EDBT 2026 Demo / reviewers in the wild / expert
Maritta Heisel
dblp:h/MarittaHeisel
· DBLP profile ↗
81ranked-venue papers
9as first author
9since 2021 · last 2025
0000-0002-3275-2819ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 37 · 4 first-author · 3 since 2021Software engineering, systems software and programming languages · 34 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 5 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4Theory of computation · 3 · 2 first-authorHuman-computer interaction and ubiquitous computing · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Towards Consistent Policy Enforcement in Dataspaces
Julia Pampus, Maritta Heisel |
DATA | 2 |
| 2025 | Management of Customized Privacy Policies
Jens Leicht, Maritta Heisel |
ICISSP (2) | 2 |
| 2024 | Extending PriPoCoG: A Privacy Policy Editor for GDPR-Compliant Privacy Policies
Jens Leicht, Maritta Heisel |
ENASE | 2 |
| 2024 | An Empirical Examination of the Technical Aspects of Data Sovereignty
Julia Pampus, Maritta Heisel |
ICSOFT | 2 |
| 2023 | P2BAC: Privacy Policy Based Access Control Using P-LPL
Jens Leicht, Maritta Heisel |
ICISSP | 2 |
| 2023 | Model-Based Documentation of Architectures for Cloud-Based Systems
Marvin Wagner, Maritta Heisel |
ICSOFT | 2 |
| 2022 | PriPoCoG: Guiding Policy Authors to Define GDPR-Compliant Privacy Policies
Jens Leicht, Maritta Heisel, Armin Gerl |
TrustBus | 2 |
| 2021 | Mitigating Privacy Concerns by Developing Trust-related Software Features for a Hybrid Social Media Application
Angela Borchert, Aidmar Wainakh, Nicole C. Krämer, Max Mühlhäuser, Maritta Heisel |
ENASE | 5 |
| 2021 | P2P Frames: Pattern-based Characterization of Functional Requirements for Peer-to-peer Systems
Lirijan Sabani, Roman Wirtz, Maritta Heisel |
ENASE | 3 |
| 2020 | Balancing trust and privacy in computer-mediated introduction: featuring risk as a determinant for trustworthiness requirements elicitationabstractIn requirements elicitation methods, it is not unusual that conflicts between software requirements or between software goals and requirements can be detected. It is efficient to deal with those conflicts before further costs are invested to implement a solution that includes insufficient software features. This work introduces risk as an extension of a method for eliciting trust-related software features for computer-mediated introduction (CMI) so that software engineers can i) decide on the implementation of conflicting requirements in the problem space and ii) additionally reduce risks that accompany CMI use. CMI describes social media platforms on which strangers with compatible interests get acquainted online and build trust relationships with each other for potential offline encounters (e.g.: online dating and sharing economy). CMI involves security and safety risks such as data misuse, deceit or violence. In the engineering process, software goals and requirements for trust building often come along with the disclosure of personal data, which may result in conflicts with goals and requirements for privacy protection. In order to tackle i) conflicting requirements and goals and ii) CMI risks, our approach involves risk assessment of user concerns and requirements in order to rank goals by their importance for the application. Based on the prioritization, conflicting requirements can be managed. The findings are presented with explicit examples of the application field online dating. Angela Borchert, Nicolás E. Díaz Ferreyra, Maritta Heisel |
ARES | 3 |
| 2020 | A Conceptual Method for Eliciting Trust-related Software Features for Computer-mediated Introduction
Angela Borchert, Nicolás E. Díaz Ferreyra, Maritta Heisel |
ENASE | 3 |
| 2020 | Assisted Generation of Privacy Policies using Textual Patterns
Nazila Gol Mohammadi, Jens Leicht, Ludger Goeke, Maritta Heisel |
ENASE | 4 |
| 2020 | Systematic Treatment of Security Risks during Requirements Engineering
Roman Wirtz, Maritta Heisel |
ENASE | 2 |
| 2020 | Risk Identification: From Requirements to Threat Models
Roman Wirtz, Maritta Heisel |
ICISSP | 2 |
| 2020 | Threat Modeling for Cyber-Physical Systems: A Two-dimensional Taxonomy Approach for Structuring Attack Actions
Monika Maidl, Gerhard Münz, Stefan Seltzsam, Marvin Wagner, Roman Wirtz, Maritta Heisel |
ICSOFT | 6 |
| 2019 | Systematic Asset Identification and Modeling During Requirements Engineering
Nazila Gol Mohammadi, Roman Wirtz, Maritta Heisel |
CRiSIS | 3 |
| 2019 | Architecture to Manage and Protect Personal Data Utilising BlockchainabstractMany Internet users employ a multitude of online services. Many services require the same data to be entered and users enter it repeatedly. Instead of entering information for every new service a user wants to use, we propose a system that allows users to simply share a set of information with any service they want to use. The information is entered once and stored in a distributed storage system. Users can easily share the data with any service provider, in order to use a service. Our proposed system makes use of the distributed ledger, provided by blockchains, to manage access rights. By taking the data away from the service providers, the personal data is also protected against unwanted data leaks. Jens Leicht, Maritta Heisel |
ENASE | 2 |
| 2019 | CVSS-based Estimation and Prioritization for Security RisksabstractDuring software development, it is of essential importance to consider security threats. The number of reported incidents and the harm for organizations due to such incidents highly increased during the last few years. The efforts for treating threats need to be spent in an effective manner. A prioritization can be derived from the risk level of a threat, which is defined as the likelihood of occurence and the consequence for an asset. In this paper, we propose a risk estimation and evaluation method for information security based on the Common Vulnerability Scoring System (CVSS). Our method can be applied during requirements engineering. The application in one of the earliest stages of a software development lifecycle enables security engineers to focus on the most servere risks right from the beginning. As initial input, we make use of a pattern-based description of relevant threats to the software. When estimating the risk level of those threats, we consider three perspectives: (1) software providers, (2) data owner, and (3) third parties for which a potential harm may exist, too. Our method combines attributes of the pattern and the different perspectives to estimate and prioritize risks. The pattern-based description allows a semi-automatic application of our method, which ends with a ranking of risks according to their priority as final outcome. Roman Wirtz, Maritta Heisel |
ENASE | 2 |
| 2019 | RE4DIST: Model-based Elicitation of Functional Requirements for Distributed Systems
Roman Wirtz, Maritta Heisel |
ICSOFT | 2 |
| 2019 | Privacy Policy Specification Framework for Addressing End-Users' Privacy Requirements
Nazila Gol Mohammadi, Jens Leicht, Nelufar Ulfat-Bunyadi, Maritta Heisel |
TrustBus | 4 |
| 2018 | A Systematic Method to Describe and Identify Security Threats Based on Functional Requirements
Roman Wirtz, Maritta Heisel |
CRiSIS | 2 |
| 2018 | Problem-based Elicitation of Security Requirements - The ProCOR Method
Roman Wirtz, Maritta Heisel, Rene Meis, Aida Omerovic, Ketil Stølen |
ENASE | 2 |
| 2018 | Towards an End-to-End Architecture for Run-Time Data Protection in the CloudabstractProtecting sensitive data is a key concern for the adoption of cloud solutions. Protecting data in the cloud is made particularly challenging by the dynamic changes that cloud systems may undergo at run-time, as well as the complex interactions among multiple software and hardware components, services, and stakeholders. Conformance to data protection requirements in such a dynamic environment cannot any longer be ensured during design time; e.g. due to the dynamic changes imposed by replication and migration of components. It requires run-time data protection mechanisms. This paper proposes combining multiple existing data protection approaches and extending them to run-time, ultimately delivering an end-to-end architecture for run-time data protection in the cloud. We validate the practical applicability of our approach by a commercial case study. Nazila Gol Mohammadi, Zoltán Ádám Mann, Andreas Metzger, Maritta Heisel, James Greig |
SEAA | 4 |
| 2018 | Supporting the Systematic Goal Refinement in KAOS using the Six-Variable Model
Nelufar Ulfat-Bunyadi, Nazila Gol Mohammadi, Maritta Heisel |
ICSOFT | 3 |
| 2018 | The Gender Gap in Wikipedia Talk Pages
Benjamin Cabrera, Björn Ross, Marielle Dado, Maritta Heisel |
ICWSM | 4 |
| 2018 | At Your Own Risk: Shaping Privacy Heuristics for Online Self-disclosureabstractRevealing private and sensitive information on Social Network Sites (SNSs) like Facebook is a common practice which sometimes results in unwanted incidents for the users. One approach for helping users to avoid regrettable scenarios is through awareness mechanisms which inform a priori about the potential privacy risks of a self-disclosure act. Privacy heuristics are instruments which describe recurrent regrettable scenarios and can support the generation of privacy awareness. One important component of a heuristic is the group of people who should not access specific private information under a certain privacy risk. However, specifying an exhaustive list of unwanted recipients for a given regrettable scenario can be a tedious task which necessarily demands the user's intervention. In this paper, we introduce an approach based on decision trees to instantiate the audience component of privacy heuristics with minor intervention from the users. We introduce Disclosure- Acceptance Trees, a data structure representative of the audience component of a heuristic and describe a method for their generation out of user-centred privacy preferences. Nicolás E. Díaz Ferreyra, Rene Meis, Maritta Heisel |
PST | 3 |
| 2018 | Problem-based Derivation of Trustworthiness Requirements from Users' Trust ConcernsabstractThe trustworthiness of cyber-physical systems (CPS) that support complex collaborative business processes is an emergent property. New technologies like cloud computing bring new capabilities for hosting and offering complex collaborative business operations. However, these advances might introduce new vulnerabilities and threats caused by collaboration and data exchange over the Internet. Hence, users become more concerned about trust. In order to address users' trust concerns, trustworthiness requirements for the CPS must be elicited and satisfied. They describe the properties (qualities) the CPS must possess in order to be trustworthy. In this paper, we suggest a problem-based requirements engineering method that supports specifically the derivation of trustworthiness requirements. Based on identified trust concerns of users, trust assumptions are made explicit in problem diagrams. They express the conditions under which users are willing to trust. The problem diagrams and trust assumptions are then refined until they are concrete enough to derive trustworthiness requirements from them. During the refinement process, trust assumptions may influence and modify the system design (and vice versa, i.e., due to a certain system design, new trust concerns may arise that need to be addressed). In this way, users' trust concerns are considered right from the beginning and trustworthiness is designed into the CPS. An application example from the healthcare domain is used to demonstrate our approach. Nazila Gol Mohammadi, Nelufar Ulfat-Bunyadi, Maritta Heisel |
PST | 3 |
| 2018 | Trustworthiness Cases - Toward Preparation for the Trustworthiness Certification
Nazila Gol Mohammadi, Nelufar Ulfat-Bunyadi, Maritta Heisel |
TrustBus | 3 |
| 2017 | Online Self-disclosure: From Users' Regrets to Instructional Awareness
Nicolás E. Díaz Ferreyra, Rene Meis, Maritta Heisel |
CD-MAKE | 3 |
| 2017 | Towards Systematic Privacy and Operability (PRIOP) Studies
Rene Meis, Maritta Heisel |
SEC | 2 |
| 2017 | Pattern-Based Representation of Privacy Enhancing Technologies as Early Aspects
Rene Meis, Maritta Heisel |
TrustBus | 2 |
| 2016 | Addressing self-disclosure in social media: An instructional awareness approachabstractNowadays the information flowing across the different Social Network Sites (SNSs) like Facebook is highly diverse and rich in its content. It is precisely the diversity of the users' contributions to SNSs that makes these platforms attractive and interesting to engage with. Nevertheless, there is a high amount of private and sensitive information being disclosed permanently by these users in order to take full advantage of the services offered by such sites. Current privacy-protection approaches (like the one provided by Facebook) allow users to restrict the audience of their contributions and hide particular pieces of information; however, they are still far from being widely adopted and put proactively into practice. For this reason, we propose to analyze and address different aspects of online self-disclosure in Social Media from a pedagogical and self-adaptive perspective. In this work we introduce the architecture of an Instructional Awareness System (IAS) based on the MAPE-K blueprint for autonomic systems, and provide a definition of its feedback mechanism using principles of Constraint-Based Modeling (CBM). Nicolás E. Díaz Ferreyra, Johanna Schäwel, Maritta Heisel, Christian Meske |
AICCSA | 3 |
| 2016 | Understanding the Privacy Goal Intervenability
Rene Meis, Maritta Heisel |
TrustBus | 2 |
| 2016 | A Framework for Systematic Analysis and Modeling of Trustworthiness Requirements Using i* and BPMN
Nazila Gol Mohammadi, Maritta Heisel |
TrustBus | 2 |
| 2015 | A Structured Validation and Verification Method for Automotive Systems Considering the OEM/Supplier Interface
Kristian Beckers, Isabelle Côté, Thomas Frese, Denis Hatebur, Maritta Heisel |
SAFECOMP | 5 |
| 2015 | A Taxonomy of Requirements for the Privacy Goal Transparency
Rene Meis, Roman Wirtz, Maritta Heisel |
TrustBus | 3 |
| 2014 | A Structured Approach for Eliciting, Modeling, and Using Quality-Related Domain Knowledge
Azadeh Alebrahim, Maritta Heisel, Rene Meis |
ICCSA (5) | 2 |
| 2014 | Problem-Based Requirements Interaction Analysis
Azadeh Alebrahim, Stephan Faßbender, Maritta Heisel, Rene Meis |
REFSQ | 3 |
| 2014 | Systematic Derivation of Functional Safety Requirements for Automotive Systems
Kristian Beckers, Isabelle Côté, Thomas Frese, Denis Hatebur, Maritta Heisel |
SAFECOMP | 5 |
| 2014 | Privacy-Aware Cloud Deployment Scenario Selection
Kristian Beckers, Stephan Faßbender, Stefanos Gritzalis, Maritta Heisel, Christos Kalloniatis, Rene Meis |
TrustBus | 4 |
| 2013 | A Usability Evaluation of the NESSoS Common Body of KnowledgeabstractThe common body of knowledge (CBK) of the Network of Excellence on Engineering Secure Future Internet Software Services and Systems (NESSoS) is a ontology that contains knowledge objects (methods, tools, notations, etc.) for secure systems engineering. The CBK is intended to support one of the main goals of the NESSoS NoE, namely to create a long-lasting research community on engineering secure software services and systems and to bring together researchers and practitioners from security engineering, service computing, and software engineering. Hence, the usability of the CBK is of utmost importance to stimulate participations in the effort of collecting and distributing knowledge about secure systems engineering. This paper is devoted to identifying and ameliorating usability deficiencies in the initial version of the CBK and its current implementation in the SMW+ framework. We report on usability tests that we performed on the initial version of the CBK and the suggestions for improvement that resulted from the usability tests. We also show some exemplary solutions, which we already implemented. We discuss our experiences so that other researchers can benefit from them. Kristian Beckers, Maritta Heisel |
ARES | 2 |
| 2013 | Structured Pattern-Based Security Requirements Elicitation for CloudsabstractEconomic benefits make cloud computing systems a very attractive alternative to traditional IT-systems. However, numerous concerns about the security of cloud computing services exist. Potential cloud customers have to be confident that the cloud services they acquire are secure for them to use. Therefore, they have to have a clear set of security requirements covering their security needs. Eliciting these requirements is a difficult task, because of the amount of stakeholders and technical components to consider in a cloud environment. That is why we propose a structured, pattern-based method supporting eliciting security requirements. The method guides a potential cloud customer to model a cloud system via our cloud system analysis pattern. The instantiated pattern establishes the context of a cloud scenario. Then, the information of the instantiated pattern can be used to fill-out our textual security requirements patterns. The presented method is tool-supported. Our tool supports the instantiation of the cloud system analysis pattern and automatically transferes the information from the instance to the security requirements patterns. In addition, we have validation conditions that check e.g., if a security requirement refers to at least one element in the cloud. We illustrate our method using an online-banking system as running example. Kristian Beckers, Maritta Heisel, Isabelle Côté, Ludger Goeke, Selim Güler |
ARES | 2 |
| 2013 | A Problem-Based Threat Analysis in Compliance with Common CriteriaabstractIn order to gain their customers' trust, software vendors can certify their products according to security standards, e.g., the Common Criteria (ISO 15408). A Common Criteria certification requires a comprehensible documentation of the software product, including a detailed threat analysis. In our work, we focus on improving that threat analysis. Our method is based upon an attacker model, which considers attacker types like software attacker that threaten only specific parts of a system. We use OCL expressions to check if all attackers for a specific domain have been considered. For example, we propose a computer-aided method that checks if all software systems have either considered a software attacker or documented an assumption that excludes software attackers. Hence, we propose a structured method for threat analysis that considers the Common Criteria's (CC) demands for documentation of the system in its environment and the reasoning that all threats are discovered. We use UML4PF, a UML profile and support tool for Jackson's problem frame method and OCL for supporting security reasoning, validation of models, and also to generate Common Criteria-compliant documentation. Our threat analysis method can also be used for threat analysis without the common criteria, because it uses a specific part of the UML profile that can be adapted to other demands with little effort. We illustrate our approach with the development of a smart metering gateway system. Kristian Beckers, Denis Hatebur, Maritta Heisel |
ARES | 3 |
| 2013 | From Problems to Laws in Requirements Engineering - Using Model-Transformation
Stephan Faßbender, Maritta Heisel |
ICSOFT | 2 |
| 2013 | A structured and model-based hazard analysis and risk assessment method for automotive systemsabstractThe released ISO 26262 standard requires a hazard analysis and risk assessment for automotive systems to determine the necessary safety measures to be implemented for a certain feature. In this paper, we present a structured and model-based hazard analysis and risk assessment method for automotive systems. The hazard analysis and risk assessment are based on a requirements engineering process using problem frames. Their elements are represented by a UML notation extended with stereotypes. The UML model enables a rigorous validation of several constraints expressed in OCL. We illustrate our method using an electronic steering column lock system. Kristian Beckers, Maritta Heisel, Thomas Frese, Denis Hatebur |
ISSRE | 2 |
| 2013 | A pattern-based method for establishing a cloud-specific information security management system - Establishing information security management systems for clouds considering security, privacy, and legal compliance
Kristian Beckers, Isabelle Côté, Stephan Faßbender, Maritta Heisel, Stefan Hofbauer |
Requir. Eng. | 4 |
| 2013 | Erratum to: A pattern-based method for establishing a cloud-specific information security management system
Kristian Beckers, Isabelle Côté, Stephan Faßbender, Maritta Heisel, Stefan Hofbauer |
Requir. Eng. | 4 |
| 2012 | Using Security Requirements Engineering Approaches to Support ISO 27001 Information Security Management Systems Development and DocumentationabstractAn ISO 27001 compliant information security management system is difficult to create, due to the the limited support for system development and documentation provided in the standard. We present a structured analysis of the documentation and development requirements in the ISO 27001 standard. Moreover, we investigate to what extent existing security requirements engineering approaches fulfill these requirements. We developed relations between these approaches and the ISO 27001 standard using a conceptual framework originally developed for comparing security requirements engineering methods. The relations include comparisons of important terms, techniques, and documentation artifacts. In addition, we show practical applications of our results. Kristian Beckers, Stephan Faßbender, Maritta Heisel, Holger Schmidt 0001 |
ARES | 3 |
| 2012 | A Common Body of Knowledge for Engineering Secure Software and ServicesabstractThe discipline of engineering secure software and services brings together researchers and practitioners from software, services, and security engineering. This interdisciplinary community is fairly new, it is still not well integrated and is therefore confronted with differing perspectives, processes, methods, tools, vocabularies, and standards. We present a Common Body of Knowledge (CBK) to overcome the aforementioned problems. We capture use cases from research and practice to derive requirements for the CBK. Our CBK collects, integrates, and structures knowledge from the different disciplines based on an ontology that allows one to semantically enrich content to be able to query the CBK. The CBK heavily relies on user participation, making use of the Semantic MediaWiki as a platform to support collaborative writing. The ontology is complemented by a conceptual framework, consisting of concepts to structure the knowledge and to provide access to it, and a means to build a common terminology. We also present organizational factors covering dissemination and quality assurance. Widura Schwittek, Holger Schmidt 0001, Kristian Beckers, Stefan Eicker, Stephan Faßbender, Maritta Heisel |
ARES | 6 |
| 2011 | A Method to Derive Software Architectures from Quality RequirementsabstractWe present a model- and pattern-based method that allows software engineers to take quality requirements into account right from the beginning of the software development process. The method comprises requirements analysis as well as the derivation of a software architecture from requirements documents, in which quality requirements are reflected explicitly. For requirements analysis, we use an enhancement of the problem frame approach, where software development problems are represented by problem diagrams. The derivation of a software architecture starts from a set of problem diagrams, annotated with functional as well as quality requirements. First, we set up an initial software architecture, taking into account the decomposition of the overall software development problem into sub problems. Then, we incorporate quality requirements into that architecture by using security or performance patterns or mechanisms. The method is tool-supported, which allows developers to check semantic integrity conditions in the different models. Azadeh Alebrahim, Denis Hatebur, Maritta Heisel |
APSEC | 3 |
| 2011 | Towards Systematic Integration of Quality Requirements into Software Architecture
Azadeh Alebrahim, Denis Hatebur, Maritta Heisel |
ECSA | 3 |
| 2011 | Systematic Development of UMLsec Design Models Based on Security Requirements
Denis Hatebur, Maritta Heisel, Jan Jürjens, Holger Schmidt 0001 |
FASE | 2 |
| 2011 | UML4PF - A tool for problem-oriented requirements analysisabstractWe present UML4PF, a tool for requirements analysis based on problem frames. It consists of a UML profile and an Eclipse-Plugin to model and analyze problem diagrams, derive specifications, and develop architectures. Isabelle Côté, Maritta Heisel, Holger Schmidt 0001, Denis Hatebur |
RE | 2 |
| 2010 | Making Pattern- and Model-Based Software Development More Rigorous
Denis Hatebur, Maritta Heisel |
ICFEM | 2 |
| 2010 | A UML Profile for Requirements Analysis of Dependable Software
Denis Hatebur, Maritta Heisel |
SAFECOMP | 2 |
| 2010 | A comparison of security requirements engineering methods
Benjamin Fabian, Seda Gurses, Maritta Heisel, Thomas Santen, Holger Schmidt 0001 |
Requir. Eng. | 3 |
| 2009 | Problem-Oriented Documentation of Design Patterns
Alexander Fülleborn, Klaus Meffert, Maritta Heisel |
FASE | 3 |
| 2009 | A Foundation for Requirements Analysis of Dependable Software
Denis Hatebur, Maritta Heisel |
SAFECOMP | 2 |
| 2008 | Analysis and Component-based Realization of Security RequirementsabstractWe present a process to develop secure software with an extensive pattern-based security requirements engineering phase. It supports identifying and analyzing conflicts between different security requirements. In the design phase, we proceed by selecting security software components that achieve security requirements. The process enables software developers to systematically identify, analyze, and finally realize security requirements using security software components. We illustrate our approach by a lawyer agency software example. Denis Hatebur, Maritta Heisel, Holger Schmidt 0001 |
ARES | 2 |
| 2008 | A Formal Metamodel for Problem Frames
Denis Hatebur, Maritta Heisel, Holger Schmidt 0001 |
MoDELS | 2 |
| 2007 | A Pattern System for Security Requirements EngineeringabstractWe present a pattern system/or security requirements engineering, consisting of security problem frames and concretized security problem frames. These are special kinds of problem frames that serve to structure, characterize, analyze, and finally solve software development problems in the area of software and system security. We equip each frame with formal preconditions and postconditions. The analysis of these conditions results in a pattern system that explicitly shows the dependencies between the different frames. Moreover, we indicate related frames, which are commonly used together with the considered frame. Hence, our approach helps security engineers to avoid omissions and to cover all security requirements that are relevant for a given problem Denis Hatebur, Maritta Heisel, Holger Schmidt 0001 |
ARES | 2 |
| 2007 | Pattern-Based Evolution of Software Architectures
Isabelle Côté, Maritta Heisel, Ina Wentzlaff |
ECSA | 2 |
| 2007 | Pattern-Based Exploration of Design Alternatives for the Evolution of Software ArchitecturesabstractWe propose a pattern-based software development method comprising analysis (using problem frames) and design (using architectural and design patterns), from which especially evolving systems benefit. Evolution operators guide a pattern-based transformation procedure, including re-engineering tasks for adjusting a given software architecture to meet new system demands. Through application of these operators, relations between analysis and design documents are explored systematically for accomplishing desired software modifications. This allows for reusing development documents to a large extent, even when the application environment and the requirements change. Isabelle Côté, Maritta Heisel, Ina Wentzlaff |
Int. J. Cooperative Inf. Syst. | 2 |
| 2006 | Component composition through architectural patterns for problem framesabstractIn this paper, we present a pattern-based software development process using problem frames and corresponding architectural patterns. In decomposing a complex problem into simple subproblems, the relationships between the sub-problems are recorded explicitly. Based on this information, we give guidelines on how to derive the software architecture for the overall problem from the software architectures of the simple subproblems. Christine Choppy, Denis Hatebur, Maritta Heisel |
APSEC | 3 |
| 2005 | Problem Frames and Architectures for Security Problems
Denis Hatebur, Maritta Heisel |
SAFECOMP | 2 |
| 2002 | Confidentiality-Preserving Refinement is Compositional - Sometimes
Thomas Santen, Maritta Heisel, Andreas Pfitzmann |
ESORICS | 2 |
| 2002 | Toward a Formal Model of Software Components
Maritta Heisel, Thomas Santen, Jeanine Souquières |
ICFEM | 1 |
| 2002 | A Problem-Oriented Approach to Common Criteria Certification
Thomas Rottke, Denis Hatebur, Maritta Heisel, Monika Heiner |
SAFECOMP | 3 |
| 2001 | Confidentiality-Preserving RefinementabstractAbstract: We develop a condition for confidentiality-preserving refinement which is both necessary and sufficient. Using a slight extension of CSP as notation, we give a toy example to illustrate the usefulness of our condition. Systems are specified by their behavior and a window. For an abstract system, the window specifies what information is allowed to be observed by its environment. For a concrete system, the window specifies what information cannot be hidden from its environment. A concrete system is a confidentiality-preserving refinement of an abstract system, if it behaviorally refines the abstract system and if the information revealed by the concrete window is allowed to be revealed according to the abstract window. Maritta Heisel, Andreas Pfitzmann, Thomas Santen |
CSFW | 1 |
| 2001 | Specifying embedded systems with statecharts and Z: an agenda for cyclic software components
Wolfgang Grieskamp, Maritta Heisel, Heiko Dörr |
Sci. Comput. Program. | 2 |
| 1999 | A Method for Requirements Elicitation and Formal Specification
Maritta Heisel, Jeanine Souquières |
ER | 1 |
| 1999 | Modeling Safety-Critical Systems with Z and Petri Nets
Monika Heiner, Maritta Heisel |
SAFECOMP | 2 |
| 1998 | Specifying Embedded Systems with Staecharts and Z: An Agenda for Cyclic Software Components
Wolfgang Grieskamp, Maritta Heisel, Heiko Dörr |
FASE | 2 |
| 1998 | An Agenda for Specifying Software Components with Complex Data Models
Kirsten Winter, Thomas Santen, Maritta Heisel |
SAFECOMP | 3 |
| 1997 | Methodological Support for Formally Specifying Safety-Critical Software
Maritta Heisel, Carsten Siihl |
SAFECOMP | 1 |
| 1996 | Formal Specification of Safety-Critical Software with Z and Real-Time CSP
Maritta Heisel, Carsten Sühl |
SAFECOMP | 1 |
| 1995 | Six Steps Towards Provably Safe Software
Maritta Heisel |
SAFECOMP | 1 |
| 1992 | Formalizing and Implementing Gries' Program Development Method in Dynamic Logic
Maritta Heisel |
Sci. Comput. Program. | 1 |
| 1990 | Tactical Theorem Proving in Program Verification
Maritta Heisel, Wolfgang Reif, Werner Stephan 0001 |
CADE | 1 |
| 1988 | Implementing Verification Strategies in the KIV-System
Maritta Heisel, Wolfgang Reif, Werner Stephan 0001 |
CADE | 1 |
| 1986 | An Interactive Verification System Based on Dynamic Logic
Reiner Hähnle, Maritta Heisel, Wolfgang Reif, Werner Stephan 0001 |
CADE | 2 |