6 papers
A Bird's-Eye View on Security Considerations in RFCs
Jukka Ruohonen, Qusai Ramadan
Request for comments (RFCs) are Internet standards, memorandums, and related technical documents about core Internet protocols made via and released by the Internet Engineering Tas…
An Alignment Between the CRA's Essential Requirements and the ATT&CK's Mitigations
Jukka Ruohonen, Eun-Young Kang, Qusai Ramadan
The paper presents an alignment evaluation between the mitigations present in the MITRE's ATT&CK framework and the essential cyber security requirements of the recently introduced…
Towards Systematic Specification and Verification of Fairness Requirements: A Position Paper
Qusai Ramadan, Jukka Ruohonen, Abhishek Tiwari +2
Decisions suggested by improperly designed software systems might be prone to discriminate against people based on protected characteristics, such as gender and ethnicity. Previous…
Tracing Vulnerability Propagation Across Open Source Software Ecosystems
Jukka Ruohonen, Qusai Ramadan
The paper presents a traceability analysis of how over 84 thousand vulnerabilities have propagated across 28 open source software ecosystems. According to the results, the propagat…
Snaps: Bloated and Outdated?
Jukka Ruohonen, Qusai Ramadan
Snap is an alternative software packaging system developed by Canonical and provided by default in the Ubuntu Linux distribution. Given the heterogeneity of various Linux distribut…
The Popularity Hypothesis in Software Security: A Large-Scale Replication with PHP Packages
Jukka Ruohonen, Qusai Ramadan
There has been a long-standing hypothesis that a software's popularity is related to its security or insecurity in both research and popular discourse. There are also a few empiric…