EDBT 2026 Demo / reviewers in the wild / expert
Ludwig Fuchs
dblp:28/6518
· DBLP profile ↗
16ranked-venue papers
6as first author
4since 2021 · last 2024
0009-0002-8432-6755ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 6 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | A Framework for Managing Separation of Duty PoliciesabstractSeparation of Duty (SoD) is a fundamental principle in information security. Especially large and highly regulated companies have to manage a huge number of SoD policies. These policies need to be maintained in an ongoing effort in order to remain accurate and compliant with regulatory requirements. In this work we develop a framework for managing SoD policies that pays particular attention to policy comprehensibility. We conducted seven semi-structured interviews with SoD practitioners from large organizations in order to understand the requirements for managing and maintaining SoD policies. Drawing from the obtained insights, we developed a framework, which includes the relevant stakeholders and tasks, as well as a policy structure that aims to simplify policy maintenance. We anchor the proposed policy structure in a generic IAM data model to ensure compatibility and flexibility with other IAM models. We then show exemplary how our approach can be enforced within Role-Based Access Control. Finally, we evaluate the proposed framework with a real-world IAM data set provided by a large finance company. Sebastian Groll, Sascha Kern, Ludwig Fuchs, Günther Pernul |
ARES | 3 |
| 2023 | Maintain High-Quality Access Control Policies: An Academic and Practice-Driven Approach
Sascha Kern, Thomas Baumer, Ludwig Fuchs, Günther Pernul |
DBSec | 3 |
| 2022 | Optimization of Access Control PoliciesabstractOrganizations undertake complex and costly projects to model high-quality Access Control Policies (ACPs). Once built, these policies must be maintained and managed in an ongoing process to keep their quality high. Insufficient maintenance leads to inaccurate authorization decisions and increases the policies’ administrative effort and susceptibility to errors. While the initial modeling of ACPs has received significant research interest, their optimization is not yet covered as broadly. This work provides a theoretical foundation for ACP quality and its optimization. Furthermore, it analyzes how existing research addresses optimization of ACPs with regard to six crucial optimization dimensions. It presents a structured literature survey tracing these optimization dimensions, the contributed research artifact and data requirements. Building on this literature catalogue, this work elaborates on inaccuracies for user permission assignments, data availability, minimal perturbation and recommendation-based optimization. Sascha Kern, Thomas Baumer, Sebastian Groll, Ludwig Fuchs, Günther Pernul |
J. Inf. Secur. Appl. | 4 |
| 2021 | Monitoring Access Reviews by Crowd Labelling
Sebastian Groll, Sascha Kern, Ludwig Fuchs, Günther Pernul |
TrustBus | 3 |
| 2019 | Attribute quality management for dynamic identity and access management
Michael Kunz, Alexander Puchta, Sebastian Groll, Ludwig Fuchs, Günther Pernul |
J. Inf. Secur. Appl. | 4 |
| 2018 | Measuring Identity and Access Management Performance - An Expert Survey on Possible Performance Indicators
Matthias Hummer, Sebastian Groll, Michael Kunz, Ludwig Fuchs, Günther Pernul |
ICISSP | 4 |
| 2016 | Adaptive identity and access management - contextual data based policiesabstractDue to compliance and IT security requirements, company-wide identity and access management within organizations has gained significant importance in research and practice over the last years. Companies aim at standardizing user management policies in order to reduce administrative overhead and strengthen IT security. These policies provide the foundation for every identity and access management system no matter if poured into IT systems or only located within responsible identity and access management (IAM) engineers’ mind. Despite its relevance, hardly any supportive means for the automated detection and refinement as well as management of policies are available. As a result, policies outdate over time, leading to security vulnerabilities and inefficiencies. Existing research mainly focuses on policy detection and enforcement without providing the required guidance for policy management nor necessary instruments to enable policy adaptibility for today’s dynamic IAM. This paper closes the existing gap by proposing a dynamic policy management process which structures the activities required for policy management in identity and access management environments. In contrast to current approaches, it utilizes the consideration of contextual user management data and key performance indicators for policy detection and refinement and offers result visualization techniques that foster human understanding. In order to underline its applicability, this paper provides an evaluation based on real-life data from a large industrial company. Matthias Hummer, Michael Kunz, Michael Netter, Ludwig Fuchs, Günther Pernul |
EURASIP J. Inf. Secur. | 4 |
| 2015 | Advanced Identity and Access Policy Management Using Contextual DataabstractDue to compliance and IT security requirements, company-wide Identity and Access Management within organizations has gained significant importance in research and practice over the last years. Companies aim at standardizing user management policies in order to reduce administrative overhead and strengthen IT security. Despite of its relevance, hardly any supportive means for the automated detection and refinement as well as management of policies are available. As a result, policies outdate over time, leading to security vulnerabilities and inefficiencies. Existing research mainly focuses on policy detection without providing the required guidance for policy management. This paper closes the existing gap by proposing a Dynamic Policy Management Process which structures the activities required for policy management in Identity and Access Management environments. In contrast to current approaches it fosters the consideration of contextual user management data for policy detection and refinement and offers result visualization techniques that foster human understanding. In order to underline its applicability, this paper provides a naturalistic evaluation based on real-life data from a large industrial company. Matthias Hummer, Michael Kunz, Michael Netter, Ludwig Fuchs, Günther Pernul |
ARES | 4 |
| 2015 | Analyzing Quality Criteria in Role-based Identity and Access ManagementabstractRoles have turned into the de facto standard for access control in enterprise identity management systems. However, as roles evolve over time, companies struggle to develop and maintain a consistent role model. Up to now, the core challenge of measuring the current quality of a role model and selecting criteria for its optimization remains unsolved. In this paper, we conduct a survey of existing role mining techniques and\nidentify quality criteria inherently used by these approaches. This guides organizations during the selection of a role mining technique that matches their company-specific quality references. Moreover, our analysis aims to stimulate the research community to integrate quality metrics in future role mining approaches. Michael Kunz, Ludwig Fuchs, Michael Netter, Günther Pernul |
ICISSP | 2 |
| 2012 | Minimizing insider misuse through secure Identity ManagementabstractABSTRACT To avoid insider computer misuse, identity, and authorization data referring to the legitimate users of systems must be properly organized, constantly and systematically analyzed, and evaluated. In order to support this, structured and secure Identity Management is required. A comprehensive methodology supporting Identity Management within organizations has been developed, including gathering of identity data spread among different applications, systematic cleansing of user account data in order to detect semantic as well as syntactic errors, grouping of privileges and access rights, and semiautomatic engineering of user roles. The focus of this paper is on the cleansing of identity and account data leading to feedback where insider misuse due to existing privileges which go beyond the scope of the users' current need‐to‐know may occur. The paper in detail presents used data cleansing mechanisms and underlines their applicability in two real‐world case studies. Copyright © 2011 John Wiley & Sons, Ltd. Ludwig Fuchs, Günther Pernul |
Secur. Commun. Networks | 1 |
| 2011 | The Role Mining Process Model - Underlining the Need for a Comprehensive Research PerspectiveabstractOrganizations that migrate from identity-centric to role-based Identity Management face the initial task of defining a valid set of roles for their employees. Due to its capabilities of automated and fast role detection, role mining as a solution for dealing with this challenge has gathered a rapid increase of interest in the academic community. Research activities throughout the last years resulted in a large number of different approaches, each covering specific aspects of the challenge. In this paper, firstly, a survey of the research area provides insight into the development of the field, underlining the need for a comprehensive perspective on role mining. Consecutively, a generic process model for role mining including pre- and post-processing activities is introduced and existing research activities are classified according to this model. The goal is to provide a basis for evaluating potentially valuable combinations of those approaches in the future. Ludwig Fuchs, Stefan Meier |
ARES | 1 |
| 2011 | Roles in information security - A survey and classification of the research area
Ludwig Fuchs, Günther Pernul, Ravi S. Sandhu |
Comput. Secur. | 1 |
| 2009 | Different Approaches to In-House Identity Management - Justification of an AssumptionabstractThe use of roles in identity management infrastructures (IdMI) has proven to be a solution for reorganising and securing access structures of employees. The definition of enterprise-wide roles is one of the most challenging and costly tasks during role development projects. It needs to be carried out on the basis of a predefined role development methodology (RDM). In this paper we present existing methodologies and show their respective pros and cons. Lately some researchers have informally stated that hybrid role development is the most promising way to define roles, however, there hasnpsilat been given a well-defined justification for this decision. The main contribution of this paper is hence the deduction of evaluation criteria based on information gathered from literature, practical experiences, and shortcomings of existing role development approaches. The evaluation criteria form the basis for a comparison framework verifying the assumption that hybrid RDMs are superior to role engineering and role mining methodologies. Ludwig Fuchs, Christian Broser, Günther Pernul |
ARES | 1 |
| 2008 | Intensive Programme on Information and Communication SecurityabstractIT Security is a problem that can only be addressed and taught holistically. Just as broad as the field of ICT itself, IT Security is an integral part of all network and software applications. Security must be guaranteed throughout services. Too often, a single university or department cannot offer the complete range of IT Security subjects to their students or provide the up-to-date information and knowledge needed. Consequently, the demand of keeping up with hackers, threats, and risks is hardly met. Our proposal is a combination of the know-how of multiple institutions, aligned in an Intensive Programme for Master- and PhD Students of Computer Science, Information Systems, and Business Informatics. The proposed Intensive Programme on Information and Communication Security (IPICS) uses e-learning and traditional learning methods to form a blended learning course. Using the synergies of 19 contracted European Universities and their IT Security experts, IPICS will deliver momentum for IT Security education and training to those who take part and furthermore through their networks. Christian Schläger, Ludwig Fuchs, Günther Pernul |
ARES | 2 |
| 2008 | BusiROLE: A Model for Integrating Business Roles into Identity Management
Ludwig Fuchs, Anton Preis |
TrustBus | 1 |
| 2007 | Supporting Compliant and Secure User Handling - A Structured Approach for In-House Identity ManagementabstractThe catchword "compliance" dominates the actual debate about identity management and information security like few before. Companies need to comply with a variety of internal and external standards and regulations like the US SOX Act. Identity management is seen as a main provider of compliance in modern companies. However, its organisational aspects are underestimated in many projects, lacking a comprehensive approach to introduce in-house identity management. This work is based on the experiences gained from industry projects using identity management functionalities to strengthen security and to reach a high level of compliance. We develop a structured process-oriented methodology for introducing an identity management infrastructure for organisations using drivers from IT security management to evaluate, rank, and implement subprojects. The methodology consists of an iterative process which enables even large and unstructured organisations to reach a suitable and profitable level of identity management by emphasising on organisational aspects rather than taking a merely technical approach Ludwig Fuchs, Günther Pernul |
ARES | 1 |