EDBT 2026 Demo / reviewers in the wild / expert
Martin Gilje Jaatun
dblp:66/3035
· DBLP profile ↗
68ranked-venue papers
19as first author
19since 2021 · last 2026
0000-0001-7127-6694ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 29 · 12 first-author · 4 since 2021Software engineering, systems software and programming languages · 7 · 1 first-author · 4 since 2021Systems, architecture and hardware · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-authorHuman-computer interaction and ubiquitous computing · 2Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Causal mapping of the risks of using generative AI in software developmentabstractContext Generative AI tools can enhance the productivity and effectiveness of software development. These tools are evolving rapidly, as are the associated risks. Therefore, software organizations adopting these tools need to understand their risks, why they occur, and how they evolve over time. Objective Previous research has highlighted risks related to using generative AI in software development; however, the underlying causes of these risks remain largely unexplored. To effectively manage these risks, we need to understand what causes them. Therefore, we examine the causal explanations behind the risks of using generative AI in software development organizations. Methods In a multi-case study of three Danish software organizations during the early stages of generative AI tool adoption, we interviewed software developers and managers within these organizations to uncover the causal explanations of risks associated with generative AI. We employed a causal mapping approach to understand and visualize the differences and similarities across software organizations’ causal explanations of risks. A year later, we returned to validate the risks and causal maps with representatives from each software organization. Results Our study shows that the software organizations exhibit circular reasoning regarding a perpetual uncertainty in the validity of AI-generated code, with the three risks: Mistrust of AI, Insufficient validation of AI output , and Insufficient/insecure AI output. They are also concerned about similar root risks, which solely cause other risks without being caused by any risks themselves, such as Lacking AI competencies . While they differed in emphasis on tail-end risks, which are understood as not causing any additional risks. Conclusion The causal mapping approach proved appropriate for showing similarities and differences in software organizations’ perceptions of risks and causal explanations related to the use of generative AI in software development. The same applies to visualizing how the emphasis on risks can change over time. David Kinnberg Hein, John Stouby Persson, Victor Vadmand Jensen, Anders Bruun, Martin Gilje Jaatun |
Inf. Softw. Technol. | 5 |
| 2025 | Cybersecurity Guidances for Medical Devices: An MDCG and FDA Regulatory ComparisonabstractThis paper compares the distinct cybersecurity requirements for certifying connected medical devices (CMDs) in the EU and the US, as outlined in the MDCG 2019–16 guidance and the FDA premarket and postmarket guidances, respectively. By examining both the organizational approaches of the MDCG and FDA and their specific guidance documents, this study identifies key differences and areas of convergence. Findings, informed by stakeholder feedback gathered within the Horizon Europe NEMECYS project, reveal a notable disparity, with CMD stakeholders expressing significant dissatisfaction with the current EU regulatory framework, particularly regarding its applicability and clarity. The analysis highlights the strengths and weaknesses of each approach from a practical implementation perspective. Ultimately, the paper emphasizes the critical need for the European regulatory landscape to evolve towards clearer and more actionable guidance, especially in rapidly emerging fields like AI-driven medical devices, to effectively support the secure advancement of CMDs. Andrea Neverdal Skytterholm, Christos Androutsos, Adamantios Ntanis, Martin Gilje Jaatun |
SMARTCOMP | 4 |
| 2025 | Federated Large Domain Model SystemabstractAs organizations increasingly seek to build Foundation Models (FMs) using their own proprietary data, many are adopting private and in-house cloud infrastructures (often in addition to public clouds) to address concerns over cost, data privacy, and data sovereignty. However, these isolated private clouds frequently lack interoperability, creating barriers to cross-institutional collaboration, which is vital for training robust Domain-Specific Foundation Models (DSFMs) that rely on large and diverse datasets. Additionally, underutilized resources in private clouds lead to significant global energy inefficiencies. In this paper, we propose the Federated Large Domain Model System (FLDMS), a conceptual framework designed to facilitate collaborative foundation model development across multiple private cloud environments. We review the necessary enabling technologies, including decentralized protocols for data privacy and Large Language Models (LLMs) for automated orchestration, and present a high-level system design demonstrating how these components can be integrated. By enabling secure and efficient cross-organization cooperation, FLDMS provides a blueprint for building DSFMs while addressing the inefficiencies inherent in siloed private cloud systems. Chunming Rong, Jungwon Seo, Ferhat Özgür Çatak, Jiahui Geng, Martin Gilje Jaatun |
Blockchain Res. Appl. | 6 |
| 2024 | A Framework Addressing Challenges in Cybersecurity Testing of IoT Ecosystems and ComponentsabstractThis paper describes challenges within IoT ecosystems from the perspective of cybersecurity testing along with a proposed approach to address them that will be investigated in a recently started Horizon Europe project named TELEMETRY. The key observations regarding the design of the framework are summarised as follows. There is a need to consider the full lifecycle of IoT components – at their design time, their integration into systems, and operation of those systems. Threats and risks can propagate when components are connected together in systems - vulnerabilities in one component can affect other components in a system. IoT devices present limitations to current testing and management due to geographical distribution, opacity and limited processing power. Risk assessment fulfils an important requirement because it enables assessment of what elements are important to the system’s stakeholders, how these elements may be compromised, and how the compromises may be controlled. Feedback from operational monitoring of IoT devices can inform firmware updates / patches to the devices but there is a significant challenge in rolling out these patches to multiple low-power devices geographically distributed Stephen Taylor 0002, Martin Gilje Jaatun, Alan Mc Gibney, Robert Seidl, Pavlo Hrynchenko, Dmytro Prosvirin, Rosella Mancilla |
IoTBDS | 2 |
| 2024 | Identification of Cyber Threats and Vulnerabilities in Norwegian Distribution Networks
Martin Gilje Jaatun, Jørn Foros, Maren Istad |
SEC | 1 |
| 2023 | Software Bill of Materials in Critical InfrastructureabstractCritical infrastructure today is comprised of cyber-physical systems, and therefore also vulnerable to cyber threats. Many of these threats come from within, through malicious code in software updates or bugs that can be exploited. Further exacerbating the issue is the fact that most software suppliers in critical infrastructure are developing proprietary systems and giving out minimal information about the composition of their software products. With the US introduction of a Software Bill of Materials (SBOM) requirement in federal information systems, they are better prepared to deal with cyber incidents. This article examines regulations regarding software in critical infrastructure, and whether there is any benefit to mandating SBOMs in critical infrastructure. Lars Andreassen Jaatun, Silje Marie Sørlien, Ravishankar Borgaonkar, Stephen Taylor 0002, Martin Gilje Jaatun |
CloudCom | 5 |
| 2022 | Privacy and security challenges for autonomous agents : A study of two social humanoid service robotsabstractThe development of autonomous agents have gained renewed interest, largely due to the recent successes of machine learning. Social robots can be considered a special class of autonomous agents that are often intended to be integrated into sensitive environments. We present experiences from our work with two specific humanoid social service robots, and highlight how eschewing privacy and security by design principles leads to implementations with serious privacy and security flaws. The paper introduces the robots as platforms and their associated features, ecosystems and cloud platforms that are required for certain use cases or tasks. The paper encourages design aims for privacy and security, and then in this light studies the implementation from two different manufacturers. The results show a worrisome lack of design focus in handling privacy and security. The paper aims not to cover all the security flaws and possible mitigations, but does look closer into the use of the WebSocket protocol and it’s challenges when used for operational control. The conclusions of the paper provide insights on how manufacturers can rectify the discovered security flaws and presents key policies like accountability when it comes to implementing technical features of autonomous agents. Dennis Biström, Magnus Westerlund, Bob Duncan, Martin Gilje Jaatun |
CloudCom | 4 |
| 2022 | Yet Another Blockchain-based Privacy-friendly Social NetworkabstractCurrent social media platforms suffer from the fact that ownership of personal data is transferred to the owner of the network the moment you post it. This paper demonstrates that it is possible to create and maintain a social network using Hyperledger Fabric, where personal data is protected from users that should not have it, and all operations on data is recorded in the ledger, so you can audit how your data has been used by others, even the owner of the social network. Lars Andreassen Jaatun, Anders Ringen, Martin Gilje Jaatun |
CloudCom | 3 |
| 2022 | A Survey on Cybersecurity Barrier Management in Process Control EnvironmentsabstractThe concept of barriers is well known in the safety domain that includes traditional process control environments. However, as critical infrastructures are moving to more interconnected scenarios connected to cloud computing service providers and the internet in general, an increased focus on security is necessary. In this paper we present a survey on how cybersecurity barriers have been presented in the literature, concluding that the concept has received little attention. More specifically, the aim of the paper is to survey the state of the art in cybersecurity barrier management and the integration with safety barrier management. Like the concept of cybersecurity barrier, the integration of safety and cybersecurity barrier management has received little attention. Most of the work focus on integration of safety and cybersecurity management in general, not on barrier management specifically. We eventually aim to integrate cybersecurity barrier management into the already existing safety barrier management regime. Knut Øien, Stein Hauge, Martin Gilje Jaatun, Lars Halvdan Flå, Lars Bodsberg |
CloudCom | 3 |
| 2022 | Managing Digital Objects with Decentralised Identifiers based on NFT-like schemaabstractThe diversity (text, images, algorithms, etc.) and the ambiguity of data sovereignty and privacy make the management of digital objects very challenging. Users need a unified and convenient way to manage their digital objects. This places a high demand on the findability and interoperability of the management model. In recent years blockchain has provided a new route to an open and secure platform due to its attributes such as distributed, traceable, and tamper-evident. In this paper, a new NFT-like scheme is proposed, which uses metadata converts digital assets into digital object identifiers, and transforms digital objects that require clear sovereignty into NFTs to ensure the authenticity and uniqueness of ownership. Our scheme can facilitate the dynamic management of digital objects using smart contracts. Chunming Rong, Jiahui Geng, Martin Gilje Jaatun |
CloudCom | 3 |
| 2022 | Blockchain Empowered and Self-sovereign Access Control SystemabstractLack of trustworthiness, access policy flexibility, and user privacy preservation in centralized access control systems raise numerous security issues and reduce the collaboration maturity of global data sharing systems. In this paper, we propose a Self-Sovereign Identity-based, Decentralized, and Dynamic (SSIDD) access control system. SSIDD utilizes blockchain technologies to build trust for untrusted data sharing networks and ensures user privacy. Our access control provides high access policy flexibility and security for global inter-enterprise collaborations from a diverse industrial environment. SSIDD authenticates its users based on their Decentralized Identifiers (DID), which are under control of users and can be resolved into a DID document stored on the blockchain. Our data management technology keeps the data sharing systems safe against issues such as data breaches, identity thefts, and privacy violations. Besides, the authorization process of SSIDD is dynamic by adopting several smart contracts. The transparency of rules and agreements in smart contracts and the traceability of records on blockchain ledger provide a high level of security and trust. For proof of concept, we have developed and evaluated a prototype of SSIDD. Our evaluations show that the throughput and latency of our method are within an acceptable range. Hanif Tadjik, Jiahui Geng, Martin Gilje Jaatun, Chunming Rong |
CloudCom | 3 |
| 2022 | A Survey on Infrastructure-as-Code Solutions for Cloud DevelopmentabstractCloud software is increasingly written according to the DevOps paradigm, where use of virtualization and Infrastructure-as-Code is prevalent. This paper surveys the state of the art of IaC cloud development, and proposes a combination of Cloud-Native software to build an on-premise PaaS for a Security Lab. Håkon Teppan, Lars Halvdan Flå, Martin Gilje Jaatun |
CloudCom | 3 |
| 2022 | Needs and Challenges Concerning Cyber-risk Assessment in the Cyber-physical Smart GridabstractCyber-risk assessment methods are used by energy companies to manage security risks in smart grids. However, current standards, methods and tools do not adequately provide the support needed in practice and the industry is struggling to adopt and carry out cyber-risk assessments. The contribution of this paper is twofold. First, we interview six companies from the energy sector to better understand their needs and challenges. Based on the interviews, we identify seven success criteria cyber-risk assessment methods for the energy sector need to fulfill to provide adequate support. Second, we present the methods CORAS, VAF, TM-STRIDE, and DA-SAN and evaluate the extent to which they fulfill the identified success criteria. Based on the evaluation, we provide lessons learned in terms of gaps that need to be addressed in general to improve cyber-risk assessment in the context of smart grids. Our results indicate the need for the following improvements: 1) ease of use and comprehensible m ethods, 2) support to determine whether a method is a good match for a given context, 3) adequate preparation to conduct cyber-risk assessment, 4) manage complexity, 5) adequate support for risk estimation, 6) support for trustworthiness and uncertainty handling, and 7) support for maintaining risk assessments. Gencer Erdogan, Inger Anne Tøndel, Shukun Tokas, Michele Garau, Martin Gilje Jaatun |
ICSOFT | 5 |
| 2022 | Automating Security in a Continuous Integration PipelineabstractTraditional approaches to software security are based on manual methods, which tend to stall development, leading to inefficiency. To speed up a software development lifecycle, security needs to be integrated and automated into the development process. This paper will identify solutions for automating the security phase into a continuous software delivery process, integrating security tools into a Github repository by using Github Actions to create automated vulnerability scanning workflows for a software project. Sohrab Chalishhafshejani, Bao Khanh Pham, Martin Gilje Jaatun |
IoTBDS | 3 |
| 2022 | Influencing the security prioritisation of an agile software development projectabstractSoftware security is a complex topic, and for development projects it can be challenging to assess what security is necessary and cost-effective. Agile Software Development (ASD) values self-management. Thus, teams and their Product Owners are expected to also manage software security prioritisation. In this paper we build on the notion that security experts who want to influence the priority given to security in ASD need to do this through interactions and support for teams rather than prescribing certain activities or priorities. But to do this effectively, there is a need to understand what hinders and supports teams in prioritising security. Based on a longitudinal case study, this article offers insight into the strategy used by one security professional in an SME to influence the priority of security in software development projects in the company. The main result is a model of influences on security prioritisation that can assist in understanding what supports or hinders the prioritisation of security in ASD, thus providing recommendations for security professionals. Two alternative strategies are outlined for software security in ASD – prescribed and emerging – where we hypothesise that an emerging approach can be more relevant for SMEs doing ASD, and that this can impact how such companies should consider software security maturity. Inger Anne Tøndel, Daniela S. Cruzes, Martin Gilje Jaatun, Guttorm Sindre |
Comput. Secur. | 3 |
| 2022 | Adopting threat modelling in agile software development projects
Karin Bernsmed, Daniela S. Cruzes, Martin Gilje Jaatun, Monica Iovan |
J. Syst. Softw. | 3 |
| 2021 | DID-eFed: Facilitating Federated Learning as a Service with Decentralized IdentitiesabstractWe have entered the era of big data, and it is considered to be the ”fuel” for the flourishing of artificial intelligence applications. The enactment of the EU General Data Protection Regulation (GDPR) raises concerns about individuals’ privacy in big data. Federated learning (FL) emerges as a functional solution that can help build high-performance models shared among multiple parties while still complying with user privacy and data confidentiality requirements. Although FL has been intensively studied and used in real applications, there is still limited research related to its prospects and applications as a FLaaS (Federated Learning as a Service) to interested 3rd parties. In this paper, we present a FLaaS system: DID-eFed, where FL is facilitated by decentralized identities (DID) and a smart contract. DID enables a more flexible and credible decentralized access management in our system, while the smart contract offers a frictionless and less error-prone process. We describe particularly the scenario where our DID-eFed enables the FLaaS among hospitals and research institutions. Jiahui Geng, Neel Kanwal, Martin Gilje Jaatun, Chunming Rong |
EASE | 3 |
| 2021 | Improving smart grid security through 5G enabled IoT and edge computingabstractAbstract This article investigates and analyzes the security aspects of 5G specifications from the perspective of IoT‐based smart grids. As the smart grid requires high‐speed and reliable communication to enable real‐time grid monitoring via Internet of Things (IoT) devices, 5G can be considered a catalyst to transform the current power grid infrastructure into a smart grid. Thus, an understanding of what 5G can bring in terms of cyber security in IoT‐based smart grids is important for design decisions and future risk analysis efforts. In this article, we explore a smart grid use case on automatic voltage control—a use case utilizing 5G as a wireless communication infrastructure with edge support. We identify the benefits 5G brings to several security aspects, and show how 5G security techniques are applicable to the smart grid, thus providing a foundation for future security analysis of 5G enabled smart grid systems. Future research should extend this work to additional smart grid use cases. Ravishankar Borgaonkar, Inger Anne Tøndel, Merkebu Z. Degefa, Martin Gilje Jaatun |
Concurr. Comput. Pract. Exp. | 4 |
| 2021 | Secure mobile cloud computingabstractSecure mobile Joanna Kolodziej, Martin Gilje Jaatun |
Concurr. Comput. Pract. Exp. | 2 |
| 2020 | Achieving "Good Enough" Software Security: The Role of ObjectivityabstractToday's software development projects need to consider security as one of the qualities the software should possess. However, overspending on security will imply that the software will become more expensive and often also delayed. This paper discusses the role of objectivity in assessing and researching the goal of good enough security. Different understandings of objectivity are introduced, and the paper explores how these can guide the way forward in improving judgements on what level of security is good enough. The paper recommends adopting and improving upon methods that include different perspectives, support the building of interactive expertise, and support confirmability by keeping documentation of the basis on which judgements were made. Inger Anne Tøndel, Daniela S. Cruzes, Martin Gilje Jaatun |
EASE | 3 |
| 2020 | Using Situational and Narrative Analysis for Investigating the Messiness of Software SecurityabstractBackground: Software engineering work and its context often has characteristics of what in social science is termed 'messy'; it has ephemeral and irregular qualities. This puts high demands on researchers doing inquiry and analysis. Aims: This paper aims to show what a combination of situational analysis (SA) and narrative analysis (NA) can bring to qualitative software engineering research, and in particular for situations characterised by mess. Method: SA and NA were applied to a case study on software security. Results: We found that these analysis methods helped us gain new insights and understandings and a broader perspective of the situation we are studying. Additionally, the methods helped collaboration in the analysis. Conclusion: We recommend applying and studying these and similar combinations of analysis approaches further. Inger Anne Tøndel, Daniela S. Cruzes, Martin Gilje Jaatun |
ESEM | 3 |
| 2020 | A Trustworthy Blockchain-based Decentralised Resource Management System in the CloudabstractQuality Critical Decentralised Applications (QC-DApp) have high requirements for system performance and service quality, involve heterogeneous infrastructures (Clouds, Fogs, Edges and IoT), and rely on the trustworthy collaborations among participants of data sources and infrastructure providers to deliver their business value. The development of the QCDApp has to tackle the low-performance challenge of the current blockchain technologies due to the low collaboration efficiency among distributed peers for consensus. On the other hand, the resilience of the Cloud has enabled significant advances in software-defined storage, networking, infrastructure, and every technology; however, those rich programmabilities of infrastructure (in particular, the advances of new hardware accelerators in the infrastructures) can still not be effectively utilised for QCDApp due to lack of suitable architecture and programming model. Zhiming Zhao, Chunming Rong, Martin Gilje Jaatun |
ICPADS | 3 |
| 2019 | Managing Security in Software: Or: How I Learned to Stop Worrying and Manage the Security Technical DebtabstractContext: Security work in software development is generally under-prioritized. Software developers are not aware of security engineering practices, or find them external to the software development process. To the management, security work presents itself in the form of reactive testing performed out of necessity, incurring only costs in terms of time and resources. The long-term benefits of the security work are more difficult to demonstrate and the security investment harder to justify. Kalle Rindell, Karin Bernsmed, Martin Gilje Jaatun |
ARES | 3 |
| 2019 | The Security Intention Meeting Series as a way to increase visibility of software security decisions in agile development projectsabstractTo achieve a level of security that is just right, software development projects need to strike a balance between security and cost. This necessitates making such decisions as to what security activities to perform in development and which security requirements should be given priority. Current evidence indicates that in many agile development projects, software security is dealt with in a more or less "accidental" way based on individuals' security awareness and interest. This approach is unlikely to lead to an optimal security level for the product. This paper suggests Security Intention Recap Meetings as a recurring organisational tool for evaluating current practices regarding the security intentions of a software project, and to make decisions on how to move forward. These meetings involve key decision makers in the project, such as the product owner and the project manager, with the purpose of making security decisions visible and deliberate and to monitor their results Inger Anne Tøndel, Daniela S. Cruzes, Martin Gilje Jaatun, Kalle Rindell |
ARES | 3 |
| 2019 | Putting the "Account" into Cloud Accountability
Martin Gilje Jaatun |
CLOSER | 1 |
| 2019 | Architectural Risk Analysis in Agile Development of Cloud SoftwareabstractSoftware in the cloud is predominantly developed using agile methodologies, where practices such as continuous deployment and DevOps contribute to increased speed and quick turnarounds. This increased speed does however require additional focus on software security in order to avoid security bugs and architectural flaws from crippling a cloud business. Architectural Risk Analysis has been touted as one of the most powerful software security activities, but in some agile development projects there is no distinct architecture activity, and often no dedicated architects. In this paper we will examine the challenges of performing Architectural Risk Analysis in agile development projects. Martin Gilje Jaatun |
CloudCom | 1 |
| 2019 | Tackling the Cloud Forensic Problem While Keeping Your Eye on the GDPRabstractIf the cloud is just someone else's computer, securing forensic evidence in case of a breach can be tricky. A blockchain-based distributed ledger could contribute to solve this problem, provided the required forensic information finds its way onto the blockchain. In this paper we sketch how blockchain technology and smart contracts apply to various processing models and their respective forensic challenges, and highlight how an accountability-based approach will be instrumental to the overall acceptability of the solution. Magnus Westerlund, Martin Gilje Jaatun |
CloudCom | 2 |
| 2019 | Collaborative security risk estimation in agile software developmentabstractPurpose Today, agile software development teams in general do not adopt security risk-assessment practices in an ongoing manner to prioritize security work. Protection Poker is a collaborative and lightweight software security risk-estimation technique that is particularly suited for agile teams. Motivated by a desire to understand why security risk assessments have not yet gained widespread adoption in agile development, this study aims to assess to what extent the Protection Poker game would be accepted by agile teams and how it can be successfully integrated into the agile practices. Design/methodology/approach Protection Poker was studied in capstone projects, in teams doing a graduate software security course and in sessions with industry representatives. Data were collected via questionnaires, observations and group interviews. Findings Results show that Protection Poker has the potential to be adopted by agile teams. Key benefits include good discussions on security and the development project, along with increased knowledge and awareness. Challenges include ensuring efficient use of time and gaining impact on the end product. Research limitations/implications Using students allowed easy access to subjects and an ability to collect rich data over time, but at the cost of generalizability to professional settings. Results from interactions with professionals supplement the data from students, showing similarities and differences in their opinions on Protection Poker. Originality/value The paper proposes ways to tackle the main obstacles to the adoption of the Protection Poker technique, as identified in this study. Inger Anne Tøndel, Martin Gilje Jaatun, Daniela S. Cruzes, Laurie A. Williams |
Inf. Comput. Secur. | 2 |
| 2018 | Software Security Activities that Support Incident Management in Secure DevOpsabstractMany software services are currently created using DevOps, where developers and operations personnel are more tightly integrated. The DevOps paradigm enables shorter development cycles, but increased speed has raised concerns over whether security issues may be overlooked. However, perfect security is never achievable, and in addition to the proactive software security efforts, we also need a reactive effort to handle flaws and bugs that are not discovered before they are used in an attack. In this paper we explore how focus on incident management and collaboration with developers can contribute to improved software security. Martin Gilje Jaatun |
ARES | 1 |
| 2017 | DevOps for Better Software Security in the Cloud Invited PaperabstractThe DevOps paradigm means that development and operations for an organisation blend together. For security, this implies that information on detected attacks can be fed back to the development, enabling faster eradication of vulnerabilities in software. This is particularly important in cloud installations, where release cycles can be less than a day. This paper argues that DevOps can be employed for overall improved software security. Martin Gilje Jaatun, Daniela S. Cruzes, Jesus Luna |
ARES | 1 |
| 2017 | Accountability Requirements for the CloudabstractIn order to be responsible stewards of other people's data, cloud providers must be accountable for their data handling practices. The potential long provider chains in cloud computing introduces additional accountability challenges, and this paper examines requirements which must be fulfilled to achieve an accountability-based approach. Martin Gilje Jaatun, Inger Anne Tøndel, Nils Brede Moe, Daniela S. Cruzes, Karin Bernsmed, Børge Haugset |
CloudCom | 1 |
| 2016 | Cyber Security Incident Management in the Aviation DomainabstractCyber Security Incident Management is an emerging paradigm and capability within the aviation domain. To date, limited research has addressed the requirements and developed tangible solutions for the deployment of such a capability. This paper leverages good practice and experiences from other critical infrastructure settings in order to sketch a recommendation for cyber incident response management for the aviation domain. Martin Gilje Jaatun, Rainer Koelle |
ARES | 1 |
| 2016 | An Empirical Study on the Relationship between Software Security Skills, Usage and Training Needs in Agile SettingsabstractOrganizations recognize that protecting their assets against attacks is an important business. However, achieving what is adequate security requires taking bold steps to address security practices within the organization. In the Agile software development world, security engineering process is unacceptable as it runs counter to the agile values. Agile teams have thus approached software security activities in their own way. To improve security within agile settings requires that management understands the current practices of software security activities within their agile teams. In this study, we use survey to investigate software security usage, competence, and training needs in two agile organizations. We find that (1) The two organizations perform differently in core software security activities but are similar when activities that could be leveraged for security are considered (2) regardless of cost or benefit, skill drives the kind of activities that are performed (3) Secure design is expressed as the most important training need by all groups in both organizations (4) Effective software security adoption in agile setting is not automatic, it requires a driver. Tosin Daniel Oyetoyan, Daniela S. Cruzes, Martin Gilje Jaatun |
ARES | 3 |
| 2016 | Zebras and Lions: Better Incident Handling Through Improved Cooperation
Martin Gilje Jaatun, Maria B. Line, Inger Anne Tøndel |
I4CS | 1 |
| 2016 | Playing Protection Poker for Practical Software Security
Martin Gilje Jaatun, Inger Anne Tøndel |
PROFES | 1 |
| 2015 | How Much Cloud Can You Handle?abstractOutsourcing computing and storage to the cloud does not eliminate the need for handling of information security incidents. However, the long provider chains and unclear responsibilities in the cloud make incident response difficult. In this paper we present results from interviews in critical infrastructure organisations that highlight incident handling needs that would apply to cloud customers, and suggest mechanisms that facilitate inter-provider collaboration in handling of incidents in the cloud, improving the accountability of the cloud service providers. Martin Gilje Jaatun, Inger Anne Tøndel |
ARES | 1 |
| 2015 | Cloud Provider Transparency - A View from Cloud Customers
Daniela S. Cruzes, Martin Gilje Jaatun |
CLOSER | 2 |
| 2015 | Passing the Buck: Outsourcing Incident Response ManagementabstractMany organizations are outsourcing computer operations to third parties, and the next logical step is to outsource management of computer security incidents as well. This paper describes a case study where we have studied several organizations who are active in this space today. Our results indicate that outsourcing of incident management is a viable security approach for many organizations, but that transitioning between providers frequently is a challenge. Alfredo Ramiro Reyes Zúñiga, Martin Gilje Jaatun |
CloudCom | 2 |
| 2015 | Software Security Maturity in Public Organisations
Martin Gilje Jaatun, Daniela S. Cruzes, Karin Bernsmed, Inger Anne Tøndel, Lillian Røstad |
ISC | 1 |
| 2014 | Healthcare Services in the Cloud - Obstacles to Adoption, and a Way ForwardabstractCloud computing has been receiving a great deal of attention during the past few years. A major feature of public cloud services is that data are processed remotely in unknown systems that the users do not own or operate. This context creates a number of challenges related to data privacy and security and may hinder the adoption of cloud technology in, for example, the healthcare domain. This paper presents results from a stakeholder elicitation activity, in which the participants identified a number of obstacles to the adoption of cloud computing for the processing of healthcare data. We compare our results with previous studies and outline accountability as a possible way forward to increase the adoption of cloud services in the healthcare domain. Karin Bernsmed, Daniela S. Cruzes, Martin Gilje Jaatun, Børge Haugset, Erlend Andreas Gjære |
ARES | 3 |
| 2014 | Learn to SWIMabstractThis paper is meant to provide an overview over SWIM and its context from a security point of view. Rather than describing everything in detail it refers to the relevant SJU deliverables where possible and tries to provide the "glue" between the different pieces of information. Matias Krempel, Martin Gilje Jaatun |
ARES | 2 |
| 2014 | Towards Strong Accountability for Cloud Service ProvidersabstractIn order to be an accountable organisation, Cloud Providers need to commit to being responsible stewards of other people's information. This implies demonstrating both willingness and capacity for such stewardship. This paper outlines the fundamental requirements that must be met by accountable organisations, and sketches what kind of tools, mechanisms and guidelines support this in practice. Martin Gilje Jaatun, Siani Pearson, Frederic Gittler, Ronald E. Leenes |
CloudCom | 1 |
| 2014 | Information security incident management: Current practice as reported in the literature
Inger Anne Tøndel, Maria B. Line, Martin Gilje Jaatun |
Comput. Secur. | 3 |
| 2013 | Towards an Ontology for Cloud Security ObligationsabstractThis paper presents an ontology for Cloud security obligations, which is based on a number of industry accepted standards and guidelines. The ontology terms and relationships have been defined in the W3C ontology language OWL and includes a number of technical security controls that can be implemented by public Cloud providers. This paper outlines the ontology and demonstrates how it can be used in two different application areas. Karin Bernsmed, Astrid Undheim, Per Håkon Meland, Martin Gilje Jaatun |
ARES | 4 |
| 2013 | Sink or SWIM: Information Security Requirements in the SkyabstractDespite the inherently cooperative nature of air traffic control, the ICT infrastructure supporting it has, metaphorically speaking, largely remained isolated islands of technology. To this day, most of the interaction between ATM centers is based on voice and point-to-point data communication. Speed and accuracy of coordination is thus frequently limited by human capacities. This also imposes severe restrictions on the scale of coordination efforts among ATM centers. There are, however, changes underway. The main ambition of the System-Wide Information Management (SWIM) concept is to realize a European-wide network of interconnected ATM systems that promises, among other things, to bring substantial gains in efficiency of coordination and improved utilization of valuable airspace. This paper presents challenges, approaches and experiences from ongoing work on security requirements within SWIM. Martin Gilje Jaatun, Tor Erlend Fægri |
ARES | 1 |
| 2013 | "Security-Aware and Data Intensive Low-Cost Mobile Systems" EditorialabstractWe are witnessing a paradigm shift in the way mobile devices are being used and operated.What was once a voice network is now predominantly a data network.As a consequence, end-users are now using mobile systems for applications that fall under the data intensive paradigm, such as Skyline queries, streaming information relays, and crowd sourced disaster management.However, this paradigm shift has opened new research directions, such as: (a) Security, as the system now has numerous distributed entry points and the behavior of a malicious entity does not really correlate with any previously known phenomenon (e.g., Internet virus attacks, DOS attacks, etc.).(b) Data interoperability that must cater to the fundamental issue that mobile devices are required to work seamlessly with Internet data, thus requiring revision of protocols, data exchange frameworks to improve data sharing among mobile devices and with the Internet.(c) Sustainable software development that entails the development of software models for mobile devices that have a longer life-cycle and require fewer updates.This also effectively translates into an economically viable mobile system.Privacy and security aspects need to be covered at all layers of mobile networks, from mobile users' devices, to privacy-respecting credentials and mobile identity management.All of the above mentioned research domains are complex on their own, which makes it a very attractive research area for academia and industry.The eventual goal is to make the mobile systems seamless integrate with Inter and Intranet devices without a measurable performance degradation.Is is arguably required to investigate novel methods and techniques to enable secure access to data, network nodes and services, flexible communication, efficient scheduling, self-adaptation, decentralization, and self-organization.This special issue herewith presents six research papers with novel concepts in the analysis, implementation, and evaluation of the next generation of intelligent scalable techniques for data intensive processing and security related problems in modern mobile environments.The first three papers span the fields of key management, power modeling and mobility modeling, but all share a relevance to security aspects.Cryptographic and key management systems in mobile networks must be computationally low-cost because of the limitations of computational and data storage capacities and battery life of most of the network nodes.Wu and Lin present non-interactive authenticated key agreement (NI-AKA) protocols based on the idea of bilinear pairingbased cryptosystem model and Elliptic Curve Encryption (ECE) scheme.The ECE allows the encryption of message multiple times with different keys that can be decrypted in Joanna Kolodziej, Martin Gilje Jaatun, Samee Ullah Khan, Mario Köppen |
Mob. Networks Appl. | 2 |
| 2012 | Expressing Cloud Security Requirements in Deontic Contract Languages
Per Håkon Meland, Karin Bernsmed, Martin Gilje Jaatun, Astrid Undheim, Humberto Nicolás Castejón Martínez |
CLOSER | 3 |
| 2012 | Thunder in the Clouds: Security challenges and solutions for federated CloudsabstractCloud federation brings together different service providers and their offered services, so that many Cloud variants can be tailored to match different sets of customer requirements. To mitigate security risks and convince hesitant customers, security must be an integrated part of the federated Cloud concept. This paper surveys the state of the art in Cloud computing security, identifies unsolved issues related to federated Clouds, discusses possible approaches to deal with the threats and points out directions for further work. Karin Bernsmed, Martin Gilje Jaatun, Per Håkon Meland, Astrid Undheim |
CloudCom | 2 |
| 2012 | Accountability for cloud and other future Internet servicesabstractCloud and IT service providers should act as responsible stewards for the data of their customers and users. However, the current absence of accountability frameworks for distributed IT services makes it difficult for users to understand, influence and determine how their service providers honour their obligations. The A4Cloud project will create solutions to support users in deciding and tracking how their data is used by cloud service providers. By combining methods of risk analysis, policy enforcement, monitoring and compliance auditing with tailored IT mechanisms for security, assurance and redress, A4Cloud aims to extend accountability across entire cloud service value chains, covering personal and business sensitive information in the cloud. Siani Pearson, Vasilios Tountopoulos, Daniele Catteddu, Mario Südholt, Refik Molva, Christoph Reich, Simone Fischer-Hübner, Christopher Millard, Volkmar Lotz, Martin Gilje Jaatun, Ronald E. Leenes, Chunming Rong, Javier López 0001 |
CloudCom | 10 |
| 2012 | Threat Modeling of AMI
Inger Anne Tøndel, Martin Gilje Jaatun, Maria B. Line |
CRITIS | 2 |
| 2012 | Reference deployment models for eliminating user concerns on cloud security
Gansen Zhao, Chunming Rong, Martin Gilje Jaatun, Frode Eika Sandnes |
J. Supercomput. | 3 |
| 2011 | Security SLAs for Federated Cloud ServicesabstractThe federated Cloud paradigm aims to provide flexible and reliable services composed of a mixture of internal and external mini-clouds, but this heterogeneous nature is also fuelling the security concerns of the customers. To allay the fears and deal with the threats associated with outsourcing data and applications to the Cloud, new methods for security assurance are urgently needed. This paper presents current work on Cloud Security Service Level Agreements and our approach on how to manage this in the context of hybrid clouds. The purpose is to facilitate rapid service composition and agreements based on the necessary security requirements and establish trust between the customer and provider. We also show how this can be applied on a realistic case study related to a hybrid Unified Communication service. Karin Bernsmed, Martin Gilje Jaatun, Per Håkon Meland, Astrid Undheim |
ARES | 2 |
| 2011 | Security in Model Driven Development: A SurveyabstractModel driven development (MDD) is considered a promising approach for software development. In this paper the results of a systematic survey is reported to identify the state-of-the-art within the topic of security in model driven development, with a special focus on finding empirical studies. We provide an introduction to the major secure MDD initiatives, but our survey shows that there is a lack of empirical work on the topic. We conclude that better standardisation initiatives and more empirical research in the field is necessary before it can be considered mature. Jostein Jensen, Martin Gilje Jaatun |
ARES | 2 |
| 2011 | Security in Service Level Agreements for Cloud Computing
Karin Bernsmed, Martin Gilje Jaatun, Astrid Undheim |
CLOSER | 2 |
| 2011 | A Cryptographic Protocol for Communication in a Redundant Array of Independent Net-storagesabstractThis paper describes a cryptographic protocol for storing and processing data in a Cloud Computing setting, where users need not place absolute trust in the various Cloud Processing providers. This is achieved by distributing data among various Cloud Storage providers in such a manner that an individual data item does not divulge useful information about its owner, and only re-assembling data when it needs to be processed or returned to the user. Martin Gilje Jaatun, Gansen Zhao, Stian Alapnes |
CloudCom | 1 |
| 2011 | As Strong as the Weakest Link: Handling Compromised Components in OpenStackabstractThis paper presents an approach to handle compromised components in an Infrastructure-as-a-Service Cloud Computing platform. Our experiments show that traditional incident handling procedures are applicable for cloud computing, but need some modification to function optimally. Aryan TaheriMonfared, Martin Gilje Jaatun |
CloudCom | 2 |
| 2011 | Monitoring Intrusions and Security Breaches in Highly Distributed Cloud EnvironmentsabstractCloud computing is a new computing model, and security is ranked first among its challenges. This paper reviews existing security monitoring mechanisms compared with new challenges which are caused by this new model. We highlight possible weaknesses in existing monitoring mechanisms, and propose approaches to mitigate them. Aryan TaheriMonfared, Martin Gilje Jaatun |
CloudCom | 2 |
| 2010 | The Road to Hell is Paved with Good Intentions: A Story of (In)secure Software DevelopmentabstractIn this paper, we present the results of a security assessment performed on a home care system based on SOA, realized as web services. The security design concepts of this platform were specifically tailored to meet new security challenges and to be compliant with legal frameworks applicable to the healthcare domain. This security design was fed as input to the development team,which implemented the system. However, our assessment revealed a software platform with severe security weaknesses and vulnerabilities, demonstrating pitfalls that are, or should be, well known. Our experience re-confirms that security must be built as an intrinsic software property and emphasizes the need for security awareness throughout the whole software development lifecycle. Richard Sasson, Martin Gilje Jaatun, Jostein Jensen |
ARES | 2 |
| 2009 | Reusable Security Requirements for Healthcare ApplicationsabstractHealthcare information systems are currently being migrated from paper based journals to fully digitalised information platforms. Protecting patient privacy is thus becoming an increasingly complex task, where several national and international legal requirements must be met. These legal requirements present only high-level goals for privacy protection, leaving the details of security requirements engineering to the developers of electronic healthcare systems. Our objective has been to map legal requirements for sensitive personal information to a set of reusable technical information security requirements. This paper presents examples of such requirements extracted from legislation applicable to the healthcare domain. Jostein Jensen, Inger Anne Tøndel, Martin Gilje Jaatun, Per Håkon Meland, Herbjørn Andresen |
ARES | 3 |
| 2009 | Privacy in a Semantic Cloud: What's Trust Got to Do with It?
Åsmund Ahlmann Nyre, Martin Gilje Jaatun |
CloudCom | 2 |
| 2008 | Covering Your Assets in Software EngineeringabstractMany security requirements elicitation techniques implicitly assume that assets are identified on beforehand, but few actually describe how this should be done. In this paper we suggest one specific method that can be used to identify and prioritize assets in any software engineering project. Martin Gilje Jaatun, Inger Anne Tøndel |
ARES | 1 |
| 2008 | A Study of Information Security Practice in a Critical Infrastructure Application
Martin Gilje Jaatun, Eirik Albrechtsen, Maria B. Line, Stig Ole Johnsen, Irene Wærø, Odd Helge Longva, Inger Anne Tøndel |
ATC | 1 |
| 2008 | Secure Safety: Secure Remote Access to Critical Safety Systems in Offshore Installations
Martin Gilje Jaatun, Tor Olav Grøtan, Maria B. Line |
ATC | 1 |
| 2008 | A Structured Approach to Incident Response Management in the Oil and Gas Industry
Maria B. Line, Eirik Albrechtsen, Martin Gilje Jaatun, Inger Anne Tøndel, Stig Ole Johnsen, Odd Helge Longva, Irene Wærø |
CRITIS | 3 |
| 2008 | Penetration Testing of OPC as Part of Process Control Systems
Maria B. Line, Martin Gilje Jaatun, Zi Bin Cheah, A. B. M. Omar Faruk, Håvard Husevåg Garnes, Petter Wedum |
UIC | 2 |
| 2008 | An Analysis of the Manufacturing Messaging Specification Protocol
Jan Tore Sørensen, Martin Gilje Jaatun |
UIC | 2 |
| 2007 | Survival by Deception
Martin Gilje Jaatun, Åsmund Ahlmann Nyre, Jan Tore Sørensen |
SAFECOMP | 1 |
| 2006 | Secure Fast Handover in an Open Broadband Access Network using Kerberos-style TicketsabstractIn an Open Broadband Access Network consisting of multiple Internet Service Providers, delay due to multi-hop processing of authentication credentials is a major obstacle to fast handover between access points, effectively preventing delay-sensitive interactive applications such as Voice over IP. By exploiting existing trust relationships between service providers and access points, it is possible to pre-authenticate a mobile terminal to an access point, creating a Kerberos-style ticket that can be evaluated locally. The terminal can thus perform a handover and be authenticated to the new access point, without incurring communication and processing delays by involving other servers. Martin Gilje Jaatun, Inger Anne Tøndel, Frédéric Paint, Tor Hjalmar Johannessen, John Charles Francis, Claire Duranton |
SEC | 1 |