-home (WFH) or work-from-anywhere (WFA) has increased the importance of cybersecurity. An industrial case study revealed that raising awareness is crucial. We developed two serious games, CyberSecurity Challenges (CSC) and Cloud of Assets and Threats (CATS) to enhance cybersecurity training. These games empower practitioners to address hybrid work challenges while ensuring secure software development and cloud security. Empirical evidence supports the effectiveness of serious games in raising awareness among software professionals. Tiange Zhao, Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque |
CSEE&T | 3 |
| 2024 | A Deep Dive Into CATS Evaluator Algorithm: Quantification Of The Probability in Serious Game Cloud Security Defense ScenariosabstractCloud deployment has become increasingly common due to its flexibility and business value. However, cloud assets face cybersecurity challenges and need to be configured securely. Industry practitioners must be trained to understand key con-cepts in cloud security, including ‘defense & attack’ and ‘roles & responsibilities.’ A serious game provides an engaging and helpful way to convey such messages. This work introduces the core evaluator algorithm developed for Cloud of Asset and Threats (CATS), a serious game designed to enhance cloud security awareness. This work builds upon our previous efforts, focusing on refining the Evaluator algorithm that quantifies the probabilities of the defender strategies as defined by the players to prevent a given attack vector from being successful. We present the results collected from industry training events where the refined algorithm was incorporated into CATS and compare them to the initial implementation. The promising results indicate that with the refinement of the evaluator algorithm, more elements derived from reality are addressed, and the game maintains a similar difficulty level for participants. Tiange Zhao, Didem Ongu, Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque |
CSEE&T | 4 |
| 2024 | Digital Sovereignty and Open-Source Software - A Discussion Paper
John Bechara, Ulrike Lechner |
I4CS | 2 |
| 2024 | The Digital Product Passport: Enabling Interoperable Information Flows Through Blockchain Consortia for Sustainability
Maximilian Greiner, Karl Seidenfad, Christoph Langewisch, Andreas Hofmann, Ulrike Lechner |
I4CS | 5 |
| 2024 | Scared? Prepared? Toward a Ransomware Incident Response Scenario
Maximilian Greiner, Judith Strussenberg, Andreas Seiler, Stefan Hofbauer, Michael Schuster, Damian Stano, Günter Fahrnberger, Stefan Schauer, Ulrike Lechner |
I4CS | 9 |
| 2024 | Greenhouse Gas Emissions as Commons: A Community Service Approach with Blockchain on the Edge
Karl Seidenfad, Maximilian Greiner, Jan Biermann, David Dannenberg, Sven Keineke, Ulrike Lechner |
I4CS | 6 |
| 2024 | Operation Raven - Design of a Cyber Security Incident Response Game
Andreas Seiler, Ulrike Lechner, Judith Strussenberg, Stefan Hofbauer |
I4CS | 2 |
| 2024 | COPYCAT: Applying Serious Games in Industry for Defending Supply Chain Attack
Tiange Zhao, Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque, Didem Ongu |
I4CS | 3 |
| 2024 | Thriving in the era of hybrid work: Raising cybersecurity awareness using serious games in industry trainings
Tiange Zhao, Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque |
J. Syst. Softw. | 3 |
| 2023 | CarbonEdge: Demonstrating Blockchain-Based Monitoring, Reporting and Verification of Greenhouse Gas Emissions on the EdgeabstractRaising ambition inside the Paris Agreement calls for collaboration on climate action. Efficient a nd trustworthy monitoring, reporting and verification (MRV) of greenhouse gas (GHG) emissions is important in decarbonization efforts. This article proposes a collaborative approach, and exemplifies two scenarios in MRV. Therefore, we propose a consortium blockchain as platform, and aim on the reduction of costs and efforts by collaboration and automation of different aspects in GHG management. We present a demonstrator with Hyperledger Fabric, which employs a industry grade RFID security approach to distribute and manage certificate material, a low-code interface to interact with the network, and the operation of Fabric nodes on industrial edge devices. We argue that a toolkit approach like CarbonEdge may be a step towards ease of use for blockchain based GHG emissions management. Karl Seidenfad, Jan Biermann, Ulrike Lechner |
ICBC | 3 |
| 2023 | CarbonEdge: Collaborative Blockchain-Based Monitoring, Reporting, and Verification of Greenhouse Gas Emissions on the Edge
Karl Seidenfad, Maximilian Greiner, Jan Biermann, Ulrike Lechner |
I4CS | 4 |
| 2022 | Towards a Layer Model for Digital Sovereignty: A Holistic Approach
Isabelle Fries, Maximilian Greiner, Manfred Hofmeier, Razvan Hrestic, Ulrike Lechner, Thomas Wendeborn |
CRITIS | 5 |
| 2022 | Demonstrating Feasibility of Blockchain-Driven Carbon Accounting - A Design Study and Demonstrator
Karl Seidenfad, Tobias Wagner 0003, Razvan Hrestic, Ulrike Lechner |
I4CS | 4 |
| 2021 | Raising Security Awareness of Cloud Deployments using Infrastructure as Code through CyberSecurity ChallengesabstractImproper deployment of software can have serious consequences, ranging from simple downtime to permanent data loss and data breaches. Infrastructure as Code tools serve to streamline delivery by promising consistency and speed, by abstracting away from the underlying actions. However, this simplicity may distract from architectural or configuration faults, potentially compromising the secure development lifecycle. One way to address this issue involves awareness training. Sifu is a platform that provides education on security through serious games, developed in the industry, for the industry. The presented work extends the Sifu platform with challenges addressing Terraform-aided cloud deployment on Amazon Web Services. This paper proposes an evaluation pipeline behind the challenges, and provides details of the vulnerability detection and feedback mechanisms, as well as a novel technique for detecting undesired differences between a given architecture and a target result. Furthermore, this paper quantifies the challenges’ perceived usefulness and impact, by evaluating the challenges among a total of twelve participants. Our preliminary results show that the challenges are suitable for education and the industry, with potential usage in internal training. A key finding is that, although the participants understand the importance of secure coding, their answers indicate that universities leave them unprepared in this area. Finally, our results are compared with related industry works, to extract and provide good practices and advice for practitioners. Tiago Gasiba, Andrei-Cristian Iosif, Ulrike Lechner, Maria Pinto-Albuquerque |
ARES | 3 |
| 2020 | Awareness of Secure Coding Guidelines in the Industry - A first data analysisabstractSoftware needs to be secure, in particular, when deployed to critical infrastructures. Secure coding guidelines capture practices in industrial software engineering to ensure the security of code. This study aims to assess the level of awareness of secure coding in industrial software engineering, the skills of software developers to spot weaknesses in software code, avoid them, and the organizational support to adhere to coding guidelines. The approach draws on well-established theories of policy compliance, neutralization theory, and security-related stress and the authors' many years of experience in industrial software engineering and on lessons identified from training secure coding in the industry. The paper presents the questionnaire design for the online survey and the first analysis of data from the pilot study. Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque, Daniel Méndez 0001 |
TrustCom | 2 |
| 2020 | Sifu - a cybersecurity awareness platform with challenge assessment and intelligent coachabstractAbstract Software vulnerabilities, when actively exploited by malicious parties, can lead to catastrophic consequences. Proper handling of software vulnerabilities is essential in the industrial context, particularly when the software is deployed in critical infrastructures. Therefore, several industrial standards mandate secure coding guidelines and industrial software developers’ training, as software quality is a significant contributor to secure software. CyberSecurity Challenges (CSC) form a method that combines serious game techniques with cybersecurity and secure coding guidelines to raise secure coding awareness of software developers in the industry. These cybersecurity awareness events have been used with success in industrial environments. However, until now, these coached events took place on-site. In the present work, we briefly introduce cybersecurity challenges and propose a novel platform that allows these events to take place online. The introduced cybersecurity awareness platform, which the authors call Sifu, performs automatic assessment of challenges in compliance to secure coding guidelines, and uses an artificial intelligence method to provide players with solution-guiding hints. Furthermore, due to its characteristics, the Sifu platform allows for remote (online) learning, in times of social distancing. The CyberSecurity Challenges events based on the Sifu platform were evaluated during four online real-life CSC events. We report on three surveys showing that the Sifu platform’s CSC events are adequate to raise industry software developers awareness on secure coding. Tiago Gasiba, Ulrike Lechner, Maria Pinto-Albuquerque |
Cybersecur. | 2 |
| 2019 | Towards an Integration of Information Security Management, Risk Management and Enterprise Architecture Management - A Literature ReviewabstractOrganizations are faced with an increased number of security-related challenges. Our research interest is on information security matters with our proposition being that enterprise architecture management (EAM) can support risk management (RM) and information security management (ISM) for instance by providing a plethora of information about an organization's information assets. We conducted a literature review, which underlines our proposition. The pivotal question we aim to answer is how EAM, RM and ISM efforts can be integrated for "the greater good", i.e., to achieve a facilitation of RM and ISM through the adoption of EAM. As a result, we present an integrated conceptual model which places our findings in the context of the well-established concepts defined in ISO-27001, ISO-31000 and ISO-42010. Thomas Diefenbach, Carsten Lucke, Ulrike Lechner |
CloudCom | 3 |
| 2017 | Cybersecurity Ontology for Critical Infrastructures
Sandra Bergner, Ulrike Lechner |
KEOD | 2 |
| 2016 | An Operator-Driven Approach for Modeling Interdependencies in Critical Infrastructures Based on Critical Services and Sectors
Elisa Canzani, Helmut Kaufmann, Ulrike Lechner |
CRITIS | 3 |
| 2016 | Towards a Cybersecurity Game: Operation Digital Chameleon
Andreas Rieb, Ulrike Lechner |
CRITIS | 2 |
| 2016 | A Threat Analysis Model for Identity and Access Management
Nadia Jemil Abdu, Ulrike Lechner |
ICISSP | 2 |
| 2016 | A Cyberthreat Search Process and Service
Yogesh Bhanu, Sebastian Dännart, Henning von Kielpinski, Alexander Laux, Ulrike Lechner, Tobias Lehmann, Andreas Rieb, Martin Riedl 0001, Florian Wolf 0005 |
ICISSP | 5 |
| 2016 | Operation Digital Chameleon: Towards an Open Cybersecurity MethodabstractIn the Serious Game Operation Digital Chameleon red and blue teams develop attack and defense strategies to explore IT-Security of Critical Infrastructures as part of an IT-Security training. Operation Digital Chameleon is the training game of the IT-Security Matchplay series in the IT-Security for Critical Infrastructure research program funded by BMBF. We present the design of Operation Digital Chameleon in its current form as well as results from game #3. We analyze the potential and innovation capability of Operation Digital Chameleon as an Open Innovation method for the domain of IT-Security of Critical Infrastructures. We find that Operation Digital Chamaeleon facilitates creativity, opens the process of IT-Security strategy development and --despite being designed for training purposes -- opens the process to explore innovative attack vectors. Andreas Rieb, Ulrike Lechner |
OpenSym | 2 |
| 1998 | Constructs, Concepts and Criteria for Reuse in Concurrent Object-Oriented languages
Ulrike Lechner |
FASE | 1 |
| 1996 | (Objects + Concurrency) & Reusability - A Proposal to Circumvent the Inheritance Anomaly
Ulrike Lechner, Christian Lengauer, Friederike Nickl, Martin Wirsing |
ECOOP | 1 |