3 papers
cs.SE2024
Usefulness of data flow diagrams and large language models for security threat validation: a registered report
Winnie Bahati Mbaka, Katja Tuma
The arrival of recent cybersecurity standards has raised the bar for security assessments in organizations, but existing techniques don't always scale well. Threat analysis and ris…
cs.CR2022
A replication of a controlled experiment with two STRIDE variants
Winnie Mbaka, Katja Tuma
To avoid costly security patching after software deployment, security-by-design techniques (e.g., STRIDE threat analysis) are adopted in organizations to root out security issues b…
cs.SE2022
Human Aspect of Threat Analysis: A Replication
Katja Tuma, Winnie Mbaka
Background: Organizations are experiencing an increasing demand for security-by-design activities (e.g., STRIDE analyses) which require a high manual effort. This situation is wors…