Karsten Sohr

Affiliations:
  • University of Bremen, Center for Computing Technologies (TZI), Germany
  • University of Marburg, Department of Mathematics and Computer Science, Germany


According to our database1, Karsten Sohr authored at least 58 papers between 1999 and 2023.

Collaborative distances:
  • Dijkstra number2 of four.
  • Erdős number3 of four.

Timeline

Legend:

Book 
In proceedings 
Article 
PhD thesis 
Dataset
Other 

Links

Online presence:

On csauthors.net:

Bibliography

2023
Verständliche Informationssicherheit in Smarthome-Netzen.
Datenschutz und Datensicherheit (dud), May, 2023

Machine Learning for SAST: A Lightweight and Adaptable Approach.
Proceedings of the Computer Security - ESORICS 2023, 2023

2022
It's Long and Complicated! Enhancing One-Pager Privacy Policies in Smart Home Applications.
Proceedings of the NordiCHI '22: Nordic Human-Computer Interaction Conference, Aarhus, Denmark, October 8, 2022

"Do Metaphors Influence the Usability of Access Control?": A Gamified Survey.
Proceedings of the MuC '22: Mensch und Computer 2022, Darmstadt Germany, September 4, 2022

2021
Erfahrbarer Datenschutz und IT-Sicherheit in Smart Home-Anwendungen.
Datenschutz und Datensicherheit, 2021

A Category-Based Framework for Privacy-Aware Collaborative Access Control.
Proceedings of the Trust, Privacy and Security in Digital Business, 2021

[Engineering] eNYPD - Entry Points Detector Jakarta Server Faces Use Case.
Proceedings of the 21st IEEE International Working Conference on Source Code Analysis and Manipulation, 2021

2020
Towards supporting software assurance assessments by detecting security patterns.
Softw. Qual. J., 2020

Modeling and Validating Role-Based Authorization Policies for a Port Communication System with UML and OCL.
J. Object Technol., 2020

Praktische Erfahrungen und Ansätze für âSecurity by Design' auf Basis der STRIDE-Methodik.
Datenschutz und Datensicherheit, 2020

Static Extraction of Enforced Authorization Policies SeeAuthz.
Proceedings of the 20th IEEE International Working Conference on Source Code Analysis and Manipulation, 2020

Modeling Low-Level Network Configurations for Analysis, Simulation and Testing.
Proceedings of the Modellierung 2020, 19.-21. Februar 2020, Wien, Österreich., 2020

Enhancing Game-Based Learning Through Infographics in the Context of Smart Home Security.
Proceedings of the Entertainment Computing - ICEC 2020, 2020

Good vs. Evil: Investigating the Effect of Game Premise in a Smart Home Security Educational Game.
Proceedings of the CHI PLAY '20: The Annual Symposium on Computer-Human Interaction in Play, Virtual Event, Canada, November 2-4, 2020, 2020

2019
The Architectural Security Tool Suite - ARCHSEC.
Proceedings of the 19th International Working Conference on Source Code Analysis and Manipulation, 2019

Towards Effective Verification of Multi-Model Access Control Properties.
Proceedings of the 24th ACM Symposium on Access Control Models and Technologies, 2019

Make my Phone Secure!: Using Gamification for Mobile Security Settings.
Proceedings of Mensch und Computer 2019, Hamburg, Germany, September 8-11, 2019, 2019

What Could Go Wrong?: Raising Mobile Privacy and Security Awareness Through a Decision-Making Game.
Proceedings of the Extended Abstracts of the Annual Symposium on Computer-Human Interaction in Play Companion Extended Abstracts, 2019

HappyPermi: Presenting Critical Data Flows in Mobile Application to Raise User Security Awareness.
Proceedings of the Extended Abstracts of the 2019 CHI Conference on Human Factors in Computing Systems, 2019

2016
Integrating UML/OCL Derived Properties into Validation and Verification Processes.
Proceedings of the 16th International Workshop on OCL and Textual Modelling co-located with 19th International Conference on Model Driven Engineering Languages and Systems (MODELS 2016), 2016

Automatically Extracting Threats from Extended Data Flow Diagrams.
Proceedings of the Engineering Secure Software and Systems - 8th International Symposium, 2016

2015
Understanding the implemented access control policy of Android system services with slicing and extended static checking.
Int. J. Inf. Sec., 2015

Achieving Security Assurance with Assertion-based Application Construction.
EAI Endorsed Trans. Collab. Comput., 2015

Monitoring Database Access Constraints with an RBAC Metamodel: A Feasibility Study.
Proceedings of the Engineering Secure Software and Systems - 7th International Symposium, 2015

2014
Zertifizierte Datensicherheit für Android-Anwendungen auf Basis statischer Programmanalysen.
Proceedings of the Sicherheit 2014: Sicherheit, 2014

2013
Employing UML and OCL for designing and analysing role-based access control.
Math. Struct. Comput. Sci., 2013

UML/OCL based Design and Analysis of Role-Based Access Control Policies.
Proceedings of the Joint Proceedings of the First International Workshop On the Globalization of Modeling Languages (GEMOC 2013) and the First International Workshop: Towards the Model Driven Organization (AMINO 2013) Co-located with the 16th International Conference on Model Driven Engineering Languages and Systems (MODELS 2013), Miami, USA, September 29, 2013

Extracting and Analyzing the Implemented Security Architecture of Business Applications.
Proceedings of the 17th European Conference on Software Maintenance and Reengineering, 2013

Verifying Access Control Properties with Design by Contract: Framework and Lessons Learned.
Proceedings of the 37th Annual IEEE Computer Software and Applications Conference, 2013

The Transitivity-of-Trust Problem in Android Application Interaction.
Proceedings of the 2013 International Conference on Availability, Reliability and Security, 2013

2012
Comprehensive two-level analysis of role-based delegation and revocation policies with UML and OCL.
Inf. Softw. Technol., 2012

The Transitivity of Trust Problem in the Interaction of Android Applications
CoRR, 2012

An Approach to Detecting Inter-Session Data Flow Induced by Object Pooling.
Proceedings of the Information Security and Privacy Research, 2012

IO: An Interconnected Asset Ontology in Support of Risk Management Processes.
Proceedings of the Seventh International Conference on Availability, 2012

2011
Unternehmensübergreifender Austausch von sicherheitsrelevantem Wissen.
Datenschutz und Datensicherheit, 2011

An Android Security Case Study with Bauhaus.
Proceedings of the 18th Working Conference on Reverse Engineering, 2011

Comprehensive Two-Level Analysis of Static and Dynamic RBAC Constraints with UML and OCL.
Proceedings of the Fifth International Conference on Secure Software Integration and Reliability Improvement, 2011

Software security aspects of Java-based mobile phones.
Proceedings of the 2011 ACM Symposium on Applied Computing (SAC), TaiChung, Taiwan, March 21, 2011

An Architecture-Centric Approach to Detecting Security Patterns in Software.
Proceedings of the Engineering Secure Software and Systems - Third International Symposium, 2011

2010
Grundzüge eines Sicherheitskonzeptes für Arztpraxen mit Hilfe von Attack Trees und unter Berücksichtigung der Gesundheitstelematik.
Proceedings of the perspeGKtive 2010, 2010

Typed Linear Chain Conditional Random Fields and Their Application to Intrusion Detection.
Proceedings of the Intelligent Data Engineering and Automated Learning, 2010

Towards formal specification and verification of a role-based authorization engine using JML.
Proceedings of the ICSE Workshop on Software Engineering for Secure Systems, 2010

Secure Mobile Business Information Processing.
Proceedings of the IEEE/IFIP 8th International Conference on Embedded and Ubiquitous Computing, 2010

Idea: Towards Architecture-Centric Security Analysis of Software.
Proceedings of the Engineering Secure Software and Systems, Second International Symposium, 2010

2008
Analyzing and Managing Role-Based Access Control Policies.
IEEE Trans. Knowl. Data Eng., 2008

Implementing Advanced RBAC Administration Functionality with USE.
Electron. Commun. Eur. Assoc. Softw. Sci. Technol., 2008

Supporting Agile Development of Authorization Rules for SME Applications.
Proceedings of the Collaborative Computing: Networking, 2008

Enforcing Role-Based Access Control Policies in Web Services with UML and OCL.
Proceedings of the Twenty-Fourth Annual Computer Security Applications Conference, 2008

2007
Angepasste Benutzerschnittstellen für das Wearable Computing im Projekt SiWear.
Proceedings of the Mensch & Computer 2007 Workshopband, 2007

2006
A model-checking approach to analysing organisational controls in a loan origination process.
Proceedings of the 11th ACM Symposium on Access Control Models and Technologies, 2006

2005
Articulating and enforcing authorisation policies with UML and OCL.
ACM SIGSOFT Softw. Eng. Notes, 2005

Formal specification of role-based security policies for clinical information systems.
Proceedings of the 2005 ACM Symposium on Applied Computing (SAC), 2005

Specification and Validation of Authorisation Constraints Using UML and OCL.
Proceedings of the Computer Security, 2005

2004
A First Step Towards Formal Verification of Security Policy Properties for RBAC.
Proceedings of the 4th International Conference on Quality Software (QSIC 2004), 2004

2003
A temporal-logic extension of role-based access control covering dynamic separation of duties.
Proceedings of the 10th International Symposium on Temporal Representation and Reasoning / 4th International Conference on Temporal Logic (TIME-ICTL 2003), 2003

2001
Die Sicherheitsaspekte von mobilem Code.
PhD thesis, 2001

Pini - A Jini-Like Plug&Play Technology for the KVM/CLDC.
Proceedings of the Innovative Internet Computing Systems, 2001

1999
Nicht verifizierter Code: Eine neue Sicherheitslücke in Java.
Proceedings of the JIT '99, 1999


  Loading...