5 papers
Validating Threat Modeling Results with the Help of Vulnerable Test Applications
Oleksandr Adamov, Davide Fucci, Felix Viktor Jedrzejewski +2
Validating threat modeling results remains difficult because completeness is hard to judge without an external oracle. Existing studies often rely on expert-produced reference mode…
Experience Report on the Adaptable Integration of Requirements Engineering Courses into Curricula for Professionals
Oleksandr Kosenkov, Konstantin Blaschke, Tony Gorschek +3
There is a growing demand for software engineering education (SEE) for professionals because of the increasing demand, active evolution of the technological landscape, and changes…
The Attribution Story of WhisperGate: An Academic Perspective
Oleksandr Adamov, Anders Carlsson
This paper explores the challenges of cyberattack attribution, specifically APTs, applying the case study approach for the WhisperGate cyber operation of January 2022 executed by t…
Policy-driven Software Bill of Materials on GitHub: An Empirical Study
Oleksii Novikov, Davide Fucci, Oleksandr Adamov +1
Background. The Software Bill of Materials (SBOM) is a machine-readable list of all the software dependencies included in a software. SBOM emerged as way to assist securing the sof…
ThreMoLIA: Threat Modeling of Large Language Model-Integrated Applications
Felix Viktor Jedrzejewski, Davide Fucci, Oleksandr Adamov
Large Language Models (LLMs) are currently being integrated into industrial software applications to help users perform more complex tasks in less time. However, these LLM-Integrat…