Kim Wuyts

dblp:23/6789 · DBLP profile ↗
← Back
9ranked-venue papers
3as first author
2since 2021 · last 2025
0000-0002-0950-9490ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author
YearPublicationVenuePosition
2025 Robust and reusable LINDDUN privacy threat knowledge
Laurens Sion, Dimitri Van Landuyt, Kim Wuyts, Wouter Joosen
Comput. Secur.3
2024 From insight to compliance: Appropriate technical and organisational security measures through the lens of cybersecurity maturity models
Christof Koolen, Kim Wuyts, Wouter Joosen, Peggy Valcke
Comput. Law Secur. Rev.2
2019 An Architectural View for Data Protection by Design
abstract
Data Protection by Design (DPbD) is a truly interdisciplinary effort that involves many stakeholders such as legal experts, requirements engineers, software architects, developers, and system operators. Building software-intensive systems that respect the fundamental rights to privacy and data protection is the result of intensive dialogue and careful trade-off decisions. In practice however, there is a dichotomy between the legal reasoning which is conducted in Data Protection Impact Assessments (DPIA) and software engineering approaches, such as threat modeling, aimed at identifying privacy requirements and privacy risks. These activities are commonly performed in total isolation, which negatively impacts (i) the compliance exercise, (ii) the ability to evolve the system over time, and (iii) the architectural trade-offs made during system design. In this article, we present an architectural viewpoint for describing software architectures from a legal, data protection perspective whose core modeling abstractions are based on an in-depth legal analysis of the EU General Data Protection Regulation. This viewpoint is tied to Data Flow Diagrams-commonly used in threat modeling-through correspondence rules. The proposed viewpoint supports the automation of a number of data protection impact assessment steps through (i) meta-model constraints, (ii) model analysis, and (iii) interaction with the involved stakeholders. This enables a streamlined compliance exercise, reconciling legal privacy and data protection notions with architecture-driven software engineering practices. We validate our approach in the context of a realistic e-health application for a number of complementary development scenarios.
Laurens Sion, Pierre Dewitte, Dimitri Van Landuyt, Kim Wuyts, Ivo Emanuilov, Peggy Valcke, Wouter Joosen
ICSA4
2019 A Data Utility-Driven Benchmark for De-identification Methods
abstract
De-identification is the process of removing the associations between data and identifying elements of individual data subjects. Its main purpose is to allow use of data while preserving the privacy of individual data subjects. It is thus an enabler for compliance with legal regulations such as the EU’s General Data Protection Regulation. While many de-identification methods exist, the required knowledge regarding technical implications of different de-identification methods is largely missing. In this paper, we present a data utility-driven benchmark for different de-identification methods. The proposed solution systematically compares de-identification methods while considering their nature, context and de-identified data set goal in order to provide a combination of methods that satisfies privacy requirements while minimizing losses of data utility. The benchmark is validated in a prototype implementation which is applied to a real life data set.
Oleksandr Tomashchuk, Dimitri Van Landuyt, Daniel Pletea, Kim Wuyts, Wouter Joosen
TrustBus4
2015 A descriptive study of Microsoft's threat modeling technique
Riccardo Scandariato, Kim Wuyts, Wouter Joosen
Requir. Eng.2
2014 Empirical evaluation of a privacy-focused threat modeling methodology
Kim Wuyts, Riccardo Scandariato, Wouter Joosen
J. Syst. Softw.1
2011 A privacy threat analysis framework: supporting the elicitation and fulfillment of privacy requirements
Mina Deng, Kim Wuyts, Riccardo Scandariato, Bart Preneel, Wouter Joosen
Requir. Eng.2
2009 Linking Privacy Solutions to Developer Goals
abstract
Privacy is gaining importance since more and more data becomes digitalized. There is also a growing interest from the security community because of the existing synergy between security and privacy. Unfortunately, the privacy development life cycle is less advanced than the security one. A clear classification into different objectives is not available yet. This paper attempts to scope the privacy landscape for software engineering by proposing an operational definition for privacy and by describing a privacy taxonomy. The taxonomy is rooted in the definition and presents a classification of privacy objectives, which correspond to the developer's goals. Each objective can be achieved by one or more strategies. As a validation for the taxonomy, existing privacy solutions are matched to each strategy.
Kim Wuyts, Riccardo Scandariato, Bart De Decker, Wouter Joosen
ARES1
2008 Hardening XDS-Based Architectures
abstract
Healthcare is an information-intensive domain and therefore information technologies are playing an ever-growing role in this sector. They are expected to increase the efficiency of the delivery of healthcare services in order to both improve the quality and reduce the costs. In this context, security has been identified as a priority although several gaps still exist. This paper reports on the results of assessing the threats to XDS-based architectures. Accordingly, an architectural solution to the identified threats is presented.
Kim Wuyts, Riccardo Scandariato, Geert Claeys, Wouter Joosen
ARES1