EDBT 2026 Demo / reviewers in the wild / expert
Pontus Johnson
dblp:79/6862
· DBLP profile ↗
35ranked-venue papers
10as first author
5since 2021 · last 2024
0000-0002-3293-1681ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 11 · 4 first-authorSecurity and privacy · 9 · 4 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Anomaly Detection in Security Logs using Sequence ModelingabstractAs cyberattacks are becoming more sophisticated, automated activity logging and anomaly detection are becoming important tools for defending computer systems. Recent deep learning-based approaches have demonstrated promising results in cybersecurity contexts, typically using supervised learning combined with large amounts of labeled data. Self-supervised learning has seen growing interest as a method of training models because it does not require labeled training data, which can be difficult and expensive to collect. However, existing self-supervised approaches to anomaly detection in user authentication logs either suffer from low precision or rely on large pre-trained natural language models. This makes them slow and expensive both during training and inference. Building on previous works, we therefore propose an end-to-end trained self-supervised transformer-based sequence model for anomaly detection in user authentication events. Thanks in part to an adapted masked-language modeling (MLM) learning task and domain knowledge-based improvements to the anomaly detection method, our proposed model outperforms previous long short-term memory (LSTM)-based approaches at detecting red-team activity in the "Comprehensive, Multi-Source Cyber-Security Events" authentication event dataset, improving the area under the receiver operating characteristic curve (AUC) from 0.9760 to 0.9989 and achieving an average precision of 0.0410. Our work presents the first application of end-to-end trained self-supervised transformer models to user authentication data in a cybersecurity context, and demonstrates the potential of transformer-based approaches for anomaly detection. Simon G. E. Gökstorp, Jakob Nyberg, Yeongwoo Kim, Pontus Johnson, György Dán |
NOMS | 4 |
| 2023 | The meta attack language - a formal descriptionabstractNowadays, IT infrastructures are involved in making innumerable aspects of our lives convenient, starting with water or energy distribution systems, and ending with e-commerce solutions and online banking services. In the worst case, cyberattacks on such infrastructures can paralyze whole states and lead to losses in terms of both human lives and money. One of the approaches to increase security of IT infrastructures relies on modeling possible ways of compromising them by potential attackers. To facilitate creation and reusability of such models, domain specific languages (DSLs) can be created. Ideally, a user will employ a DSL for modeling their infrastructure of interest, with the domain-specific threats and attack logic being already encoded in the DSL by the domain experts. The Meta Attack Language (MAL) has been introduced previously as a meta-DSL for development of security-oriented DSLs. In this work, we define formally the syntax and a semantics of MAL to ease a common understanding of MAL’s functionalities and enable reference implementations on different technical platforms. It’s applicability for modeling and analysis of security of IT infrastructures is illustrated with an example. Wojciech Widel, Simon Hacks, Mathias Ekstedt, Pontus Johnson, Robert Lagerström |
Comput. Secur. | 4 |
| 2023 | Automated Security Assessments of Amazon Web Services EnvironmentsabstractMigrating enterprises and business capabilities to cloud platforms like Amazon Web Services (AWS) has become increasingly common. However, securing cloud operations, especially at large scales, can quickly become intractable. Customer-side issues such as service misconfigurations, data breaches, and insecure changes are prevalent. Furthermore, cloud-specific tactics and techniques paired with application vulnerabilities create a large and complex search space. Various solutions and modeling languages for cloud security assessments exist. However, no single one appeared sufficiently cloud-centered and holistic. Many also did not account for tactical security dimensions. This article, therefore, presents a domain-specific modeling language for AWS environments. When used to model AWS environments, manually or automatically, the language automatically constructs and traverses attack graphs to assess security. Assessments, therefore, require minimal security expertise from the user. The modeling language was primarily tested on four third-party AWS environments through securiCAD Vanguard, a commercial tool built around the AWS modeling language. The language was validated further by measuring performance on models provided by anonymous end users and a comparison with a similar open source assessment tool. As of March 2020, the modeling language could represent essential AWS structures, cloud tactics, and threats. However, the tests highlighted certain shortcomings. Data collection steps, such as planted credentials, and some missing tactics were obvious. Nevertheless, the issues covered by the DSL were already reminiscent of common issues with real-world precedents. Future additions to attacker tactics and addressing data collection should yield considerable improvements. Viktor Engström, Pontus Johnson, Robert Lagerström, Erik Ringdahl, Max Wällstedt |
ACM Trans. Priv. Secur. | 2 |
| 2022 | Cyber threat response using reinforcement learning in graph-based attack simulationsabstractIn this ongoing project we employ reinforcement learning in a simulation environment to learn policies for cyber defense. The environment is based on attack graphs produced using the Meta Attack Language, a modeling language used to assess the security of systems.Two RL algorithms are utilized to prevent a simulated attacker agent to reach a series of targets within attack graphs. The defensive agent has to make decisions based on the value of keeping assets enabled, or suffering the consequence of the attacker reaching its goal.The initial results are promising, and show that both algorithms are able to find distinct strategies for defense. However, further analysis is needed to evaluate policy quality, including the implementation of sensible baseline policies for comparison. Jakob Nyberg, Pontus Johnson, András Méhes |
NOMS | 2 |
| 2022 | VehicleLang: A probabilistic modeling and simulation language for modern vehicle IT infrastructuresabstractAttack simulations are a feasible means of assessing the cyber security of various systems. Simulations can replicate the steps taken by an attacker to compromise sensitive system assets, and the time required for the acquisition of assets of interests can be calculated. One widely accepted approach to such simulations is the modelling of attack steps and their dependencies in a formal manner using attack graphs. To reduce the effort of creating new attack graphs for each system in a given domain, one can employ domain-specific attack-modeling languages to codify common attack logic. The Meta Attack Language has been proposed as a framework for developing domain-specific attack languages. In this article, we propose vehicleLang as a domain-specific language for modeling vehicles in the context of corresponding information technology infrastructures and analyzing weaknesses related to known attacks. To model domain-specific attributes, we reviewed existing literature to develop a comprehensive language, which was then verified through a series of interviews with domain experts from the automotive industry. Specifically, a systematic literature review was performed to identify possible attacks against vehicles. The identified attacks served as a blueprint for the evaluation of vehicleLang’s simulation capabilities. Finally, the language was validated using the Feigenbaum test methodology. Sotirios Katsikeas, Pontus Johnson, Simon Hacks, Robert Lagerström |
Comput. Secur. | 2 |
| 2019 | Probabilistic Modeling and Simulation of Vehicular Cyber Attacks: An Application of the Meta Attack LanguageabstractAttack simulations are a feasible means to assess the cyber security of systems. The simulations trace the steps taken by an attacker to compromise sensitive system assets. Moreover, they allow to ... Sotirios Katsikeas, Pontus Johnson, Simon Hacks, Robert Lagerström |
ICISSP | 2 |
| 2018 | A Meta Language for Threat Modeling and Attack SimulationsabstractAttack simulations may be used to assess the cyber security of systems. In such simulations, the steps taken by an attacker in order to compromise sensitive system assets are traced, and a time estimate may be computed from the initial step to the compromise of assets of interest. Attack graphs constitute a suitable formalism for the modeling of attack steps and their dependencies, allowing the subsequent simulation. Pontus Johnson, Robert Lagerström, Mathias Ekstedt |
ARES | 1 |
| 2018 | Can the Common Vulnerability Scoring System be Trusted? A Bayesian AnalysisabstractThe Common Vulnerability Scoring System (CVSS) is the state-of-the art system for assessing software vulnerabilities. However, it has been criticized for lack of validity and practitioner relevance. In this paper, the credibility of the CVSS scoring data found in five leading databases-NVD, X-Force, OSVDB, CERT-VN, and Cisco-is assessed. A Bayesian method is used to infer the most probable true values underlying the imperfect assessments of the databases, thus circumventing the problem that ground truth is not known. It is concluded that with the exception of a few dimensions, the CVSS is quite trustworthy. The databases are relatively consistent, but some are better than others. The expected accuracy of each database for a given dimension can be found by marginalizing confusion matrices. By this measure, NVD is the best and OSVDB is the worst of the assessed databases. Pontus Johnson, Robert Lagerström, Mathias Ekstedt, Ulrik Franke |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2016 | pwnPr3d: An Attack-Graph-Driven Probabilistic Threat-Modeling ApproachabstractIn this paper we introduce pwnPr3d, a probabilistic threat modeling approach for automatic attack graph generation based on network modeling. The aim is to provide stakeholders in organizations with a holistic approach that both provides high-level overview and technical details. Unlike many other threat modeling and attack graph approaches that rely heavily on manual work and security expertise, our language comes with built-in security analysis capabilities. pwnPr3d generates probability distributions over the time to compromise assets. Pontus Johnson, Alexandre Vernotte, Mathias Ekstedt, Robert Lagerström |
ARES | 1 |
| 2016 | Time between vulnerability disclosures: A measure of software product vulnerability
Pontus Johnson, Dan Gorton, Robert Lagerström, Mathias Ekstedt |
Comput. Secur. | 1 |
| 2016 | The Tarpit - A general theory of software engineering
Pontus Johnson, Mathias Ekstedt |
Inf. Softw. Technol. | 1 |
| 2015 | Towards general theories of software engineering
Pontus Johnson, Mathias Ekstedt, Michael Goedicke, Ivar Jacobson |
Sci. Comput. Program. | 1 |
| 2014 | An architecture framework for enterprise IT service availability analysis
Ulrik Franke, Pontus Johnson, Johan König |
Softw. Syst. Model. | 2 |
| 2013 | Modeling and Prediction of Monetary and Non-monetary Business ValuesabstractIn existing business model frameworks little attention is paid to a thorough understanding of the perceived customer value of a business' offering as compared to competing offers. In this paper, we propose to use utility theory in combination with e3value models to address this issue. An actor's joint utility function specifies how much value the actor attaches to a given product or service's different qualities. Competing value offerings map to different points on the customer utility function, since they provide certain quantities of each quality. Since the customer can be expected to exhibit a utility maximizing behavior, his/her choices between offerings can be predicted. Thus, given the proposed utility extension, it becomes possible to quantitatively reason about the relative customer value of an offering compared to those of the competition. This, in turn, allows the optimization of price, the key ingredient in any business model. Margus Välja, Magnus Österlind, Maria E. Iacob, Marten van Sinderen, Pontus Johnson |
EDOC | 5 |
| 2013 | 2nd SEMAT workshop on a general theory of software engineering (GTSE 2013)abstractMost academic disciplines emphasize the importance of their general theories. Examples of well-known general theories include the Big Bang theory, Maxwell's equations, the theory of the cell, the theory of evolution, and the theory of demand and supply. Less known to the wider audience, but established within their respective fields, are theories with names such as the general theory of crime and the theory of marriage. Few general theories of software engineering have, however, been proposed, and none have achieved significant recognition. This workshop, organized by the SEMAT initiative, aims to provide a forum for discussing the concept of a general theory of software engineering. The topics considered include the benefits, the desired qualities, the core components and the form of a such a theory. Pontus Johnson, Ivar Jacobson, Michael Goedicke, Mira Kajko-Mattsson |
ICSE | 1 |
| 2012 | Re-founding software engineering - SEMAT at the age of three (keynote abstract)abstractSoftware engineering is gravely hampered by immature practices. Specific problems include: The prevalence of fads more typical of the fashion industry than an engineering discipline; a huge number of methods and method variants, with differences little understood and artificially magnified; the lack of credible experimental evaluation and validation; and the split between industry practice and academic research. Ivar Jacobson, Ian Spence, Pontus Johnson, Mira Kajko-Mattsson |
ASE | 3 |
| 2012 | Using enterprise architecture and technology adoption models to predict application usage
Per Närman, Hannes Holm, David Höök, Nicholas Honeth, Pontus Johnson |
J. Syst. Softw. | 5 |
| 2012 | Availability of enterprise IT systems: an expert-based Bayesian framework
Ulrik Franke, Pontus Johnson, Johan König, Liv Marcks von Würtemberg |
Softw. Qual. J. | 2 |
| 2010 | Hybrid Probabilistic Relational Models for System Quality AnalysisabstractThe formalism Probabilistic Relational Models (PRM) couples discrete Bayesian Networks with a modeling formalism similar to UML class diagrams and has been used for architecture analysis. PRMs are well-suited to perform architecture analysis with respect to system qualities since they support both modeling and analysis within the same formalism. A particular strength of PRMs is the ability to perform meaningful analysis of domains where there is a high level of uncertainty, as is often the case when performing system quality analysis. However, the use of discrete Bayesian networks in PRMs complicates the analysis of continuous phenomena. The main contribution of this paper is the Hybrid Probabilistic Relational Models (HPRM) formalism which extends PRMs to enable continuous analysis thus extending the applicability for architecture analysis and especially for trade-off analysis of system qualities. HPRMs use hybrid Bayesian networks which allow combinations of discrete and continuous variables. In addition to presenting the HPRM formalism, the paper contains an example which details the use of HPRMs for architecture trade-off analysis. Per Närman, Markus Buschle, Johan König, Pontus Johnson |
EDOC | 4 |
| 2010 | A probabilistic relational model for security risk analysis
Teodor Sommestad, Mathias Ekstedt, Pontus Johnson |
Comput. Secur. | 3 |
| 2010 | Architecture analysis of enterprise systems modifiability - Models, analysis, and validation
Robert Lagerström, Pontus Johnson, David Höök |
J. Syst. Softw. | 2 |
| 2010 | Architecture analysis of enterprise systems modifiability: a metamodel for software change cost estimation
Robert Lagerström, Pontus Johnson, Mathias Ekstedt |
Softw. Qual. J. | 2 |
| 2009 | Modeling the IT Impact on Organizational StructureabstractThe impact IT systems have on organizations is widely debated, both in academia and industry. This paper describes a quantitative framework for analyzing organizational impact from IT systems. The framework consists of an abstract model that is a metamodel suitable for expressing organizational structure incorporated with an extended influence diagram for analysis. The purpose is to create enterprise architecture (EA) models that can be used for analysis of the enterprise. The framework has been validated through a case study where the framework has been used to analyze the changes in organizational structure after the introduction of an IT system. Pia Närman, David Höök, Ulrik Franke, Pontus Johnson |
EDOC | 4 |
| 2009 | Enterprise Architecture Analysis for Data Accuracy AssessmentsabstractPoor data in information systems impede the quality of decision-making in many modern organizations. Manual business process activities and application services are never executed flawlessly which results in steadily deteriorating data accuracy, the further away from the source the data gets, the poorer its accuracy becomes. This paper proposes an architecture analysis method based on Bayesian Networks to assess data accuracy deterioration in a quantitative manner. The method is model-based and uses the ArchiMate language to model business processes and the way in which data objects are transformed by various operations. A case study at a Swedish utility demonstrates the approach. Per Närman, Pontus Johnson, Mathias Ekstedt, Moustafa Chenine, Johan König |
EDOC | 2 |
| 2009 | A formal method for cost and accuracy trade-off analysis in software assessment measuresabstractCreating accurate models of information systems is an important but challenging task. It is generally well understood that such modeling encompasses general scientific issues, but the monetary aspects of the modeling of software systems are not equally well acknowledged. The present paper describes a method using Bayesian networks for optimizing modeling strategies, perceived as a trade-off between these two aspects. Using GeNIe, a graphical tool with the proper Bayesian algorithms implemented, decision support can thus be provided to the modeling process. Specifically, an informed trade-off can be made, based on the modeler's prior knowledge of the predictive power of certain models, combined with his projection of their costs. It is argued that this method might enhance modeling of large and complex software systems in two principal ways: Firstly, by enforcing rigor and making hidden assumptions explicit. Secondly, by enforcing cost awareness even in the early phases of modeling. The method should be used primarily when the choice of modeling can have great economic repercussions. Ulrik Franke, Pontus Johnson, Robert Lagerström, Johan Ullberg, David Höök, Mathias Ekstedt, Johan König |
RCIS | 2 |
| 2008 | A Bayesian network for IT governance performance predictionabstractThe goal of IT governance is not only to achieve internal efficiency in an IT organization, but also to support IT’s role as a business enabler. The latter is here denoted IT governance performance. IT management cannot control the IT governance performance directly. Instead, their realm of control includes several IT governance maturity indicators such as the existence of different IT activities, documents, metrics and roles. Current IT governance frameworks are suitable for describing IT governance, IT-systems, and business processes, but lack the ability to predict how changes to the IT governance maturity indicators affect IT governance performance. Bayesian networks are widely used for goal modeling and prediction in several research fields. This paper presents an application of Bayesian networks for IT governance performance prediction. Data from 35 case studies conducted in a variety of organizations has been used to determine the behavior of the network. An assumption on linearity is introduced in order to compensate for the limited amount of data, and the network learns using the proposed Linear Conditional Probability Matrix Generator. The resulting Bayesian network for IT governance performance prediction can be used to support IT governance decision-making. Mårten Simonsson, Robert Lagerström, Pontus Johnson |
ICEC | 3 |
| 2008 | The IT Organization Modeling and Assessment Tool for IT Governance Decision Support
Mårten Simonsson, Pontus Johnson, Mathias Ekstedt |
CAiSE | 2 |
| 2008 | Using Enterprise Architecture Models for System Quality AnalysisabstractEnterprise Architecture is a model-based approach to business-oriented IT management. To promote good IT decision making, an Enterprise Architecture framework needs to explicate what kind of analyses it supports. Since creating Enterprise Architecture models is expensive and without intrinsic value, it is desirable to only create Enterprise Architecture models based on metamodels that support well-defined analyses. This paper presents the content and extension of a metamodel which supports creating models containing the information necessary to conduct system quality analyses, specifically with respect to availability, accuracy, confidentiality and integrity. The metamodel is an extension and formalization of the metamodel underlying the ArchiMate modelling language for Enterprise Architecture. The use of the extended metamodel is demonstrated in a case study where the availability, accuracy, confidentiality and integrity of the two Service Oriented Architecture (SOA) platforms Sun JCaps and PrOSeRO were evaluated. Per Närman, Marten Schönherr, Pontus Johnson, Mathias Ekstedt, Moustafa Chenine |
EDOC | 3 |
| 2008 | Combining Defense Graphs and Enterprise Architecture Models for Security AnalysisabstractSecurity is dependent on a mixture of interrelated concepts such as technical countermeasures, organizational policies, security procedures, and more. To facilitate rational decision making, these concepts need to be combined into an overall judgment on the current security posture, as well as potential future ones. Decision makers are, however, faced with uncertainty regarding both what countermeasures that is in place, and how well different countermeasures contribute to mitigating attacks. This paper presents a security assessment framework using the Bayesian statistics-based extended influence diagrams to combine attack graphs with countermeasures into defense graphs. The approach makes it possible to calculate the probability that attacks succeed based on an enterprise architecture model. The framework also takes uncertainties of the security assessment into consideration. Moreover, using the extended influence diagram formalism the expected loss from each attack can be calculated. Teodor Sommestad, Mathias Ekstedt, Pontus Johnson |
EDOC | 3 |
| 2007 | A Tool for Enterprise Architecture AnalysisabstractThe discipline of enterprise architecture advocates the use of models to support decision-making on enterprise-wide information system issues. In order to provide such support, enterprise architecture models should be amenable to analyses of various properties, as e.g. the availability, performance, interoperability, modifiability, and information security of the modeled enterprise information systems. This paper presents a software tool for such analyses. The tool guides the user in the generation of enterprise architecture models and subjects these models to analyses resulting in quantitative measures of the chosen quality attribute. The paper describes and exemplifies both the architecture and the usage of the tool. 1. Pontus Johnson, Erik Johansson, Teodor Sommestad, Johan Ullberg |
EDOC | 1 |
| 2007 | Enterprise Architecture: A Framework Supporting System Quality AnalysisabstractEnterprise Architecture is a model-based approach to business-oriented IT management. To promote good IT decision making, an enterprise architecture framework needs to explicate what kind of analyses it supports. Since creating enterprise architecture models is expensive and without intrinsic value, it is desirable to only create enterprise architecture models based on metamodels that support well-defined analyses. This paper suggests a metamodel derived specifically with a set of theory-based system quality analyses in mind. The ISO 9126-based theory behind the system quality analysis is introduced in the shape of an extended influence diagram. Finally, an example illustrates that our theory-based metamodel does support system quality analysis. Per Närman, Pontus Johnson, Lars Nordström |
EDOC | 2 |
| 2007 | In Search of a Unified Theory of Software EngineeringabstractHighly successful scientific disciplines have at least one common denominator; they have developed unified theories that span a large set of phenomena within the discipline. The discipline of software engineering today features a multitude of disparate and fragmented micro-theories. Among these micro-theories, many speak of different things, many speak differently of similar things, and few can be employed consistently together. Since these micro-theories are so numerous and diverse, software engineering also lacks a common vocabulary for communication and argumentation. There are no real rules for separating sound arguments from unsound ones. This article argues that the search for a single unified theory of software engineering is both viable and desirable, hi order to do so, requirements for such a unified theory are outlined. Then three well-known software engineering theories that could constitute embryos to unified theories are considered in the light of the presented requirements. Pontus Johnson, Mathias Ekstedt |
ICSEA | 1 |
| 2006 | Extended Influence Diagrams for Enterprise Architecture AnalysisabstractThe discipline of enterprise architecture advocates the use of models to support decision-making on enterprise-wide information system issues. In order to provide such support, enterprise architecture models should be amenable to analyses of various properties, as e.g. the level of enterprise information security. This paper proposes the use of a formal language to support such analysis. Such a language needs to be able to represent causal relations between, and definitions of, various concepts as well as uncertainty with respect to both concepts and relations. To support decision-making properly, the language must also allow the representation of goals and decision alternatives. This paper evaluates a number of languages with respect to these requirements, and selects influence diagrams for further consideration. The influence diagrams are then extended to fully satisfy the requirements. The syntax and semantics of the extended influence diagrams are detailed in the paper, and their use is demonstrated in an example Pontus Johnson, Robert Lagerström, Per Närman, Mårten Simonsson |
EDOC | 1 |
| 2005 | Assessment of Enterprise Information Security - The Importance of PrioritizationabstractAssessing the level of information security in an enterprise is a serious challenge for many organizations. This paper considers the prioritization of the field of enterprise information security. The paper thus considers how we may know what parts of information security are important for a company to address and what parts are not. Two methods for prioritization are used. The results demonstrate to what extent different standards committees, guideline authors and expert groups differ in their opinions on what the important issues are in enterprise information security. The ISO/IEC 17799, the NIST SP 800-26, the ISF standards committees, the CMU/SEI OCTAVE framework authors and an expert panel at the Swedish Information Processing Society (DFS) are considered. The differences in prioritization have important consequences on enterprise information security assessments. The effects on the information security assessment results in a European energy company are presented in the paper. Erik Johansson, Pontus Johnson |
EDOC | 2 |
| 2001 | Architectural Integration Styles for Large-Scale Enterprise Software SystemsabstractA predominant problem in the management of large-scale enterprise software systems is application integration. Despite the considerable efforts spent on the development of new standards and technologies for software interoperation, the integration of systems that originally were not designed to interact with each other is a major undertaking, requiring in-depth knowledge of existing systems, incorporation of integration products, and development and/or parameterization of various kinds of adapters and gateways. The article presents the concept of architectural integration styles, i.e. architectural styles describing software structures of integration solutions for enterprise software systems. The article further proposes an approach for selection of styles based on the characteristics of the existing software applications and the desired quality attributes of the integrated system. A number of architectural integration styles for enterprise systems are presented, and a case study of the style selection process applied to a mid-sized Swedish electricity retailer is described. Jonas Andersson 0003, Pontus Johnson |
EDOC | 2 |