Ulrik Franke

dblp:71/3754 · DBLP profile ↗
← Back
32ranked-venue papers
13as first author
3since 2021 · last 2023
0000-0003-2017-7914ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 9 · 3 first-authorArtificial intelligence and machine learning · 3Databases, data management, data science and information retrieval · 3 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 3 · 2 first-authorComputer networks · 2 · 2 first-authorHuman-computer interaction and ubiquitous computing · 2
YearPublicationVenuePosition
2023 Duopoly insurers' incentives for data quality under a mandatory cyber data sharing regime
abstract
We study the impact of data sharing policies on cyber insurance markets. These policies have been proposed to address the scarcity of data about cyber threats, which is essential to manage cyber risks. We propose a Cournot duopoly competition model in which two insurers choose the number of policies they offer (i.e., their production level) and also the resources they invest to ensure the quality of data regarding the cost of claims (i.e., the data quality of their production cost). We find that enacting mandatory data sharing sometimes creates situations in which at most one of the two insurers invests in data quality, whereas both insurers would invest when information sharing is not mandatory. This raises concerns about the merits of making data sharing mandatory.
Carlos A. Barreto, Olof Reinert, Tobias Wiesinger, Ulrik Franke
Comput. Secur.4
2021 The Cost of Incidents in Essential Services - Data from Swedish NIS Reporting
abstract
Abstract The NIS Directive aims to increase the overall level of cyber security in the EU and establishes a mandatory reporting regime for operators of essential services and digital service providers. While this reporting has attracted much attention, both in society at large and in the scientific community, the non-public nature of reports has led to a lack of empirically based research. This paper uses the unique set of all the mandatory NIS reports in Sweden in 2020 to shed light on incident costs. The costs reported exhibit large variability and skewed distributions, where a single or a few higher values push the average upwards. Numerical values are in the range of tens to hundreds of kSEK per incident. The most common incident causes are malfunctions and mistakes, whereas attacks are rare. No operators funded their incident costs using loans or insurance. Even though the reporting is mandated by law, operator cost estimates are incomplete and sometimes difficult to interpret, calling for additional assistance and training of operators to make the data more useful.
Ulrik Franke, Johan Turell, Ivar Johansson
CRITIS1
2021 Cyber-threat perception and risk management in the Swedish financial sector
abstract
The financial sector relies heavily on information systems for business. This study sets out to investigate cyber situation awareness in the financial sector in Sweden, by examining what information elements that are needed for a common operational picture, and exploring how key actors perceive cyber-threats. Data was collected through a survey and a series of interviews with key actors in the sector in conjunction with a national level crisis management exercise. The data was then analyzed and contrasted to theory. Conclusions were drawn and results discussed. Finally, possible mitigation actions were suggested. It was found that actors in the Swedish financial sector have a well developed crisis management working concept. However, information about rational adversaries that cause prolonged disturbances is possibly not collected, analyzed and utilized systematically. Much effort is put into ensuring that timely and relevant information from organizations is shared in an efficient manner. The sector perceives cyber-threats against the underlying financial infrastructure, as well as against IT service availability and data confidentiality, besides financial theft. The sector has particular concerns for the potential of reputational loss due to cyberattacks. There are also special concerns about the insider threat. Respondents agree that risk management has to account for cyber risk. A possible route to enhance risk management practices is to ensure that cyber personnel is integrated in crisis management teams.
Stefan Varga, Joel Brynielsson, Ulrik Franke
Comput. Secur.3
2020 A Census of Swedish Government Administrative Authority Employee Communications on Cybersecurity during the COVID-19 Pandemic
abstract
Cybersecurity is the backbone of a successful digitalization of society, and cyber situation awareness is an essential aspect of managing it. The COVID-19 pandemic has sped up an already ongoing digitalization of Swedish government agencies, but the cybersecurity maturity level varies across agencies. In this study, we conduct a census of Swedish government administrative authority communications on cybersecurity to employees at the beginning of the COVID-19 pandemic. The census shows that the employee communications in the beginning of the pandemic to a greater extent have focused on first-order risks, such as video meetings and telecommuting, rather than on second-order risks, such as invoice fraud or social engineering. We also find that almost two thirds of the administrative authorities have not yet implemented, but only initiated or documented, their cybersecurity policies.
Annika Andreasson, Henrik Artman, Joel Brynielsson, Ulrik Franke
ASONAM4
2020 An Empirical Investigation of the Right to Explanation Under GDPR in Insurance
Jacob Dexe, Jonas Ledendal, Ulrik Franke
TrustBus3
2020 Automating threat modeling using an ontology framework
abstract
Abstract Threat modeling is of increasing importance to IT security, and it is a complex and resource demanding task. The aim of automating threat modeling is to simplify model creation by using data that are already available. However, the collected data often lack context; this can make the automated models less precise in terms of domain knowledge than those created by an expert human modeler. The lack of domain knowledge in modeling automation can be addressed with ontologies. In this paper, we introduce an ontology framework to improve automatic threat modeling. The framework is developed with conceptual modeling and validated using three different datasets: a small scale utility lab, water utility control network, and university IT environment. The framework produced successful results such as standardizing input sources, removing duplicate name entries, and grouping application software more logically.
Margus Välja, Fredrik Heiding, Ulrik Franke, Robert Lagerström
Cybersecur.3
2020 Veracity assessment of online data
abstract
Fake news, malicious rumors, fabricated reviews, generated images and videos, are today spread at an unprecedented rate, making the task of manually assessing data veracity for decision-making purposes a daunting task. Hence, it is urgent to explore possibilities to perform automatic veracity assessment. In this work we review the literature in search for methods and techniques representing state of the art with regard to computerized veracity assessment. We study what others have done within the area of veracity assessment, especially targeted towards social media and open source data, to understand research trends and determine needs for future research. The most common veracity assessment method among the studied set of papers is to perform text analysis using supervised learning. Regarding methods for machine learning much has happened in the last couple of years related to the advancements made in deep learning. However, very few papers make use of these advancements. Also, the papers in general tend to have a narrow scope, as they focus on solving a small task with only one type of data from one main source. The overall veracity assessment problem is complex, requiring a combination of data sources, data types, indicators, and methods. Only a few papers take on such a broad scope, thus, demonstrating the relative immaturity of the veracity assessment domain.
Marianela García Lozano, Joel Brynielsson, Ulrik Franke, Magnus Rosell, Edward Tjörnhammar, Stefan Varga, Vladimir Vlassov
Decis. Support Syst.3
2020 The cyber-insurance market in Norway
abstract
Purpose This paper aims to describe the cyber-insurance market in Norway but offers conclusions that are interesting to a wider audience. Design/methodology/approach The study is based on semi-structured interviews with supply-side actors: six general insurance companies, one marine insurance company and two insurance intermediaries. Findings The Norwegian cyber-insurance market supply-side has grown significantly in the past two years. The General Data Protection Regulation (GDPR) is found to have had a modest effect on the market so far but has been used by the supply-side as an icebreaker to discuss cyber-insurance with customers. The NIS Directive has had little or no impact on the Norwegian cyber-insurance market until now. Informants also indicate that Norway is still the least mature of the four Nordic markets. Practical implications Some policy lessons for different stakeholders are identified. Originality/value Empirical investigation of cyber-insurance is still rare, and the paper offers original insights on market composition and actor motivations, ambiguity of coverage, the NIS Directive and GDPR.
Hayretdin Bahsi, Ulrik Franke, Even Langfeldt Friberg
Inf. Comput. Secur.2
2019 Sharing of Vulnerability Information Among Companies - A Survey of Swedish Companies
abstract
Software products are rarely developed from scratch and vulnerabilities in such products might reside in parts that are either open source software or provided by another organization. Hence, the total cybersecurity of a product often depends on cooperation, explicit or implicit, between several organizations. We study the attitudes and practices of companies in software ecosystems towards sharing vulnerability information. Furthermore, we compare these practices to contemporary cybersecurity recommendations. This is performed through a questionnaire-based qualitative survey. The questionnaire is divided into two parts: the providers' perspective and the acquirers' perspective. The results show that companies are willing to share information with each other regarding vulnerabilities. Sharing is not considered to be harmful neither to the cybersecurity nor their business, even though a majority of the respondents consider vulnerability information sensitive. However, the companies, despite being open to sharing, are less inclined to proactively sharing vulnerability information. Furthermore, the providers do not perceive that there is a large interest in vulnerability information from their customers. Hence, the companies' overall attitude to sharing vulnerability information is passive but open. In contrast, contemporary cybersecurity guidelines recommend active disclosure and sharing among actors in an ecosystem.
Thomas Olsson 0001, Martin Hell, Martin Höst, Ulrik Franke, Markus Borg
SEAA4
2019 Risks and assets: a qualitative study of a software ecosystem in the mining industry
abstract
Digitalization and servitization are impacting many domains, including the mining industry. As the equipment becomes connected and technical infrastructure evolves, business models and risk management need to adapt. In this paper, we present a study on how changes in asset and risk distribution are evolving for the actors in a software ecosystem (SECO) and system-of-systems (SoS) around a mining operation. We have performed a survey to understand how Service Level Agreements (SLAs) -- a common mechanism for managing risk -- are used in other domains. Furthermore, we have performed a focus group study with companies. There is an overall trend in the mining industry to move the investment cost (CAPEX) from the mining operator to the vendors. Hence, the mining operator instead leases the equipment (as operational expense, OPEX) or even acquires a service. This change in business model impacts operation, as knowledge is moved from the mining operator to the suppliers. Furthermore, as the infrastructure becomes more complex, this implies that the mining operator is more and more reliant on the suppliers for the operation and maintenance. As this change is still in an early stage, there is no formalized risk management, e.g. through SLAs, in place. Rather, at present, the companies in the ecosystem rely more on trust and the incentives created by the promise of mutual future benefits of innovation activities. We believe there is a need to better understand how to manage risk in SECO as it is established and evolves. At the same time, in a SECO, the focus is on cooperation and innovation, the companies do not have incentives to address this unless there is an incident. Therefore, industry need, we believe, help in systematically understanding risk and defining quality aspects such as reliability and performance in the new business environment.
Thomas Olsson 0001, Ulrik Franke
ESEC/SIGSOFT FSE2
2018 Information Requirements for National Level Cyber Situational Awareness
abstract
As modern societies become more dependent on IT services, the potential impact both of adversarial cyberattacks and non-adversarial service management mistakes grows. This calls for better cyber situational awareness-decision-makers need to know what is going on. The main focus of this paper is to examine the information elements that need to be collected and included in a common operational picture in order for stakeholders to acquire cyber situational awareness. This problem is addressed through a survey conducted among the participants of a national information assurance exercise conducted in Sweden. Most participants were government officials and employees of commercial companies that operate critical infrastructure. The results give insight into information elements that are perceived as useful, that can be contributed to and required from other organizations, which roles and stakeholders would benefit from certain information, and how the organizations work with creating cyber common operational pictures today. Among findings, it is noteworthy that adversarial behavior is not perceived as interesting, and that the respondents in general focus solely on their own organization.
Stefan Varga, Joel Brynielsson, Ulrik Franke
ASONAM3
2018 Characterization of trade-off preferences between non-functional properties
Ulrik Franke, Federico Ciccozzi
Inf. Syst.1
2018 A decision-making process-line for selection of software asset origins and components
Deepika Badampudi, Krzysztof Wnuk, Claes Wohlin, Ulrik Franke, Darja Smite, Antonio Cicchetti
J. Syst. Softw.4
2018 What can we learn from enterprise architecture models? An experiment comparing models and documents for capability development
Ulrik Franke, Mika Cohen, Johan Sigholm
Softw. Syst. Model.1
2018 Can the Common Vulnerability Scoring System be Trusted? A Bayesian Analysis
abstract
The Common Vulnerability Scoring System (CVSS) is the state-of-the art system for assessing software vulnerabilities. However, it has been criticized for lack of validity and practitioner relevance. In this paper, the credibility of the CVSS scoring data found in five leading databases-NVD, X-Force, OSVDB, CERT-VN, and Cisco-is assessed. A Bayesian method is used to infer the most probable true values underlying the imperfect assessments of the databases, thus circumventing the problem that ground truth is not known. It is concluded that with the exception of a few dimensions, the CVSS is quite trustworthy. The databases are relatively consistent, but some are better than others. The expected accuracy of each database for a given dimension can be found by marginalizing confusion matrices. By this measure, NVD is the best and OSVDB is the worst of the assessed databases.
Pontus Johnson, Robert Lagerström, Mathias Ekstedt, Ulrik Franke
IEEE Trans. Dependable Secur. Comput.4
2017 The cyber insurance market in Sweden
abstract
This article is a characterization of the cyber insurance market in Sweden. As empirical investigations of cyber insurance are rarely reported in the literature, the results are novel. The investigation is based on semi-structured interviews with 10 insurance companies active on the Swedish market, and additional interviews with 2 re-insurance companies and 3 insurance intermediaries. These informants represent essentially all companies selling cyber insurance on the Swedish market. Findings include descriptions of the coverages offered, including discrepancies between insurers, and the underwriting process used. Typical annual premiums are found to be in the span of some 5–10 kSEK per MSEK indemnity limit, i.e. 0.5–1% of the indemnity limit. For business interruption coverage, waiting periods are found to be relatively long compared to many outages. Furthermore, insurance companies impose information and IT security requirements on their customers, and do not insure customers that are too immature or have too poor security. Thus cyber insurance, in practice, is not merely an instrument of risk transfer, but also contains aspects of avoidance and mitigation. Based on the findings, market segmentation, pricing, business continuity, and asymmetry of information are discussed, and some future work is suggested.
Ulrik Franke
Comput. Secur.1
2016 Analysis of Enterprise Architecture Evolution Using Markov Decision Processes
Sérgio Guerreiro 0001, Khaled Gaaloul, Ulrik Franke
EOMAS@CAiSE3
2016 Towards Preference Elicitation for Trade-Offs between Non-Functional Properties
abstract
In the design and evolution of software intensive systems, it is desirable to make informed decisions as early as possible in the life cycle. To do this, it is both necessary to be able to predict properties of these future systems and to know how one would like to prioritize among those properties. This paper addresses the latter problem of how to make trade-offs between non-functional properties of software intensive systems. An approach based on the elicitation of utility functions from stake-holders and subsequent checks for consistency among these functions is proposed. A sample GUI is presented, along with some examples. Limitations are discussed and several avenues for future work, including empirical validation, are proposed.
Ulrik Franke
EDOC1
2016 Using cyber defense exercises to obtain additional data for attacker profiling
abstract
In order to be able to successfully defend an IT system it is useful to have an accurate appreciation of the cyber threat that goes beyond stereotypes. To effectively counter potentially decisive and skilled attackers it is necessary to understand, or at least model, their behavior. Although the real motives for untraceable anonymous attackers will remain a mystery, a thorough understanding of their observable actions can still help to create well-founded attacker profiles that can be used to design effective countermeasures and in other ways enhance cyber defense efforts. In recent work empirically founded attacker profiles, so-called attacker personas, have been used to assess the overall threat situation for an organization. In this paper we elaborate on 1) the use of attacker personas as a technique for attacker profiling, 2) the design of tailor-made cyber defense exercises for the purpose of obtaining the necessary empirical data for the construction of such attacker personas, and 3) how attacker personas can be used for enhancing the situational awareness within the cyber domain. The paper concludes by discussing the possibilities and limitations of using cyber defense exercises for data gathering, and what can and cannot be studied in such exercises.
Joel Brynielsson, Ulrik Franke, Muhammad Adnan Tariq, Stefan Varga
ISI2
2016 Decision-Making in Automotive Software Development - An Observational Study
abstract
This paper reports results from an independent observational study of an automotive software development research project. The study is carried out as a monitoring activity of the project, which is inexpensive but still representative of real automotive software development cases, thus providing the basis for more rigorous studies. The objective is to take initial steps to improve our understanding of architectural decision-making in the development of software in the automotive domain. The key findings summarize issues surfacing during the development process related to the problem articulation and formulation, the impact of participant experience, the definition of requirements, the decision process, and the effect of the decisions made on the system architecture evolution. The paper offers some insights that can be useful to gain understanding of how decisions are typically made in real settings, i.e., based on gut-feeling, which is important when designing decision support systems for architectural design decisions.
Efi Papatheocharous, Ulrik Franke
SoMeT2
2016 Experimental Evidence on Decision-Making in Availability Service Level Agreements
abstract
As more enterprises buy information technology services, studying their underpinning contracts becomes more important. With cloud computing and outsourcing, these service level agreements (SLAs) are now often the only link between the business and the supporting IT services. This paper presents an experimental economics investigation of decision-making with regard to availability SLAs, among enterprise IT professionals. The method and the ecologically valid subjects make the study unique to date among IT service SLA studies. The experiment consisted of pairwise choices under uncertainty, and subjects (N=46) were incentivized by payments based on one of their choices, randomly selected. The research question investigated in this paper is: Do enterprise IT professionals maximize expected value when procuring availability SLAs, as would be optimal from the business point of view? The main result is that enterprise IT professionals fail to maximize expected value. Whereas some subjects do maximize expected value, others are risk-seeking, risk-averse, or exhibit nonmonotonic preferences. The nonmonotonic behavior in particular is an interesting observation, which has no obvious explanation in the literature. For a subset of the subjects (N=29), a few further hypotheses related to associations between general attitude to risk or professional experience on the one hand, and behavior in SLAs on the other hand, were investigated. No support for these associations was found. The results should be interpreted with caution, due to the limited number of subjects. However, given the prominence of SLAs in modern IT service management, the results are interesting and call for further research, as they indicate that current professional decision-making regarding SLAs can be improved. In particular, if general attitude to risk and professional experience do not impact decision-making with regard to SLAs, more extensive use of decision-support systems might be called for in order to facilitate proper risk management.
Ulrik Franke, Markus Buschle
IEEE Trans. Netw. Serv. Manag.1
2015 An experiment in ontology use for command and control interoperability
Mika Cohen, Ulrik Franke
Autom. Softw. Eng.2
2015 A test of intrusion alert filtering based on network information
abstract
Intrusion detection systems continue to be a promising security technology. The arguably biggest problem with today's intrusion detection systems is the sheer number of alerts they produce for events that are regarded as benign or non-critical by system administrators. A plethora of more and less complex solutions has been proposed to filter the relevant i.e., correct alerts that signature-based intrusion detection sensors produce. This paper reports on a test performed to test a number of filtering alternatives that take advantage of information about static properties of the monitored computer network, such as vulnerabilities and exposure of ports and hosts. The results show that none of the filters are able to maintain a high recall portion of detected attacks while increasing the precision portion of relevant alerts. At most, precision increased from 1.4% to 2.9%, and this also resulted in a decrease in recall from 44% to 26%. Even when combined in an exploratory fashion, the filters fail to provide improved precision. It is concluded that filters based on static properties of the computer network do not result in clear improvements to alert lists produced by signature-based intrusion detection systems. Copyright © 2015 John Wiley & Sons, Ltd.
Teodor Sommestad, Ulrik Franke
Secur. Commun. Networks2
2014 Enterprise Architecture Analysis with Production Functions
abstract
Enterprise Architecture (EA) is a discipline designed to cope with the complexity of modern enterprises at the intersection of information technology and business operations. This article demonstrates how EA models can be enriched with the production function concept from microeconomics, enabling new and business relevant kinds of analysis. The approach is demonstrated through examples regarding growth strategies, architectural efficiency with changing relative prices, and strategies for high availability IT services.
Ulrik Franke
EDOC1
2014 Cyber situational awareness - A systematic review of the literature
Ulrik Franke, Joel Brynielsson
Comput. Secur.1
2014 An architecture framework for enterprise IT service availability analysis
Ulrik Franke, Pontus Johnson, Johan König
Softw. Syst. Model.1
2014 The Distribution of Time to Recovery of Enterprise IT Services
abstract
The context of this article is the availability of enterprise IT services, a key concern for many enterprises. While there is a plethora of literature concerned with service availability, there is no previous systematic empirical study on IT service time to recovery following outages. The existing literature typically assumes a distribution, or builds on analogies to related areas such as software engineering. Therefore, our objective is to find the statistical distribution of IT service time to recovery. Method-wise, this investigation is based on logs of more than 1800 incidents in a large Nordic bank, corresponding to more than 11000 hours of recorded downtime. Five possible distributions of time to recovery from the literature were investigated using the Akaike Information Criterion to find the distribution offering the best fit. The results show that the log-normal distribution outperformed the others for all tested service channels (collections of IT services). It is concluded that the log-normal distribution offers the best fit of IT service time to recovery. Using this distribution in simulation and decision-support tools offers the prospect of better predictions of downtime and downtime costs to the practitioner community.
Ulrik Franke, Hannes Holm, Johan König
IEEE Trans. Reliab.1
2012 Availability of enterprise IT systems: an expert-based Bayesian framework
Ulrik Franke, Pontus Johnson, Johan König, Liv Marcks von Würtemberg
Softw. Qual. J.1
2012 Optimal IT Service Availability: Shorter Outages, or Fewer?
abstract
High enterprise IT service availability is a key success factor throughout many industries. While understanding of the economic importance of availability management is becoming more widespread, the implications for management of Service Level Agreements (SLAs) and thinking about availability risk management are just beginning to unfold. This paper offers a framework within which to think about availability management, highlighting the importance of variance of outage costs. The importance of variance is demonstrated using simulations on existing data sets of revenue data. An important implication is that when outage costs are proportional to outage duration, more but shorter outages should be preferred to fewer but longer, in order to minimize variance. Furthermore, two archetypal cases where the cost of an outage depends non-linearly on its duration are considered. An optimal outage length is derived, and some guidance is also given for its application when the variance of hourly downtime costs is considered. The paper is concluded with a discussion about the feasibility of the method, its practitioner relevance and its implications for SLA management.
Ulrik Franke
IEEE Trans. Netw. Serv. Manag.1
2010 Enterprise Architecture Meta Models for IT/Business Alignment Situations
abstract
Enterprise Architecture models can be used to support IT/business alignment. However, existing approaches do not distinguish between different IT/business alignment situations. Since companies face diverse challenges in achieving a high degree of IT/business alignment, a universal `one size fits all' approach does not seem appropriate. This paper proposes to decompose the IT/business alignment problem into tangible qualities for business, IT systems, and IT governance. An explorative study among 162 professionals is used to distinguish four IT/business alignment situations, i.e. four clusters of IT/business alignment problems. These situations each represent the current state according to certain qualities and also the priorities for future development. In order to increase IT/business alignment, enterprise architecture meta models are proposed for each identified situation. One core meta model (to reflect common priorities) as well as situation specific extensions are presented.
Jan Saat, Ulrik Franke, Robert Lagerström, Mathias Ekstedt
EDOC2
2009 Modeling the IT Impact on Organizational Structure
abstract
The impact IT systems have on organizations is widely debated, both in academia and industry. This paper describes a quantitative framework for analyzing organizational impact from IT systems. The framework consists of an abstract model that is a metamodel suitable for expressing organizational structure incorporated with an extended influence diagram for analysis. The purpose is to create enterprise architecture (EA) models that can be used for analysis of the enterprise. The framework has been validated through a case study where the framework has been used to analyze the changes in organizational structure after the introduction of an IT system.
Pia Närman, David Höök, Ulrik Franke, Pontus Johnson
EDOC3
2009 A formal method for cost and accuracy trade-off analysis in software assessment measures
abstract
Creating accurate models of information systems is an important but challenging task. It is generally well understood that such modeling encompasses general scientific issues, but the monetary aspects of the modeling of software systems are not equally well acknowledged. The present paper describes a method using Bayesian networks for optimizing modeling strategies, perceived as a trade-off between these two aspects. Using GeNIe, a graphical tool with the proper Bayesian algorithms implemented, decision support can thus be provided to the modeling process. Specifically, an informed trade-off can be made, based on the modeler's prior knowledge of the predictive power of certain models, combined with his projection of their costs. It is argued that this method might enhance modeling of large and complex software systems in two principal ways: Firstly, by enforcing rigor and making hidden assumptions explicit. Secondly, by enforcing cost awareness even in the early phases of modeling. The method should be used primarily when the choice of modeling can have great economic repercussions.
Ulrik Franke, Pontus Johnson, Robert Lagerström, Johan Ullberg, David Höök, Mathias Ekstedt, Johan König
RCIS1