EDBT 2026 Demo / reviewers in the wild / expert
Günther Pernul
dblp:p/GPernul
· DBLP profile ↗
114ranked-venue papers
15as first author
35since 2021 · last 2026
0000-0003-1338-9003ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 90 · 9 first-author · 30 since 2021Databases, data management, data science and information retrieval · 16 · 6 first-author · 1 since 2021Artificial intelligence and machine learning · 9 · 3 first-authorHuman-computer interaction and ubiquitous computing · 4 · 4 since 2021Computer networks · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | T1GER: An Instructional Re-Design of a Cyber Range Exercise in a Commercial Security Operations Center
Magdalena Glas, Leon Kersten, Tom Mulders, Günther Pernul, Luca Allodi |
CHI | 4 |
| 2026 | Moving Beyond Passwords: Investigating the Effect of Digital Nudges on Passkey AdoptionabstractPasswords suffer from major usability hurdles that foster insecure practices and undermine cybersecurity. Passkeys were introduced to address these issues, however, adoption remains low. Digital nudges offer a promising way to accelerate passkey adoption, yet research lacks empirical insight about when to nudge and which nudge types and designs are most effective. We therefore employed a mixed-methods approach to examine the impact of nudges on passkey adoption across five touchpoints in the digital user journey: During registration, login, account recovery, while in the settings menu, and during user activity. First, we conducted 15 expert interviews to identify candidate nudges and their design principles. We evaluate these nudges in a randomized controlled trial (RCT) with 3,680 participants on a commercial healthcare platform. Our results indicate that digital nudges can significantly increase passkey adoption when applied at the right touchpoints, encouraging users to move beyond passwords. Tobias Reittinger, Magdalena Glas, Günther Pernul |
CHI | 3 |
| 2026 | In Sync or Sink? About Tactical Divides Between Attackers and Defenders
Johannes Grill, Daniel Oberhofer, Philip Empl, Stefan Schönig, Günther Pernul |
DBSec | 5 |
| 2026 | Formalizing Access Requests in IAM: Beyond Roles and Permissions
Alexander Puchta, Sebastian Groll, Günther Pernul |
DBSec | 3 |
| 2026 | No Password, No Problem? A Large-Scale Field Study of Passkey Adoption and Usage
Tobias Reittinger, Günther Pernul |
SP | 2 |
| 2025 | Transaction Logs in Access Control: Leveraging an Under-Utilized Data Source
Sascha Kern, Thomas Baumer, Raphael Neudert, Günther Pernul |
DBSec | 4 |
| 2024 | A Trust and Reputation System for Examining Compliance with Access ControlabstractTrust is crucial when a truster allows a trustee to carry out desired services. Regulatory authorities thus set requirements for organizations under their jurisdiction to ensure a basic trust level. Trusted auditors periodically verify the auditee’s compliance with these requirements. However, the quality of the auditees’ compliance and the auditors’ verification performance often remain unclear and unavailable to the public. In this work, we examine the regulations of Identity and Access Management (IAM) and identify typical patterns. We enhance these patterns to include trust measurements for the auditee providing services and the auditors verifying compliance. We demonstrate the feasibility of this approach for an application utilizing decentralized blockchain technologies and discuss the implications, potential, and benefits of this architecture. Thomas Baumer, Johannes Grill, Jacob Adan, Günther Pernul |
ARES | 4 |
| 2024 | Sustainability in Digital ForensicsabstractSustainability has become a crucial aspect of modern society and research. The emerging fusion of digital spaces with societal functions highlights the importance of sustainability. With digital technologies becoming essential, cybersecurity and digital forensics are gaining prominence. While cybersecurity’s role in sustainability is recognized, sustainable practices in digital forensics are still in their early stages. This paper presents a holistic view of innovative approaches for the sustainable design and management of digital forensics concerning people, processes, and technology. It outlines how these aspects contribute to sustainability, which aligns with the core principles of economic viability, social equity, and environmental responsibility. As a result, this approach provides novel perspectives on the development of sustainability in the field of digital forensics. Sabrina Friedl, Charlotte Zajewski, Günther Pernul |
ARES | 3 |
| 2024 | A Framework for Managing Separation of Duty PoliciesabstractSeparation of Duty (SoD) is a fundamental principle in information security. Especially large and highly regulated companies have to manage a huge number of SoD policies. These policies need to be maintained in an ongoing effort in order to remain accurate and compliant with regulatory requirements. In this work we develop a framework for managing SoD policies that pays particular attention to policy comprehensibility. We conducted seven semi-structured interviews with SoD practitioners from large organizations in order to understand the requirements for managing and maintaining SoD policies. Drawing from the obtained insights, we developed a framework, which includes the relevant stakeholders and tasks, as well as a policy structure that aims to simplify policy maintenance. We anchor the proposed policy structure in a generic IAM data model to ensure compatibility and flexibility with other IAM models. We then show exemplary how our approach can be enforced within Role-Based Access Control. Finally, we evaluate the proposed framework with a real-world IAM data set provided by a large finance company. Sebastian Groll, Sascha Kern, Ludwig Fuchs, Günther Pernul |
ARES | 4 |
| 2024 | Elevating TARA: A Maturity Model for Automotive Threat Analysis and Risk AssessmentabstractThe importance of automotive cybersecurity is increasing in tandem with the evolution of more complex vehicles, fueled by trends like V2X or over-the-air updates. Regulatory bodies are trying to cope with this problem with the introduction of ISO 21434, which standardizes automotive cybersecurity engineering. One piece of the puzzle for compliant cybersecurity engineering is the creation of a TARA (Threat Analysis and Risk Assessment) for identifying and managing cybersecurity risks. The more time security experts invest in creating a TARA, the more detailed and mature it becomes. Thus, organizations must balance the benefits of a more mature TARA against the costs and resources required to achieve it. However, there is a lack of guidance on determining the appropriate level of effort. In this paper, we propose a data-driven maturity model as a management utility facilitating the decision on the maturity-cost trade-off for creating TARAs. To evaluate the model, we conducted interviews with seven automotive cybersecurity experts from the industry. Manfred Vielberth, Kristina Raab, Magdalena Glas, Patrick Grümer, Günther Pernul |
ARES | 5 |
| 2024 | Process-Aware Intrusion Detection in MQTT NetworksabstractIntrusion Detection Systems (IDS) allow for detecting malicious activities in organizational networks and hosts. As the Industrial Internet of Things (Industrial IoT) has gained momentum and attackers become process-aware, it elevates the focus on anomaly-based Network Intrusion Detection Systems (NIDS) in IoT. While previous research has primarily concentrated on fortifying SCADA systems with NIDS, keeping track of the latest advancements in resource-efficient messaging (e.g., MQTT, CoAP, and OPC-UA) is paramount. In our work, we straightforwardly derive IoT processes for NIDS using distributed tracing and process mining. We introduce a pioneering framework called MISSION which effectively captures, consolidates, and models MQTT flows, leading to a heightened process awareness in NIDS. Through our prototypical implementation, we demonstrate exceptional performance and high-quality models. Moreover, our experiments provide empirical evidence for rediscovering pre-defined processes and successfully detecting two distinct MQTT attacks in a simulated IoT network. Philip Empl, Fabian Böhm, Günther Pernul |
CODASPY | 3 |
| 2024 | From Play to Profession: A Serious Game to Raise Awareness on Digital Forensics
Sabrina Friedl, Tobias Reittinger, Günther Pernul |
DBSec | 3 |
| 2024 | IAM Meets CTI: Make Identity and Access Management Ready for Cyber Threat Intelligence
Alexander Puchta, Thomas Baumer, Mathis Müller, Günther Pernul |
DBSec | 4 |
| 2024 | Do You Play It by the Books? A Study on Incident Response Playbooks and Influencing FactorsabstractIncident response "playbooks" are structured sets of operational procedures organizations use to instruct humans or machines on performing countermeasures against cybersecurity threats. These playbooks generally combine information about a given threat and organizational aspects relevant within the context of an organization. Both types of information are crucial for using, maintaining, and sharing playbooks across organizations as they ensure effectiveness and confidentiality. While practitioners show great interest in playbooks, their characteristics have not yet been thoroughly investigated from a research perspective. For this reason, we explore the topic by analyzing what is inside a playbook. Our approach consists of a comprehensive empirical assessment of available data (1217 playbooks), an online study with 147 participants, and final in-depth interviews with nine security professionals to consolidate and validate our findings. We notably find intrinsic ambiguities in the way practitioners and organizations define their playbooks. Furthermore, we notice that available playbooks cannot be used outright which might currently impair their wide use across different cybersecurity actors. As a result, we can conclude that organizations do "play it by the books" but individually define what is inside their playbooks and which areas of incident response they might address. Daniel Schlette, Philip Empl, Marco Caselli, Thomas Schreck, Günther Pernul |
SP | 5 |
| 2024 | Complex yet attainable? An interdisciplinary approach to designing better cyber range exercisesabstractThe global shortage of cybersecurity professionals poses a daunting challenge for organizations seeking to protect their assets and data. To counteract this workforce shortage, cyber range exercises (CRXs) can equip individuals with the necessary knowledge and skills to become security professionals. However, the complexity of CRXs tends to overwhelm trainees with little prior cybersecurity experience, resulting in ineffective learning experiences. To address this issue, we take an interdisciplinary approach, leveraging established models on learning and motivation for cybersecurity. In this pursuit, we propose a literature-based framework of six design principles that aim to facilitate CRX designers in creating more effective CRXs. To illustrate the framework’s utility, we introduce a CRX for incident response built upon these principles. To evaluate the effectiveness of this principle-driven CRX design, we conducted a user study with N=89 participants. The results of this study showed that the design provided an engaging learning experience that enabled participants to effectively acquire incident response knowledge and skills. Magdalena Glas, Gerhard Messmann, Günther Pernul |
Comput. Secur. | 3 |
| 2023 | Train as you Fight: Evaluating Authentic Cybersecurity Training in Cyber RangesabstractHumans can play a decisive role in detecting and mitigating cyber attacks if they possess sufficient cybersecurity skills and knowledge. Realizing this potential requires effective cybersecurity training. Cyber range exercises (CRXs) represent a novel form of cybersecurity training in which trainees can experience realistic cyber attacks in authentic environments. Although evaluation is undeniably essential for any learning environment, it has been widely neglected in CRX research. Addressing this issue, we propose a taxonomy-based framework to facilitate a comprehensive and structured evaluation of CRXs. To demonstrate the applicability and potential of the framework, we instantiate it to evaluate Iceberg CRX, a training we recently developed to improve cybersecurity education at our university. For this matter, we conducted a user study with 50 students to identify both strengths and weaknesses of the CRX. Magdalena Glas, Manfred Vielberth, Günther Pernul |
CHI | 3 |
| 2023 | Digital Twins for IoT Security Management
Philip Empl, Henric Hager, Günther Pernul |
DBSec | 3 |
| 2023 | Maintain High-Quality Access Control Policies: An Academic and Practice-Driven Approach
Sascha Kern, Thomas Baumer, Ludwig Fuchs, Günther Pernul |
DBSec | 4 |
| 2023 | Improving cybersecurity skill development through visual programmingabstractPurpose Cybersecurity training plays a decisive role in overcoming the global shortage of cybersecurity experts and the risks this shortage poses to organizations' assets. Seeking to make the training of those experts as efficacious and efficient as possible, this study investigates the potential of visual programming languages (VPLs) for training in cyber ranges. For this matter, the VPL Blockly was integrated into an existing cyber range training to facilitate learning a code-based cybersecurity task, namely, creating code-based correlation rules for a security information and event management (SIEM) system. Design/methodology/approach To evaluate the VPL’s effect on the cyber range training, the authors conducted a user study as a randomized controlled trial with 30 participants. In this study, the authors compared skill development of participants creating SIEM rules using Blockly (experimental group) with participants using a textual programming approach (control group) to create the rules. Findings This study indicates that using a VPL in a cybersecurity training can improve the participants' perceived learning experience compared to the control group while providing equally good learning outcomes. Originality/value The originality of this work lies in studying the effect of using a VPL to learn a code-based cybersecurity task. Investigating this effect in comparison with the conventional textual syntax through a randomized controlled trial has not been investigated yet. Magdalena Glas, Manfred Vielberth, Tobias Reittinger, Fabian Böhm, Günther Pernul |
Inf. Comput. Secur. | 5 |
| 2022 | SOAR4IoT: Securing IoT Assets with Digital TwinsabstractAs more and more security tools provide organizations with cybersecurity capabilities, security analysts are overwhelmed by security events. Resolving these events is challenging due to extensive manual processes, limited financial resources, and human errors. Security Orchestration, Automation, and Response (SOAR) is an established approach to manage security tools and assets. However, SOAR platforms typically integrate traditional IT systems only. Additional considerations are required to deal with the Internet of Things (IoT), its multiple devices and complex networks. Therefore, we adapt SOAR to IoT. We first aggregate existing research and information on SOAR and SOAR platforms. We envision the SOAR4IoT framework, making IoT assets manageable for SOAR via middleware. We implement a prototypical digital twin-based SOAR application integrating IoT assets and security tools to validate our framework. The experimental setup includes two playbooks coping with Mirai and Sybil attacks. Results show feasibility as our SOAR application enables securing IoT assets with digital twins. Philip Empl, Daniel Schlette, Daniel Zupfer, Günther Pernul |
ARES | 4 |
| 2022 | BISCUIT - Blockchain Security Incident Reporting based on Human ObservationsabstractSecurity incidents in blockchain-based systems are frequent nowadays, which calls for more structured efforts in incident reporting and response. To improve the current status quo of reporting incidents on blogs and social media, we propose a decentralized incident reporting and discussion system. Our approach guides users (security novices) towards a classification of their observations using a tiered taxonomy of blockchain incidents. Questions based on previous incidents interactively support the classification. Post submission a security incident response committee then discusses these observations on our decentralized platform to decide on an appropriate response. For evaluation, we implement our model as a decentralized application and demonstrate its practical suitability in a preliminary user study. Benedikt Putz, Manfred Vielberth, Günther Pernul |
ARES | 3 |
| 2022 | Harnessing Digital Twin Security Simulations for systematic Cyber Threat IntelligenceabstractUnderstanding cybersecurity threats, attacks, and incidents is crucial for organizations to perform preventive or re-active measures. Nevertheless, detailed Cyber Threat Intelligence (CTI) is reluctantly shared. Digital twins, the virtual counterparts of real-world assets, offer security simulation capabilities. The simulation of attack scenarios on industrial control systems (ICS) with digital twins yields valuable threat information. In our work, we outline the systematic steps towards a structured threat report starting with digital twin security simulations: We first present the course of action and define formal requirements for framework deployment. We then conduct an attack simulation with a prototypical digital twin application to evaluate our frame-work. Using the STIX2.1 standard, we assist CTI generation by providing utility tools guiding through the process steps. Our experimental results show that a STIX2.1 CTI report can be systematically constructed with the opportunity to customize according to the use case at hand. Adding digital twin security simulations to the list of CTI sources can provide shareable CTI and help organizations improve their security posture. Marietheres Dietz, Daniel Schlette, Günther Pernul |
COMPSAC | 3 |
| 2022 | Security Operations Center Roles and Skills: A Comparison of Theory and Practice
Andreas Reisser, Manfred Vielberth, Sofia Fohringer, Günther Pernul |
DBSec | 4 |
| 2022 | Optimization of Access Control PoliciesabstractOrganizations undertake complex and costly projects to model high-quality Access Control Policies (ACPs). Once built, these policies must be maintained and managed in an ongoing process to keep their quality high. Insufficient maintenance leads to inaccurate authorization decisions and increases the policies’ administrative effort and susceptibility to errors. While the initial modeling of ACPs has received significant research interest, their optimization is not yet covered as broadly. This work provides a theoretical foundation for ACP quality and its optimization. Furthermore, it analyzes how existing research addresses optimization of ACPs with regard to six crucial optimization dimensions. It presents a structured literature survey tracing these optimization dimensions, the contributed research artifact and data requirements. Building on this literature catalogue, this work elaborates on inaccuracies for user permission assignments, data availability, minimal perturbation and recommendation-based optimization. Sascha Kern, Thomas Baumer, Sebastian Groll, Ludwig Fuchs, Günther Pernul |
J. Inf. Secur. Appl. | 5 |
| 2021 | A Digital Twin-Based Cyber Range for SOC Analysts
Manfred Vielberth, Magdalena Glas, Marietheres Dietz, Stylianos Karagiannis, Emmanouil Magkos, Günther Pernul |
DBSec | 6 |
| 2021 | Bridging Knowledge Gaps in Security AnalyticsabstractIn a cyber-physical world, the number of links between corporate assets is growing and infrastructures are becoming more complex. This and related developments significantly enlarge the attack surface of organizations. Additionally, more and more attacks do not exploit technical vulnerabilities directly but gain a foothold through phishing or social engineering. Since traditional security systems prove to be no longer sufficient to detect incidents effectively, humans and their specialized knowledge are becoming a critical security factor. Therefore, it is vital to maintain an overview of the cybersecurity knowledge spread across the entire company. However, there is no uniform understanding of knowledge in the field of security analytics. We aim to close this gap by formalizing knowledge and defining a conceptual knowledge model in the context of security analytics. This allows existing research to be better classified and shows that individual areas offer much potential for future r esearch. In particular, the collaboration between domain experts but also between machines and employees could enable the exploitation of previously unused but crucial knowledge. For example, this knowledge is of great value for defining security rules in current security analytics systems. We introduce a proof of concept implementation using visual programming to showcase how even security novices can easily contribute their knowledge to security analytics. Fabian Böhm, Manfred Vielberth, Günther Pernul |
ICISSP | 3 |
| 2021 | Leveraging Dynamic Information for Identity and Access Management: An Extension of Current Enterprise IAM Architecture
Alexander Puchta, Sebastian Groll, Günther Pernul |
ICISSP | 3 |
| 2021 | Enhancing Industrial Control System Forensics Using Replication-Based Digital Twins
Marietheres Dietz, Ludwig Englbrecht, Günther Pernul |
IFIP Int. Conf. Digital Forensics | 3 |
| 2021 | HyperSec: Visual Analytics for Blockchain Security Monitoring
Benedikt Putz, Fabian Böhm, Günther Pernul |
SEC | 3 |
| 2021 | Monitoring Access Reviews by Crowd Labelling
Sebastian Groll, Sascha Kern, Ludwig Fuchs, Günther Pernul |
TrustBus | 4 |
| 2021 | Visual Decision-Support for Live Digital ForensicsabstractPerforming a live digital forensics investigation on a running system is challenging due to the time pressure under which decisions have to be made. Newly proliferating and frequently applied types of malware (e.g., fileless malware) increase the need to conduct digital forensic investigations in real-time. In the course of these investigations, forensic experts are confronted with a wide range of different forensic tools. The decision, which of those are suitable for the current situation, is often based on the cyber forensics experts’ experience. Currently, there is no reliable automated solution to support this decision-making. Therefore, we derive requirements for visually supporting the decision-making process for live forensic investigations and introduce a research prototype that provides visual guidance for cyber forensic experts during a live digital forensics investigation. Our prototype collects relevant core information for live digital forensics and provides visual representations for connections between occurring events, developments over time, and detailed information on specific events. To show the applicability of our approach, we analyze an exemplary use case using the prototype and demonstrate the support through our approach. Fabian Böhm, Ludwig Englbrecht, Sabrina Friedl, Günther Pernul |
VizSec | 4 |
| 2021 | Towards GDPR-compliant data processing in modern SIEM systems
Florian Menges, Tobias Latzo, Manfred Vielberth, Sabine Sobola, Henrich Christopher Pöhls, Benjamin Taubmann, Johannes Köstler, Alexander Puchta, Felix C. Freiling, Hans P. Reiser, Günther Pernul |
Comput. Secur. | 11 |
| 2021 | CTI-SOC2M2 - The quest for mature, intelligence-driven security operations and incident response capabilities
Daniel Schlette, Manfred Vielberth, Günther Pernul |
Comput. Secur. | 3 |
| 2021 | Improving data quality for human-as-a-security-sensor. A process driven quality improvement approach for user-provided incident informationabstractPurpose In the past, people were usually seen as the weakest link in the IT security chain. However, this view has changed in recent years and people are no longer seen only as a problem, but also as part of the solution. In research, this change is reflected in the fact that people are enabled to report security incidents that they have detected. During this reporting process, however, it is important to ensure that the reports are submitted with the highest possible data quality. This paper aims to provide a process-driven quality improvement approach for human-as-a-security-sensor information. Design/methodology/approach This work builds upon existing approaches for structured reporting of security incidents. In the first step, relevant data quality dimensions and influencing factors are defined. Based on this, an approach for quality improvement is proposed. To demonstrate the feasibility of the approach, it is prototypically implemented and evaluated using an exemplary use case. Findings In this paper, a process-driven approach is proposed, which allows improving the data quality by analyzing the similarity of incidents. It is shown that this approach is feasible and leads to better data quality with real-world data. Originality/value The originality of the approach lies in the fact that data quality is already improved during the reporting of an incident. In addition, approaches from other areas, such as recommender systems, are applied innovatively to the area of the human-as-a-security-sensor. Manfred Vielberth, Ludwig Englbrecht, Günther Pernul |
Inf. Comput. Secur. | 3 |
| 2021 | EtherTwin: Blockchain-based Secure Digital Twin Information Management
Benedikt Putz, Marietheres Dietz, Philip Empl, Günther Pernul |
Inf. Process. Manag. | 4 |
| 2020 | Integrating digital twin security simulations in the security operations centerabstractWhile industrial environments are increasingly equipped with sensors and integrated to enterprise networks, current security strategies are generally not prepared for the growing attack surface that resides from the convergence of their IT infrastructure with the industrial systems. As a result, the organizations responsible for corporate security, the Security Operations Center (SOC), are overwhelmed with the integration of the industrial systems. Marietheres Dietz, Manfred Vielberth, Günther Pernul |
ARES | 3 |
| 2020 | A privacy-aware digital forensics investigation in enterprisesabstractStricter policies, laws and regulations for companies on the handling of private information arise challenges in the handling of data for Digital Forensics investigations. This paper describes an approach that can meet necessary requirements to conduct a privacy-aware Digital Forensics investigation in an enterprise. The core of our approach is an entropy-based identification algorithm to detect specific patterns within files that can indicate non-private information. Files containing sensitive information are excluded systematically. This privacy preserving method can be integrated into a Digital Forensics examination process to prepare an image which is free from private as well as critical information for the investigation. The approach demonstrates that investigations in enterprises can be supported and improved by adapting existing algorithms and processes from related subject areas to implement privacy preserving measures into an investigation process. Ludwig Englbrecht, Günther Pernul |
ARES | 2 |
| 2020 | Designing a Decision-Support Visualization for Live Digital Forensic Investigations
Fabian Böhm, Ludwig Englbrecht, Günther Pernul |
DBSec | 3 |
| 2020 | Security Enumerations for Cyber-Physical Systems
Daniel Schlette, Florian Menges, Thomas Baumer, Günther Pernul |
DBSec | 4 |
| 2020 | SSIBAC: Self-Sovereign Identity Based Access ControlabstractIneffective data management practices pose serious issues to individuals and companies, e.g., risk of identity theft and online exposure. Self-sovereign identity (SSI) is a new identity management approach that ensures users have full control of their personal data. In this work, we alleviate data breach and user privacy problems by showing how SSI can fit within the context of established enterprise identity and access management technologies. In light of recent endeavors, we explore the use of decentralized identifiers, verifiable credentials, and blockchains that support SSI. We propose Self-Sovereign Identity Based Access Control (SSIBAC), an access control model for cross-organization identity management. SSIBAC leverages conventional access control models and blockchain technology to provide decentralized authentication, followed by centralized authorization. The access control process does not require storing user sensitive data. A prototype was implemented and evaluated, processing 55,000 access control requests per second with a latency of 3 seconds. Rafael Belchior, Benedikt Putz, Günther Pernul, Miguel Correia 0001, André Vasconcelos 0001, Sérgio Guerreiro 0001 |
TrustCom | 3 |
| 2020 | A Serious Game-Based Peer-Instruction Digital Forensics Workshop
Ludwig Englbrecht, Günther Pernul |
WISE | 2 |
| 2020 | Towards a capability maturity model for digital forensic readiness
Ludwig Englbrecht, Stefan Meier, Günther Pernul |
Wirel. Networks | 3 |
| 2019 | Enhancing credibility of digital evidence through provenance-based incident response handlingabstractDigital forensics are becoming increasingly important for the investigation of computer-related crimes, white-collar crimes and massive hacker attacks. After an incident has been detected an appropriate incident response is usually initiated with the aim to mitigate the attack and ensure the recovery of the IT systems. Digital Forensics pursues the goal of acquiring evidence that will stand up in court for sentencing and sometimes opposes contradicting objectives of incident response approaches. The concept presented here provides a solution to strengthen the credibility of digital evidence during actions related to incident response. It adapts an approach for data provenance to accurately track the transformation of digital evidence. For this purpose, the affected system and the incident response systems are equipped with a whole system data provenance capturing mechanism and then data provenance is captured simultaneously during an incident response. Context information about the incident response is also documented. An adapted algorithm for sub-graph detection is used to identify similarities between two provenance graphs. By applying the proposed concept to a use case, the advantages are demonstrated and possibilities for further development are presented. Ludwig Englbrecht, Gregor Langner, Günther Pernul, Gerald Quirchmayr |
ARES | 3 |
| 2019 | A Distributed Ledger Approach to Digital Twin Secure Data Sharing
Marietheres Dietz, Benedikt Putz, Günther Pernul |
DBSec | 3 |
| 2019 | Contributing to Current Challenges in Identity and Access Management with Visual Analytics
Alexander Puchta, Fabian Böhm, Günther Pernul |
DBSec | 3 |
| 2019 | Unifying Cyber Threat Intelligence
Florian Menges, Christine Sperl, Günther Pernul |
TrustBus | 3 |
| 2019 | A secure and auditable logging infrastructure based on a permissioned blockchain
Benedikt Putz, Florian Menges, Günther Pernul |
Comput. Secur. | 3 |
| 2019 | Human-as-a-security-sensor for harvesting threat intelligenceabstractAbstract Humans are commonly seen as the weakest link in corporate information security. This led to a lot of effort being put into security training and awareness campaigns, which resulted in employees being less likely the target of successful attacks. Existing approaches, however, do not tap the full potential that can be gained through these campaigns. On the one hand, human perception offers an additional source of contextual information for detected incidents, on the other hand it serves as information source for incidents that may not be detectable by automated procedures. These approaches only allow a text-based reporting of basic incident information. A structured recording of human delivered information that also provides compatibility with existing SIEM systems is still missing. In this work, we propose an approach, which allows humans to systematically report perceived anomalies or incidents in a structured way. Our approach furthermore supports the integration of such reports into analytics systems. Thereby, we identify connecting points to SIEM systems, develop a taxonomy for structuring elements reportable by humans acting as a security sensor and develop a structured data format to record data delivered by humans. A prototypical human-as-a-security-sensor wizard applied to a real-world use-case shows our proof of concept. Manfred Vielberth, Florian Menges, Günther Pernul |
Cybersecur. | 3 |
| 2019 | Attribute quality management for dynamic identity and access management
Michael Kunz, Alexander Puchta, Sebastian Groll, Ludwig Fuchs, Günther Pernul |
J. Inf. Secur. Appl. | 5 |
| 2018 | Big Log Data Stream Processing: Adapting an Anomaly Detection Technique
Marietheres Dietz, Günther Pernul |
DEXA (2) | 2 |
| 2018 | Measuring Identity and Access Management Performance - An Expert Survey on Possible Performance Indicators
Matthias Hummer, Sebastian Groll, Michael Kunz, Ludwig Fuchs, Günther Pernul |
ICISSP | 5 |
| 2018 | A comparative analysis of incident reporting formats
Florian Menges, Günther Pernul |
Comput. Secur. | 2 |
| 2018 | Graph-based visual analytics for cyber threat intelligenceabstractThe ever-increasing amount of major security incidents has led to an emerging interest in cooperative approaches to encounter cyber threats. To enable cooperation in detecting and preventing attacks it is an inevitable necessity to have structured and standardized formats to describe an incident. Corresponding formats are complex and of an extensive nature as they are often designed for automated processing and exchange. These characteristics hamper the readability and, therefore, prevent humans from understanding the documented incident. This is a major problem since the success and effectiveness of any security measure rely heavily on the contribution of security experts. To meet these shortcomings we propose a visual analytics concept enabling security experts to analyze and enrich semi-structured cyber threat intelligence information. Our approach combines an innovative way of persisting this data with an interactive visualization component to analyze and edit the threat information. We demonstrate the feasibility of our concept using the Structured Threat Information eXpression, the state-of-the-art format for reporting cyber security issues. Fabian Böhm, Florian Menges, Günther Pernul |
Cybersecur. | 3 |
| 2018 | State of the art of reputation-enhanced recommender systemsabstractRecommender systems are pivotal components of modern Internet platforms and constitute a well-established research field. By now, research has resulted in highly sophisticated recommender algorithms whose further optimization often yields only marginal improvements. This paper goes beyond the commo nly dominating focus on optimizing algorithms and instead follows the idea of enhancing recommender systems with reputation data. Since the concept of reputation-enhanced recommender systems has attracted considerable attention in recent years, the main aim of the paper is to provide a comprehensive survey of the approaches proposed so far. To this end, existing work is identified by means of a systematic literature review and classified according to seven carefully considered dimensions. In addition, the resulting structured analysis of the state of the art serves as a basis for the deduction and discussion of several future research directions. Christian Richthammer, Michael Weber 0010, Günther Pernul |
Web Intell. | 3 |
| 2016 | Adaptive identity and access management - contextual data based policiesabstractDue to compliance and IT security requirements, company-wide identity and access management within organizations has gained significant importance in research and practice over the last years. Companies aim at standardizing user management policies in order to reduce administrative overhead and strengthen IT security. These policies provide the foundation for every identity and access management system no matter if poured into IT systems or only located within responsible identity and access management (IAM) engineers’ mind. Despite its relevance, hardly any supportive means for the automated detection and refinement as well as management of policies are available. As a result, policies outdate over time, leading to security vulnerabilities and inefficiencies. Existing research mainly focuses on policy detection and enforcement without providing the required guidance for policy management nor necessary instruments to enable policy adaptibility for today’s dynamic IAM. This paper closes the existing gap by proposing a dynamic policy management process which structures the activities required for policy management in identity and access management environments. In contrast to current approaches, it utilizes the consideration of contextual user management data and key performance indicators for policy detection and refinement and offers result visualization techniques that foster human understanding. In order to underline its applicability, this paper provides an evaluation based on real-life data from a large industrial company. Matthias Hummer, Michael Kunz, Michael Netter, Ludwig Fuchs, Günther Pernul |
EURASIP J. Inf. Secur. | 5 |
| 2015 | Advanced Identity and Access Policy Management Using Contextual DataabstractDue to compliance and IT security requirements, company-wide Identity and Access Management within organizations has gained significant importance in research and practice over the last years. Companies aim at standardizing user management policies in order to reduce administrative overhead and strengthen IT security. Despite of its relevance, hardly any supportive means for the automated detection and refinement as well as management of policies are available. As a result, policies outdate over time, leading to security vulnerabilities and inefficiencies. Existing research mainly focuses on policy detection without providing the required guidance for policy management. This paper closes the existing gap by proposing a Dynamic Policy Management Process which structures the activities required for policy management in Identity and Access Management environments. In contrast to current approaches it fosters the consideration of contextual user management data for policy detection and refinement and offers result visualization techniques that foster human understanding. In order to underline its applicability, this paper provides a naturalistic evaluation based on real-life data from a large industrial company. Matthias Hummer, Michael Kunz, Michael Netter, Ludwig Fuchs, Günther Pernul |
ARES | 5 |
| 2015 | Personalized Composition of Trustful Reputation Systems
Johannes Sänger, Christian Richthammer, André Kremser, Günther Pernul |
DBSec | 4 |
| 2015 | Analyzing Quality Criteria in Role-based Identity and Access ManagementabstractRoles have turned into the de facto standard for access control in enterprise identity management systems. However, as roles evolve over time, companies struggle to develop and maintain a consistent role model. Up to now, the core challenge of measuring the current quality of a role model and selecting criteria for its optimization remains unsolved. In this paper, we conduct a survey of existing role mining techniques and\nidentify quality criteria inherently used by these approaches. This guides organizations during the selection of a role mining technique that matches their company-specific quality references. Moreover, our analysis aims to stimulate the research community to integrate quality metrics in future role mining approaches. Michael Kunz, Ludwig Fuchs, Michael Netter, Günther Pernul |
ICISSP | 4 |
| 2015 | Privacy in Social Networks - Existing Challenges and Proposals for Solution
Günther Pernul |
ICISSP | 1 |
| 2014 | Visualizing Transaction Context in Trust and Reputation SystemsabstractTransaction context is an important aspect that should be taken into account for reputation-based trust assessment, because referrals are bound to the situation-specific context in which they were created. The non-consideration of transaction context may cause several threats such as the value imbalance problem. Exploiting this weakness, a seller can build high reputation by selling cheap products while cheating on the expensive ones. In the recent years, multiple approaches have been introduced that address this challenge. All of them chose metrics leading to numerical reputation values. These values, however, are non-transparent and quite hard to understand for the end-user. In this work, in contrast, we combine reputation assessment and visual analytics to provide an interactive visualization of multivariate reputation data. We thereby allow the user to analyze the data sets and draw conclusions by himself. In this way, we enhance transparency, involve the user in the evaluation process and as a consequence increase the users' trust in the reputation system. Johannes Sänger, Günther Pernul |
ARES | 2 |
| 2014 | Efficiently Managing the Security and Costs of Big Data Storage using Visual AnalyticsabstractWe are currently living in the age of big data with ever growing volumes of heterogeneous and fast moving data. Whether they are mobile devices, internal or external systems or cloud-based systems data is generated, stored, processed and distributed in many different systems. This leads to various information security and privacy risks. To address these issues, especially from the viewpoint of data management and data governance we propose a conceptual analysis model. Thereby, our model takes into account the dimension of data storage location together with their respective risks and costs while considering the strategic value and sensitivity of data assets. For demonstrating our approach we developed a visual analytics web application which is based on parallel sets visualizations. By being able to interactively explore the analysis dimensions users are supported in developing enhanced situational awareness for making decisions in the context of secure and economical data storage. Sabri Hassan, Günther Pernul |
iiWAS | 2 |
| 2014 | Taxonomy of social network data typesabstractOnline social networks (OSNs) have become an integral part of social interaction and communication between people. Reasons include the ubiquity of OSNs that is offered through mobile devices and the possibility to bridge spatial and temporal communication boundaries. However, several researchers have raised privacy concerns due to the large amount of user data shared on OSNs. Yet, despite the large body of research addressing OSN privacy issues, little differentiation of data types on social network sites is made and a generally accepted classification and terminology for such data is missing. The lack of a terminology impedes comparability of related work and discussions among researchers, especially in the case of privacy implications of different data types. To overcome these shortcomings, this paper develops a well-founded terminology based on a thorough literature analysis and a conceptualization of typical OSN user activities. The terminology is organized hierarchically resulting in a taxonomy of data types. The paper furthermore discusses and develops a metric to assess the privacy relevance of different data types. Finally, the taxonomy is applied to the five major OSNs to evaluate its generalizability. Christian Richthammer, Michael Netter, Moritz Riesner, Johannes Sänger, Günther Pernul |
EURASIP J. Inf. Secur. | 5 |
| 2013 | Taxonomy for Social Network Data Types from the Viewpoint of Privacy and User ControlabstractThe growing relevance and usage intensity of Online Social Networks (OSNs) along with the accumulation of a large amount of user data has led to privacy concerns among researchers and end users. Despite a large body of research addressing OSN privacy issues, little differentiation of data types on social network sites is made and a generally accepted classification and terminology for such data is missing, hence leading to confusion in related discussions. This paper proposes a taxonomy for data types on OSNs based on a thorough literature analysis and a conceptualization of typical OSN user activities. It aims at clarifying discussions among researchers, benefiting comparisons of data types within and across OSNs and at educating the end user about characteristics and implications of OSN data types. The taxonomy is evaluated by applying it to four major OSNs. Christian Richthammer, Michael Netter, Moritz Riesner, Günther Pernul |
ARES | 4 |
| 2013 | Analyzing settings for social identity management on Social Networking Sites: Classification, current state, and proposed developments
Moritz Riesner, Michael Netter, Günther Pernul |
Inf. Secur. Tech. Rep. | 3 |
| 2012 | An Analysis of Implemented and Desirable Settings for Identity Management on Social Networking SitesabstractTo address privacy threats stemming from interacting with other users on Social Networking Sites (SNS), effective Social Identity Management (SIdM) is a key requirement. SIdM refers to the deliberate and targeted disclosure of personal attribute values to a subset of one's contacts on SNS. While a variety of privacy-enhancing approaches have been proposed, these are often isolated solutions that lack integration into a reference framework that states the requirements for successfully managing one's identity. In this paper, a reference framework of existing and desired SIdM settings is derived from identity theory, literature analysis, and existing SNS. Based thereupon, we examine the SIdM capabilities of prevalent SNS and highlight possible improvements. Moritz Riesner, Michael Netter, Günther Pernul |
ARES | 3 |
| 2012 | An Autonomous Social Web Privacy Infrastructure with Context-Aware Access Control
Michael Netter, Sabri Hassan, Günther Pernul |
TrustBus | 3 |
| 2012 | Minimizing insider misuse through secure Identity ManagementabstractABSTRACT To avoid insider computer misuse, identity, and authorization data referring to the legitimate users of systems must be properly organized, constantly and systematically analyzed, and evaluated. In order to support this, structured and secure Identity Management is required. A comprehensive methodology supporting Identity Management within organizations has been developed, including gathering of identity data spread among different applications, systematic cleansing of user account data in order to detect semantic as well as syntactic errors, grouping of privileges and access rights, and semiautomatic engineering of user roles. The focus of this paper is on the cleansing of identity and account data leading to feedback where insider misuse due to existing privileges which go beyond the scope of the users' current need‐to‐know may occur. The paper in detail presents used data cleansing mechanisms and underlines their applicability in two real‐world case studies. Copyright © 2011 John Wiley & Sons, Ltd. Ludwig Fuchs, Günther Pernul |
Secur. Commun. Networks | 2 |
| 2011 | Roles in information security - A survey and classification of the research area
Ludwig Fuchs, Günther Pernul, Ravi S. Sandhu |
Comput. Secur. | 2 |
| 2010 | A Semantic Security Architecture for Web ServicesabstractThe shift from mere service-oriented architectures (SOA) to semantically enriched approaches is especially being forced in multi-domain environments that the public sector in the European Union is an example for. The security aspect is lagging behind its possibilities, and new access control approaches native to the semantic environment need to be applied. Based on architectural research work conducted within the EU-funded research project Access-eGov, we outline our implementation of a semantic security architecture for web services by using industry-standard technologies and combining them with semantic enhancements. Stefan Durbeck, Christoph Fritsch, Günther Pernul, Rolf Schillinger |
ARES | 3 |
| 2010 | Visualizing Past Personal Data DisclosuresabstractToday's rich service offer in the World Wide Web increasingly requires the disclosure of personal user data. Service providers' appetite for personal user data, however, is accompanied by growing privacy implications for Internet users. Addressing this rising threat, privacy-enhancing technologies aim at aiding users in protecting their personal data. Even though effective privacy laws facilitate users to edit and revoke already disclosed personal data, few PET solutions support users in exercising this right. Available tools lack intuitive interfaces and are built on powerful infrastructures on the provider side. In this paper we introduce the Data Disclosure Log component within a user-centric privacy architecture. Built on a browser-based logging extension, we present a visualization tool that displays past personal data disclosures from different perspectives. A graph-based view allows for the dynamic presentation of relations between selected entity types. Such an overview enables users to know the conditions of past personal data transactions at any time. This knowledge represents a prerequisite for an ex post revision or revocation of personal data. Usability and user acceptance of the developed prototype is evaluated in a conducted user test. Jan Paul Kolter, Michael Netter, Günther Pernul |
ARES | 3 |
| 2010 | Refining the Pattern-Based Reference Model for Electronic Invoices by Incorporating ThreatsabstractAlmost every company needs to process invoices to either claim money from their customers or to pay for products or services. Although companies are allowed to electronically process their invoices, most of them still rely on the paper-based invoice process. Within this paper we built upon existing work to develop a methodology for defining a reference model for the electronic invoice based on security patterns. This paper identifies threats of the e-invoice process in order to create a context for the security problem, which allows us to refine our methodology. Michael Netter, Eduardo B. Fernández, Günther Pernul |
ARES | 3 |
| 2010 | Preventing Malicious Portlets from Communicating and Intercepting in Collaboration Portals
Oliver Gmelch, Günther Pernul |
SECRYPT | 2 |
| 2010 | Attacking Image Recognition Captchas - A Naive but Effective Approach
Christoph Fritsch, Michael Netter, Andreas Reisser, Günther Pernul |
TrustBus | 4 |
| 2010 | Security for Dynamic Service-Oriented eCollaboration - Architectural Alternatives and Proposed Solution
Christoph Fritsch, Günther Pernul |
TrustBus | 2 |
| 2010 | Collaborative privacy management
Jan Paul Kolter, Thomas Kernchen, Günther Pernul |
Comput. Secur. | 3 |
| 2009 | Different Approaches to In-House Identity Management - Justification of an AssumptionabstractThe use of roles in identity management infrastructures (IdMI) has proven to be a solution for reorganising and securing access structures of employees. The definition of enterprise-wide roles is one of the most challenging and costly tasks during role development projects. It needs to be carried out on the basis of a predefined role development methodology (RDM). In this paper we present existing methodologies and show their respective pros and cons. Lately some researchers have informally stated that hybrid role development is the most promising way to define roles, however, there hasnpsilat been given a well-defined justification for this decision. The main contribution of this paper is hence the deduction of evaluation criteria based on information gathered from literature, practical experiences, and shortcomings of existing role development approaches. The evaluation criteria form the basis for a comparison framework verifying the assumption that hybrid RDMs are superior to role engineering and role mining methodologies. Ludwig Fuchs, Christian Broser, Günther Pernul |
ARES | 3 |
| 2009 | Generating User-Understandable Privacy PreferencesabstractMaking use of the World Wide Web's numerous services increasingly requires the disclosure of personal user data. While these data represent an important value for service providers, users are increasingly concerned about growing privacy threats, as more and more of their personal and private information is released to a rising number of parties. Privacy-enhancing technologies, like the P3P specification, assist users in protecting their privacy. P3P provides means to express a machine-readable P3P privacy policy of a Web site and allows the interpretation of a dedicated P3P user agent that recommends a certain disclosure behavior. The agent's recommendation, however, is based on the quality of pre-defined privacy preferences of the user. Accordingly, the creation of these disclosure rules requires tools that accurately record individual privacy preferences in an understandable way. This paper introduces a novel, user-friendly privacy preference generator that allows the definition of privacy preferences for twelve different Internet service types, allowing for more precise and practical user preferences. Addressing the needs of users with different levels of experience, we present a multi-level user interface. Our solution includes a user-friendly P3P-based wizard as well as a clear and understandable configuration summary. The resulting privacy preferences of this tool will allow moreaccurate recommendations of future privacy agents. Jan Paul Kolter, Günther Pernul |
ARES | 2 |
| 2009 | Collaborative Privacy - A Community-Based Privacy Infrastructure
Jan Paul Kolter, Thomas Kernchen, Günther Pernul |
SEC | 3 |
| 2008 | Intensive Programme on Information and Communication SecurityabstractIT Security is a problem that can only be addressed and taught holistically. Just as broad as the field of ICT itself, IT Security is an integral part of all network and software applications. Security must be guaranteed throughout services. Too often, a single university or department cannot offer the complete range of IT Security subjects to their students or provide the up-to-date information and knowledge needed. Consequently, the demand of keeping up with hackers, threats, and risks is hardly met. Our proposal is a combination of the know-how of multiple institutions, aligned in an Intensive Programme for Master- and PhD Students of Computer Science, Information Systems, and Business Informatics. The proposed Intensive Programme on Information and Communication Security (IPICS) uses e-learning and traditional learning methods to form a blended learning course. Using the synergies of 19 contracted European Universities and their IT Security experts, IPICS will deliver momentum for IT Security education and training to those who take part and furthermore through their networks. Christian Schläger, Ludwig Fuchs, Günther Pernul |
ARES | 3 |
| 2008 | Trust Modelling in E-Commerce through Fuzzy Cognitive MapsabstractTrust and its role in e-commerce is a major topic for researchers, clients, and service providers alike. However, questions of origin and practical usage of trust in e-commerce are still not answered. Two eminent obstacles in the integration of information on trust and reputation are limited data about customers, and a missing fine grained access control model. The first hindrance is shrinking as users generate personal data in the Web 2.0 as they go (or rather surf). The aim of this paper is to show potentials for e-commerce federations using an attribute-based authentication and authorisation infrastructure to use customer information for the derivation of metric trust and reputation values. Using Fuzzy Cognitive Maps and trust metrics, a prototype integrates a federation’s user data within an easy to use service provider interface for reputation management. To assure user privacy the data is categorised and stored distributedly. Christian Schläger, Günther Pernul |
ARES | 2 |
| 2008 | Patterns and Pattern Diagrams for Access Control
Eduardo B. Fernández, Günther Pernul, María M. Larrondo-Petrie |
TrustBus | 2 |
| 2007 | Supporting Compliant and Secure User Handling - A Structured Approach for In-House Identity ManagementabstractThe catchword "compliance" dominates the actual debate about identity management and information security like few before. Companies need to comply with a variety of internal and external standards and regulations like the US SOX Act. Identity management is seen as a main provider of compliance in modern companies. However, its organisational aspects are underestimated in many projects, lacking a comprehensive approach to introduce in-house identity management. This work is based on the experiences gained from industry projects using identity management functionalities to strengthen security and to reach a high level of compliance. We develop a structured process-oriented methodology for introducing an identity management infrastructure for organisations using drivers from IT security management to evaluate, rank, and implement subprojects. The methodology consists of an iterative process which enables even large and unstructured organisations to reach a suitable and profitable level of identity management by emphasising on organisational aspects rather than taking a merely technical approach Ludwig Fuchs, Günther Pernul |
ARES | 2 |
| 2007 | A Privacy-Enhanced Attribute-Based Access Control System
Jan Paul Kolter, Rolf Schillinger, Günther Pernul |
DBSec | 3 |
| 2007 | Building a Distributed Semantic-aware Security Architecture
Jan Paul Kolter, Rolf Schillinger, Günther Pernul |
SEC | 3 |
| 2007 | Infrastructures for Authentication, Authorization and Privilege Management Scope, Evaluation and use in the Access-eGov Project
Günther Pernul |
SECRYPT | 1 |
| 2007 | Panel Discussion: Managing Digital Identities - Challenges and Opportunities
Günther Pernul, Marco Casassa Mont, Eduardo B. Fernández, Sokratis K. Katsikas, Alfred Kobsa, Rolf Oppliger |
TrustBus | 1 |
| 2006 | Authrule: A Generic Rule-Based Authorization Module
Sönke Busch, Björn Muschall, Günther Pernul, Torsten Priebe |
DBSec | 3 |
| 2004 | A Pattern System for Access ControlabstractIn order to develop trustworthy information systems, security aspects should be considered from the early project stages. This is particularly true for authorization and access control services, which decide which users can access which parts of the system and in what ways. Software patterns have been used with success to encapsulate best practices in software design. A good collection of patterns is an invaluable aid in designing new systems by inexperienced developers and is also useful to teach and understand difficult problems. Following in this direction, this paper presents a pattern system to describe authorization and access control models. First, we present a set of patterns that include a basic authorization pattern that is the basis for patterns for the well-established discretionary and role-based access control models. Metadata access control models have appeared recently to address the high flexibility requirements of open, heterogeneous systems, such as enterprise or e-commerce portals. These models are complex and we use the basic patterns to develop a set of patterns for metadata-based access control. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Torsten Priebe, Eduardo B. Fernández, Jens Ingo Mehlau, Günther Pernul |
DBSec | 4 |
| 2004 | A Flexible Security System for Enterprise and e-Government Portals
Torsten Priebe, Björn Muschall, Wolfgang Dobmeier, Günther Pernul |
DEXA | 4 |
| 2004 | Authentication and authorization infrastructures (AAIs): a comparative survey
Javier López 0001, Rolf Oppliger, Günther Pernul |
Comput. Secur. | 3 |
| 2003 | Towards integrative enterprise knowledge portalsabstractKnowledge portals make an important contribution to enabling enterprise knowledge management by providing users with a consolidated, personalized user interface that allows efficient access to various types of (structured and unstructured) information. Today's portal systems allow combining access modules to different information sources side by side on a single portal webpage. However, there is no interaction between those so called portlets. When a user navigates within one portlet, the others remain unchanged, which means that each source has to be searched individually for relevant information.This paper discusses integration aspects within enterprise knowledge portals and presents an approach for communicating the user context (revealing the user's information need) among portlets, utilizing Semantic Web technologies. For example, the query context of an OLAP portlet, which provides access to structured data stored in a data warehouse, can be used by an information retrieval portlet in order to automatically provide the user with related documents found in the organization's document management system. The paper shortly presents a prototype that we are building to evaluate our approach, demonstrating such an OLAP and information retrieval integration. Torsten Priebe, Günther Pernul |
CIKM | 2 |
| 2003 | CSAP - An Adaptable Security Module for the E-Government System Webocrat
Fredj Dridi, Michael Fischer 0008, Günther Pernul |
SEC | 3 |
| 2003 | Security requirements for e-government services: a methodological approach for developing a common PKI-based security policy
Costas Lambrinoudakis, Stefanos Gritzalis, Fredj Dridi, Günther Pernul |
Comput. Commun. | 4 |
| 2001 | A Pragmatic Approach to Conceptual Modeling of OLAP Security
Torsten Priebe, Günther Pernul |
ER | 2 |
| 2000 | Towards OLAP Security Design - Survey and Research IssuesabstractWith the use of data warehousing and online analytical processing (OLAP) for decision support applications new security issues arise.The goal of this paper is to introduce an OLAP security design methodology, pointing out fields that require further research work.We present possible access control requirements categorized by their complexity.OLAP security mechanisms and their implementations in commercial systems are presented and checked for their suitability to address the requirements.Traditionally data warehouses were queried by high level users (executive management, business analysts) only.As the range of potential users with data warehouse access is steadily growing, this assumption is no longer appropriate and the necessity of proper access control mechanisms arises.However, a data warehouse is primarily built as an open system.Especially exploratory OLAP analysis requires this open nature; security controls may hinder the analytical discovery process. Torsten Priebe, Günther Pernul |
DOLAP | 2 |
| 2000 | COPS: a model and infrastructure for secure and fair electronic markets
Alexander W. Röhm, Günther Pernul |
Decis. Support Syst. | 2 |
| 1999 | A Language for Modeling Secure Business TransactionsabstractAmong other areas, electronic commerce includes the fields of electronic markets and workflow management. Workflow management systems are usually used to specify and manage inter- and intra-organisational business processes. Although workflow management techniques are capable of specifying and conducting at least parts of market transactions, these techniques are not or are very rarely used for this purpose yet. In both fields, users demand security and integrity to protect for example their privacy, their property rights or digital payments. To satisfy these security demands, a variety of existing security services, mechanisms, protocols, and organisational measures may be used. On the one hand, to encourage using these techniques it is necessary to have a tool which enables a firm's executive to formulate market transaction security demands at a high abstraction level. On the other hand, executing market transactions needs a more formal, machine readable description of the transaction and its security requirements. We present a methodology to specify secure protocols, which are usable to automatically conduct business processes, as well as market transactions. Alexander W. Röhm, Gaby Herrmann, Günther Pernul |
ACSAC | 3 |
| 1999 | Trust for Electronic Commerce Transactions
Günther Pernul, Alexander W. Röhm, Gaby Herrmann |
ADBIS | 1 |
| 1998 | Modeling Secure and Fair Electronic CommerceabstractSecurity and fairness in business transactions are basic requirements demanded by any participant in electronic markets. We propose COPS as an infrastructure for building adaptable electronic markets with main focus on security and fairness and MOSS as a methodology for analysing and modelling the security semantics of business transactions. Both are necessary to control the risks involved in dealing (trading) with untrusted parties in an open electronic commerce environment. We address the phases information, negotiation and execution of a business transaction and discuss security requirements which in the past were recognised as being very important for electronic market participants but had only received limited or little attention in the electronic commerce research community. Alexander W. Röhm, Günther Pernul, Gaby Herrmann |
ACSAC | 2 |
| 1998 | Modelling Data Secrecy and Integrity
Günther Pernul, A Min Tjoa, Werner Winiwarter |
Data Knowl. Eng. | 1 |
| 1997 | Access Controls by Object-Oriented Concepts
Wolfgang Eßmayr, Günther Pernul, A Min Tjoa |
DBSec | 2 |
| 1996 | Automatic Classification of Semantic Concepts in View Specifications
Ernst Ellmer, Christian Huemer, Dieter Merkl, Günther Pernul |
DEXA | 4 |
| 1996 | Authorization and Access Control in IRO-DBabstractThe paper describes authorization and access control in the IRO-DB database system, a system supporting interoperable access between relational and object oriented databases. The security policy developed is a federated administrative discretionary access control policy which supports positive, negative, as well as implied authorization, includes a procedure for conflict resolution within the set of specified authorization rules, and concentrates on role based security. Wolfgang Eßmayr, Fritz Kastner, Günther Pernul, Stefan Preishuber, A Min Tjoa |
ICDE | 3 |
| 1996 | The security architecture of IRO-DB
Wolfgang Eßmayr, Fritz Kastner, Günther Pernul, A Min Tjoa |
SEC | 3 |
| 1995 | Combining Reverse with Classical Forward Database Engineering - A Step Forward to Solve the Legacy System Dilemma
Günther Pernul, Hubert Hasenauer |
DEXA | 1 |
| 1994 | Organizing MLS databases from a data modelling point of viewabstractThe conceptual and logical design of multilevel secure (MLS) database applications are treated in an integrated way. For the conceptual design, a powerful semantic data model is suggested in order to represent the data and security semantics of the application domain. For the logical design, a two-phase approach is developed. Phase one consists of the transformation of the database conceptualization into multilevel relational concepts, while phase two is concerned with integrity management. Enforcing the integrity in MLS databases is known to be a difficult task. Careful data modelling is a necessary prerequisite in order to arrive at consistent and secure MLS applications.> Günther Pernul, Gerald Quirchmayr |
ACSAC | 1 |
| 1994 | Security Object Modelling for Level-Based Policies
Günther Pernul |
DBSec | 1 |
| 1993 | The deductive filter approach to MLS database prototypingabstractThis paper proposes building a prototyping environment as part of the standard design process of multilevel secure database applications. For this paper we see the following contributions: First, based on a careful study of multilevel security requirements we developed a security constraints language (SCL) for specifying application dependent database security semantics. Second, we implemented SCL by using the deductive database systems LDL thereby offering a useful toolset with which a prototype of a multilevel secure relational database application can efficiently be developed. Prototyping will help the database designer to arrive at a consistent data classification and at a satisfactory database design.> Günther Pernul, Werner Winiwarter, A Min Tjoa |
ACSAC | 1 |
| 1993 | The Entity-Relationship Model for Multilevel Security
Günther Pernul, Werner Winiwarter, A Min Tjoa |
ER | 1 |
| 1992 | Security constraint processing during multilevel secure database designabstractBy means of simple examples, a design technique for multilevel secure databases is proposed. The design activity covers the conceptual modeling and design phase and consists of the development of secure data schemata and secure function schemata. Data schemata represent the semantics and secrecy properties of data while function schemata describe processes and activities within the system. As security constraints defined on data or functions may influence each other, it argued that the design of a secure system must be data- as well as function-driven. Although the example chosen is quite simple, it is possible to express and model complex security relevant data semantics.> Günther Pernul |
ACSAC | 1 |
| 1992 | Security Constraint Processing in Multilevel Secure AMAC Schemata
Günther Pernul |
ESORICS | 1 |
| 1991 | A multilevel secure relational data model based on viewsabstractIn order to overcome certain limitations when applied to relational databases, a data model is introduced that is not fully based on the bell-LaPadula security paradigm. The starting point is a conceptual relational database schema and a set of views, representing user groups and applications. Based on the definition of views, the relations of the conceptual schema are decomposed in a set of disjoint fragments. Fragments and views are the granularity of data to which they provide automated security labeling. In order to keep fragmented databases consistent during database update, they give algorithms useful to keep the integrity. Databases based on this model contain data at a variety of classifications, serve a set of users cleared only to access certain data items and may be implemented by using a general purpose database management system extended by a trusted component supporting mandatory access control.> Günther Pernul, Gottfried Luef |
ACSAC | 1 |
| 1991 | Relational Database Organization Based on Views and Fragments
Günther Pernul, Kamalakar Karlapalem, Shamkant B. Navathe |
DEXA | 1 |
| 1991 | A View Integration Approach for the Design of Multilevel Security
Günther Pernul, A Min Tjoa |
ER | 1 |