EDBT 2026 Demo / reviewers in the wild / expert
Teodor Sommestad
dblp:23/4603
· DBLP profile ↗
27ranked-venue papers
16as first author
3since 2021 · last 2025
0000-0002-2606-4139ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 14 first-author · 3 since 2021Software engineering, systems software and programming languages · 3Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Realistic and balanced automated threat emulation
Hannes Holm, Teodor Sommestad |
Comput. Secur. | 2 |
| 2025 | Training for improved information security culture: a longitudinal randomized controlled trialabstractPurpose The information security behaviors of individuals can pose a risk to their organization’s information security. To address employees’ information security behaviors and managers’ information security leadership behaviors, this paper aims to develop a behavioral training program called Training for Improved Information Security Culture (TIISC). TIISC consisted of information-security training for the employees and managerial behavioral training for the managers. The training program aimed at direct change of behavior as well as indirect change through improved information security culture, as manifested through information security climate. Design/methodology/approach The effects of TIISC on information security culture was assessed in a longitudinal randomized controlled trial. Data were collected over a 16-month period, using both behavioral measurements and questionnaires on behavior and climate. Latent growth modeling was used for the statistical analysis of change, in terms of how change differed between the control and experimental groups. Findings The results show that the training program had significant positive effects on the information security leadership of managers; but for employees, significant positive effects were only found for information security learning. Training programs that incorporate managerial behavioral training can realize important improvements in organizations’ information security culture, primarily by addressing managers’ information security leadership behaviors through behavior analysis and practice with performance feedback. Originality/value The authors report the results of a longitudinal randomized controlled trial testing the effects of information security training on multiple types of information security behaviors and approaches as indicators of information security culture. Longitudinal randomized controlled trials in security education training and awareness research are important because they advance the understanding of how information security culture can be effectively improved. Martin Grill, Teodor Sommestad, Henrik Karlzén, Anders Pousette |
Inf. Comput. Secur. | 2 |
| 2023 | Automatic incident response solutions: a review of proposed solutions' input and outputabstractMany organizations are exposed to the risk of cyber attacks that penetrate their computer networks. When such cyber attacks occur, e.g. a ransomware outbreak, it is desirable to quickly respond by containing the threat or limit its consequences. Technologies that support this process have been widely used for decades, including antivirus software and deep-packet inspection firewalls. A large number of researches on cyber security have been initiated to automate the incident handling process further, often motivated by the need to respond to more advanced cyber attacks or the increasing cyber risks at stake. This paper reviews the research on automatic incident response solutions published since the year 2000, in order to identify gaps as well as guide further research. The proposed solutions are categorized in terms of the input they use (e.g. intrusion signals) and the output they perform (e.g. reconfiguring a network) using the D3FEND framework. The solutions presented in 45 papers published in the academic literature are analyzed and compared to four commercially available solutions for automatic response. Many of the 45 papers described input and output in vague terms. The most common inputs were from asset inventories, platform monitoring and network traffic analysis. The most common output was network isolation measures, e.g. to reconfigure firewalls. Commercially available solutions focus more on looking for identifiers in reputation systems and individual analyzing files. Henrik Karlzén, Teodor Sommestad |
ARES | 2 |
| 2019 | The Theory of Planned Behavior and Information Security Policy ComplianceabstractMuch of the research on security policy compliance has tested the relationships posited by the theory of planned behavior. This theory explains far from all of the measurable variance in policy compliance intentions. However, it is associated with something called the sufficiency assumption, which essentially states that no variable is missing from the theory. This paper addresses this assumption in the context of information security policy compliance. A meta-analysis of published tests on information security behavior and a review of the literature in related fields are used to identify variables that have the potential to improve the theory’s predictions. These results are tested using a random sample of 645 white-collar workers. The results suggest that the variables anticipated regret and habit improve the predictions. The variables increase the explained variance by 3.4 and 2.6 percentage points, respectively, when they are added individually, and by 5.4 percentage points when both are added. Teodor Sommestad, Henrik Karlzén, Jonas Hallberg |
J. Comput. Inf. Syst. | 1 |
| 2018 | Work-related groups and information security policy complianceabstractPurpose It is widely acknowledged that norms and culture influence decisions related to information security. The purpose of this paper is to investigate how work-related groups influence information security policy compliance intentions and to what extent this influence is captured by the Theory of Planned Behavior, an established model over individual decision-making. Design/methodology/approach A multilevel model is used to test the influence of work-related groups using a cluster sample of responses from 2,291 employees from 203 worksites, 119 organizations, 6 industries and 38 professions. Findings The results suggest that work-related groups influence individuals’ decision-making in the manner in which contemporary theories of information security culture posit. However, the influence is weak to modest and overshadowed by individual perceptions that are straightforward to measure. Research limitations/implications This paper is limited to one national culture and four types of work-related groups. However, the results suggest that the Theory of Planned Behavior captures most of the influence that work-related groups have on decision-making. Future research on security culture and similar phenomena should take this into account. Practical implications Information security perceptions in work-related groups are diverse and information security decisions appear to be based on individual perceptions and priorities rather than groupthink or peer-pressure. Security management interventions may be more effective if they target individuals rather than groups. Originality/value This paper tests some of the basic ideas related to information security culture and its influence on individuals’ decision-making. Teodor Sommestad |
Inf. Comput. Secur. | 1 |
| 2017 | So long, and thanks for only using readily available scriptsabstractPurpose It is often argued that the increased automation and availability of offensive cyber tools has decreased the skill and knowledge required by attackers. Some say that all it takes to succeed with an attack is to follow some instructions and push some buttons. This paper aims to tests this idea empirically through live exploits and vulnerable machines in a cyber range. Design/methodology/approach The experiment involved 204 vulnerable machines in a cyber range. Exploits were chosen based on the results of automated vulnerability scanning. Each exploit was executed following a set of carefully planned actions that enabled reliable tests. A total of 1,223 exploitation attempts were performed. Findings A mere eight exploitation attempts succeeded. All these involved the same exploit module (ms08_067_netapi). It is concluded that server-side attacks still are too complicated for novices who lack the skill or knowledge to tune their attacks. Originality/value This paper presents the largest conducted test of exploit effectiveness to date. It also presents a sound method for reliable tests of exploit effectiveness (or system vulnerability). Hannes Holm, Teodor Sommestad |
Inf. Comput. Secur. | 2 |
| 2016 | An empirical test of the perceived relationship between risk and the constituents severity and probabilityabstractPurpose In methods and manuals, the product of an information security incident’s probability and severity is seen as a risk to manage. The purpose of the test described in this paper is to investigate if information security risk is perceived in this way, if decision-making style influences the perceived relationship between the three variables and if the level of information security expertise influences the relationship between the three variables. Design/methodology/approach Ten respondents assessed 105 potential information security incidents. Ratings of the associated risks were obtained independently from ratings of the probability and severity of the incidents. Decision-making style was measured using a scale inspired from the Cognitive Style Index; information security expertise was self-reported. Regression analysis was used to test the relationship between variables. Findings The ten respondents did not assess risk as the product of probability and severity, regardless of experience, expertise and decision-making style. The mean variance explained in risk ratings using an additive term is 54.0 or 38.4 per cent, depending on how risk is measured. When a multiplicative term was added, the mean variance only increased by 1.5 or 2.4 per cent. For most of the respondents, the contribution of the multiplicative term is statistically insignificant. Practical Implications The inability or unwillingness to see risk as a product of probability and severity suggests that procedural support (e.g. risk matrices) has a role to play in the risk assessment processes. Originality/value This study is the first to test if information security risk is assessed as an interaction between probability and severity using suitable scales and a within-subject design. Teodor Sommestad, Henrik Karlzén, Jonas Hallberg |
Inf. Comput. Secur. | 1 |
| 2015 | Requirements engineering: The quest for the dependent variableabstractRequirements engineering is a vibrant and broad research area. It covers a range of activities with different objectives. By reviewing experiments previously included in systematic literature reviews, this paper provides an overview of the dependent variables used in experimental requirements engineering research. This paper also identifies the theoretical motivation for the use of these variables in the experiments. The results show that a wide range of different variables has been applied in experiments and operationalized through both subjective assessments (e.g., subjects' perceived utility of a technique) and objective measurements (e.g., the number of defects found in a requirements specification). The theoretical basis for these variables and operationalizations are unclear in most cases. Directions for theoretical work to identify suitable dependent variables are provided. Hannes Holm, Teodor Sommestad, Johan E. Bengtsson |
RE | 2 |
| 2015 | Social Groupings and Information Security Obedience Within Organizations
Teodor Sommestad |
SEC | 1 |
| 2015 | A Meta-Analysis of Studies on Protection Motivation Theory and Information Security BehaviourabstractIndividuals' willingness to take security precautions is imperative to their own information security and the information security of the organizations they work within. This paper presents a meta-analysis of the protection motivation theory (PMT) to assess how its efficacy is influenced by the information security behavior it is applied to. It investigates if the PMT explains information security behavior better if: 1) The behavior is voluntary? 2) The threat and coping method is concrete or specific? 3) The information security threat is directed to the person itself? Synthesized data from 28 surveys suggests that the answers to all three questions are yes. Weighted mean correlation coefficients are on average 0.03 higher for voluntary behavior than mandatory behavior, 0.05 higher for specific behaviors than studies of general behaviors, 0.08 higher to threat appraisal when the threat targets the individual person instead of the person's organization or someone else. Teodor Sommestad, Henrik Karlzén, Jonas Hallberg |
Int. J. Inf. Secur. Priv. | 1 |
| 2015 | The sufficiency of the theory of planned behavior for explaining information security policy complianceabstractPurpose – This paper aims to challenge the assumption that the theory of planned behaviour (TPB) includes all constructs that explain information security policy compliance and investigates if anticipated regret or constructs from the protection motivation theory add explanatory power. The TPB is an established theory that has been found to predict compliance with information security policies well. Design/methodology/approach – Responses from 306 respondents at a research organization were collected using a questionnaire-based survey. Extensions in terms of anticipated regret and constructs drawn from the protection motivation theory are tested using hierarchical regression analysis. Findings – Adding anticipated regret and the threat appraisal process results in improvements of the predictions of intentions. The improvements are of sufficient magnitude to warrant adjustments of the model of the TPB when it is used in the area of information security policy compliance. Originality/value – This study is the first test of anticipated regret as a predictor of information security policy compliance and the first to assess its influence in relation to the TPB and the protection motivation theory. Teodor Sommestad, Henrik Karlzén, Jonas Hallberg |
Inf. Comput. Secur. | 1 |
| 2015 | An empirical test of the accuracy of an attack graph analysis toolabstractPurpose – The purpose of this paper is to test the practical utility of attack graph analysis. Attack graphs have been proposed as a viable solution to many problems in computer network security management. After individual vulnerabilities are identified with a vulnerability scanner, an attack graph can relate the individual vulnerabilities to the possibility of an attack and subsequently analyze and predict which privileges attackers could obtain through multi-step attacks (in which multiple vulnerabilities are exploited in sequence). Design/methodology/approach – The attack graph tool, MulVAL, was fed information from the vulnerability scanner Nexpose and network topology information from 8 fictitious organizations containing 199 machines. Two teams of attackers attempted to infiltrate these networks over the course of two days and reported which machines they compromised and which attack paths they attempted to use. Their reports are compared to the predictions of the attack graph analysis. Findings – The prediction accuracy of the attack graph analysis was poor. Attackers were more than three times likely to compromise a host predicted as impossible to compromise compared to a host that was predicted as possible to compromise. Furthermore, 29 per cent of the hosts predicted as impossible to compromise were compromised during the two days. The inaccuracy of the vulnerability scanner and MulVAL’s interpretation of vulnerability information are primary reasons for the poor prediction accuracy. Originality/value – Although considerable research contributions have been made to the development of attack graphs, and several analysis methods have been proposed using attack graphs, the extant literature does not describe any tests of their accuracy under realistic conditions. Teodor Sommestad, Fredrik Sandström |
Inf. Comput. Secur. | 1 |
| 2015 | A test of intrusion alert filtering based on network informationabstractIntrusion detection systems continue to be a promising security technology. The arguably biggest problem with today's intrusion detection systems is the sheer number of alerts they produce for events that are regarded as benign or non-critical by system administrators. A plethora of more and less complex solutions has been proposed to filter the relevant i.e., correct alerts that signature-based intrusion detection sensors produce. This paper reports on a test performed to test a number of filtering alternatives that take advantage of information about static properties of the monitored computer network, such as vulnerabilities and exposure of ports and hosts. The results show that none of the filters are able to maintain a high recall portion of detected attacks while increasing the precision portion of relevant alerts. At most, precision increased from 1.4% to 2.9%, and this also resulted in a decrease in recall from 44% to 26%. Even when combined in an exploratory fashion, the filters fail to provide improved precision. It is concluded that filters based on static properties of the computer network do not result in clear improvements to alert lists produced by signature-based intrusion detection systems. Copyright © 2015 John Wiley & Sons, Ltd. Teodor Sommestad, Ulrik Franke |
Secur. Commun. Networks | 1 |
| 2014 | Overview of Enterprise Information Needs in Information Security Risk AssessmentabstractMethods for risk assessment in information security suggest users to collect and consider sets of input information, often notably different, both in type and size. To explore these differences, this study compares twelve established methods on how their input suggestions map to the concepts of ArchiMate, a widely used modeling language for enterprise architecture. Hereby, the study also tests the extent, to which ArchiMate accommodates the information suggested by the methods (e.g., for the use of ArchiMate models as a source of information for risk assessment). Results of this study show how the methods differ in suggesting input information in quantity, as well as in the coverage of the ArchiMate structure. Although the translation between ArchiMate and the methods' input suggestions is not perfect, our results indicate that ArchiMate is capable of modeling fair portions of the information needed for the methods for information security risk assessment, which makes ArchiMate models a promising source of guidance for performing risk assessments. Matus Korman, Teodor Sommestad, Jonas Hallberg, Johan E. Bengtsson, Mathias Ekstedt |
EDOC | 2 |
| 2014 | Indicators of expert judgement and their significance: an empirical investigation in the area of cyber securityabstractAbstract In situations when data collection through observations is difficult to perform, the use of expert judgement can be justified. A challenge with this approach is, however, to value the credibility of different experts. A natural and state‐of‐the art approach is to weight the experts' judgements according to their calibration, that is, on the basis of how well their estimates of a studied event agree with actual observations of that event. However, when data collection through observations is difficult to perform, it is often also difficult to estimate the calibration of experts. As a consequence, variables thought to indicate calibration are generally used as a substitute of it in practice. This study evaluates the value of three such indicative variables: consensus, experience and self‐proclamation. The significances of these variables are analysed in four surveys covering different domains in cyber security, involving a total of 271 subjects. Results show that consensus is a reasonable indicator of calibration. The mean Pearson correlation between these two variables across the four studies was 0.407. No significant correlations were found between calibration and experience or calibration and self‐proclamation. However, as a side result, it was discovered that a subject that perceives itself as more knowledgeable than others likely also is more experienced. Hannes Holm, Teodor Sommestad, Mathias Ekstedt, Nicholas Honeth |
Expert Syst. J. Knowl. Eng. | 2 |
| 2014 | Variables influencing information security policy compliance: A systematic review of quantitative studiesabstractPurpose – The purpose of this paper is to identify variables that influence compliance with information security policies of organizations and to identify how important these variables are. Design/methodology/approach – A systematic review of empirical studies described in extant literature is performed. This review found 29 studies meeting its inclusion criterion. The investigated variables in these studies and the effect size reported for them were extracted and analysed. Findings – In the 29 studies, more than 60 variables have been studied in relation to security policy compliance and incompliance. Unfortunately, no clear winners can be found among the variables or the theories they are drawn from. Each of the variables only explains a small part of the variation in people's behaviour and when a variable has been investigated in multiple studies the findings often show a considerable variation. Research limitations/implications – It is possible that the disparate findings of the reviewed studies can be explained by the sampling methods used in the studies, the treatment/control of extraneous variables and interplay between variables. These aspects ought to be addressed in future research efforts. Practical implications – For decision makers who seek guidance on how to best achieve compliance with their information security policies should recognize that a large number of variables probably influence employees' compliance. In addition, both their influence strength and interplay are uncertain and largely unknown. Originality/value – This is the first systematic review of research on variables that influence compliance with information security policies of organizations. Teodor Sommestad, Jonas Hallberg, Kristoffer Lundholm, Johan E. Bengtsson |
Inf. Manag. Comput. Secur. | 1 |
| 2013 | A Review of the Theory of Planned Behaviour in the Context of Information Security Policy Compliance
Teodor Sommestad, Jonas Hallberg |
SEC | 1 |
| 2013 | Intrusion detection and the role of the system administratorabstractPurpose The expertise of a system administrator is believed to be important for effective use of intrusion detection systems (IDS). This paper examines two hypotheses concerning the system administrators' ability to filter alarms produced by an IDS by comparing the performance of an IDS to the performance of a system administrator using the IDS. Design/methodology/approach An experiment was constructed where five computer networks are attacked during four days. The experiment assessed difference made between the output of a system administrator using an IDS and the output of the IDS alone. The administrator's analysis process was also investigated through interviews. Findings The experiment shows that the system administrator analysing the output from the IDS significantly improves the portion of alarms corresponding to attacks, without decreasing the probability that an attack is detected significantly. In addition, an analysis is made of the types of expertise that is used when output from the IDS is processed by the administrator. Originality/value Previous work, based on interviews with system administrators, has suggested that competent system administrators are important in order to achieve effective IDS solutions. This paper presents a quantitative test of the value system administrators add to the intrusion detection solution. Teodor Sommestad, Amund Hunstad |
Inf. Manag. Comput. Secur. | 1 |
| 2012 | Estimates of success rates of remote arbitrary code execution attacksabstractPurpose The purpose of this paper is to identify the importance of the factors that influence the success rate of remote arbitrary code execution attacks. In other words, attacks which use software vulnerabilities to execute the attacker's own code on targeted machines. Both attacks against servers and attacks against clients are studied. Design/methodology/approach The success rates of attacks are assessed for 24 scenarios: 16 scenarios for server‐side attacks and eight for client‐side attacks. The assessment is made through domain experts and is synthesized using Cooke's classical method, an established method for weighting experts' judgments. The variables included in the study were selected based on the literature, a pilot study, and interviews with domain experts. Findings Depending on the scenario in question, the expected success rate varies between 15 and 67 percent for server‐side attacks and between 43 and 67 percent for client‐side attacks. Based on these scenarios, the influence of different protective measures is identified. Practical implications The results of this study offer guidance to decision makers on how to best secure their assets against remote code execution attacks. These results also indicate the overall risk posed by this type of attack. Originality/value Attacks that use software vulnerabilities to execute code on targeted machines are common and pose a serious risk to most enterprises. However, there are no quantitative data on how difficult such attacks are to execute or on how effective security measures are against them. The paper provides such data using a structured technique to combine expert judgments. Teodor Sommestad, Hannes Holm, Mathias Ekstedt |
Inf. Manag. Comput. Secur. | 1 |
| 2011 | Estimates of Success Rates of Denial-of-Service AttacksabstractDenial-of-service (DoS) attacks are an imminent and real threat to many enterprises. Decision makers in these enterprises need be able to assess the risk associated with such attacks and to make decisions regarding measures to put in place to increase the security posture of their systems. Experiments, simulations and analytical research have produced data related to DoS attacks. However, these results have been produced for different environments and are difficult to interpret, compare, and aggregate for the purpose of decision making. This paper aims to summarize knowledge available in the field by synthesizing the judgment of 23 domain experts using an establishing method for expert judgment analysis. Different system architecture's vulnerability to DoS attacks are assessed together with the impact of a number of countermeasures against DoS attacks. Teodor Sommestad, Hannes Holm, Mathias Ekstedt |
TrustCom | 1 |
| 2011 | A quantitative evaluation of vulnerability scanningabstractPurpose The purpose of this paper is to evaluate if automated vulnerability scanning accurately identifies vulnerabilities in computer networks and if this accuracy is contingent on the platforms used. Design/methodology/approach Both qualitative comparisons of functionality and quantitative comparisons of false positives and false negatives are made for seven different scanners. The quantitative assessment includes data from both authenticated and unauthenticated scans. Experiments were conducted on a computer network of 28 hosts with various operating systems, services and vulnerabilities. This network was set up by a team of security researchers and professionals. Findings The data collected in this study show that authenticated vulnerability scanning is usable. However, automated scanning is not able to accurately identify all vulnerabilities present in computer networks. Also, scans of hosts running Windows are more accurate than scans of hosts running Linux. Research limitations/implications This paper focuses on the direct output of automated scans with respect to the vulnerabilities they identify. Areas such as how to interpret the results assessed by each scanner (e.g. regarding remediation guidelines) or aggregating information about individual vulnerabilities into risk measures are out of scope. Practical implications This paper describes how well automated vulnerability scanners perform when it comes to identifying security issues in a network. The findings suggest that a vulnerability scanner is a useable tool to have in your security toolbox given that user credentials are available for the hosts in your network. Manual effort is however needed to complement automated scanning in order to get satisfactory accuracy regarding network security problems. Originality/value Previous studies have focused on the qualitative aspects on vulnerability assessment. This study presents a quantitative evaluation of seven of the most popular vulnerability scanners available on the market. Hannes Holm, Teodor Sommestad, Jonas Almroth, Mats Persson |
Inf. Manag. Comput. Secur. | 2 |
| 2011 | Security mistakes in information system deployment projectsabstractPurpose This paper aims to assess the influence of a set of human and organizational factors in information system deployments on the probability that a number of security‐related mistakes are in the deployment. Design/methodology/approach A Bayesian network (BN) is created and analyzed over the relationship between mistakes and causes. The BN is created by eliciting qualitative and quantitative data from experts of industrial control system deployments in the critical infrastructure domain. Findings The data collected in this study show that domain experts have a shared perception of how strong the influence of human and organizational factors are. According to domain experts, this influence is strong. This study also finds that security flaws are common in industrial control systems operating critical infrastructure. Research limitations/implications The model presented in this study is created with the help of a number of domain experts. While they agree on qualitative structure and quantitative parameters, future work should assure that their opinion is generally accurate. Practical implications The influence of a set of important variables related to organizational/human aspects on information security flaws is presented. Social implications The context of this study is deployments of systems that operate nations' critical infrastructure. The findings suggest that initiatives to secure such infrastructures should not be purely technical. Originality/value Previous studies have focused on either the causes of security flaws or the actual flaws that can exist in installed information systems. However, little research has been spent on the relationship between them. The model presented in this paper quantifies such relationships. Teodor Sommestad, Mathias Ekstedt, Hannes Holm |
Inf. Manag. Comput. Secur. | 1 |
| 2010 | A probabilistic relational model for security risk analysis
Teodor Sommestad, Mathias Ekstedt, Pontus Johnson |
Comput. Secur. | 1 |
| 2008 | Combining Defense Graphs and Enterprise Architecture Models for Security AnalysisabstractSecurity is dependent on a mixture of interrelated concepts such as technical countermeasures, organizational policies, security procedures, and more. To facilitate rational decision making, these concepts need to be combined into an overall judgment on the current security posture, as well as potential future ones. Decision makers are, however, faced with uncertainty regarding both what countermeasures that is in place, and how well different countermeasures contribute to mitigating attacks. This paper presents a security assessment framework using the Bayesian statistics-based extended influence diagrams to combine attack graphs with countermeasures into defense graphs. The approach makes it possible to calculate the probability that attacks succeed based on an enterprise architecture model. The framework also takes uncertainties of the security assessment into consideration. Moreover, using the extended influence diagram formalism the expected loss from each attack can be calculated. Teodor Sommestad, Mathias Ekstedt, Pontus Johnson |
EDOC | 1 |
| 2008 | Web Service-Based Business Process Development, Threat Modeling and Security Assessment ToolabstractSummary form only given. A business process is a collection of related structures and activities, undertaken by organizations in order to achieve certain business goals. The Web services-based business processes with a new set of protocols bring a new set of security challenges. As security has become an essential component for all software, several security solutions for XML and Web services have been proposed. In general, a security threat model is an organized representation of relevant threats, attacks, and vulnerabilities to a system. In this context, security threat modeling is an engineering technique which can be used to shape the Web service-based business processes with security requirements. The topic of security threat modeling in business process is becoming increasingly important to industry. This tutorial strives to reflect recent trends in research and developments of business processes integration and management with security concerns. In addition this tutorial will cover the fundamental concepts of security threat modeling from the perspectives of Web service-based business process. This tutorial will also address the common practices and related tools/procedures for addressing the security vulnerabilities, especially in XML attacks. A research prototype of security assessment will also be presented and demonstrated in the tutorial. Jianxin Li 0002, Teodor Sommestad, Patrick C. K. Hung |
ICWS | 2 |
| 2008 | Emergency Response Framework for Aviation XML Services on MANETabstractA XML service is a software component that supports interoperable application-to-application interaction over a network. Each service makes its functionality available through well-defined or standardized XML interfaces. Aviation XML services refer to the services that make operating an airplane in air and on ground possible. In this paper, we present an emergency response framework to organize the aviation XML services to work cooperatively on mobile ad hoc networks (MANETs). A MANET is defined as a self-organized and rapidly deployed network of XML services in order to exchange information without using any pre-existing fixed network infrastructure. Note that the framework does not have to be limited to the aviation sector. The methodology can also be adopted into other MANET computing scenarios including: natural disaster communications (e.g., tsunami, earthquakes), emergency relief scenarios, car-based networks, and the provision of wireless connectivity in remote areas. Teodor Sommestad, Casey K. Fung, Patrick C. K. Hung |
ICWS | 2 |
| 2007 | A Tool for Enterprise Architecture AnalysisabstractThe discipline of enterprise architecture advocates the use of models to support decision-making on enterprise-wide information system issues. In order to provide such support, enterprise architecture models should be amenable to analyses of various properties, as e.g. the availability, performance, interoperability, modifiability, and information security of the modeled enterprise information systems. This paper presents a software tool for such analyses. The tool guides the user in the generation of enterprise architecture models and subjects these models to analyses resulting in quantitative measures of the chosen quality attribute. The paper describes and exemplifies both the architecture and the usage of the tool. 1. Pontus Johnson, Erik Johansson, Teodor Sommestad, Johan Ullberg |
EDOC | 3 |