Mathias Ekstedt

dblp:23/402 · DBLP profile ↗
← Back
43ranked-venue papers
0as first author
6since 2021 · last 2024
0000-0003-3922-9606ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 25 · 6 since 2021Software engineering, systems software and programming languages · 8Databases, data management, data science and information retrieval · 4Artificial intelligence and machine learning · 3Applied, interdisciplinary, general and emerging computing · 3
YearPublicationVenuePosition
2024 A Metalanguage for Dynamic Attack Graphs and Lazy Generation
abstract
Two types of dynamics are important when modeling cyberattacks: how adversaries chain together techniques across systems and how they change the target systems. Attack graphs are prominent within research communities for automatically mapping and chaining together actions. Modeling adversary-driven system changes is comparatively unexplored, however. One reason could be that modeling adversarial change dynamics poses a blend of problems where the typical attack graph approaches could produce state-space explosions and infinite graphs. Therefore, this work presents the core modeling aspects of the Dynamic Meta Attack Language (DynaMAL), a project to lazily generate attack graphs by combining attack graph construction and simulation methods. DynaMAL lets users declare domain-specific modeling and attack graph generation languages. Then, the attack graphs are generated one step at a time based on the actions of an adversary agent. By only generating what is explicitly requested, DynaMAL can demonstrably change the system model as the attack graph grows while sidestepping typical state-space explosions and graph re-calculation problems. Shifting to a lazy generation process poses new challenges, however. Nevertheless, there is likely a point where lazy approaches will prevail when analyzing large and complex systems.
Viktor Engström, Giuseppe Nebbione, Mathias Ekstedt
ARES3
2024 Development and validation of coreLang: A threat modeling language for the ICT domain
abstract
ICT infrastructures are getting increasingly complex, and defending them against cyber attacks is cumbersome. As cyber threats continue to increase and expert resources are limited, organizations must find more efficient ways to evaluate their resilience and take proactive measures. Threat modeling is an excellent method of assessing the resilience of ICT systems, for example, by building Attack Graphs that illustrate an adversary's attack vectors. Previously, the Meta Attack Language (MAL) was proposed, which serves as a framework to develop Domain Specific Languages (DSLs) and generate Attack Graphs for modeled infrastructures. coreLang is a MAL-based threat modeling language that utilizes Attack Graphs to enable attack simulations and security assessments. In this work, we present the first release version of coreLang in which MITRE ATT&CK tactics and techniques are mapped onto to serve as a validation and identify strengths and weaknesses to benefit the development cycle. Our validation showed that coreLang does cover 46% of all the techniques included in the matrix, while if we additionally exclude the tactics that are intrinsically not covered by coreLang and MAL, the coverage percentage increases to 64%.
Sotirios Katsikeas, Andrei Buhaiu, Mathias Ekstedt, Zeeshan Afzal 0001, Simon Hacks, Preetam Mukherjee 0001
Comput. Secur.3
2024 Empirical evaluation of a threat modeling language as a cybersecurity assessment tool
abstract
The complexity of ICT infrastructures is continuously increasing, presenting a formidable challenge in safeguarding them against cyber attacks. In light of escalating cyber threats and limited availability of expert resources, organizations must explore more efficient approaches to assess their resilience and undertake proactive measures. Threat modeling is an effective approach for assessing the cyber resilience of ICT systems. One method is to utilize Attack Graphs, which visually represent the steps taken by adversaries during an attack. Previously, MAL (the Meta Attack Language) was proposed, which serves as a framework for developing Domain-Specific Languages (DSLs) and generating Attack Graphs for modeled infrastructures. coreLang is a MAL-based threat modeling language that utilizes such Attack Graphs to enable attack simulations and security assessments for the generic ICT domain. Developing domain-specific languages for threat modeling and attack simulations provides a powerful approach for conducting security assessments of infrastructures. However, ensuring the correctness of these modeling languages raises a separate research question. In this study we conduct an empirical experiment aiming to falsify such a domain-specific threat modeling language. The potential inability to falsify the language through our empirical testing would lead to its corroboration, strengthening our belief in its validity within the parameters of our study. The outcomes of this approach indicated that, on average, the assessments generated by attack simulations outperformed those of human experts. Additionally, both human experts and simulations exhibited significantly superior performance compared to random guessers in their assessments. While specific human experts occasionally achieved better assessments for particular questions in the experiments, the efficiency of simulation-generated assessments surpasses that of human domain experts.
Sotirios Katsikeas, Engla Ling, Pontus Johnsson, Mathias Ekstedt
Comput. Secur.4
2023 The meta attack language - a formal description
abstract
Nowadays, IT infrastructures are involved in making innumerable aspects of our lives convenient, starting with water or energy distribution systems, and ending with e-commerce solutions and online banking services. In the worst case, cyberattacks on such infrastructures can paralyze whole states and lead to losses in terms of both human lives and money. One of the approaches to increase security of IT infrastructures relies on modeling possible ways of compromising them by potential attackers. To facilitate creation and reusability of such models, domain specific languages (DSLs) can be created. Ideally, a user will employ a DSL for modeling their infrastructure of interest, with the domain-specific threats and attack logic being already encoded in the DSL by the domain experts. The Meta Attack Language (MAL) has been introduced previously as a meta-DSL for development of security-oriented DSLs. In this work, we define formally the syntax and a semantics of MAL to ease a common understanding of MAL’s functionalities and enable reference implementations on different technical platforms. It’s applicability for modeling and analysis of security of IT infrastructures is illustrated with an example.
Wojciech Widel, Simon Hacks, Mathias Ekstedt, Pontus Johnson, Robert Lagerström
Comput. Secur.3
2022 Containment Strategy Formalism in a Probabilistic Threat Modelling Framework
abstract
Background - Foreseeing, mitigating and preventing cyber-attacks is more important than ever before. Advances in the field of probabilistic threat modelling can help organisations understand their own resilience profile against cyber-attacks. Previous research has proposed MAL, a meta language for capturing the attack logic of a considered domain and running attack simulations in a depicted model of the defender’s system. While this modality is already somewhat established, less is known about how to proactively model containment protocols for when an incident already has occurred. Purpose - By proposing a formalism for how to describe and reason about containment in a MAL-based system-specific model, this study aims to bridge the divide between probabilistic threat modelling and the containment phase in the incident response life-cycle. The main issues are how to formalise containment as well as how to reason about selecting the most beneficial strategy for a considered model. Method - The study firstly sets out to identify practical instances of incident containment in the literature. Then, some of these incidents and respective containment items will be encoded with a novel methodology. A containment strategy selection algorithm will be proposed that guides containment decisions by working with the encoded constructs and a system-specific model. Finally, the encoded items will be verified and the algorithm validated through example scenarios. Result & Analysis - The verification tests showed that all implementations of encoded constructs yielded results according to expectation. Validity tests also indicated that the algorithm endorsed the correct solution to a significant extent. The null hypothesis, being that the number of correctly predicted containment strategies could be explained strictly by coincidence, was namely rejected by two validity tests with respective p-values of 8:2. 10-12 and 2:9 . 10-17, both < 0:05. Conclusion - The study demonstrates a viable methodology for describing and reasoning about containment of incidents in a MAL-based framework. This was indicated by verification and validity testing that confirmed the correctness of the incident and containment action implementations as well as that the propensity for the algorithm to favour containment strategies that align with human reasoning.
Per Fahlander, Mathias Ekstedt, Preetam Mukherjee 0001, Ashish Kumar Dwivedi
ICISSP2
2022 Estimating the Time-To-Compromise of Exploiting Industrial Control System Vulnerabilities
Engla Ling, Mathias Ekstedt
ICISSP2
2020 A Systematic Literature Review of Information Sources for Threat Modeling in the Power Systems Domain
abstract
Abstract Power systems are one of the critical infrastructures that has seen an increase in cyber security threats due to digitalization. The digitalization also affects the size and complexity of the infrastructure and therefore makes it more difficult to gain an overview in order to secure the entire power system from attackers. One method of how to gain an overview of possible vulnerabilities and security threats is to use threat modeling. In threat modeling, information regarding the vulnerabilities and possible attacks of power systems is required to create an accurate and useful model. There are several different sources for this information. In this paper we conduct a systematic literature review to find which information sources that have been used in power system threat modeling research. Six different information sources were found: expert knowledge, logs & alerts, previous research, system’s state, vulnerability scoring & databases, and vulnerability scanners.
Engla Ling, Robert Lagerström, Mathias Ekstedt
CRITIS3
2020 Threat Modeling and Attack Simulations of Smart Cities: A Literature Review and Explorative Study
abstract
Threat Modeling and Attack Simulations of Smart Cities : A literature review and explorative study
Robert Lagerström, Mathias Ekstedt
ICISSP3
2018 A Meta Language for Threat Modeling and Attack Simulations
abstract
Attack simulations may be used to assess the cyber security of systems. In such simulations, the steps taken by an attacker in order to compromise sensitive system assets are traced, and a time estimate may be computed from the initial step to the compromise of assets of interest. Attack graphs constitute a suitable formalism for the modeling of attack steps and their dependencies, allowing the subsequent simulation.
Pontus Johnson, Robert Lagerström, Mathias Ekstedt
ARES3
2018 Identification of Attack-based Digital Forensic Evidences for WAMPAC Systems
abstract
Power systems domain has generally been very conservative in terms of conducting digital forensic investigations, especially so since the advent of smart grids. This lack of research due to a multitude of challenges has resulted in absence of knowledge base and resources to facilitate such an investigation. Digitalization in the form of smart grids is upon us but in case of cyber-attacks, attribution to such attacks is challenging and difficult if not impossible. In this research, we have identified digital forensic artifacts resulting from a cyber-attack on Wide Area Monitoring, Protection and Control (WAMPAC) systems, which will help an investigator attribute an attack using the identified evidences. The research also shows the usage of sandboxing for digital forensics along with hardware-in-the-loop (HIL) setup. This is first of its kind effort to identify and acquire all the digital forensic evidences for WAMPAC systems which will ultimately help in building a body of knowledge and taxonomy for power system forensics.
Asif Iqbal 0012, Farhan Mahmood, Andrii Shalaginov, Mathias Ekstedt
IEEE BigData4
2018 RICS-el: Building a National Testbed for Research and Training on SCADA Security (Short Paper)
Magnus Almgren, Peter Andersson, Gunnar Björkman, Mathias Ekstedt, Jonas Hallberg, Simin Nadjm-Tehrani, Erik Westring
CRITIS4
2018 Can the Common Vulnerability Scoring System be Trusted? A Bayesian Analysis
abstract
The Common Vulnerability Scoring System (CVSS) is the state-of-the art system for assessing software vulnerabilities. However, it has been criticized for lack of validity and practitioner relevance. In this paper, the credibility of the CVSS scoring data found in five leading databases-NVD, X-Force, OSVDB, CERT-VN, and Cisco-is assessed. A Bayesian method is used to infer the most probable true values underlying the imperfect assessments of the databases, thus circumventing the problem that ground truth is not known. It is concluded that with the exception of a few dimensions, the CVSS is quite trustworthy. The databases are relatively consistent, but some are better than others. The expected accuracy of each database for a given dimension can be found by marginalizing confusion matrices. By this measure, NVD is the best and OSVDB is the worst of the assessed databases.
Pontus Johnson, Robert Lagerström, Mathias Ekstedt, Ulrik Franke
IEEE Trans. Dependable Secur. Comput.3
2017 Exploratory studies into forensic logs for criminal investigation using case studies in industrial control systems in the power sector
abstract
This is a set of work-in-progress exploratory studies dealing with the log analysis and correlation of very specialized setups in industrial control systems implemented in the context of power systems. These cases consider the behavior of logs and their ability or inability to shed light on the incriminating nature of a criminal investigation. Our research is novel and unique in the sense that no such previous study exists detailing the forensic investigation on ICS within power sector.
Asif Iqbal 0012, Mathias Ekstedt, Hanan Alobaidli
IEEE BigData2
2017 Digital Forensic Readiness in Critical Infrastructures: A Case of Substation Automation in the Power Sector
Asif Iqbal 0012, Mathias Ekstedt, Hanan Alobaidli
ICDF2C2
2016 pwnPr3d: An Attack-Graph-Driven Probabilistic Threat-Modeling Approach
abstract
In this paper we introduce pwnPr3d, a probabilistic threat modeling approach for automatic attack graph generation based on network modeling. The aim is to provide stakeholders in organizations with a holistic approach that both provides high-level overview and technical details. Unlike many other threat modeling and attack graph approaches that rely heavily on manual work and security expertise, our language comes with built-in security analysis capabilities. pwnPr3d generates probability distributions over the time to compromise assets.
Pontus Johnson, Alexandre Vernotte, Mathias Ekstedt, Robert Lagerström
ARES3
2016 Shaping intention to resist social engineering through transformational leadership, information security culture and awareness
Waldo Rocha Flores, Mathias Ekstedt
Comput. Secur.2
2016 Time between vulnerability disclosures: A measure of software product vulnerability
Pontus Johnson, Dan Gorton, Robert Lagerström, Mathias Ekstedt
Comput. Secur.4
2016 The Tarpit - A general theory of software engineering
Pontus Johnson, Mathias Ekstedt
Inf. Softw. Technol.2
2015 Investigating personal determinants of phishing and the effect of national culture
abstract
Purpose – The purpose of the study was twofold: to investigate the correlation between a sample of personal psychological and demographic factors and resistance to phishing; and to investigate if national culture moderates the strength of these correlations. Design/methodology/approach – To measure potential determinants, a survey was distributed to 2,099 employees of nine organizations in Sweden, USA and India. Then, the authors conducted unannounced phishing exercises, in which a phishing attack targeted the same sample. Findings – Intention to resist social engineering, general information security awareness, formal IS training and computer experience were identified to have a positive significant correlation to phishing resilience. Furthermore, the results showed that the correlation between phishing determinants and employees’ observed that phishing behavior differs between Swedish, US and Indian employees in 6 out of 15 cases. Research limitations/implications – The identified determinants had, even though not strong, a significant positive correlation. This suggests that more work needs to be done to more fully understand determinants of phishing. The study assumes that culture effects apply to all individuals in a nation. However, differences based on cultures might exist based on firm characteristics within a country. The Swedish sample is dominating, while only 40 responses from Indian employees were collected. This unequal size of samples suggests that conclusions based on the results from the cultural analysis should be drawn cautiously. A natural continuation of the research is therefore to further explore the generalizability of the findings by collecting data from other nations with similar cultures as Sweden, USA and India. Originality/value – Using direct observations of employees’ security behaviors has rarely been used in previous research. Furthermore, analyzing potential differences in theoretical models based on national culture is an understudied topic in the behavioral information security field. This paper addresses both these issues.
Waldo Rocha Flores, Hannes Holm, Marcus Nohlberg, Mathias Ekstedt
Inf. Comput. Secur.4
2015 A Bayesian network model for likelihood estimations of acquirement of critical software vulnerabilities and exploits
Hannes Holm, Matus Korman, Mathias Ekstedt
Inf. Softw. Technol.3
2015 Towards general theories of software engineering
Pontus Johnson, Mathias Ekstedt, Michael Goedicke, Ivar Jacobson
Sci. Comput. Program.2
2015 P2CySeMoL: Predictive, Probabilistic Cyber Security Modeling Language
abstract
This paper presents the Predictive, Probabilistic Cyber Security Modeling Language (P2CySeMoL), an attack graph tool that can be used to estimate the cyber security of enterprise architectures. P2CySeMoL includes theory on how attacks and defenses relate quantitatively; thus, users must only model their assets and how these are connected in order to enable calculations. The performance of P2CySeMoL enables quick calculations of large object models. It has been validated on both a component level and a system level using literature, domain experts, surveys, observations, experiments and case studies.
Hannes Holm, Markus Buschle, Mathias Ekstedt
IEEE Trans. Dependable Secur. Comput.4
2014 Overview of Enterprise Information Needs in Information Security Risk Assessment
abstract
Methods for risk assessment in information security suggest users to collect and consider sets of input information, often notably different, both in type and size. To explore these differences, this study compares twelve established methods on how their input suggestions map to the concepts of ArchiMate, a widely used modeling language for enterprise architecture. Hereby, the study also tests the extent, to which ArchiMate accommodates the information suggested by the methods (e.g., for the use of ArchiMate models as a source of information for risk assessment). Results of this study show how the methods differ in suggesting input information in quantity, as well as in the coverage of the ArchiMate structure. Although the translation between ArchiMate and the methods' input suggestions is not perfect, our results indicate that ArchiMate is capable of modeling fair portions of the information needed for the methods for information security risk assessment, which makes ArchiMate models a promising source of guidance for performing risk assessments.
Matus Korman, Teodor Sommestad, Jonas Hallberg, Johan E. Bengtsson, Mathias Ekstedt
EDOC5
2014 Information security knowledge sharing in organizations: Investigating the effect of behavioral information security governance and national culture
Waldo Rocha Flores, Egil Antonsen, Mathias Ekstedt
Comput. Secur.3
2014 Indicators of expert judgement and their significance: an empirical investigation in the area of cyber security
abstract
Abstract In situations when data collection through observations is difficult to perform, the use of expert judgement can be justified. A challenge with this approach is, however, to value the credibility of different experts. A natural and state‐of‐the art approach is to weight the experts' judgements according to their calibration, that is, on the basis of how well their estimates of a studied event agree with actual observations of that event. However, when data collection through observations is difficult to perform, it is often also difficult to estimate the calibration of experts. As a consequence, variables thought to indicate calibration are generally used as a substitute of it in practice. This study evaluates the value of three such indicative variables: consensus, experience and self‐proclamation. The significances of these variables are analysed in four surveys covering different domains in cyber security, involving a total of 271 subjects. Results show that consensus is a reasonable indicator of calibration. The mean Pearson correlation between these two variables across the four studies was 0.407. No significant correlations were found between calibration and experience or calibration and self‐proclamation. However, as a side result, it was discovered that a subject that perceives itself as more knowledgeable than others likely also is more experienced.
Hannes Holm, Teodor Sommestad, Mathias Ekstedt, Nicholas Honeth
Expert Syst. J. Knowl. Eng.3
2014 Automatic data collection for enterprise architecture models
Hannes Holm, Markus Buschle, Robert Lagerström, Mathias Ekstedt
Softw. Syst. Model.4
2014 An enterprise architecture framework for multi-attribute information systems analysis
Per Närman, Markus Buschle, Mathias Ekstedt
Softw. Syst. Model.3
2013 Estimates on the effectiveness of web application firewalls against targeted attacks
abstract
Purpose – The purpose of this paper is to estimate the effectiveness of web application firewalls (WAFs) at preventing injection attacks by professional penetration testers given presence or absence of four conditions: whether there is an experienced operator monitoring the WAF; whether an automated black box tool has been used when tuning the WAF; whether the individual tuning the WAF is an experienced professional; and whether significant effort has been spent tuning the WAF. Design/methodology/approach – Estimates on the effectiveness of WAFs are made for 16 operational scenarios utilizing judgments by 49 domain experts participating in a web survey. The judgments of these experts are pooled using Cooke's classical method. Findings – The results show that the median prevention rate of a WAF is 80 percent if all measures have been employed. If no measure is employed then its median prevention rate is 25 percent. Also, there are no strong dependencies between any of the studied measures. Research limitations/implications – The results are only valid for the attacker profile of a professional penetration tester who prepares one week for attacking a WA protected by a WAF. Practical implications – The competence of the individual(s) tuning a WAF, employment of an automated black box tool for tuning and the manual effort spent on tuning are of great importance for the effectiveness of a WAF. The presence of an operator monitoring it has minor positive influence on its effectiveness. Originality/value – WA vulnerabilities are widely considered a serious concern. To manage them in deployed software, many enterprises employ WAFs. However, the effectiveness of this type of countermeasure under different operational scenarios is largely unknown.
Hannes Holm, Mathias Ekstedt
Inf. Manag. Comput. Secur.2
2013 Using enterprise architecture analysis and interview data to estimate service response time
Per Närman, Hannes Holm, Mathias Ekstedt, Nicholas Honeth
J. Strateg. Inf. Syst.3
2012 Assessment of Social Impact Costs and Social Impact Magnitude from Breakdowns in Critical Infrastructures
Mats B.-O. Larsson, Gunnar Björkman, Mathias Ekstedt
CRITIS3
2012 Estimates of success rates of remote arbitrary code execution attacks
abstract
Purpose The purpose of this paper is to identify the importance of the factors that influence the success rate of remote arbitrary code execution attacks. In other words, attacks which use software vulnerabilities to execute the attacker's own code on targeted machines. Both attacks against servers and attacks against clients are studied. Design/methodology/approach The success rates of attacks are assessed for 24 scenarios: 16 scenarios for server‐side attacks and eight for client‐side attacks. The assessment is made through domain experts and is synthesized using Cooke's classical method, an established method for weighting experts' judgments. The variables included in the study were selected based on the literature, a pilot study, and interviews with domain experts. Findings Depending on the scenario in question, the expected success rate varies between 15 and 67 percent for server‐side attacks and between 43 and 67 percent for client‐side attacks. Based on these scenarios, the influence of different protective measures is identified. Practical implications The results of this study offer guidance to decision makers on how to best secure their assets against remote code execution attacks. These results also indicate the overall risk posed by this type of attack. Originality/value Attacks that use software vulnerabilities to execute code on targeted machines are common and pose a serious risk to most enterprises. However, there are no quantitative data on how difficult such attacks are to execute or on how effective security measures are against them. The paper provides such data using a structured technique to combine expert judgments.
Teodor Sommestad, Hannes Holm, Mathias Ekstedt
Inf. Manag. Comput. Secur.3
2012 Empirical Analysis of System-Level Vulnerability Metrics through Actual Attacks
abstract
The Common Vulnerability Scoring System (CVSS) is a widely used and well-established standard for classifying the severity of security vulnerabilities. For instance, all vulnerabilities in the US National Vulnerability Database (NVD) are scored according to this method. As computer systems typically have multiple vulnerabilities, it is often desirable to aggregate the score of individual vulnerabilities to a system level. Several such metrics have been proposed, but their quality has not been studied. This paper presents a statistical analysis of how 18 security estimation metrics based on CVSS data correlate with the time-to-compromise of 34 successful attacks. The empirical data originates from an international cyber defense exercise involving over 100 participants and were collected by studying network traffic logs, attacker logs, observer logs, and network vulnerabilities. The results suggest that security modeling with CVSS data alone does not accurately portray the time-to-compromise of a system. However, results also show that metrics employing more CVSS data are more correlated with time-to-compromise. As a consequence, models that only use the weakest link (most severe vulnerability) to compose a metric are less promising than those that consider all vulnerabilities.
Hannes Holm, Mathias Ekstedt, Dennis Andersson
IEEE Trans. Dependable Secur. Comput.2
2011 Estimates of Success Rates of Denial-of-Service Attacks
abstract
Denial-of-service (DoS) attacks are an imminent and real threat to many enterprises. Decision makers in these enterprises need be able to assess the risk associated with such attacks and to make decisions regarding measures to put in place to increase the security posture of their systems. Experiments, simulations and analytical research have produced data related to DoS attacks. However, these results have been produced for different environments and are difficult to interpret, compare, and aggregate for the purpose of decision making. This paper aims to summarize knowledge available in the field by synthesizing the judgment of 23 domain experts using an establishing method for expert judgment analysis. Different system architecture's vulnerability to DoS attacks are assessed together with the impact of a number of countermeasures against DoS attacks.
Teodor Sommestad, Hannes Holm, Mathias Ekstedt
TrustCom3
2011 Security mistakes in information system deployment projects
abstract
Purpose This paper aims to assess the influence of a set of human and organizational factors in information system deployments on the probability that a number of security‐related mistakes are in the deployment. Design/methodology/approach A Bayesian network (BN) is created and analyzed over the relationship between mistakes and causes. The BN is created by eliciting qualitative and quantitative data from experts of industrial control system deployments in the critical infrastructure domain. Findings The data collected in this study show that domain experts have a shared perception of how strong the influence of human and organizational factors are. According to domain experts, this influence is strong. This study also finds that security flaws are common in industrial control systems operating critical infrastructure. Research limitations/implications The model presented in this study is created with the help of a number of domain experts. While they agree on qualitative structure and quantitative parameters, future work should assure that their opinion is generally accurate. Practical implications The influence of a set of important variables related to organizational/human aspects on information security flaws is presented. Social implications The context of this study is deployments of systems that operate nations' critical infrastructure. The findings suggest that initiatives to secure such infrastructures should not be purely technical. Originality/value Previous studies have focused on either the causes of security flaws or the actual flaws that can exist in installed information systems. However, little research has been spent on the relationship between them. The model presented in this paper quantifies such relationships.
Teodor Sommestad, Mathias Ekstedt, Hannes Holm
Inf. Manag. Comput. Secur.2
2010 Enterprise Architecture Meta Models for IT/Business Alignment Situations
abstract
Enterprise Architecture models can be used to support IT/business alignment. However, existing approaches do not distinguish between different IT/business alignment situations. Since companies face diverse challenges in achieving a high degree of IT/business alignment, a universal `one size fits all' approach does not seem appropriate. This paper proposes to decompose the IT/business alignment problem into tangible qualities for business, IT systems, and IT governance. An explorative study among 162 professionals is used to distinguish four IT/business alignment situations, i.e. four clusters of IT/business alignment problems. These situations each represent the current state according to certain qualities and also the priorities for future development. In order to increase IT/business alignment, enterprise architecture meta models are proposed for each identified situation. One core meta model (to reflect common priorities) as well as situation specific extensions are presented.
Jan Saat, Ulrik Franke, Robert Lagerström, Mathias Ekstedt
EDOC4
2010 A probabilistic relational model for security risk analysis
Teodor Sommestad, Mathias Ekstedt, Pontus Johnson
Comput. Secur.2
2010 Architecture analysis of enterprise systems modifiability: a metamodel for software change cost estimation
Robert Lagerström, Pontus Johnson, Mathias Ekstedt
Softw. Qual. J.3
2009 Enterprise Architecture Analysis for Data Accuracy Assessments
abstract
Poor data in information systems impede the quality of decision-making in many modern organizations. Manual business process activities and application services are never executed flawlessly which results in steadily deteriorating data accuracy, the further away from the source the data gets, the poorer its accuracy becomes. This paper proposes an architecture analysis method based on Bayesian Networks to assess data accuracy deterioration in a quantitative manner. The method is model-based and uses the ArchiMate language to model business processes and the way in which data objects are transformed by various operations. A case study at a Swedish utility demonstrates the approach.
Per Närman, Pontus Johnson, Mathias Ekstedt, Moustafa Chenine, Johan König
EDOC3
2009 A formal method for cost and accuracy trade-off analysis in software assessment measures
abstract
Creating accurate models of information systems is an important but challenging task. It is generally well understood that such modeling encompasses general scientific issues, but the monetary aspects of the modeling of software systems are not equally well acknowledged. The present paper describes a method using Bayesian networks for optimizing modeling strategies, perceived as a trade-off between these two aspects. Using GeNIe, a graphical tool with the proper Bayesian algorithms implemented, decision support can thus be provided to the modeling process. Specifically, an informed trade-off can be made, based on the modeler's prior knowledge of the predictive power of certain models, combined with his projection of their costs. It is argued that this method might enhance modeling of large and complex software systems in two principal ways: Firstly, by enforcing rigor and making hidden assumptions explicit. Secondly, by enforcing cost awareness even in the early phases of modeling. The method should be used primarily when the choice of modeling can have great economic repercussions.
Ulrik Franke, Pontus Johnson, Robert Lagerström, Johan Ullberg, David Höök, Mathias Ekstedt, Johan König
RCIS6
2008 The IT Organization Modeling and Assessment Tool for IT Governance Decision Support
Mårten Simonsson, Pontus Johnson, Mathias Ekstedt
CAiSE3
2008 Using Enterprise Architecture Models for System Quality Analysis
abstract
Enterprise Architecture is a model-based approach to business-oriented IT management. To promote good IT decision making, an Enterprise Architecture framework needs to explicate what kind of analyses it supports. Since creating Enterprise Architecture models is expensive and without intrinsic value, it is desirable to only create Enterprise Architecture models based on metamodels that support well-defined analyses. This paper presents the content and extension of a metamodel which supports creating models containing the information necessary to conduct system quality analyses, specifically with respect to availability, accuracy, confidentiality and integrity. The metamodel is an extension and formalization of the metamodel underlying the ArchiMate modelling language for Enterprise Architecture. The use of the extended metamodel is demonstrated in a case study where the availability, accuracy, confidentiality and integrity of the two Service Oriented Architecture (SOA) platforms Sun JCaps and PrOSeRO were evaluated.
Per Närman, Marten Schönherr, Pontus Johnson, Mathias Ekstedt, Moustafa Chenine
EDOC4
2008 Combining Defense Graphs and Enterprise Architecture Models for Security Analysis
abstract
Security is dependent on a mixture of interrelated concepts such as technical countermeasures, organizational policies, security procedures, and more. To facilitate rational decision making, these concepts need to be combined into an overall judgment on the current security posture, as well as potential future ones. Decision makers are, however, faced with uncertainty regarding both what countermeasures that is in place, and how well different countermeasures contribute to mitigating attacks. This paper presents a security assessment framework using the Bayesian statistics-based extended influence diagrams to combine attack graphs with countermeasures into defense graphs. The approach makes it possible to calculate the probability that attacks succeed based on an enterprise architecture model. The framework also takes uncertainties of the security assessment into consideration. Moreover, using the extended influence diagram formalism the expected loss from each attack can be calculated.
Teodor Sommestad, Mathias Ekstedt, Pontus Johnson
EDOC2
2007 In Search of a Unified Theory of Software Engineering
abstract
Highly successful scientific disciplines have at least one common denominator; they have developed unified theories that span a large set of phenomena within the discipline. The discipline of software engineering today features a multitude of disparate and fragmented micro-theories. Among these micro-theories, many speak of different things, many speak differently of similar things, and few can be employed consistently together. Since these micro-theories are so numerous and diverse, software engineering also lacks a common vocabulary for communication and argumentation. There are no real rules for separating sound arguments from unsound ones. This article argues that the search for a single unified theory of software engineering is both viable and desirable, hi order to do so, requirements for such a unified theory are outlined. Then three well-known software engineering theories that could constitute embryos to unified theories are considered in the light of the presented requirements.
Pontus Johnson, Mathias Ekstedt
ICSEA2