EDBT 2026 Demo / reviewers in the wild / expert
Mark Strembeck
dblp:05/6430
· DBLP profile ↗
36ranked-venue papers
3as first author
5since 2021 · last 2023
0000-0003-1680-9296ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 13 · 2 first-authorSecurity and privacy · 9 · 1 first-authorTheory of computation · 9 · 5 since 2021Databases, data management, data science and information retrieval · 4Artificial intelligence and machine learning · 3Human-computer interaction and ubiquitous computing · 2Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Mainstream and Alternative Narratives in the Wake of Gun Shootings
Lisa Grobelscheg, Ema Kusen, Mark Strembeck |
COMPLEXIS | 3 |
| 2023 | An Analysis of Twitter Communities Related to the 2022 War in Ukraine
Karolina Sliwa, Ema Kusen, Mark Strembeck |
COMPLEXIS | 3 |
| 2022 | Automated Narratives: On the Influence of Bots in Narratives during the 2020 Vienna Terror Attack
Lisa Grobelscheg, Ema Kusen, Mark Strembeck |
COMPLEXIS | 3 |
| 2022 | Dynamics of Personal Responses to Terror Attacks: A Temporal Network Analysis Perspective
Ema Kusen, Mark Strembeck |
COMPLEXIS | 2 |
| 2021 | Structural Similarities of Emotion-exchange Networks: Evidence from 18 Crisis EventsabstractOnline social networks (OSNs) play a significant role during crisis events by offering a convenient channel for information seeking, social bonding, and opinion sharing. In this context, people express their fear, panic, shock, as well as gratitude, well-wishing, and empathy as a crisis event evolves over time. Though emotional responses during crisis events have been studied both in offline and online settings, it is yet unclear which communication structures are representative for the exchange of specific types of emotions. In this paper, we report on new findings which indicate that not all negative emotions are exchanged in the same way. In particular, we used emotion-exchange motifs to compare the structure of emotion-annotated communication networks that resulted from 18 crisis events. Our findings clearly indicate that 1) exchanges of sadness on the one hand, and joy/love on the other show more structural similarity than any other pair of emotions, 2) emotion-exchange networks can be clustered into two families, each of which includes different types of emotions, 3) membership in the two families of emotion-exchange networks fluctuates over time. A related data-set is available for download from IEEE DataPort, DOI: 10.21227/yajb-6y77. Ema Kusen, Mark Strembeck |
COMPLEXIS | 2 |
| 2020 | You talkin' to me? Exploring Human/Bot Communication Patterns during Riot Events
Ema Kusen, Mark Strembeck |
Inf. Process. Manag. | 2 |
| 2019 | A Generalized Notion of Time for Modeling Temporal NetworksabstractMost approaches for modeling and analyzing temporal networks do not explicitly discuss the underlying notion of time. In this paper, we therefore introduce a generalized notion of time for temporal networks. Our approach also allows for considering non-deterministic time and incomplete data, two issues that are often found when analyzing data-sets extracted from online social networks, for example. In order to demonstrate the consequences of our generalized notion of time, we also discuss the implications for the computation of (shortest) temporal paths in temporal networks. Konstantin Kueffner, Mark Strembeck |
COMPLEXIS | 2 |
| 2019 | An Analysis of Three Legal Citation Networks Derived from Austrian Supreme Court DecisionsabstractIn this paper, we present a case study on the structural properties of three citations networks derived from Austrian Supreme Court decisions. In particular, we analyzed 250.984 Supreme Court decisions ranging from 1922 to 2017. As part of our case study, we analyzed the degree distributions, the structural properties of prominent court decisions, as well as changes in the frequency of legal citations over time. Markus Moser, Mark Strembeck |
COMPLEXIS | 2 |
| 2018 | On Message Exchange Motifs Emerging During Human/Bot Interactions in Multilayer Networks: The Case of Two Riot EventsabstractIn this paper, we analyze the message exchange patterns that emerge when social bots and human users communicate via Twitter. In particular, we use a multilayer network to analyze the emergence of the corresponding representative and statistically significant sub-graphs (so called motifs). Our analysis is based on two recent riot events, namely the Philadelphia Super-bowl 2018 riots and the 2017 G20 riots in Hamburg (Germany). We found that in these two events message exchanges between humans form characteristic and re-occurring communication patterns. In contrast, message exchanges including bots occur rather sporadically and do not follow a particular statistically significant pattern. Ema Kusen, Mark Strembeck |
ASONAM | 2 |
| 2018 | Why so Emotional? An Analysis of Emotional Bot-generated Content on Twitter
Ema Kusen, Mark Strembeck |
COMPLEXIS | 2 |
| 2018 | On the Public Perception of Police Forces in Riot Events - The Role of Emotions in Three Major Social Networks During the 2017 G20 Riots
Ema Kusen, Mark Strembeck |
COMPLEXIS | 2 |
| 2017 | On the Influence of Emotional Valence Shifts on the Spread of Information in Social NetworksabstractIn this paper, we present a study on 4.4 million Twitter messages related to 24 systematically chosen real-world events. For each of the 4.4 million tweets, we first extracted sentiment scores based on the eight basic emotions according to Plutchik's wheel of emotions. Subsequently, we investigated the effects of shifts in the emotional valence on the spread of information. We found that in general OSN users tend to conform to the emotional valence of the respective real-world event. However, we also found empirical evidence that prospectively negative real-world events exhibit a significant amount of shifted emotions in the corresponding tweets (i.e. positive messages). To explain this finding, we use the theory of social connection and emotional contagion. To the best of our knowledge, this is the first study that provides empirical evidence for the undoing hypothesis in online social networks (OSNs). The undoing hypothesis postulates that positive emotions serve as an antidote during negative events. Ema Kusen, Mark Strembeck, Giuseppe Cascavilla, Mauro Conti |
ASONAM | 2 |
| 2017 | Reusable and generic design decisions for developing UML-based domain-specific languages
Bernhard Hoisl, Stefan Sobernig, Mark Strembeck |
Inf. Softw. Technol. | 3 |
| 2016 | Extracting reusable design decisions for UML-based domain-specific languages: A multi-method study
Stefan Sobernig, Bernhard Hoisl, Mark Strembeck |
J. Syst. Softw. | 3 |
| 2015 | A Discussion of Communication Schemes for Process Execution Histories to Enforce Entailment Constraints in Process-Driven SOAsabstractA distributed business process is executed in a distributed computing environment. In this context, the service-oriented architecture (SOA) paradigm provides a mature and well-understood framework for the integration of software services. Entailment constraints, such as mutual exclusion or binding constraints, are an important means to specify and enforce business processes in a SOA. Process engines control the process flow and are responsible for the coordination of the services that participate in a distributed business process. Since the enforcement of entailment constraints requires knowledge of the subjects and roles who executed particular task instances, we need to communicate the execution history of the respective tasks and processes between the services and the process engines. However, the inherent concurrency of a distributed system may lead to omission failures. Such failures may impair the enforcement of entailment constraints in a process-driven SOA. In particular, the impact of these failures as well as the corresponding countermeasures depend on the architecture of the respective process engine. In this paper, we discuss communication schemes for (distributed) process execution histories in a SOA. In particular, we provide generic procedures for different communication schemes and examine the efficiency of these schemes as well as their characteristics if omission failures occur. In this context, we especially consider if the respective process engine acts as an orchestration engine or as a choreography engine. Thomas Quirchmayr, Mark Strembeck |
Comput. J. | 2 |
| 2014 | Natural-language Scenario Descriptions for Testing Core Language Models of Domain-Specific LanguagesabstractAbstract: The core language model is a central artifact of domain-specific modeling languages (DSMLs) as it captures all relevant domain abstractions and their relations. Natural-language scenarios are a means to capture require-ments in a way that can be understood by technical as well as non-technical stakeholders. In this paper, we use scenarios for the testing of structural properties of DSML core language models. In our approach, domain experts and DSML engineers specify requirements via structured natural-language scenarios. These scenario descriptions are then automatically transformed into executable test scenarios providing forward and backward traceability of domain requirements. To demonstrate the feasibility of our approach, we used Eclipse Xtext to implement a requirements language for the definition of semi-structured scenarios. Transformation specifica-tions generate executable test scenarios that run in our test platform which is built on the Eclipse Modeling Framework and the Epsilon language family. 1 Bernhard Hoisl, Stefan Sobernig, Mark Strembeck |
MODELSWARD | 3 |
| 2014 | Model-driven specification and enforcement of RBAC break-glass policies for process-aware information systems
Sigrid Schefer-Wenzl, Mark Strembeck |
Inf. Softw. Technol. | 2 |
| 2014 | Modeling and enforcing secure object flows in process-driven SOAs: an integrated model-driven approach
Bernhard Hoisl, Stefan Sobernig, Mark Strembeck |
Softw. Syst. Model. | 3 |
| 2013 | Supporting Customized Views for Enforcing Access Control Constraints in Real-Time Collaborative Web Applications
Patrick Gaubatz, Waldemar Hummer, Uwe Zdun, Mark Strembeck |
ICWE | 4 |
| 2013 | Higher-order Rewriting of Model-to-Text Templates for Integrating Domain-specific Modeling LanguagesabstractAbstract: Domain-specific modeling languages (DSMLs) are commonly used in model-driven development projects. In this context, model-to-text (M2T) transformation templates generate source code from DSML models. When integrating two (or more) DSMLs, the reuse of such templates for the composed DSML would yield a number of benefits, such as, a reduced testing and maintenance effort. However, in order to reuse the original templates for an integrated DSML, potential syntactical mismatches between the templates and the integrated metamodel must be solved. This paper proposes a technology-independent approach to template rewriting based on higher-order model transformations to address such mismatches in an automated manner. By considering M2T generator templates as first-class models and by reusing transformation traces, our approach enables syntactical template rewriting. To demonstrate the feasibility of this rewriting technique, we built a prototype for Eclipse EMF and Epsilon. 1 Bernhard Hoisl, Stefan Sobernig, Mark Strembeck |
MODELSWARD | 3 |
| 2013 | Developing a Domain-Specific Language for Scheduling in the European Energy Sector
Stefan Sobernig, Mark Strembeck |
SLE | 2 |
| 2013 | Enforcement of entailment constraints in distributed service-based business processesabstractCONTEXT: A distributed business process is executed in a distributed computing environment. The service-oriented architecture (SOA) paradigm is a popular option for the integration of software services and execution of distributed business processes. Entailment constraints, such as mutual exclusion and binding constraints, are important means to control process execution. Mutually exclusive tasks result from the division of powerful rights and responsibilities to prevent fraud and abuse. In contrast, binding constraints define that a subject who performed one task must also perform the corresponding bound task(s). OBJECTIVE: We aim to provide a model-driven approach for the specification and enforcement of task-based entailment constraints in distributed service-based business processes. METHOD: Based on a generic metamodel, we define a domain-specific language (DSL) that maps the different modeling-level artifacts to the implementation-level. The DSL integrates elements from role-based access control (RBAC) with the tasks that are performed in a business process. Process definitions are annotated using the DSL, and our software platform uses automated model transformations to produce executable WS-BPEL specifications which enforce the entailment constraints. We evaluate the impact of constraint enforcement on runtime performance for five selected service-based processes from existing literature. RESULTS: Our evaluation demonstrates that the approach correctly enforces task-based entailment constraints at runtime. The performance experiments illustrate that the runtime enforcement operates with an overhead that scales well up to the order of several ten thousand logged invocations. Using our DSL annotations, the user-defined process definition remains declarative and clean of security enforcement code. CONCLUSION: Our approach decouples the concerns of (non-technical) domain experts from technical details of entailment constraint enforcement. The developed framework integrates seamlessly with WS-BPEL and the Web services technology stack. Our prototype implementation shows the feasibility of the approach, and the evaluation points to future work and further performance optimizations. Waldemar Hummer, Patrick Gaubatz, Mark Strembeck, Uwe Zdun, Schahram Dustdar |
Inf. Softw. Technol. | 3 |
| 2013 | Bridging the gap between role mining and role engineering via migration guides
Anne Baumgraß, Mark Strembeck |
Inf. Secur. Tech. Rep. | 2 |
| 2012 | An Approach to Bridge the Gap between Role Mining and Role Engineering via Migration GuidesabstractMining approaches, such as role mining or organizational mining, can be applied to derive permissions and roles from a system's configuration or from log files. In this way, mining techniques document the current state of a system and produce current-state RBAC models. However, such current-state RBAC models most often follow from structures that have evolved over time and are not the result of a systematic rights management procedure. In contrast, role engineering is applied to define a tailored RBAC model for a particular organization or information system. Thus, role engineering techniques produce a target-state RBAC model that is customized for the business processes supported via the respective information system. The migration from a current-state RBAC model to a tailored target-state RBAC model is, however, a complex task. In this paper, we present a systematic approach to migrate current-state RBAC models to target-state RBAC models. In particular, we use model comparison techniques to identify differences between two RBAC models. Based on these differences, we derive migration rules that define which elements and element relations must be changed, added, or removed. A migration guide then includes all migration rules that need to be applied to a particular current-state RBAC model to produce the corresponding target-state RBAC model. In addition, we discuss different options for tool support and describe our implementation for the derivation of migration guides which is based on the Eclipse Modeling Framework (EMF). Anne Baumgraß, Mark Strembeck |
ARES | 2 |
| 2012 | Factors of process model comprehension - Findings from a series of experiments
Jan Mendling, Mark Strembeck, Jan Recker |
Decis. Support Syst. | 2 |
| 2011 | Comparing complexity of API designs: an exploratory experiment on DSL-based framework integrationabstractEmbedded, textual DSLs are often provided as an API wrapped around object-oriented application frameworks to ease framework integration. While literature presents claims that DSL-based application development is beneficial, empirical evidence for this is rare. We present the results of an experiment comparing the complexity of three different object-oriented framework APIs and an embedded, textual DSL. For this comparative experiment, we implemented the same, non-trivial application scenario using these four different APIs. Then, we performed an Object-Points (OP) analysis, yielding indicators for the API complexity specific to each API variant. The main observation for our experiment is that the embedded, textual DSL incurs the smallest API complexity. Although the results are exploratory, as well as limited to the given application scenario and a single embedded DSL, our findings can direct future empirical work. The experiment design is applicable for similar API design evaluations. Stefan Sobernig, Patrick Gaubatz, Mark Strembeck, Uwe Zdun |
GPCE | 3 |
| 2011 | Deriving role engineering artifacts from business processes and scenario modelsabstractScenario-driven role engineering is a systematic approach to engineer and maintain RBAC models. Such as every engineering process, this approach heavily depends on human factors and many of the corresponding engineering tasks must be conducted manually. However, based on the experiences we gained from our projects and case studies, we identified several tasks in role engineering that are monotonous, time-consuming, and can get tedious if conducted manually. These tasks include the derivation of candidate RBAC artifacts from business processes and scenario models. In this paper, we present an approach to automatically derive role engineering artifacts from process and scenario models. While our general approach is independent from a specific document format, we especially discuss the derivation of role engineering artifacts from UML activity models, UML interaction models, and BPMN collaboration models. In particular, we use the XMI (XML Metadata Interchange) representation of these models as a tool- and vendor-independent format to identify and automatically derive different role engineering artifacts. Anne Baumgraß, Mark Strembeck, Stefanie Rinderle-Ma |
SACMAT | 2 |
| 2011 | An integrated approach for identity and access management in a SOA contextabstractIn this paper, we present an approach for identity and access management (IAM) in the context of (cross-organizational) service-oriented architectures (SOA). In particular, we defined a domain-specific language (DSL) for role-based access control (RBAC) that allows for the definition of IAM policies for SOAs. For the application in a SOA context, our DSL environment automatically produces WS-BPEL (Business Process Execution Language for Web services) specifications from the RBAC models defined in our DSL. We use the WS-BPEL extension mechanism to annotate parts of the process definition with directives concerning the IAM policies. At deployment time, the WS-BPEL process is instrumented with special activities which are executed at runtime to ensure its compliance to the IAM policies. The algorithm that produces extended WS-BPEL specifications from DSL models is described in detail. Thereby, policies defined via our DSL are automatically mapped to the implementation level of a SOA-based business process. This way, the DSL decouples domain experts' concerns from the technical details of IAM policy specification and enforcement. Our approach thus enables (non-technical) domain experts, such as physicians or hospital clerks, to participate in defining and maintaining IAM policies in a SOA context. Based on a prototype implementation we also discuss several performance aspects of our approach. Waldemar Hummer, Patrick Gaubatz, Mark Strembeck, Uwe Zdun, Schahram Dustdar |
SACMAT | 3 |
| 2011 | Modeling process-related RBAC models with extended UML activity models
Mark Strembeck, Jan Mendling |
Inf. Softw. Technol. | 1 |
| 2009 | An approach for the systematic development of domain-specific languagesabstractAbstract Building tailored software systems for a particular application domain is a complex task. For this reason,domain‐specific languages(DSLs) receive a constantly growing attention in recent years. So far the main focus of DSL research is on case studies and experience reports for the development of individual DSLs, design approaches and implementation techniques for DSLs, and the integration of DSLs with other software development approaches on a technical level. In this paper, we identify and describe the different activities that we conduct when engineering a DSL, and describe how these activities can be combined in order to define a tailored DSL engineering process. Our research results are based on the experiences we gained from multiple different DSL development projects and prototyping experiments. Copyright © 2009 John Wiley & Sons, Ltd. Mark Strembeck, Uwe Zdun |
Softw. Pract. Exp. | 1 |
| 2007 | Object-based and class-based composition of transitive mixins
Uwe Zdun, Mark Strembeck, Gustaf Neumann |
Inf. Softw. Technol. | 2 |
| 2004 | An integrated approach to engineer and enforce context constraints in RBAC environmentsabstractWe present an approach that uses special purpose role-based access control (RBAC) constraints to base certain access control decisions on context information. In our approach a context constraint is defined as a dynamic RBAC constraint that checks the actual values of one or more contextual attributes for predefined conditions. If these conditions are satisfied, the corresponding access request can be permitted. Accordingly, a conditional permission is an RBAC permission that is constrained by one or more context constraints. We present an engineering process for context constraints that is based on goal-oriented requirements engineering techniques, and describe how we extended the design and implementation of an existing RBAC service to enable the enforcement of context constraints. With our approach we aim to preserve the advantages of RBAC and offer an additional means for the definition and enforcement of fine-grained context-dependent access control policies. Mark Strembeck, Gustaf Neumann |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2003 | Experiences with the enforcement of access rights extracted from ODRL-based digital contractsabstractIn this paper, we present our experiences concerning the enforcement of access rights extracted from ODRL-based digital contracts. We introduce the generalized Contract Schema (CoSa) which is an approach to provide a generic representation of contract information on top of rights expression languages. We give an overview of the design and implementation of the xoRELInterpreter software component. In particular, the xoRELInterpreter interprets digital contracts that are based on rights expression languages (e.g. ODRL or XrML) and builds a runtime CoSa object model. We describe how the xorbac access control component and the xoRELInterpreter component are used to enforce access rights that we extract from ODRL-based digital contracts. Thus, our approach describes how ODRL-based contracts can be used as a means to disseminate certain types of access control information in distributed systems. Susanne Guth, Gustaf Neumann, Mark Strembeck |
Digital Rights Management Workshop | 3 |
| 2003 | An approach to engineer and enforce context constraints in an RBAC environmentabstractThis paper presents an approach that uses special purpose RBAC constraints to base certain access control decisions on context information. In our approach a context constraint is defined as a dynamic RBAC constraint that checks the actual values of one or more contextual attributes for predefined conditions. If these conditions are satisfied, the corresponding access request can be permitted. Accordingly, a conditional permission is an RBAC permission which is constrained by one or more context constraints. We present an engineering process for context constraints, that is based on goal-oriented requirements engineering techniques, and describe how we extended the design and implementation of an existing RBAC service to enable the enforcement of context constraints. With our approach we aim to preserve the advantages of RBAC, and offer an additional means for the definition and enforcement of fine-grained context-dependent access control policies. Gustaf Neumann, Mark Strembeck |
SACMAT | 2 |
| 2002 | A scenario-driven role engineering process for functional RBAC rolesabstractIn this paper we present a novel scenario-driven role engineering process for RBAC roles. The scenario concept is of central significance for the presented approach. Due to the strong human factor in role engineering scenarios are a good means to drive the process. We use scenarios to derive permissions and to define tasks. Our approach considers changeability issues and enables the straightforward incorporation of changes into a#ected models. Finally we discuss the experiences we gained by applying the scenario-driven role engineering process in three case studies. Gustaf Neumann, Mark Strembeck |
SACMAT | 2 |
| 2001 | Design and implementation of a flexible RBAC-service in an object-oriented scripting languageabstractIn this paper we present the design and implementation of the xorbac component that provides a flexible RBAC service. The xorbac, implementation conforms to level 4a of the unified NIST model for RBAC and can be reused for arbitrary applications on Unix or Windows with a C or Tcl linkage. xorbac runtime elements can be serialized and recreated from RDF data models conforming to a well-defined RDF schema. Furthermore we present our experiences with xorbac for the deployment within the HTTP environment for a web-based mobile code system. Gustaf Neumann, Mark Strembeck |
CCS | 2 |