Endre søk
Link to record
Permanent link

Direct link
Publikasjoner (10 av 47) Visa alla publikasjoner
Raavikanti, S., Hacks, S. & Katsikeas, S. (2023). A Recommender Plug-in for Enterprise Architecture Models. In: Proceedings of the 25th International Conference on Enterprise Information Systems - Volume 2, ICEIS 2023: . Paper presented at 25th International Conference on Enterprise Information Systems, ICEIS 2023, Prague, Czechia, Apr 24 2023 - Apr 26 2023 (pp. 474-480). INSTICC
Åpne denne publikasjonen i ny fane eller vindu >>A Recommender Plug-in for Enterprise Architecture Models
2023 (engelsk)Inngår i: Proceedings of the 25th International Conference on Enterprise Information Systems - Volume 2, ICEIS 2023, INSTICC , 2023, s. 474-480Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

IT has evolved over the decades, where its role and impact have transitioned from being a tactical tool to a more strategic one for driving business strategies to transform organizations. The right alignment between IT strategy and business has become a compelling factor for Chief Information Officers and Enterprise Architecture (EA) in practice is one of the approaches where this alignment can be achieved. Enterprise Modeling complements EA with models that are composed of enterprise components and relationships, that are stored in a repository. Over time, the repository grows which opens up research avenues to provide data intelligence. Recommender Systems is a field that can take different forms in the modeling domain and each form of recommendation can be enhanced with sophisticated models over time. Within this work, we focus on the latter problem by providing a recommender architecture framework eases the integration of different Recommender Systems. Thus, researchers can easily compare the performance of different recommender systems for EA models. The framework is developed as a distributed plugin for Archi, a widely used modeling tool to create EA models in the ArchiMate notation.

sted, utgiver, år, opplag, sider
INSTICC, 2023
Emneord
Archi, ArchiMate, Enterprise Architecture, Enterprise Modeling, Recommender Systems
HSV kategori
Identifikatorer
urn:nbn:se:kth:diva-338634 (URN)10.5220/0011709000003467 (DOI)2-s2.0-85160855254 (Scopus ID)
Konferanse
25th International Conference on Enterprise Information Systems, ICEIS 2023, Prague, Czechia, Apr 24 2023 - Apr 26 2023
Merknad

Part of ISBN 9789897586484

QC 20231123

Tilgjengelig fra: 2023-10-31 Laget: 2023-10-31 Sist oppdatert: 2023-11-23bibliografisk kontrollert
Ekstedt, M., Afzal, Z., Mukherjee, P., Hacks, S. & Lagerström, R. (2023). Yet another cybersecurity risk assessment framework. International Journal of Information Security, 22(6), 1713-1729
Åpne denne publikasjonen i ny fane eller vindu >>Yet another cybersecurity risk assessment framework
Vise andre…
2023 (engelsk)Inngår i: International Journal of Information Security, ISSN 1615-5262, E-ISSN 1615-5270, Vol. 22, nr 6, s. 1713-1729Artikkel i tidsskrift (Fagfellevurdert) Published
Abstract [en]

IT systems pervade our society more and more, and we become heavily dependent on them. At the same time, these systems are increasingly targeted in cyberattacks, making us vulnerable. Enterprise and cybersecurity responsibles face the problem of defining techniques that raise the level of security. They need to decide which mechanism provides the most efficient defense with limited resources. Basically, the risks need to be assessed to determine the best cost-to-benefit ratio. One way to achieve this is through threat modeling; however, threat modeling is not commonly used in the enterprise IT risk domain. Furthermore, the existing threat modeling methods have shortcomings. This paper introduces a metamodel-based approach named Yet Another Cybersecurity Risk Assessment Framework (Yacraf). Yacraf aims to enable comprehensive risk assessment for organizations with more decision support. The paper includes a risk calculation formalization and also an example showing how an organization can use and benefit from Yacraf.

sted, utgiver, år, opplag, sider
Springer Nature, 2023
Emneord
Attack tree, Enterprise IT risk, Risk assessment, Threat modeling
HSV kategori
Identifikatorer
urn:nbn:se:kth:diva-338542 (URN)10.1007/s10207-023-00713-y (DOI)001027329600001 ()2-s2.0-85164669184 (Scopus ID)
Merknad

QC 20231108

Tilgjengelig fra: 2023-11-08 Laget: 2023-11-08 Sist oppdatert: 2023-11-08bibliografisk kontrollert
Hacks, S., Katsikeas, S., Rencelj Ling, E., Xiong, W., Pfeiffer, J. & Wortmann, A. (2022). Towards a Systematic Method for Developing Meta Attack Language Instances. In: Enterprise, Business-Process and Information Systems Modeling 23rd International Conference, BPMDS 2022 and 27th International Conference, EMMSAD 2022, Held at CAiSE 2022, Leuven, Belgium, June 6–7, 2022, Proceedings: . Paper presented at 34th International Conference on Advanced Information Systems Engineering CAiSE 2022, Leuven, Belgium, June 6–7, 2022 (pp. 139-154). Springer Nature, 450
Åpne denne publikasjonen i ny fane eller vindu >>Towards a Systematic Method for Developing Meta Attack Language Instances
Vise andre…
2022 (engelsk)Inngår i: Enterprise, Business-Process and Information Systems Modeling 23rd International Conference, BPMDS 2022 and 27th International Conference, EMMSAD 2022, Held at CAiSE 2022, Leuven, Belgium, June 6–7, 2022, Proceedings, Springer Nature , 2022, Vol. 450, s. 139-154Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

Successfully developing domain-specific languages (DSLs) demands language engineers to consider their organizational context, which is challenging. Action design research (ADR) provides a conceptual framework to address this challenge. Since ADR’s application to the engineering of DSLs has not yet been examined, we investigate applying it to the development of threat modeling DSLs based on the Meta Attack Language (MAL), a metamodeling language for the specification of domain-specific threat modeling languages. To this end, we conducted a survey with experienced MAL developers on their development activities. We extract guidelines and align these, together with established DSL design guidelines, to the conceptual model of ADR. The research presented, aims to be the first step to investigate whether ADR can be used to systematically engineer DSLs.

sted, utgiver, år, opplag, sider
Springer Nature, 2022
Serie
Lecture Notes in Business Information Processing, ISSN 1865-1348 ; 450
Emneord
Action design research (ADR), Domain specific language (DSL), Language engineering, Digital subscriber lines, Modeling languages, Action design research, Conceptual frameworks, Design research, Domain specific language, Domains specific languages, Metamodeling, Organizational context, Systematic method, Threat modeling, Problem oriented languages
HSV kategori
Identifikatorer
urn:nbn:se:kth:diva-315994 (URN)10.1007/978-3-031-07475-2_10 (DOI)000894110300010 ()2-s2.0-85131307190 (Scopus ID)
Konferanse
34th International Conference on Advanced Information Systems Engineering CAiSE 2022, Leuven, Belgium, June 6–7, 2022
Merknad

QC 20230130

Tilgjengelig fra: 2022-08-05 Laget: 2022-08-05 Sist oppdatert: 2025-02-07bibliografisk kontrollert
Katsikeas, S., Johnsson, P., Hacks, S. & Lagerström, R. (2022). VehicleLang: A probabilistic modeling and simulation language for modern vehicle IT infrastructures. Computers & Security, 117, Article ID 102705.
Åpne denne publikasjonen i ny fane eller vindu >>VehicleLang: A probabilistic modeling and simulation language for modern vehicle IT infrastructures
2022 (engelsk)Inngår i: Computers & Security, ISSN 0167-4048, E-ISSN 1872-6208, Vol. 117, artikkel-id 102705Artikkel i tidsskrift (Fagfellevurdert) Published
Abstract [en]

Attack simulations are a feasible means of assessing the cyber security of various systems. Simulations can replicate the steps taken by an attacker to compromise sensitive system assets, and the time required for the acquisition of assets of interests can be calculated. One widely accepted approach to such simulations is the modelling of attack steps and their dependencies in a formal manner using attack graphs. To reduce the effort of creating new attack graphs for each system in a given domain, one can employ domain-specific attack-modeling languages to codify common attack logic. The Meta Attack Language has been proposed as a framework for developing domain-specific attack languages. In this article, we propose vehicleLang as a domain-specific language for modeling vehicles in the context of corresponding information technology infrastructures and analyzing weaknesses related to known attacks. To model domain-specific attributes, we reviewed existing literature to develop a comprehensive language, which was then verified through a series of interviews with domain experts from the automotive industry. Specifically, a systematic literature review was performed to identify possible attacks against vehicles. The identified attacks served as a blueprint for the evaluation of vehicleLang's simulation capabilities. Finally, the language was validated using the Feigenbaum test methodology.

sted, utgiver, år, opplag, sider
Elsevier BV, 2022
Emneord
Domain-specific language, Cyber security, Threat modeling, Attack graphs, Vehicular security
HSV kategori
Identifikatorer
urn:nbn:se:kth:diva-313033 (URN)10.1016/j.cose.2022.102705 (DOI)000793072700008 ()2-s2.0-85127355690 (Scopus ID)
Merknad

QC 20220601

Tilgjengelig fra: 2022-06-01 Laget: 2022-06-01 Sist oppdatert: 2025-12-16bibliografisk kontrollert
Xiong, W., Hacks, S. & Lagerström, R. (2021). A Method for Assigning Probability Distributions in Attack Simulation Languages. Complex Systems Informatics and Modeling Quarterly (26), 55-77, Article ID 151.
Åpne denne publikasjonen i ny fane eller vindu >>A Method for Assigning Probability Distributions in Attack Simulation Languages
2021 (engelsk)Inngår i: Complex Systems Informatics and Modeling Quarterly, E-ISSN 2255-9922, nr 26, s. 55-77, artikkel-id 151Artikkel i tidsskrift (Fagfellevurdert) Published
Abstract [en]

Cyber attacks on IT and OT systems can have severe consequences for individuals and organizations, from water or energy distribution systems to online banking services. To respond to these threats, attack simulations can be used to assess the cyber security of systems to foster a higher degree of resilience against cyber attacks; the steps taken by an attacker to compromise sensitive system assets can be traced, and a time estimate can be computed from the initial step to the compromise of assets of interest.

Previously, the Meta Attack Language (MAL) was introduced as a framework to develop security-oriented domain-specific languages. It allows attack simulations on modeled systems and analyzes weaknesses related to known attacks. To produce more realistic simulation results, probability distributions can be assigned to attack steps and defenses to describe the efforts required for attackers to exploit certain attack steps. However, research on assessing such probability distributions is scarce, and we often rely on security experts to model attackers’ efforts. To address this gap, we propose a method to assign probability distributions to the attack steps and defenses of MAL-based languages. We demonstrate the proposed method by assigning probability distributions to a MAL-based language. Finally, the resulting language is evaluated by modeling and simulating a known cyber attack.

sted, utgiver, år, opplag, sider
Riga Technical University, 2021
Emneord
Attack Simulations; Threat Modeling; Domain-Specific Language; Cyber Security; Information Collection
HSV kategori
Forskningsprogram
Elektro- och systemteknik
Identifikatorer
urn:nbn:se:kth:diva-293920 (URN)10.7250/csimq.2021-26.04 (DOI)2-s2.0-85108209334 (Scopus ID)
Forskningsfinansiär
StandUpVinnova
Merknad

QC 20210527

Tilgjengelig fra: 2021-05-05 Laget: 2021-05-05 Sist oppdatert: 2025-05-08bibliografisk kontrollert
Xiong, W., Hacks, S. & Lagerström, R. (2021). A Method for Quality Assessment of Threat Modeling Languages: The Case of enterpriseLang. In: : . Paper presented at PoEM’21 Forum: 14th IFIP WG 8.1 Working Conference on the Practice of Enterprise Modelling (pp. 49-58). Riga, Latvia, 3045
Åpne denne publikasjonen i ny fane eller vindu >>A Method for Quality Assessment of Threat Modeling Languages: The Case of enterpriseLang
2021 (engelsk)Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

Enterprise systems are growing in complexity, and the adoption of cloud and mobile services has greatly increased the attack surface. To proactively address these security issues in enterprise systems, a threat modeling language for enterprise systems called enterpriseLang was proposed. It is a domain-specific language (DSL) designed using the Meta Attack Language (MAL) framework and focuses on describing system assets, attack steps, defenses, and asset associations. The threat models can serve as input for attack simulations to analyze the behavior of attackers within the system. However, whether and to what extent the functionality of these threat modeling languages is achieved has not been addressed. To ensure the correct functionality of threat modeling languages, this paper proposes a method to assess the quality of such languages and illustrates its application using enterpriseLang.

sted, utgiver, år, opplag, sider
Riga, Latvia: , 2021
Emneord
Threat modeling, Attack simulations, Domain-specific language, Design guidelines, Test coverage
HSV kategori
Forskningsprogram
Elektro- och systemteknik
Identifikatorer
urn:nbn:se:kth:diva-299982 (URN)
Konferanse
PoEM’21 Forum: 14th IFIP WG 8.1 Working Conference on the Practice of Enterprise Modelling
Merknad

QC 20210823

Tilgjengelig fra: 2021-08-20 Laget: 2021-08-20 Sist oppdatert: 2022-12-20bibliografisk kontrollert
Xiong, W., Hacks, S. & Lagerström, R. (2021). A Method for Quality Assessment of Threat Modeling Languages: The Case of enterpriseLang. In: CEUR Workshop Proceedings: . Paper presented at 14th IFIP WG 8.1 Working Conference on the Practice of Enterprise Modeling, PoEM-Forum 2021, 24 November 2021 through 26 November 2021 (pp. 49-58). CEUR-WS
Åpne denne publikasjonen i ny fane eller vindu >>A Method for Quality Assessment of Threat Modeling Languages: The Case of enterpriseLang
2021 (engelsk)Inngår i: CEUR Workshop Proceedings, CEUR-WS , 2021, s. 49-58Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

Enterprise systems are growing in complexity, and the adoption of cloud and mobile services has greatly increased the attack surface. To proactively address these security issues in enterprise systems, a threat modeling language for enterprise systems called enterpriseLang was proposed. It is a domain-specific language (DSL) designed using the Meta Attack Language (MAL) framework and focuses on describing system assets, attack steps, defenses, and asset associations. The threat models can serve as input for attack simulations to analyze the behavior of attackers within the system. However, whether and to what extent the functionality of these threat modeling languages is achieved has not been addressed. To ensure the correct functionality of threat modeling languages, this paper proposes a method to assess the quality of such languages and illustrates its application using enterpriseLang.

sted, utgiver, år, opplag, sider
CEUR-WS, 2021
Emneord
Attack simulations, Design guidelines, Domain-specific language, Test coverage, Threat modeling, Modeling languages, Attack simulation, Cloud services, Design guideline, Enterprise system, ITS applications, Mobile service, Quality assessment, Security issues, Test-coverage, Problem oriented languages
HSV kategori
Identifikatorer
urn:nbn:se:kth:diva-316065 (URN)2-s2.0-85121720425 (Scopus ID)
Konferanse
14th IFIP WG 8.1 Working Conference on the Practice of Enterprise Modeling, PoEM-Forum 2021, 24 November 2021 through 26 November 2021
Merknad

QC 20220905

Tilgjengelig fra: 2022-09-05 Laget: 2022-09-05 Sist oppdatert: 2022-12-20bibliografisk kontrollert
Hacks, S., Butun, I., Lagerström, R., Buhaiu, A., Georgiadou, A. & Michalitsi Psarrou, A. (2021). Integrating Security Behavior into Attack Simulations. In: ARES 2021: The 16th International Conference on Availability, Reliability and Security: . Paper presented at The 16th International Conference on Availability, Reliability and Security, Vienna Austria August 17 - 20, 2021. Association for Computing Machinery
Åpne denne publikasjonen i ny fane eller vindu >>Integrating Security Behavior into Attack Simulations
Vise andre…
2021 (engelsk)Inngår i: ARES 2021: The 16th International Conference on Availability, Reliability and Security, Association for Computing Machinery , 2021Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

The increase of cyber-attacks raised security concerns for critical assets worldwide in the last decade. Leading to more efforts spent towards increasing the cyber security among companies and countries. For the sake of enhancing cyber security, representation and testing of attacks have prime importance in understanding system vulnerabilities. One of the available tools for simulating attacks on systems is the Meta Attack Language (MAL), which allows representing the effects of certain cyber-attacks. However, only understanding the component vulnerabilities is not enough in securing enterprise systems. Another important factor is the "human", which constitutes the biggest "insider threat". For this, Security Behavior Analysis (SBA) helps understanding which system components that might be directly affected by the "human". As such, in this work, the authors present an approach for integrating user actions, so called "security behavior", by mapping SBA to a MAL-based language through MITRE ATT&CK techniques.

sted, utgiver, år, opplag, sider
Association for Computing Machinery, 2021
Serie
ARES 2021
Emneord
Security Behavior, Attack Simulations, Integration
HSV kategori
Identifikatorer
urn:nbn:se:kth:diva-300454 (URN)10.1145/3465481.3470475 (DOI)000749539200157 ()2-s2.0-85113199864 (Scopus ID)
Konferanse
The 16th International Conference on Availability, Reliability and Security, Vienna Austria August 17 - 20, 2021
Merknad

QC 20220308

Tilgjengelig fra: 2021-09-01 Laget: 2021-09-01 Sist oppdatert: 2022-12-20bibliografisk kontrollert
Jung, J., Hacks, S., de Gooijer, T., Kinnunen, M. & Rehring, K. (2021). Revealing Common Enterprise Architecture Debts: Conceptualization and Critical Reflection on a Workshop Format Industry Experience Report. In: 2021 IEEE 25Th International Enterprise Distributed Object Computing Conference Workshops (EDOCW 2021): . Paper presented at 25th IEEE International Enterprise Distributed Object Computing Conference (IEEE EDOC), OCT 25-29, 2021, ELECTR NETWORK Gold Coast, Australia (pp. 271-278). Institute of Electrical and Electronics Engineers (IEEE)
Åpne denne publikasjonen i ny fane eller vindu >>Revealing Common Enterprise Architecture Debts: Conceptualization and Critical Reflection on a Workshop Format Industry Experience Report
Vise andre…
2021 (engelsk)Inngår i: 2021 IEEE 25Th International Enterprise Distributed Object Computing Conference Workshops (EDOCW 2021), Institute of Electrical and Electronics Engineers (IEEE) , 2021, s. 271-278Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

The Enterprise Architecture (EA) discipline evolved during the past two decades and is now established in a large number of companies. Architectures in these companies changed over time and are now the result of a long creation and maintenance process. Such architectures still contain processes and services provided by legacy IT systems (e.g., systems, applications) that were reasonable during the time they were created but might now hamper the introduction of better solutions. In order to support handling those legacies, research on the notion of EA debts has been started. The concept of EA debts widens the scope of technical debts to cover also organizational aspects offering a mean for managing EA in dynamic environments. The research encompasses the development of methods for managing debts together with a repository of typical EA debts. Identifying EA debts for the repository is challenging as required knowledge is usually not documented. Therefore, a structured approach is needed to externalize this knowledge. The paper presents a workshop format that is used to identify EA debts in organizations. Corresponding workshops are performed in two distinct companies to support them in understanding certain issues they face. First results from those workshops are presented in the second part of the paper.

sted, utgiver, år, opplag, sider
Institute of Electrical and Electronics Engineers (IEEE), 2021
Serie
IEEE International Enterprise Distributed Object Computing Conference Workshops-EDOCW, ISSN 2325-6583
Emneord
Enterprise Architecture, Enterprise Architecture Debt, Action Research, Workshop Format
HSV kategori
Identifikatorer
urn:nbn:se:kth:diva-309018 (URN)10.1109/EDOCW52865.2021.00058 (DOI)000744466000033 ()2-s2.0-85122978379 (Scopus ID)
Konferanse
25th IEEE International Enterprise Distributed Object Computing Conference (IEEE EDOC), OCT 25-29, 2021, ELECTR NETWORK Gold Coast, Australia
Merknad

QC 20220218

Conference proceedings ISBN: 978-1-6654-4488-0

Tilgjengelig fra: 2022-02-18 Laget: 2022-02-18 Sist oppdatert: 2022-12-20bibliografisk kontrollert
Ebbers, F., Hacks, S. & Thakurta, R. (2021). The Business Impact of IIoT Vulnerabilities. In: : . Paper presented at PACIS 2021 Proceedings. , Article ID 225.
Åpne denne publikasjonen i ny fane eller vindu >>The Business Impact of IIoT Vulnerabilities
2021 (engelsk)Konferansepaper, Publicerat paper (Fagfellevurdert)
HSV kategori
Identifikatorer
urn:nbn:se:kth:diva-298704 (URN)
Konferanse
PACIS 2021 Proceedings
Merknad

QC 20210803

Tilgjengelig fra: 2021-07-12 Laget: 2021-07-12 Sist oppdatert: 2022-12-20bibliografisk kontrollert
Organisasjoner
Identifikatorer
ORCID-id: ORCID iD iconorcid.org/0000-0003-0478-9347