Clemens Sauerwein

dblp:171/2314 · DBLP profile ↗
← Back
17ranked-venue papers
4as first author
11since 2021 · last 2024
0009-0009-9464-5080ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 3 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 5 · 1 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2024 The Role of Threat Intelligence Sharing Platforms in Companies, Public Authorities, and Universities: Insights from an Exploratory Global Survey
abstract
Threat intelligence sharing offers a promising discipline to bolster knowledge and situational awareness amidst the rapid emergence of new cyber threats. Numerous platforms in the security solutions market enable effective and targeted sharing of threat intelligence among organizations. However, there is limited knowledge of the diffusion and use of threat intelligence platforms within companies, public authorities, and universities worldwide. To meet this challenge, we conducted an exploratory global survey of 118 security experts from companies, public authorities, and universities. Our findings show that threat intelligence sharing platforms are becoming more mature, evidenced by an increase in their prevalence and the utilization of their functionalities within the threat intelligence life cycle.
Daniel Fischer 0003, Clemens Sauerwein, Marie Liz Sayin, Dirk Stelzer, Ruth Breu
IEEE Big Data2
2024 Requirements for an Online Integrated Development Environment for Automated Programming Assessment Systems
Eduard Frankford, Daniel Crazzolara, Clemens Sauerwein, Michael Vierhauser, Ruth Breu
CSEDU (1)3
2024 Learning Analytics Support in Higher-Education: Towards a Multi-Level Shared Learning Analytics Framework
abstract
Assurance of Learning and Competency-Based Education are increasingly important in higher education, not only for accreditation or transfer of credit points. Learning Analytics is crucial for making educational goals measurable and actionable, which is beneficial for program managers, course instructors, and students. \nWhile universities typically have an established tool landscape where relevant data is managed, information is typically scattered across various systems with different responsibilities and often only limited capabilities for sharing data. This diversity, however, significantly hampers the ability to analyze data, both on the course and curriculum level.\nTo address these shortcomings and to provide program managers, course instructions, and students with valuable insights, we devised an initial concept for a Multi-Level Shared Learning Analytics Framework to provide consistent definition and measurement of learning objectives, as well as tailored information, visualization, and analysis for different stakeholders.\nIn this paper, we present the results of initial interviews with stakeholders, devising core features. In addition, we assess potential risks and concerns that may arise from the implementation of such a framework and data analytics system. As a result, we identified six essential features and six main risks to guide further requirements elicitation and development of our proposed framework.
Michael Vierhauser, Iris Groher, Clemens Sauerwein, Tobias Antensteiner, Sebastian Hatmanstorfer
CSEDU (1)3
2024 A Survey Study on the State of the Art of Programming Exercise Generation Using Large Language Models
abstract
This paper analyzes Large Language Models (LLMs) with regard to their programming exercise generation capabilities. Through a survey study, we defined the state of the art, extracted their strengths and weaknesses and finally proposed an evaluation matrix, helping researchers and educators to decide which LLM is the best fitting for the programming exercise generation use case. We also found that multiple LLMs are capable of producing useful program-ming exercises. Nevertheless, there exist challenges like the ease with which LLMs might solve exercises generated by LLMs. This paper contributes to the ongoing discourse on the integration of LLMs in education.
Eduard Frankford, Ingo Höhn, Clemens Sauerwein, Ruth Breu
CSEE&T3
2024 Towards Integrating Emerging AI Applications in SE Education
abstract
Artificial Intelligence (AI) approaches have been incorporated into modern learning environments and software engineering (SE) courses and curricula for several years. However, with the significant rise in popularity of large language models (LLMs) in general, and OpenAI's LLM-powered chatbot ChatGPT in particular in the last year, educators are faced with rapidly changing classroom environments and disrupted teaching principles. Examples range from programming assignment solutions that are fully generated via ChatGPT, to various forms of cheating during exams. However, despite these negative aspects and emerging challenges, AI tools in general, and LLM applications in particular, can also provide significant opportunities in a wide variety of SE courses, supporting both students and educators in meaningful ways. In this early research paper, we present preliminary results of a systematic analysis of current trends in the area of AI, and how they can be integrated into university-level SE curricula, guidelines, and approaches to support both instructors and learners. We collected both teaching and research papers and analyzed their potential usage in SE education, using the ACM Computer Science Curriculum Guidelines CS2023. As an initial outcome, we discuss a series of opportunities for AI applications and further research areas.
Michael Vierhauser, Iris Groher, Tobias Antensteiner, Clemens Sauerwein
CSEE&T4
2023 An Exploratory Study on the Use of Threat Intelligence Sharing Platforms in Germany, Austria and Switzerland
abstract
Threat intelligence sharing is a promising solution to enhance knowledge and situational awareness of the rapidly growing number of emerging cyber threats. Accordingly, there are a variety of platforms on the security solutions market that enable the efficient and targeted exchange of threat intelligence across organisations. Unfortunately, very little is known so far about the dissemination and use of these platforms from the end-user perspective. To address this issue, we conducted an exploratory study on the use of threat intelligence sharing platforms in Germany, Austria and Switzerland. For this purpose, we surveyed 69 security and IT experts from large companies, federal authorities and public universities in autumn 2022. Our findings show, among other things, a growing interest in threat intelligence sharing platforms and their value to information security processes.
Daniel Fischer 0003, Clemens Sauerwein, Martin Werchan, Dirk Stelzer
ARES2
2023 Towards a Success Model for Automated Programming Assessment Systems Used as a Formative Assessment Tool
abstract
The assessment of source code in university education is a central and important task for lecturers of programming courses. In doing so, educators are confronted with growing numbers of students having increasingly diverse prerequisites, a shortage of tutors, and highly dynamic learning objectives. To support lecturers in meeting these challenges, the use of automated programming assessment systems (APASs), facilitating formative assessments by providing timely, objective feedback, is a promising solution. Measuring the effectiveness and success of these platforms is crucial to understanding how such platforms should be designed, implemented, and used. However, research and practice lack a common understanding of aspects influencing the success of APASs. To address these issues, we have devised a success model for APASs based on established models from information systems as well as blended learning research and conducted an online survey with 414 students using the same APAS. In addition, we examined the role of mediators intervening between technology-, system- or self-related factors, respectively, and the users' satisfaction with APASs. Ultimately, our research has yielded a model of success comprising seven constructs influencing user satisfaction with an APAS.
Clemens Sauerwein, Tobias Antensteiner, Stefan Oppl, Iris Groher, Alexander Meschtscherjakov, Philipp Zech, Ruth Breu
ITiCSE (1)1
2021 From Threat Data to Actionable Intelligence: An Exploratory Analysis of the Intelligence Cycle Implementation in Cyber Threat Intelligence Sharing Platforms
abstract
In the last couple of years, organizations have demonstrated an increasing willingness to share data, information and intelligence regarding emerging threats to collectively protect against today’s sophisticated cyber attacks. Accordingly, several vendors started to implement software solutions that facilitate this exchange and appear under the name cyber threat intelligence sharing platforms. However, recent investigations have shown that these platforms differ significantly in their functional scope and often only provide threat data instead of the promised actionable intelligence. Moreover, it is unclear to what extent the platforms implement the expected intelligence cycle processes. In order to close this gap, we investigate the state-of-the-art in scientific literature and analyze the functional scope of nine threat intelligence sharing platforms with respect to the intelligence cycle. Our study provides a comprehensive list of software functions that should be implemented by cyber threat intelligence sharing platforms in order to support the intelligence cycle to generate actionable threat intelligence.
Clemens Sauerwein, Daniel Fischer 0003, Milena Rubsamen, Guido Rosenberger, Dirk Stelzer, Ruth Breu
ARES1
2021 Rethinking Information Technology Governance for Digital Business Ecosystems
abstract
The emergence of digital business ecosystems (DBEs) has impacted the industry tremendously. Participating in DBEs enables enterprises to offer their customers a comprehensive product and service portfolio while focusing on its core competencies. Moreover, DBEs allow enterprises to leverage new sales channels and directly access additional markets. The discipline of information technology (IT) governance is responsible to ensure that IT sustains and extends enterprise objectives. However, it is currently unclear how IT governance needs to be adapted and reorganized within DBEs to handle multiple self-contained enterprises. Therefore, we clarify the required IT governance redesign based on the results of interviews with 38 experts from 18 industries. The results reveal how IT governance is currently implemented within the industry and show its required adaptations, reorganizations, and challenges.
Robert Ehrensperger, Clemens Sauerwein, Ruth Breu
EDOC2
2021 Toward a Maturity Model for Digital Business Ecosystems from an IT perspective
abstract
The digital transformation affects longstanding business models and leads to competition not only between enterprises but also between supply chains and networks. The concept of digital business ecosystems (DBEs) allows enterprises to concentrate on network co-creation and co-evolution of bundled services and products across enterprise boundaries. This study investigates the status of existing DBEs and their maturity. We interviewed 28 experts, reviewed more than 7,108 publications, and derived a maturity model from the obtained results. This maturity model helps practitioners to identify opportunities for improvement in their collaboration within DBEs and help researchers to assess and compare the current maturity level of existing DBEs.
Robert Ehrensperger, Clemens Sauerwein, Ruth Breu
EDOC2
2021 A success model for cyber threat intelligence management platforms
Adam Zibak, Clemens Sauerwein, Andrew C. Simpson
Comput. Secur.2
2020 Current Practices in the Usage of Inter-Enterprise Architecture Models for the Management of Business Ecosystems
abstract
The ongoing digital transformation affects longstanding business models and creates opportunities for new ones. Business IT alignment plays a crucial role in this digital transformation. Enterprise architecture management (EAM) is designed to support and improve this alignment with the help of enterprise architecture (EA) models. With the introduction of new technologies such as the Internet of Things, companies are seeking new bundled or hybrid business models that combine services and products from different providers. Therefore, enterprises have to shift their focus on the management of business ecosystems. This study aims to provide a precise analysis of a practitioner's perspective to evaluate the relevance and capabilities of inter-enterprise architecture (IEA) models for the management of business ecosystems. We surveyed 268 practitioners in the field of EAM. Our results show compelling insights concerning the relevance of IEA models for the management of business ecosystems. Our analysis outline advantages, challenges, and suggestions for improvement within the industry.
Robert Ehrensperger, Clemens Sauerwein, Ruth Breu
EDOC2
2020 Risk management practices in information security: Exploring the status quo in the DACH region
Michael Brunner 0002, Clemens Sauerwein, Michael Felderer, Ruth Breu
Comput. Secur.2
2019 Applying Security Testing Techniques to Automotive Engineering
abstract
Over the past few decades, the automotive industry was mostly focused on testing the safety aspects of a vehicle. However, this was not the case with security testing as it only began to be addressed recently. As a result, multiple approaches applying various security testing techniques on different software-based vehicle IT components emerged. With that said, the research and practice lack an overview about these techniques. In this paper, we conduct a systematic mapping study. This involved the investigation on the following five dimensions: (1) security testing techniques, (2) AUTOSAR layers, (3) functional interfaces of AUTOSAR, (4) vehicle lifecycle phases and (5) attacks. In total, 39 papers presenting approaches for security testing in automotive engineering were systematically selected and classified. The results identify multiple security testing techniques focusing on early phases of vehicle life cycle through the application and services layer of the AUTOSAR architecture. Finally, there is a need for security regression testing approaches, as well as combined security and safety testing approaches.
Irdin Pekaric, Clemens Sauerwein, Michael Felderer
ARES2
2019 An analysis and classification of public information security data sources used in research and practice
Clemens Sauerwein, Irdin Pekaric, Michael Felderer, Ruth Breu
Comput. Secur.1
2018 Roadblocks on the Highway to Secure Cars: An Exploratory Survey on the Current Safety and Security Practice of the Automotive Industry
Michael M. Huber, Michael Brunner 0002, Clemens Sauerwein, Carmen Cârlan, Ruth Breu
SAFECOMP3
2018 The Tweet Advantage: An Empirical Analysis of 0-Day Vulnerability Information Shared on Twitter
Clemens Sauerwein, Christian Sillaber, Michael M. Huber, Andrea Mussmann, Ruth Breu
SEC1