EDBT 2026 Demo / reviewers in the wild / expert
Katsiaryna Labunets
dblp:139/6939
· DBLP profile ↗
13ranked-venue papers
7as first author
4since 2021 · last 2025
0000-0003-0884-2440ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 8 · 7 first-author · 1 since 2021Security and privacy · 4 · 3 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Privacy in ERP Systems: Behavioral Models of Developers and Consultants
Alicia Pang, Katsiaryna Labunets, Olga Gadyatskaya |
CRiSIS | 2 |
| 2023 | Poster: The Unknown Unknown: Cybersecurity Threats of Shadow IT in Higher EducationabstractThe growing number of employee-introduced IT solutions creates new attack vectors and challenges for cybersecurity management and IT administrators. These unauthorised hardware, software, or services are called shadow IT. In higher education, the diversity of the shadow IT landscape is even more prominent due to the flexible needs of researchers, educators, and students. Jan-Philip van Acken, Joost F. Gadellaa, Slinger Jansen, Katsiaryna Labunets |
CCS | 4 |
| 2023 | A new, evidence-based, theory for knowledge reuse in security risk analysisabstractAbstract Security risk analysis (SRA) is a key activity in software engineering but requires heavy manual effort. Community knowledge in the form of security patterns or security catalogs can be used to support the identification of threats and security controls. However, no evidence-based theory exists about the effectiveness of security catalogs when used for security risk analysis. We adopt a grounded theory approach to propose a conceptual, revised and refined theory of SRA knowledge reuse. The theory refinement is backed by evidence gathered from conducting interviews with experts (20) and controlled experiments with both experts (15) and novice analysts (18). We conclude the paper by providing insights into the use of catalogs and managerial implications. Katsiaryna Labunets, Fabio Massacci, Federica Paci, Katja Tuma |
Empir. Softw. Eng. | 1 |
| 2022 | Security at the End of the Tunnel: The Anatomy of VPN Mental Models Among Experts and Non-Experts in a Corporate Context
Veroniek Binkhorst, Tobias Fiebig, Katharina Krombholz, Wolter Pieters, Katsiaryna Labunets |
USENIX Security Symposium | 5 |
| 2018 | No search allowed: what risk modeling notation to choose?abstract[Background] Industry relies on the use of tabular notations to document the risk assessment results, while academia encourages to use graphical notations. Previous studies revealed that tabular and graphical notations with textual labels provide better support for extracting correct information about security risks in comparison to iconic graphical notation. [Aim] In this study we examine how well tabular and graphical risk modeling notations support extraction and memorization of information about risks when models cannot be searched. [Method] We present results of two experiments with 60 MSc and 31 BSc students where we compared their performance in extraction and memorization of security risk models in tabular, UML-style and iconic graphical modeling notations. [Result] Once search is restricted, tabular notation demonstrates results similar to the iconic graphical notation in information extraction. In memorization task tabular and graphical notations showed equivalent results, but it is statistically significant only between two graphical notations. [Conclusion] Three notations provide similar support to decision-makers when they need to extract and remember correct information about security risks. Katsiaryna Labunets |
ESEM | 1 |
| 2018 | Model comprehension for security risk assessment: an empirical comparison of tabular vs. graphical representationsabstractContext: Tabular and graphical representations are used to communicate security risk assessments for IT systems. However, there is no consensus on which type of representation better supports the comprehension of risks (such as the relationships between threats, vulnerabilities and security controls). Vessey's cognitive fit theory predicts that graphs should be better because they capture spatial relationships. Method: We report the results of two studies performed in two countries with 69 and 83 participants respectively, in which we assessed the effectiveness of tabular and graphical representations concerning the extraction of correct information about security risks. Results: Participants who applied tabular risk models gave more precise and complete answers to the comprehension questions when requested to find simple and complex information about threats, vulnerabilities, or other elements of the risk models. Conclusions: Our findings can be explained by Vessey's cognitive fit theory as tabular models implicitly capture elementary linear spatial relationships. Interest for ICSE: It is almost taken for granted in Software Engineering that graphical-, diagram-based models are "the" way to go (e.g., the SE Body of Knowledge [3]). This paper provides some experimental-based doubts that this might not always be the case. It will provide an interesting debate that might ripple to traditional requirements and design notations outside security. Katsiaryna Labunets, Fabio Massacci, Federica Paci, Sabrina Marczak, Flávio M. de Oliveira |
ICSE | 1 |
| 2017 | Graphical vs. Tabular Notations for Risk Models: On the Role of Textual Labels and Complexityabstract[Background] Security risk assessment methods in industry mostly use a tabular notation to represent the assessment results whilst academic works advocate graphical methods. Experiments with MSc students showed that the tabular notation is better than an iconic graphical notation for the comprehension of security risks. [Aim] We investigate whether the availability of textual labels and terse UML-style notation could improve comprehensibility. [Method] We report the results of an online comprehensibility experiment involving 61 professionals with an average of 9 years of working experience, in which we compared the ability to comprehend security risk assessments represented in tabular, UML-style with textual labels, and iconic graphical modeling notations. [Results] Tabular notation are still the most comprehensible notion in both recall and precision. However, the presence of textual labels does improve the precision and recall of participants over iconic graphical models. [Conclusion] Tabular representation better supports extraction of correct information of both simple and complex comprehensibility questions about security risks than the graphical notation but textual labels help. Katsiaryna Labunets, Fabio Massacci, Alessandra Tedeschi |
ESEM | 1 |
| 2017 | On the Equivalence Between Graphical and Tabular Representations for Security Risk Assessment
Katsiaryna Labunets, Fabio Massacci, Federica Paci |
REFSQ | 1 |
| 2017 | Model comprehension for security risk assessment: an empirical comparison of tabular vs. graphical representations
Katsiaryna Labunets, Fabio Massacci, Federica Paci, Sabrina Marczak, Flávio M. de Oliveira |
Empir. Softw. Eng. | 1 |
| 2016 | Towards Empirical Evaluation of Automated Risk Assessment Methods
Olga Gadyatskaya, Katsiaryna Labunets, Federica Paci |
CRiSIS | 2 |
| 2016 | Modeling Structured and Unstructured Processes: An Empirical Evaluation
Evellin Cardoso, Katsiaryna Labunets, Fabiano Dalpiaz, John Mylopoulos, Paolo Giorgini |
ER | 2 |
| 2015 | The Role of Catalogues of Threats and Security Controls in Security Risk Assessment: An Empirical Study with ATM Professionals
Martina de Gramatica, Katsiaryna Labunets, Fabio Massacci, Federica Paci, Alessandra Tedeschi |
REFSQ | 2 |
| 2013 | An Experimental Comparison of Two Risk-Based Security MethodsabstractA significant number of methods have been proposed to identify and analyze threats and security requirements, but there are few empirical evaluations that show these methods work in practice. This paper reports a controlled experiment conducted with 28 master students to compare two classes of risk-based methods, visual methods (CORAS) and textual methods (SREP). The aim of the experiment was to compare the effectiveness and perception of the two methods. The participants divided in groups solved four different tasks by applying the two methods using a randomized block design. The dependent variables were effectiveness of the methods measured as number of threats and security requirements identified, and perception of the methods measured through a post-task questionnaire based on the Technology Acceptance Model. The experiment was complemented with participants' interviews to determine which features of the methods influence their effectiveness. The main findings were that the visual method is more effective for identifying threats than the textual one, while the textual method is slightly more effective for eliciting security requirements. In addition, visual method overall perception and intention to use were higher than for the textual method. Katsiaryna Labunets, Fabio Massacci, Federica Paci, Le Minh Sang Tran |
ESEM | 1 |