2 citations · 2 across the 2 of their papers we have counts for
3 papers · 1 filter
Semi-Automated Threat Modeling of Cloud-Based Systems Through Extracting Software Architecture from Configuration and Network Flow
Nicholas Pecka, Lotfi Ben Othmane, Bharat Bhargava +1
Traditional threat modeling occurs during design, but cloud deployments introduce unanticipated threats, especially multi-stage attacks chaining vulnerabilities across trust bounda…
Toward Automated Security Risk Detection in Large Software Using Call Graph Analysis
Nicholas Pecka, Lotfi Ben Othmane, Renee Bryce
Threat modeling plays a critical role in the identification and mitigation of security risks; however, manual approaches are often labor intensive and prone to error. This paper in…
Making Secure Software Insecure without Changing Its Code: The Possibilities and Impacts of Attacks on the DevOps Pipeline
Nicholas Pecka, Lotfi ben Othmane, Altaz Valani
Companies are misled into thinking they solve their security issues by using a DevSecOps system. This paper aims to answer the question: Could a DevOps pipeline be misused to trans…