EDBT 2026 Demo / reviewers in the wild / expert
Maria Leitner
dblp:61/10434
· DBLP profile ↗
18ranked-venue papers
9as first author
6since 2021 · last 2025
0000-0003-1371-5446ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 7 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Data Collection in Cyber Exercises Through Monitoring Points: Observing, Steering, and Scoring
Tobias Pfaller, Florian Skopik, Lenhard Reuter, Maria Leitner |
ICISSP (1) | 4 |
| 2023 | BAnDIT: Business Process Anomaly Detection in Transactions
Nico Rudolf, Kristof Böhmer, Maria Leitner |
CoopIS | 3 |
| 2023 | A Scenario-Driven Cyber Security Awareness Exercise Utilizing Dynamic Polling: Methodology and Lessons Learned
Maria Leitner |
ICISSP | 1 |
| 2023 | Machine Learning Based Prediction of Frequency Hopping Spread Spectrum SignalsabstractIn an world shifting towards wireless communications, the already scarce electromagnetic spectrum within the unlicensed bands is becoming increasingly crowded. All wireless devices operating in those bands need to co-exist without interfering with each other. Frequency hopping spread spectrum (FHSS) is a communication technique especially resilient to interference due to its constant change of the carrier frequency and its narrowband transmission bandwidth. Furthermore, it produces minimal interference to other signals in the same frequency band using wider bandwidth. However, interference can also be harmful even for FHSS transmissions as a result of the loaded ISM bands. Intelligent spectrum sensing techniques can contribute to a more efficient spectral usage. In this paper, we propose a supervised learning algorithm which predicts the future time-frequency location of a FHSS signal. We design a convolutional neural network which is trained on a dataset, obtained from measurements of two FHSS sources. Based only on a small observation window of 50 ms, it predicts the signal appearance of the following 25 ms in a time-frequency representation. To show that we can accurately predict the signal, we introduce a special score measure. The mean score of about 0.9 with small standard deviation demonstrates the high fidelity prediction of the signal’s evolution. Pascal Thiele, Laura Bernadó, David Loeschenbrand, Benjamin Rainer, Christoph Sulzbachner, Maria Leitner, Thomas Zemen |
PIMRC | 6 |
| 2022 | Collaborative Patterns for Workflows with Collaborative Robots
Stefan Samhaber, Maria Leitner |
CoopIS | 2 |
| 2021 | Preparing for National Cyber Crises Using Non-linear Cyber ExercisesabstractCyber exercises are a well-received and established means to strengthen the problem-solving skills of personnel and to prepare staff for future cyber incidents. While this concept seems to work for the majority of expected issues, where practicing the application of specific processes, tools and methods to mitigate the effects of large-scale cyber attacks is key, existing cyber exercise approaches are just of limited use for crises management. The reason for this lies in the very nature of a crisis. While ‘common’ incidents appear to be more predictable and can usually be dealt with thoroughly prepared standard procedures and well-rehearsed responses, crises however, are inherently uncertain, and off-the-shelf solutions may even be counterproductive. Complex decisions are to be made in short time-frames, influenced by a lot more stakeholders compared to internal incidents, including regulators, the media, and even the general public. These decisions can barely be guided by prepared plans or checklists, thus new forms of preparation are required, which challenge the participants to practice decision making under pressure, but further give them the opportunity to re-consider choices, walk alternative paths and enable them to find the best possible solution for a given situation. For this purpose, this paper discusses a new approach for non-linear cyber exercises, which allow branching points to develop a storyline, and employ new techniques, such as ‘Fast Forward’ to quickly progress to the critical stages of long-lasting crises, ‘Playback’ to consolidate gained skills, and ‘Pause-Adapt-Repeat’ to play through alternative paths. In this paper, we discuss limiting factors of today’s cyber exercises for large-scale cyber crises preparation, and introduce concepts for non-linear exercises to compensate these issues. Florian Skopik, Maria Leitner |
PST | 2 |
| 2020 | An Empirical Survey of Functions and Configurations of Open-Source Capture the Flag (CTF) Environments
Stela Kucek, Maria Leitner |
J. Netw. Comput. Appl. | 2 |
| 2019 | Effectively Enforcing Authorization Constraints for Emerging Space-Sensitive TechnologiesabstractRecently, applications that deliver customized content to end-users, e.g., digital objects on top of a video stream, depending on information such as their current physical location, usage patterns, personal data, etc., have become extremely popular. Despite their promising future, some concerns still exist with respect to the proper use of such space-sensitive applications (S-Apps) inside independently-run physical spaces, e.g., schools, museums, hospitals, memorials, etc. Based on the idea that innovative technologies should be paired with novel (and effective) security measures, this paper proposes space-sensitive access control (SSAC), an approach for restricting space-sensitive functionality in such independently-run physical spaces, allowing for the specification, evaluation and enforcement of rich and flexible authorization policies, which, besides meeting the specific needs for S-Apps, are also intended to avoid the need for interruptions in their normal use as well as repetitive policy updates, thus providing a convenient solution for both policy makers and end-users. We present a theoretical model, a proof-of-concept S-App, and a supporting API framework, which facilitate the policy crafting, storage, retrieval and evaluation processes, as well as the enforcement of authorization decisions. In addition, we present a performance case study depicting our proof-of-concept S-App in a set of realistic scenarios, as well as a user study which resulted in 90% of participants being able to understand and write authorization policies using our approach, and 93% of them also recognizing the need for restricting functionality in the context of emerging space-sensitive technologies, thus providing evidence that encourages the adoption of SSAC in practice. Carlos E. Rubio-Medrano, Shaishavkumar Jogani, Maria Leitner, Ziming Zhao 0001, Gail-Joon Ahn |
SACMAT | 3 |
| 2018 | Privacy-aware Data Assessment of Online Social Network Registration ProcessesabstractPrivacy and security research has been very active concerning online social networks (OSN) as a vast amount of personal information is used and published (by users) within OSNs. However, most people do not pay attention on what personal information they provide during registration. Depending on what information is provided in (public) OSN profiles, that data might be misused by attackers e.g., for cross-site profile cloning. This paper assesses data provided by the user during the registration of OSNs. Therefore, it is investigated how OSN registration processes are typically modeled, which information is needed to create a profile in OSNs and which attack scenarios can occur based on the provided data. The results contribute to the understanding of OSN registration process design as well as requested data and to replicate and reuse processes for further privacy and security investigations. Christine Schuppler, Maria Leitner, Stefanie Rinderle-Ma |
CODASPY | 2 |
| 2017 | Analysis and Assessment of Situational Awareness Models for National Cyber Security Centers
Timea Pahi, Maria Leitner, Florian Skopik |
ICISSP | 2 |
| 2016 | Authentication in the Context of E-Participation: Current Practice, Challenges and RecommendationsabstractAuthentication as well as identification are key functions when it comes to online and democratic participatory processes that can be found in the context of e-participation. Until now, research has centered on the development of authentication and identification techniques. Why and how these techniques are currently used and what their benefits are in the context of e-participation is missing so far. In this paper, we aim to address these challenges by reviewing state of the art literature and practice in order to determine how current authentication techniques are used in e-participation. Furthermore, we conduct an expert survey in order to establish a baseline how current techniques are used and perceived. The results show that current practice focuses strongly on the use of the de facto standard user/password in e-participation. However, experts believe that multiple other authentication techniques such as biometrics or electronic signatures will become more important in future applications. Moreover, experts acknowledge the use of various authentication methods suitable for the level of participation, as opposed to current practice that often provides only one way of authentication. These findings will help to further develop and improve future technologies and applications to support participatory processes for citizens' involvement. Maria Leitner, Arndt Bonitz |
ARES | 1 |
| 2014 | Anomaly detection and visualization in generative RBAC modelsabstractWith the wide use of Role-based Access Control (RBAC), the need for monitoring, evaluation, and verification of RBAC implementations (e.g., to evaluate ex post which users acting in which roles were authorized to execute permissions) is evident. In this paper, we aim at detecting and identifying anomalies that originate from insiders such as the infringement of rights or irregular activities. To do that, we compare prescriptive (original) RBAC models (i.e. how the RBAC model is expected to work) with generative (current-state) RBAC models (i.e. the actual accesses represented by an RBAC model obtained with mining techniques). For this we present different similarity measures for RBAC models and their entities. We also provide techniques for visualizing anomalies within RBAC models based on difference graphs. This can be used for the alignment of RBAC models such as for policy updates or reconciliation. The effectiveness of the approach is evaluated based on a prototypical implementation and an experiment. Maria Leitner, Stefanie Rinderle-Ma |
SACMAT | 1 |
| 2014 | A systematic review on security in Process-Aware Information Systems - Constitution, challenges, and future directionsabstractSecurity in Process-Aware Information Systems (PAIS) has gained increased attention in current research and practice. However, a common understanding and agreement on security is still missing. In addition, the proliferation of literature makes it cumbersome to overlook and determine state of the art and further to identify research challenges and gaps. In summary, a comprehensive and systematic overview of state of the art in research and practice in the area of security in PAIS is missing. This paper investigates research on security in PAIS and aims at establishing a common understanding of terminology in this context. Further it investigates which security controls are currently applied in PAIS. A systematic literature review is conducted in order to classify and define security and security controls in PAIS. From initially 424 papers, we selected in total 275 publications that related to security and PAIS between 1993 and 2012. Furthermore, we analyzed and categorized the papers using a systematic mapping approach which resulted into 5 categories and 12 security controls. In literature, security in PAIS often centers on specific (security) aspects such as security policies, security requirements, authorization and access control mechanisms, or inter-organizational scenarios. In addition, we identified 12 security controls in the area of security concepts, authorization and access control, applications, verification, and failure handling in PAIS. Based on the results, open research challenges and gaps are identified and discussed with respect to possible solutions. This survey provides a comprehensive review of current security practice in PAIS and shows that security in PAIS is a challenging interdisciplinary research field that assembles research methods and principles from security and PAIS. We show that state of the art provides a rich set of methods such as access control models but still several open research challenges remain. Maria Leitner, Stefanie Rinderle-Ma |
Inf. Softw. Technol. | 1 |
| 2013 | An Analysis and Evaluation of Security Aspects in the Business Process Model and NotationabstractEnhancing existing business process modeling languages with security concepts has attracted increased attention in research and several graphical notations and symbols have been proposed. How these extensions can be comprehended by users has not been evaluated yet. However, the comprehensibility of security concepts integrated within business process models is of utmost importance for many purposes such as communication, training, and later automation within a process-aware information system. If users do not understand the security concepts, this might lead to restricted acceptance or even misinterpretation and possible security problems in the sequel. In this paper, we evaluate existing security extensions of Business Process Model and Notation (BPMN) as BPMN constitutes the de facto standard in business modeling languages nowadays. The evaluation is conducted along two lines, i.e., a literature study and a survey. The findings of both evaluations identify shortcomings and open questions of existing approaches. This will yield the basis to convey security-related information within business process models in a comprehensible way and consequently, unleash the full effects of security modeling in business processes. Maria Leitner, Michelle Miller 0002, Stefanie Rinderle-Ma |
ARES | 1 |
| 2012 | Definition and Enactment of Instance-Spanning Process Constraints
Maria Leitner, Juergen Mangler, Stefanie Rinderle-Ma |
WISE | 1 |
| 2011 | Security Policies in Adaptive Process-Aware Information Systems: Existing Approaches and ChallengesabstractEnabling security is one of the key challenges in adaptive Process-Aware Information Systems (PAIS). Since automating business processes involves many participants, uses private and public data, and communicates with external services security becomes inevitable. In current systems, security is enforced by an access control model and supplementary constraints imposed on workflow activities. However, existing systems provide individual implementations for security policies (e.g. separation of duties) and leave out other constraints (e.g. inter-process constraints). What is missing is a systematic analysis of security policies in PAIS. Hence, in this paper, we display state of the art and provide a taxonomy of security policies in PAIS. Furthermore, a detailed analysis of research challenges and issues is presented. We will show that there are still shortcomings and identify important requirements for security in PAIS. We will also point out open questions related to specifying, modeling, and changing security policies which will provide a road map for future research. Maria Leitner |
ARES | 1 |
| 2011 | AW-RBAC: Access Control in Adaptive Workflow SystemsabstractFlexibility is one of the key challenges for Workflow Systems nowadays. Typically, a workflow covers the following four aspects which might all be subject to change: control flow, data flow, organizational structures, and application components (services). Existing work in research and practice shows that changes must be applied in a controlled manner in order to avoid security problems. In this context, attempts have been made to manage administrative or operative changes using role-based access control (RBAC) models. However, most approaches focus on either administrative changes such as role updating and administration or operative changes, for example, inserting a new activity into a running workflow instance. The distinct handling of certain changes is cumbersome and hence should be reduced by introducing a RBAC model that pays attention to all kinds of possible workflow changes. Hence, in this paper, we present an extended RBAC model for adaptive workflow systems (AW-RBAC) that includes change operations and a variety of objects that are subject to change within workflow systems. Under such a model supervised administrative and operative changes can be enforced on a set of objects in workflow systems. Doing so, the AW-RBAC model improves security during workflow changes and reduces administration costs. The AW-RBAC model is evaluated by means of practical examples and a proof-of-concept implementation. Maria Leitner, Stefanie Rinderle-Ma, Juergen Mangler |
ARES | 1 |
| 2011 | Responsibility-driven Design and Development of Process-aware Security PoliciesabstractProcess-Aware Information Systems (PAIS) enable the automated support of business processes that are executed by a combination of human actors and systems. As processes typically require access to sensitive data, security policies are of high importance. Typically security policies in PAIS range from access rules and authorization constraints to context policies (location, time) and are scattered over the multitude of heterogeneous PAIS components, i.e. process models, repositories, organizational structures, etc. Currently, different approaches for modeling and enforcing security policies exist that assume a set of explicitly defined security policies. Because of aforementioned heterogeneity, these approaches are suboptimal for PAIS. In order to improve upon existing approaches we present a security policy data model and design methodology, based on the concept of responsibilities, permissions and constraints. The goal is to not only unify diverse security policies in different PAIS subsystems, but also to make security policies independent of these subsystems to restrain complexity from process modeling and evolution, and to allow for comprehensive security policy development and maintenance. Maria Leitner, Stefanie Rinderle-Ma, Juergen Mangler |
ARES | 1 |