EDBT 2026 Demo / reviewers in the wild / expert
Karsten Sohr
dblp:21/2614
· DBLP profile ↗
27ranked-venue papers
4as first author
7since 2021 · last 2025
0000-0001-6781-4226ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 2 first-author · 4 since 2021Software engineering, systems software and programming languages · 6 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 5 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1 · 1 first-authorTheory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Transparency and Consent Challenges in mHealth Apps: An Interdisciplinary Study of Privacy Policies, Data Sharing, and Dark Patterns
Mehrdad Bahrini, Alexander Herbst, Merle Freye, Matthias Kohn, Karsten Sohr, Rainer Malaka |
ESORICS (4) | 5 |
| 2025 | Game Elements in Cybersecurity Education: Hype or Help?
Mehrdad Bahrini, Violetta Burdina, Karsten Sohr, Rainer Malaka |
ICEC | 3 |
| 2024 | Empowering User Security Awareness and Risk Assessment Within Gamified Smartphone Environment
Mehrdad Bahrini, Joffrey Weglewski, Karsten Sohr, Rainer Malaka |
ICEC | 3 |
| 2024 | Pairing Human and Artificial Intelligence: Enforcing Access Control Policies with LLMs and Formal Specifications
Carlos E. Rubio-Medrano, Akash Kotak, Wenlu Wang, Karsten Sohr |
SACMAT | 4 |
| 2023 | Machine Learning for SAST: A Lightweight and Adaptable Approach
Lorenz Hüther, Karsten Sohr, Bernhard J. Berger, Hendrik Rothe, Stefan Edelkamp |
ESORICS (4) | 2 |
| 2021 | [Engineering] eNYPD - Entry Points Detector Jakarta Server Faces Use CaseabstractWhich parts of a software system can be accessed by an attacker is a common question in software security. The answer to this question defines where to look for input validation vulnerabilities, which parts of a system to respect during Microsoft’s Threat Modeling, or how to calculate security metrics. Identifying entry points of an application is, therefore, a frequently occurring problem. Additionally, identifying entry points is relevant when analysing many framework-based applications since they no longer have a simple main method.While different analyses implement entry point detection, the presented tool eNYPD explicitly focuses on answering this question for Java-based systems in an analysis-independent manner. It extracts information on entry points statically and persists this information to a separate file. Therefore, it allows reusing the information in different analyses, and researchers do not need to implement a custom entry point detection for each analysis.The presented tool is explained using Jakarta Server Faces, a user-interface technology for Web-based business applications implemented using Java. The paper presents the implemented extraction approach, the internal data model, and the results stored. Finally, in an evaluation, the statically assessed results of eNYPD are compared to a dynamically determined set of entry points. This comparison allows us to demonstrate the correctness of the extracted information. Rodrigue Wete Nguempnang, Bernhard J. Berger, Karsten Sohr |
SCAM | 3 |
| 2021 | A Category-Based Framework for Privacy-Aware Collaborative Access Control
Denis Obrezkov, Karsten Sohr, Rainer Malaka |
TrustBus | 2 |
| 2020 | Enhancing Game-Based Learning Through Infographics in the Context of Smart Home Security
Mehrdad Bahrini, Nima Zargham, Johannes Pfau, Stella Lemke, Karsten Sohr, Rainer Malaka |
ICEC | 5 |
| 2020 | Static Extraction of Enforced Authorization Policies SeeAuthzabstractAuthorization is an intrinsic part of a software's security. Determining whether a user is allowed to access a resource or not is crucial, not only in safety-critical applications but also in everyday applications to prevent misuse of data or software. There is plenty of research dealing with validating and verifying authorization policies in the security community. Still, an implemented authorization policy does not necessarily match the planned authorization policy, i.e., even a validated and verified authorization policy can pose security issues when implemented incorrectly. This gap between planned and implemented authorization policy poses the risk of unauthorized access to sensitive resources due to insufficient authorization checks. Therefore, it is essential to ensure a system's security to validate the implemented authorization policy against the planned one. We, therefore, describe the authorization pattern and present an algorithm to extract authorization graphs from implemented authorization policies, which can then be used to compare against the planned authorization policy. To that end, we developed a configurable context-sensitive analysis tailored to Java-based software systems, where the context is the authorization facts that hold on each point. Using a configuration for Apache Shiro, a security library that supports authorization, we evaluated our implementation using an open-source repository system for the management and dissemination of digital content and a closed-source manufacturing execution system. We discuss additional usage scenarios of the analysis results and describe how to transfer the approach to other authorization policies and programming languages. Bernhard J. Berger, Rodrigue Wete Nguempnang, Karsten Sohr, Rainer Koschke |
SCAM | 3 |
| 2020 | Towards supporting software assurance assessments by detecting security patterns
Michaela Bunke, Karsten Sohr |
Softw. Qual. J. | 2 |
| 2019 | Towards Effective Verification of Multi-Model Access Control PropertiesabstractMany existing software systems like logistics systems or enterprise applications employ data security in a more or less ad hoc fashion. Our approach focuses on access control such as permission-based discretionary access control (DAC), variants of role-based access control (RBAC) with delegation, and attribute-based access control (ABAC). Typically, software systems implement hybrid access control making an effective security analysis and assessment rather difficult. Bernhard J. Berger, Christian Maeder, Rodrigue Wete Nguempnang, Karsten Sohr, Carlos E. Rubio-Medrano |
SACMAT | 4 |
| 2019 | The Architectural Security Tool Suite - ARCHSECabstractArchitectural risk analysis is a risk management process for identifying security flaws at the level of software architectures and is used by large software vendors, to secure their products. We present our architectural security environ- ment (ARCHSEC) that has been developed at our institute during the past eight years in several research projects. ARCHSEC aims to simplify architectural risk analysis, making it easier for small and mid-sized companies to get started. With ARCHSEC, it is possible to graphically model or to reverse engineer software security architectures. The regained software architectures can then be inspected manually or au- tomatically analyzed w.r.t. security flaws, resulting in a threat model, which serves as a base for discussion between software and security experts to improve the overall security of the software system in question, beyond the level of implementation bugs. In the evaluation part of this paper, we demonstrate how we use ARCHSEC in two of our current research projects to analyze business applications. In the first project we use ARCHSEC to identify security flaws in business process diagrams. In the second project, ARCHSEC is integrated into an audit environment for software security certification. ARCHSEC is used to identify security flaws and to visualize software systems to improve the effectiveness and efficiency of the certification process. Bernhard J. Berger, Karsten Sohr, Rainer Koschke |
SCAM | 2 |
| 2014 | Achieving security assurance with assertion-based application constructionabstractModern software applications are commonly builtby leveraging pre-fabricated modules, e.g. application programming interfaces (APIs), which are essential to implement the desired functionalities of software applications, helping reduce the overall development costs and time. When APIs deal with sec Carlos E. Rubio-Medrano, Gail-Joon Ahn, Karsten Sohr |
CollaborateCom | 3 |
| 2013 | The Transitivity-of-Trust Problem in Android Application InteractionabstractMobile phones have developed into complex platforms with large numbers of installed applications and a wide range of sensitive data. Application security policies limit the permissions of each installed application. As applications may interact, restricting single applications may create a false sense of security for end users, while data may still leave the mobile phone through other applications. Instead, the information flow needs to be policed for the composite system of applications in a transparent manner. In this paper, we propose to employ static analysis, based on the software architecture and focused on data-flow analysis, to detect information flows between components. Specifically, we aim to reveal transitivity-of-trust problems in multi-component mobile platforms. We demonstrate the feasibility of our approach with two Android applications. Steffen Bartsch, Bernhard J. Berger, Michaela Bunke, Karsten Sohr |
ARES | 4 |
| 2013 | Verifying Access Control Properties with Design by Contract: Framework and Lessons LearnedabstractEnsuring the correctness of high-level security properties including access control policies in mission-critical applications is indispensable. Recent literature has shown how immaturity of such properties has caused serious security vulnerabilities, which are likely to be exploited by malicious parties for compromising a given application. This situation gets aggravated by the fact that modern applications are mostly built on previously developed reusable software modules and any failures in security properties in these reusable modules may lead to vulnerabilities across associated applications. In this paper, we propose a framework to address this issue by adopting Design by Contract (DBC) features. Our framework accommodates security properties in each application focusing on access control requirements. We demonstrate how access control requirements based on ANSI RBAC standard model can be specified and verified at the source code level. Carlos E. Rubio-Medrano, Gail-Joon Ahn, Karsten Sohr |
COMPSAC | 3 |
| 2013 | Employing UML and OCL for designing and analysing role-based access controlabstractThe stringent security requirements of organisations like banks or hospitals frequently adopt role-based access control (RBAC) principles to represent and simplify their internal permission management. While representing a fundamental advanced RBAC concept enabling precise restrictions on access rights, authorisation constraints increase the complexity of the resulting security policies so that tool support for convenient creation and adequate validation is required. A particular contribution of our work is a new approach to developing and analysing RBAC policies using a UML-based domain-specific language (DSL), which allows the hiding of the mathematical structures of the underlying authorisation constraints implemented in OCL. The DSL we present is highly configurable and extensible with respect to new concepts and classes of authorisation constraints, and allows the developer to validate RBAC policies in an effective way. The handling of dynamic (that is, time-dependent) constraints, their visual representation through the RBAC DSL and their analysis all form another part of our contribution. The approach is supported by a UML and OCL validation tool. Mirco Kuhlmann, Karsten Sohr, Martin Gogolla |
Math. Struct. Comput. Sci. | 2 |
| 2012 | IO: An Interconnected Asset Ontology in Support of Risk Management ProcessesabstractAsset information obtained via infrastructure analysis is essential for developing and establishing risk management. However, information about assets acquired by existing infrastructure analysis processes is often incomplete or lacking in detail, especially concerning their interconnected topology. In this paper, we present the Interconnected-asset Ontology, IO, as a step towards a standardized representation of detailed asset information. The utilization of an asset ontology as a machine-readable representation supports the automation of risk management processes and the standardization of asset information reduces redundant acquisition processes that are often found in practice. Henk Birkholz, Ingo Sieverdingbeck, Karsten Sohr, Carsten Bormann |
ARES | 3 |
| 2012 | An Approach to Detecting Inter-Session Data Flow Induced by Object Pooling
Bernhard J. Berger, Karsten Sohr |
SEC | 2 |
| 2012 | Comprehensive two-level analysis of role-based delegation and revocation policies with UML and OCL
Karsten Sohr, Mirco Kuhlmann, Martin Gogolla, Hongxin Hu, Gail-Joon Ahn |
Inf. Softw. Technol. | 1 |
| 2010 | Secure Mobile Business Information ProcessingabstractAn ever increasing amount of functionality is incorporated into mobile phones-this trend will continue as new mobile phone platforms are more widely used such as the iPhone or Android. Along with this trend, however, new risks arise, especially for enterprises using mobile phones for security-critical applications such as business intelligence (BI). Although platforms like Android have implemented sophisticated security mechanisms, security holes have been reported. In addition, different stakeholders have access to mobile phones such as different enterprises, service providers, operators, or manufacturers. In order to protect security-critical business applications, a trustworthy mobile phone platform is needed. Starting with typical attack scenarios, we describe a security architecture for Android mobile phones based on the concepts of Trusted Computing. In particular, this architecture allows for a dynamic policy change to reflect the current environment the phone is being used in. Nicolai Kuntze, Roland Rieke, Günther Diederich, Richard Sethmann, Karsten Sohr, Tanveer Mustafa, Kai-Oliver Detken |
EUC | 5 |
| 2010 | Typed Linear Chain Conditional Random Fields and Their Application to Intrusion Detection
Carsten Elfers, Mirko Horstmann, Karsten Sohr, Otthein Herzog |
IDEAL | 3 |
| 2008 | Enforcing Role-Based Access Control Policies in Web Services with UML and OCLabstractRole-based access control (RBAC) is a powerful means for laying out higher-level organizational policies such as separation of duty, and for simplifying the security management process. One of the important aspects of RBAC is authorization constraints that express such organizational policies. While RBAC has generated a great interest in the security community, organizations still seek a flexible and effective approach to impose role-based authorization constraints in their security-critical applications. In this paper, we present a Web Services-based authorization framework that can be employed to enforce organization-wide authorization constraints. We describe a generic authorization engine, which supports organization-wide authorization constraints and acts as a central policy decision point within the authorization framework. This authorization engine is implemented by means of the USE system, a validation tool for UML models and OCL constraints. Karsten Sohr, Tanveer Mustafa, Xinyu Bao, Gail-Joon Ahn |
ACSAC | 1 |
| 2008 | Supporting Agile Development of Authorization Rules for SME Applications
Steffen Bartsch, Karsten Sohr, Carsten Bormann |
CollaborateCom | 2 |
| 2008 | Analyzing and Managing Role-Based Access Control PoliciesabstractToday more and more security-relevant data is stored on computer systems; security-critical business processes are mapped to their digital counterparts. This situation applies to various domains such as health care industry, digital government, and financial service institutes requiring that different security requirements must be fulfilled. Authorisation constraints can help the policy architect design and express higher-level organisational rules. Although the importance of authorisation constraints has been addressed in the literature, there does not exist a systematic way to verify and validate authorisation constraints. In this paper, we specify both non-temporal and history-based authorisation constraints in the Object Constraint Language (OCL) and first-order linear temporal logic (LTL). Based upon these specifications, we attempt to formally verify role-based access control policies with the help of a theorem prover and to validate policies with the USE system, a validation tool for OCL constraints. We also describe an authorisation engine, which supports the enforcement of authorisation constraints. Karsten Sohr, Michael Drouineaud, Gail-Joon Ahn, Martin Gogolla |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2006 | A model-checking approach to analysing organisational controls in a loan origination processabstractDemonstrating the safety of a system (ie. avoiding the undesired propagation of access rights or indirect access through some other granted resource) is one of the goals of access control research, e.g. [1-4]. However, the flexibility required from enterprise resource management (ERP) systems may require the implementation of seemingly contradictory requirements (e.g. tight access control but at the same time support for discretionary delegation of workflow tasks and rights).To aid in the analysis of safety problems in workflow-based ERP system, this paper presents a model-checking based approach for automated analysis of delegation and revocation functionalities. This is done in the context of a real-world banking workflow requiring static and dynamic separation of duty properties.We derived information about the workflow from BPEL specifications and ERP business object repositories. This was captured in a SMV specification together with a definition of possible delegation and revocation scenarios. The required separation properties were translated into a set of LTL-based constraints. In particular, we analyse the interaction between delegation and revocation activities in the context of dynamic separation of duty policies. Andreas Schaad, Volkmar Lotz, Karsten Sohr |
SACMAT | 3 |
| 2005 | Specification and Validation of Authorisation Constraints Using UML and OCL
Karsten Sohr, Gail-Joon Ahn, Martin Gogolla, Lars Migge |
ESORICS | 1 |
| 2003 | A temporal-logic extension of role-based access control covering dynamic separation of dutiesabstractSecurity policies play an important role in today's computer systems. We show some severe limitations of the wide-spread standard role-based access control (RBAC) model, namely that object-based dynamic separation of duty as introduced by Nash and Poland cannot be expressed with it. We suggest to overcome these limitations by extending the RBAC model with an execution history. The natural next step is then to add temporal logic for the specification of execution orders. We show that with this, object-based dynamic separation of duty, as well as other policies, can be adequately specified. Till Mossakowski, Michael Drouineaud, Karsten Sohr |
TIME | 3 |