Denis Hatebur
Dr.-Ing. Dipl.-Inform. Denis Hatebur
Room: BB 918
Tel.: +49 203 379 3582
Fax: +49 379 4490
E-Mail: denis.hatebur[at]uni-duisburg-essen.de
· Pattern-Based Software Development (problem frames)
· Software Quality Assurance and Dependability (formal verification and testing)
· Formal Methods and Software Specification Techniques (B, LUSTRE, UML)
· Embedded Systems (mobile and distributed applications)
· Software Quality Assurance and Dependability (formal verification and testing)
· Formal Methods and Software Specification Techniques (B, LUSTRE, UML)
· Embedded Systems (mobile and distributed applications)
| Year | Title | Author | Journal/Proceedings | Publisher | |
|---|---|---|---|---|---|
| 2019 | Integration of Development Interface Agreement, Supplier Safety Assessment and Safety Management for Driver Assistance Systems | Frese, T., Côté, I., Hatebur, D. & Heisel, M. | Mobilität in Zeiten der Veränderung | Springer | |
BibTeX:
@incollection{mobi19,
year = {2019},
title = {Integration of Development Interface Agreement, Supplier Safety Assessment and Safety Management for Driver Assistance Systems},
booktitle = {Mobilit{\"{a}}t in Zeiten der Ver{\"{a}}nderung},
author = {Frese, Thomas and C{\^{o}}t{\'{e}}, Isabelle and Hatebur, Denis and Heisel, Maritta},
publisher = {Springer},
pages = {241 -- 251},
url = {www.springer.com}
}
|
|||||
| 2019 | Combining Safety and Security in Autonomous Cars Using Blockchain Technologies | Davi, L., Hatebur, D., Heisel, M. & Wirtz, R. | Proceedings of the International Conference on Computer Safety, Reliability and Security (SAFECOMP) | Springer | |
BibTeX:
@proceedings{,
year = {2019},
title = {Combining Safety and Security in Autonomous Cars Using Blockchain Technologies},
booktitle = {Proceedings of the International Conference on Computer Safety, Reliability and Security (SAFECOMP)},
author = {Davi, Lucas and Hatebur, Denis and Heisel, Maritta and Wirtz, Roman},
publisher = {Springer},
url = {www.springer.com}
}
|
|||||
| 2018 | Functional Safety Processes and Driver Assistance Systems: Evolution or Revolution? | Frese, T., Hatebur, D., Côté, I. & Heisel, M. | Mobilität und digitale Transformation - Technische und betriebswirtschaftliche Aspekte | Springer | |
BibTeX:
@incollection{mobi2018,
year = {2018},
title = {Functional Safety Processes and Driver Assistance Systems: Evolution or Revolution?},
booktitle = {Mobilit{\"{a}}t und digitale Transformation - Technische und betriebswirtschaftliche Aspekte},
author = {Frese, Thomas and Hatebur, Denis and C{\^{o}}t{\'{e}}, Isabelle and Heisel, Maritta},
publisher = {Springer},
pages = {199 - 216},
url = {www.springer.com}
}
|
|||||
| 2017 | A structured and systematic model-based development method for automotive systems, considering the OEM/supplier interface | Beckers, K., Côté, I., Frese, T., Hatebur, D. & Heisel, M. | Reliability Engineering & System Safety | ||
| Abstract: Abstract The released ISO 26262 standard for automotive systems requires to create a hazard analysis and risk assessment and to create safety goals, to break down these safety goals into functional safety requirements in the functional safety concept, to specify technical safety requirements in the safety requirements specification, and to perform several validation and verification activities. Experience shows that the definition of technical safety requirements and the planning and execution of validation and verification activities has to be done jointly by OEMs and suppliers. In this paper, we present a structured and model-based safety development approach for automotive systems. The different steps are based on Jackson's requirement engineering. The elements are represented by UML notation extended with stereotypes. The UML model enables a rigorous validation of several constraints. We make use of the results of previously published work to be able to focus on the OEM/supplier interface. We illustrate our method using a three-wheeled-tilting control system (3WTC) as running example and case study. | |||||
BibTeX:
@article{Beckers2016-4,
year = {2017},
title = {A structured and systematic model-based development method for automotive systems, considering the OEM/supplier interface},
author = {Beckers, Kristian and C{\^{o}}t{\'{e}}, Isabelle and Frese, Thomas and Hatebur, Denis and Heisel, Maritta},
journal = {Reliability Engineering \& System Safety},
volume = {158},
pages = {172 - 184},
note = {Special Sections : Reliability and Safety Certification of Software-Intensive Systems},
url = {http://www.sciencedirect.com/science/article/pii/S0951832016304057},
doi = {10.1016/j.ress.2016.08.018}
}
|
|||||
| 2017 | A structured hazard analysis and risk assessment method for automotive systems—A descriptive study | Beckers, K., Holling, D., Côté, I. & Hatebur, D. | Reliability Engineering & System Safety | ||
| Abstract: Abstract The 2011 release of the first version of the ISO 26262 standard for automotive systems demand the elicitation of safety goals following a rigorous method for hazard and risk analysis. Companies are struggling with the adoption of the standard due to ambiguities, documentation demands and the alignment of the standards demands to existing processes. We previously proposed a structured engineering method to deal with these problems developed in applying action research together with an OEM. In this work, we evaluate how applicable the method is for junior automotive software engineers by a descriptive study. We provided the method to 8 members of the master course Automotive Software Engineering (ASE) at the Technical University Munich. The participants have each been working in the automotive industry for 1–4 years in parallel to their studies. We investigated their application of our method to an electronic steering column lock system. The participants applied our method in a first round alone and afterwards discussed their results in groups. Our data analysis revealed that the participants could apply the method successfully and the hazard analysis and risk assessment achieved a high precision and productivity. Moreover, the precision could be improved significantly during group discussions. | |||||
BibTeX:
@article{Beckers2016-5,
year = {2017},
title = {A structured hazard analysis and risk assessment method for automotive systems—A descriptive study},
author = {Beckers, Kristian and Holling, Dominik and C{\^{o}}t{\'{e}}, Isabelle and Hatebur, Denis},
journal = {Reliability Engineering & System Safety},
volume = {158},
pages = {185 - 195},
note = {Special Sections : Reliability and Safety Certification of Software-Intensive Systems},
url = {http://www.sciencedirect.com/science/article/pii/S0951832016305002},
doi = {10.1016/j.ress.2016.09.004}
}
|
|||||
| 2017 | Deriving Safety Requirements according to ISO 26262 for complex systems: A method applied in the automotive industrie | Frese, T., Heisel, M., Hatebur, D. & Côté, I. | Innovative Produkte und Dienstleisungen in der Mobilität | ||
BibTeX:
@article{mobi2017,
year = {2017},
title = {Deriving Safety Requirements according to ISO 26262 for complex systems: A method applied in the automotive industrie},
author = {Frese, Thomas and Heisel, Maritta and Hatebur, Denis and C{\^{o}}t{\'{e}}, Isabelle},
journal = {Innovative Produkte und Dienstleisungen in der Mobilit{\"{a}}t},
volume = {Wissenschaftsforum Mobilit{\"{a}}t 8},
pages = {211-222}
}
|
|||||
| 2017 | Performing a More Realistic Safety Analysis by Means of the Six-Variable Model | Ulfat-Bunyadi, N., Hatebur, D. & Heisel, M. | Automotive - Safety & Security 2017 | GI | |
| Abstract: Safety analysis typically consists of hazard analysis and risk assessment (HARA) as well as fault tree analysis (FTA). During the first, possible hazardous events are identified. During the latter, failure events that can lead to a hazardous event are identified. Usually, the focus of FTA is on identifying failure events within the system. However, a hazardous event may also occur due to invalid assumptions about the system’s environment. If the possibility that environmental assumptions turn invalid is considered during safety analysis, a more realistic and complete safety analysis is performed than without considering them. Yet, a major challenge consists in eliciting first the ‘real’ environmental assumptions. Developers do not always document assumptions, and often they are not aware of the assumptions they make. In previous work, we defined the Six-Variable Model which provides support in making the ‘real’ environmental assumptions explicit. In this paper, we define a safety analysis method based on the Six-Variable Model. The benefit of our method is that we make the environmental assumptions explicit and consider them in safety analysis. In this way, assumptions that are too strong and too risky can be identified and weakened or abandoned if necessary. | |||||
BibTeX:
@inproceedings{UHH-ASS2017,
year = {2017},
title = {Performing a More Realistic Safety Analysis by Means of the Six-Variable Model},
booktitle = {Automotive - Safety & Security 2017},
author = {Ulfat-Bunyadi, Nelufar and Hatebur, Denis and Heisel, Maritta},
publisher = {GI},
volume = {P-269},
series = {Lecture Notes in Informatics},
pages = {135-148},
url = {https://dl.gi.de/handle/20.500.12116/152}
}
|
|||||
| 2015 | A Structured Validation and Verification Method for Automotive Systems considering the OEM/Supplier Interface | Beckers, K., Côté, I., Frese, T., Hatebur, D. & Heisel, M. | Proceedings of the International Conference on Computer Safety, Reliability and Security (SAFECOMP) | Springer | |
| Abstract: The released ISO 26262 standard for automotive systems requires several validation and verification activities. These validation and verification activities have to be planned and performed jointly by the OEMs and the suppliers. In this paper, we present a systematic, structured and model-based method to plan the required validation and verification activities and collect the results. Planning and the documentation of performed activities are represented by a UML notation extended with stereotypes. The UML model supports the creation of the artifacts required by ISO 26262, enables document generation and a rigorous check of several constraints expressed in OCL. We illustrate our method using the example of an electronic steering column lock system. | |||||
BibTeX:
@inproceedings{fs2015,
year = {2015},
title = {A Structured Validation and Verification Method for Automotive Systems considering the OEM/Supplier Interface},
booktitle = {Proceedings of the International Conference on Computer Safety, Reliability and Security (SAFECOMP)},
author = {Beckers, Kristian and C{\^{o}}t{\'{e}}, Isabelle and Frese, Thomas and Hatebur, Denis and Heisel, Maritta},
publisher = {Springer},
volume = {9337},
pages = {90 - 107},
url = {www.springer.com}
}
|
|||||
| 2015 | A Pattern-Based and Tool-Supported Risk Analysis Method Compliant to ISO 27001 for Cloud Systems | Alebrahim, A., Faßbender, S., Hatebur, D., Goeke, L. & Côté, I. | International Journal of Secure Software Engineering (IJSSE) | ||
| Abstract: Security plays a major role when companies decide whether to move to the cloud and use cloud services. One way to obtain the confidence of the customers is to establish security mechanisms when using clouds. The ISO 27001 standard provides general concepts for establishing information security in an organization. Risk analysis is an essential part in the ISO 27001 standard for achieving information security. This standard, however, contains ambiguous descriptions. In addition, it does not stipulate any method to identify assets, threats, and vulnerabilities. In this paper, we present a structured and pattern based method to conduct risk analysis for cloud computing systems. It is tailored to SMEs. Our method addresses the requirements of the ISO 27001. We make use of the cloud system analysis pattern, security requirement patterns, threat patterns, and control patterns for conducting the risk analysis. The method is illustrated by a cloud logistics application example. | |||||
BibTeX:
@article{IJSSE2015,
year = {2015},
title = {A Pattern-Based and Tool-Supported Risk Analysis Method Compliant to ISO 27001 for Cloud Systems},
author = {Alebrahim, Azadeh and Fa{\ss}bender, Stephan and Hatebur, Denis and Goeke, Ludger and C{\^{o}}t{\'{e}}, Isabelle},
journal = {International Journal of Secure Software Engineering (IJSSE)},
volume = {6},
number = {1},
pages = {24-46},
url = {http://www.igi-global.com/chapter/a-pattern-based-and-tool-supported-risk-analysis-method-compliant-to-iso-27001-for-cloud-systems/128695}
}
|
|||||
| 2014 | Supporting Common Criteria Security Analysis with Problem Frames | Beckers, K., Hatebur, D. & Heisel, M. | Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications (JoWUA) | Innovative Information Science & Technology Research Group (ISYOU) | |
| Abstract: Security standards, e.g., the Common Criteria (ISO 15408), are applied by software vendors to establish a level of confidence that the security functionality of their products and their applied assurance measures are sufficient. To get a Common Criteria certification, a comprehensible set of documents is necessary, including a detailed threat analysis and security objective elicitation. We focus on improving the Common Criteria threat analysis and the derivation of security objectives in our work. Our method is based upon an attacker model, which considers different attacker types, e.g., software attackers, that threaten only specific parts of a system. We provide tool support for checking the consistency and the completeness of the specified software systems using OCL expressions. For example, we check if all types of attackers have been considered for a specific domain, we check for all software domains that either a software attacker is considered or an assumption is documented that excludes software attackers, and we check if all threats are addressed by security objectives. Moreover, we can generate tables and texts from our UML models to satisfy the Common Criteria documentation demands. For instance, we can generate Common Criteria specific cross-table, which maps every security objective and assumption to a specific threat. The consistency checks are integrated in our structured method for threat analysis that considers the Common Criteria’s (CC) demands for documentation of the system in its environment and the reasoning that all threats are discovered and addressed. With our support tool UML4PF (that extends a UML tool and contains e.g., a UML profile and an OCL validator), we support security reasoning, validation of models, and we are able to generate Common Criteria-compliant documentation using model-to-text transformations. Our threat analysis method can also be used for threat analysis without the common criteria, because it uses a specific part of the UML profile that can be adapted to other demands with little effort. For example, it could be adapted for other security standards like ISO 27001.We illustrate our approach with the development of a smart metering gateway system. |
|||||
BibTeX:
@article{Beckers2014-Jowua,
year = {2014},
title = {Supporting Common Criteria Security Analysis with Problem Frames},
author = {Beckers, Kristian and Hatebur, Denis and Heisel, Maritta},
journal = {Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications (JoWUA)},
publisher = {Innovative Information Science \& Technology Research Group (ISYOU)},
volume = {5},
number = {1},
pages = {37-63},
url = {http://isyou.info/}
}
|
|||||
| 2014 | Pattern-Based and ISO 27001 Compliant Risk Analysis for Cloud Systems | Alebrahim, A., Hatebur, D. & Goeke, L. | Proceedings of the 1st International Workshop on Evolving Security and Privacy Requirements Engineering (ESPRE) | IEEE | |
| Abstract: For accepting clouds and using cloud services by companies, security plays a decisive role. For cloud providers, one way to obtain customers’ confidence is to establish security mechanisms when using clouds. The ISO 27001 standard provides general concepts for establishing information security in an organization. Risk analysis is an essential part in the ISO 27001 standard for achieving information security. This standard, however, contains ambiguous descriptions. In addition, it does not stipulate any method to identify assets, threats, and vulnerabilities. In this paper, we present a structured and patternbased method to conduct risk analysis for cloud computing systems. It is tailored to SMEs. Our method addresses the requirements of the ISO 27001. We make use of the cloud system analysis pattern, security requirement patterns, threat patterns, and control patterns for conducting the risk analysis. The method is illustrated by a cloud logistics application example. | |||||
BibTeX:
@inproceedings{ESPRE2014,
year = {2014},
title = {Pattern-Based and ISO 27001 Compliant Risk Analysis for Cloud Systems},
booktitle = {Proceedings of the 1st International Workshop on Evolving Security and Privacy Requirements Engineering (ESPRE)},
author = {Alebrahim, Azadeh and Hatebur, Denis and Goeke, Ludger},
publisher = {IEEE},
pages = {42-47},
url = {https://www.ieee.org}
}
|
|||||
| 2014 | A Structured Comparison of Security Standards | Beckers, K., Côté, I., Fenz, S., Hatebur, D. & Heisel, M. | Advances in Engineering Secure Future Internet Services and Systems | Springer | |
| Abstract: A number of dierent security standards exist and it is dif- cult to choose the right one for a particular project or to evaluate if the right standard was chosen for a certication. These standards are often long and complex texts, whose reading and understanding takes up a lot of time. We provide a conceptual model for security standards that relies upon existing research and contains concepts and phases of security standards. In addition, we developed a template based upon this model, which can be instantiated for given security standard. These instantiated templates can be compared and help software and security engineers to understand the dierences of security standards. In particular, the instantiated templates explain which information and what level of detail a system document according to a certain security standard contains. We applied our method to the well known international security standards ISO 27001 and Common Criteria, and the German IT-Grundschutz standards, as well. |
|||||
BibTeX:
@inproceedings{Lopez2014,
year = {2014},
title = {A Structured Comparison of Security Standards},
booktitle = {Advances in Engineering Secure Future Internet Services and Systems},
author = {Beckers, Kristian and C{\^{o}}t{\'{e}}, Isabelle and Fenz, Stefan and Hatebur, Denis and Heisel, Maritta},
publisher = {Springer},
number = {8431},
series = {LNCS State-of-the-Art Surveys},
pages = {1-34},
url = {http://www.springerlink.com/}
}
|
|||||
| 2014 | Systematic Derivation of Functional Safety Requirements for Automotive Systems | Beckers, K., Côté, I., Frese, T., Hatebur, D. & Heisel, M. | Proceedings of the International Conference on Computer Safety, Reliability and Security (SAFECOMP) | Springer | |
| Abstract: The released ISO 26262 standard for automotive systems requires breaking down safety goals from the hazard analysis and risk assessment into functional safety requirements in the functional safety concept. It has to be justied that the dened functional safety requirements are suitable to achieve the stated safety goals. In this paper, we present a systematic, structured and model-based method to dene functional safety requirements using a given set of safety goals. The rationale for safety goal achievement, the relevant attributes of the functional safety requirements, and their relationships are represented by a UML notation extended with stereotypes. The UML model enables a rigorous validation of several constraints expressed in OCL. We illustrate our method using an example electronic steering column lock system. |
|||||
BibTeX:
@inproceedings{safecomp2014,
year = {2014},
title = {{Systematic Derivation of Functional Safety Requirements for Automotive Systems}},
booktitle = {Proceedings of the International Conference on Computer Safety, Reliability and Security (SAFECOMP)},
author = {Beckers, Kristian and C{\^{o}}t{\'{e}}, Isabelle and Frese, Thomas and Hatebur, Denis and Heisel, Maritta},
publisher = {Springer},
series = {LNCS 8666},
pages = {65--80},
url = {https://link.springer.com/}
}
|
|||||
| 2013 | A Problem-based Threat Analysis in compliance with Common Criteria | Beckers, K., Hatebur, D. & Heisel, M. | Proceedings of the International Conference on Availability, Reliability and Security (ARES) | IEEE Computer Society | |
| Abstract: In order to gain their customers’ trust, software vendors can certify their products according to security standards, e.g., the Common Criteria (ISO 15408). A Common Criteria certification requires a comprehensible documentation of the software product, including a detailed threat analysis. In our work, we focus on improving that threat analysis. Our method is based upon an attacker model, which considers attacker types like software attacker that threaten only specific parts of a system. We use OCL expressions to check if all attackers for a specific domain have been considered. For example, we propose a computer-aided method that checks if all software systems have either considered a software attacker or documented an assumption that excludes software attackers. Hence, we propose a structured method for threat analysis that considers the Common Criteria’s (CC) demands for documentation of the system in its environment and the reasoning that all threats are discovered. We use UML4PF, a UML profile and support tool for Jackson’s problem frame method and OCL for supporting security reasoning, validation of models, and also to generate Common Criteria-compliant documentation. Our threat analysis method can also be used for threat analysis without the common criteria, because it uses a specific part of the UML profile that can be adapted to other demands with little effort. We illustrate our approach with the development of a smart metering gateway system. |
|||||
BibTeX:
@inproceedings{Beckers2013-ares1,
year = {2013},
title = {A Problem-based Threat Analysis in compliance with Common Criteria},
booktitle = {Proceedings of the International Conference on Availability, Reliability and Security ({ARES})},
author = {Beckers, Kristian and Hatebur, Denis and Heisel, Maritta},
publisher = {IEEE Computer Society},
pages = {111-120},
url = {http://www.ieee.org/}
}
|
|||||
| 2013 | A Structured and Model-Based Hazard Analysis and Risk Assessment Method for Automotive Systems | Beckers, K., Frese, T., Hatebur, D. & Heisel, M. | Proceedings of the 24th IEEE International Symposium on Software Reliability Engineering | IEEE Computer Society | |
| Abstract: The released ISO 26262 standard requires a hazard analysis and risk assessment for automotive systems to determine the necessary safety measures to be implemented for a certain feature. In this paper, we present a structured and model-based hazard analysis and risk assessment method for automotive systems. The hazard analysis and risk assessment are based on a requirements engineering process using problem frames. Their elements are represented by a UML notation extended with stereotypes. The UML model enables a rigorous validation of several constraints expressed in OCL. We illustrate our method using an electronic steering column lock system. |
|||||
BibTeX:
@inproceedings{Beckers2013-issre,
year = {2013},
title = {A Structured and Model-Based Hazard Analysis and Risk Assessment Method for Automotive Systems},
booktitle = {Proceedings of the 24th IEEE International Symposium on Software Reliability Engineering},
author = {Beckers, Kristian and Frese, Thomas and Hatebur, Denis and Heisel, Maritta},
publisher = {IEEE Computer Society},
pages = {238-247},
url = {http://www.ieee.org/}
}
|
|||||
| 2013 | Common Criteria CompliAnt Software Development (CC-CASD) | Beckers, K., Faßbender, S., Hatebur, D., Heisel, M. & Côté, I. | Proceedings of the 28th Annual ACM Symposium on Applied Computing (SAC) | ACM | |
| Abstract: In order to gain their customers’ trust, software vendors can certify their products according to security standards, e.g., the Common Criteria (ISO 15408). However, a Common Criteria certification requires a comprehensible documentation of the software product. The creation of this documentation results in high costs in terms of time and money. We propose a software development process that supports the creation of the required documentation for a Common Criteria certification. Hence, we do not need to create the documentation after the software is built. Furthermore, we propose to use an enhanced version of the requirements-driven software engineering process called ADIT to discover possible problems with the establishment of Common Criteria documents. We aim to detect these issues before the certification process. Thus, we avoid expensive delays of the certification effort. ADIT provides a seamless development approach that allows consistency checks between different kinds of UML models. ADIT also supports traceability from security requirements to design documents. We illustrate our approach with the development of a smart metering gateway system. |
|||||
BibTeX:
@inproceedings{SAC2013,
year = {2013},
title = {{Common Criteria CompliAnt Software Development (CC-CASD)}},
booktitle = {Proceedings of the 28th Annual ACM Symposium on Applied Computing (SAC)},
author = {Beckers, Kristian and Fa{\ss}bender, Stephan and Hatebur, Denis and Heisel, Maritta and C{\^{o}}t{\'{e}}, Isabelle},
publisher = {ACM},
pages = {1298--1304},
url = {https://dl.acm.org/citation.cfm?id=2480604}
}
|
|||||
| 2012 | Enterprise Applications: From Requirements to Design | Choppy, C., Reggio, G., Hatebur, D. & Heisel, M. | Aligning Enterprise, System, and Software Architectures | IGI Global | |
BibTeX:
@incollection{CRHH2012,
year = {2012},
title = {Enterprise Applications: From Requirements to Design},
booktitle = {Aligning Enterprise, System, and Software Architectures},
author = {Choppy, Christine and Reggio, G. and Hatebur, Denis and Heisel, Maritta},
publisher = {IGI Global},
pages = {96--117},
url = {www.igi-global.com}
}
|
|||||
| 2012 | Pattern- and Component-based Development of Dependable Systems | Hatebur, D. | School: University of Duisburg-Essen | Deutscher Wissenschafts-Verlag (DWV) Baden-Baden | |
BibTeX:
@phdthesis{Hatebur2012,
year = {2012},
title = {Pattern- and Component-based Development of Dependable Systems},
author = {Hatebur, Denis},
publisher = {Deutscher Wissenschafts-Verlag (DWV) Baden-Baden},
school = {University of Duisburg-Essen},
url = {http://www.dwverlag.de/index.php?art=Pattern-+and+Component-based+Development+of+Dependable+Systems&mod=Onlineshop&view=Artikel&abid=166}
}
|
|||||
| 2012 | Designing Architectures from Problem Descriptions by Interactive Model Transformation | Alebrahim, A., Côté, I., Heisel, M., Choppy, C. & Hatebur, D. | Proceedings 27th Symposium on Applied Computing | ACM | |
| Abstract: We present a structured approach to systematically derive a software architecture from a given problem description based on problem frames and a description of the environment. Our aim is to re-use the elements of the problem descriptions in creating the architecture. The derivation is performed by transforming the problem description into an initial architecture, where each subproblem corresponds to a component. The transformation is supported by model transformation rules, formally specified as operations with pre- and postconditions. This specification serves as a blueprint for a tool supporting the architectural design. We illustrate our method by the example of a patient care system. |
|||||
BibTeX:
@inproceedings{SAC2012,
year = {2012},
title = {Designing Architectures from Problem Descriptions by Interactive Model Transformation},
booktitle = {Proceedings 27th Symposium on Applied Computing},
author = {Alebrahim, Azadeh and C{\^{o}}t{\'{e}}, Isabelle and Heisel, Maritta and Choppy, Christine and Hatebur, Denis},
publisher = {ACM},
pages = {1256--1258},
url = {http://dl.acm.org/}
}
|
|||||
| 2011 | Towards Systematic Integration of Quality Requirements into Software Architecture | Alebrahim, A., Hatebur, D. & Heisel, M. | Proceedings of the 5th European Conference on Software Architecture (ECSA 2011) | Springer | |
| Abstract: We present a model- and pattern-based approach that allows software engineers to take quality requirements into account right from the beginning of the software development process. The approach comprises requirements analysis as well as the software architecture design, in which quality requirements are re ected explicitly. |
|||||
BibTeX:
@inproceedings{AHH2011a,
year = {2011},
title = {Towards Systematic Integration of Quality Requirements into Software Architecture},
booktitle = {Proceedings of the 5th European Conference on Software Architecture (ECSA 2011)},
author = {Alebrahim, Azadeh and Hatebur, Denis and Heisel, Maritta},
publisher = {Springer},
series = {LNCS 6903},
pages = {17--25},
url = {https://link.springer.com/}
}
|
|||||
| 2011 | A Method to Derive Software Architectures from Quality Requirements | Alebrahim, A., Hatebur, D. & Heisel, M. | Proceedings of the 18th Asia-Pacific Software Engineering Conference (APSEC) | IEEE Computer Society | |
| Abstract: We present a model- and pattern-based method that allows software engineers to take quality requirements into account right from the beginning of the software development process. The method comprises requirements analysis as well as the derivation of a software architecture from requirements documents, in which quality requirements are reflected explicitly. For requirements analysis, we use an enhancement of the problem frame approach, where software development problems are represented by problem diagrams. The derivation of a software architecture starts from a set of problem diagrams, annotated with functional as well as quality requirements. First, we set up an initial software architecture, taking into account the decomposition of the overall software development problem into subproblems. Then, we incorporate quality requirements into that architecture by using security or performance patterns or mechanisms. The method is toolsupported, which allows developers to check semantic integrity conditions in the different models | |||||
BibTeX:
@inproceedings{AHH2011b,
year = {2011},
title = {A Method to Derive Software Architectures from Quality Requirements},
booktitle = {Proceedings of the 18th Asia-Pacific Software Engineering Conference ({APSEC})},
author = {Alebrahim, Azadeh and Hatebur, Denis and Heisel, Maritta},
publisher = {IEEE Computer Society},
pages = {322--330},
url = {https://www.ieee.org/}
}
|
|||||
| 2011 | Systematic Architectural Design based on Problem Patterns | Choppy, C., Hatebur, D. & Heisel, M. | Relating Software Requirements and Architectures | Springer | |
| Abstract: We present a method to derive systematically software architectures from problem descriptions. The problem descriptions are based on the artifacts that are set up when following Jackson's problem frame approach. They include a context diagram describing the overall problem situation and a set of problem diagrams that describe subproblems of the overall software development problem. The different subproblems should be instances of problem frames, which are patterns for simple software development problems. Starting from these pattern-based problem descriptions, we derive a software architecture in three steps. An initial architecture contains one component for each subproblem. In the second step, we apply different architectural and design patterns and introduce coordinator and facade components. In the final step, the components of the intermediate architecture are re-arranged to form a layered architecture, and interface and driver components are added. All artefacts are expressed as UML diagrams, using specific UML profiles. The method is tool-supported. Our tool supports developers in setting up the diagrams, and it checks different validation conditions concerning the semantic integrity and the coherence of the different diagrams. We illustrate the method by deriving an architecture for an automated teller machine. |
|||||
BibTeX:
@incollection{CHH2011a,
year = {2011},
title = {Systematic Architectural Design based on Problem Patterns},
booktitle = {Relating Software Requirements and Architectures},
author = {Choppy, Christine and Hatebur, Denis and Heisel, Maritta},
publisher = {Springer},
pages = {133--159},
url = {https://link.springer.com/}
}
|
|||||
| 2011 | Systematic Development of UMLsec Design Models Based On Security Requirements | Hatebur, D., Heisel, M., Jürjens, J. & Schmidt, H. | Proceedings of the European Joint Conferences on Theory and Practice of Software (ETAPS) - Fundamental Approaches to Software Engineering (FASE) | Springer | |
BibTeX:
@inproceedings{HHJ+2011,
year = {2011},
title = {Systematic Development of {UMLsec} Design Models Based On Security Requirements},
booktitle = {Proceedings of the European Joint Conferences on Theory and Practice of Software (ETAPS) - Fundamental Approaches to Software Engineering ({FASE})},
author = {Hatebur, Denis and Heisel, Maritta and J{\"{u}}rjens, Jan and Schmidt, Holger},
publisher = {Springer},
series = {LNCS 6603},
pages = {232--246},
url = {https://link.springer.com/}
}
|
|||||
| 2011 | UML4PF -- A Tool for Problem-Oriented Requirements Analysis | Côté, I., Hatebur, D., Heisel, M. & Schmidt, H. | Proceedings of the International Conference on Requirements Engineering (RE) | IEEE Computer Society | |
| Abstract: We present a tool called UML4PF. This tool supports requirements analysis according to an enhanced version of Michael Jackson’s problem frame approach. UML4PF supports software engineers in developing a coherent and complete set of requirements documents. Moreover, it supports the systematic development of an appropriate software architecture. |
|||||
BibTeX:
@inproceedings{re2011,
year = {2011},
title = {{UML4PF} -- A Tool for Problem-Oriented Requirements Analysis},
booktitle = {Proceedings of the International Conference on Requirements Engineering ({RE})},
author = {C{\^{o}}t{\'{e}}, Isabelle and Hatebur, Denis and Heisel, Maritta and Schmidt, Holger},
publisher = {IEEE Computer Society},
pages = {349--350},
url = {https://www.ieee.org}
}
|
|||||
| 2011 | A Pattern- and Component-Based Method to Develop Secure Software | Schmidt, H., Hatebur, D. & Heisel, M. | Software Engineering for Secure Systems: Academic and Industrial Perspectives | IGI Global | |
| Abstract: We present a security engineering process based on security problem frames and concretized security problem frames. Both kinds of frames constitute patterns for analyzing security problems and associated solution approaches. They are arranged in a pattern system that makes dependencies between them explicit. We describe step-by-step how the pattern system can be used to analyze a given security problem and how solution approaches can be found. Afterwards, the security problems and the solution approaches are formally modeled in detail. The formal models serve to prove that the solution approaches are correct solutions to the security problems. Furthermore, the formal models of the solution approaches constitute a formal specification of the software to be developed. Then, the specification is implemented by generic security components and generic security architectures, which constitute architectural patterns. Finally, the generic security components and the generic security architecture that composes them are refined and the result is a secure software product built from existing and/or tailor-made security components. KEYWORDS security |
|||||
BibTeX:
@incollection{SHH2011,
year = {2011},
title = {A Pattern- and Component-Based Method to Develop Secure Software},
booktitle = {Software Engineering for Secure Systems: Academic and Industrial Perspectives},
author = {Schmidt, Holger and Hatebur, Denis and Heisel, Maritta},
publisher = {IGI Global},
pages = {32--74},
url = {http://www.igi-global.com/}
}
|
|||||
| 2011 | Towards Systematic Integration of Performance and Security Requirements into Software Architecture | Alebrahim, A., Hatebur, D. & Heisel, M. | Software Architecture | Springer Berlin Heidelberg | |
| Abstract: We present a model- and pattern-based method that allows software engineers to take quality requirements into account right from the beginning of the software development process. The method comprises requirements analysis as well as the derivation of a software architecture from requirements documents. In that architecture, quality requirements are reflected explicitly. For requirements analysis, we use an enhancement of the problem frame approach [14], where software development problems are represented by problem diagrams. In our enhanced version of the problem frame approach, we use UML notation, and we have added the possibility to complement functional requirements with quality requirements, such as security or performance requirements. The derivation of a software architecture starts from a set of problem diagrams, annotated with functional as well as quality requirements. First, we set up an initial software architecture, taking into account the decomposition of the overall software development problem into subproblems. Next, we incorporate quality requirements into that architecture by using security or performance patterns or mechanisms. To obtain the final architecture, (functional) design patterns are applied. The method is tool-supported, which allows developers to check semantic integrity conditions in the different models. |
|||||
BibTeX:
@proceedings{,
year = {2011},
title = {Towards Systematic Integration of Performance and Security Requirements into Software Architecture},
booktitle = {Software Architecture},
author = {Alebrahim, Azadeh and Hatebur, Denis and Heisel, Maritta},
publisher = {Springer Berlin Heidelberg},
url = {https://link.springer.com/chapter/10.1007%2F978-3-642-23798-0_2},
doi = {10.1007/978-3-642-23798-0_2}
}
|
|||||
| 2010 | Making Pattern- and Model-Based Software Development More Rigorous | Hatebur, D. & Heisel, M. | Proceedings of International Conference on Formal Engineering Methods (ICFEM) | Springer | |
| Abstract: Pattern-based and model-based software development approaches have a high potential to improve the quality of software. Patterns allow engineers to re-use established and proven development knowledge. Developing software by constructing a sequence of models provides engineers with various possibilities for validation, because the different development models are not independent of each other and hence can be checked for coherence. We present a UML profile equipped with numerous OCL constraints that supports a pattern- and model-based software development process. The basis of the UML profile is a representation of problem frames, which are patterns supporting requirements analysis. OCL constraints provide a formal underpinning of the development process and allow one to perform semantic checks every time a new model is set up. Our approach is supported by a tool, called UML4PF. The tool is based on the Eclipse development environment, extended by an EMF-based UML tool, in our case, Papyrus. In this paper, we specifically focus on ensuring that problem frames are instantiated correctly. We illustrate our approach by the case study of an automatic teller machine. |
|||||
BibTeX:
@inproceedings{HateburHeisel2010a,
year = {2010},
title = {Making Pattern- and Model-Based Software Development More Rigorous},
booktitle = {Proceedings of International Conference on Formal Engineering Methods ({ICFEM})},
author = {Hatebur, Denis and Heisel, Maritta},
publisher = {Springer},
series = {LNCS 6447},
pages = {253--269},
url = {https://link.springer.com/}
}
|
|||||
| 2010 | A UML Profile for Requirements Analysis of Dependable Software | Hatebur, D. & Heisel, M. | Proceedings of the International Conference on Computer Safety, Reliability and Security (SAFECOMP) | Springer | |
| Abstract: At Safecomp 2009, we presented a foundation for requirements analysis of dependable software. We defined a set of patterns for expressing and analyzing dependability requirements, such as confidentiality, integrity, availability, and reliability. The patterns take into account random faults as well as certain attacks and therefore support a combined safety and security engineering. In this paper, we demonstrate how the application of our patterns can be tool supported. We present a UML profile allowing us to express the different dependability requirements using UML diagrams. Integrity conditions are expressed using OCL. We provide tool support based on the Eclipse development environment, extended with an EMF-based UML tool, e.g., Papyrus UML. We illustrate how to use the profile to model dependability requirements of a cooperative adaptive cruise control system. |
|||||
BibTeX:
@inproceedings{HateburHeisel2010b,
year = {2010},
title = {A {UML} Profile for Requirements Analysis of Dependable Software},
booktitle = {Proceedings of the International Conference on Computer Safety, Reliability and Security (SAFECOMP)},
author = {Hatebur, Denis and Heisel, Maritta},
publisher = {Springer},
series = {LNCS 6351},
pages = {317--331},
url = {https://link.springer.com/}
}
|
|||||
| 2010 | Automated Checking of Integrity Constraints for a Model- and Pattern-Based Requirements Engineering Method (Technical Report) | Côté, I., Hatebur, D. & Heisel, M. | |||
| Abstract: We present a new UML profile serving to support a pattern- and model-based requirements engineering method based on Jackson’s problem frames. The UML profile allows us to express the different models being defined during requirements analysis using UML diagrams. In order to automatically perform semantic validations associated with the method, we provide integrity conditions, expressed as OCL constraints. These constraints concern single models as well as the coherence of different models. To provide tool support for the requirements engineering method, we have developed a tool called UML4PF. It is based on the Eclipse development environment, extended by an EMF-based UML tool, in our case, Papyrus. To demonstrate the applicability of our approach, we use the case study of a vacation rentals reservation system. |
|||||
BibTeX:
@misc{,
year = {2010},
title = {Automated Checking of Integrity Constraints for a Model- and Pattern-Based Requirements Engineering Method (Technical Report)},
author = {C{\^{o}}t{\'{e}}, Isabelle and Hatebur, Denis and Heisel, Maritta}
}
|
|||||
| 2009 | Deriving Software Architectures from Problem Descriptions | Hatebur, D. & Heisel, M. | Software Engineering 2009 - Workshopband | GI | |
| Abstract: We show how software architectures (including interface descriptions) can be derived from artifacts set up in the analysis phase of the software lifecycle. The analysis phase consists of six steps, where various models are constructed. Especially, the software development problem is decomposed into simple subproblems. The models set up in the analysis phase form the basis for (i) defining software architectures related to single subproblems, (ii) merging the subproblem architectures to obtain the overall software architecture, and (iii) to define the interfaces between the components of the overall architecture. The approach is based on problem patterns (problem frames) and the architectural style of layered software architectures. |
|||||
BibTeX:
@inproceedings{HH09a,
year = {2009},
title = {Deriving Software Architectures from Problem Descriptions},
booktitle = {Software Engineering 2009 - Workshopband},
author = {Hatebur, Denis and Heisel, Maritta},
publisher = {GI},
pages = {383--302},
url = {https://gi.de/}
}
|
|||||
| 2009 | A Foundation for Requirements Analysis of Dependable Software | Hatebur, D. & Heisel, M. | Proceedings of the International Conference on Computer Safety, Reliability and Security (SAFECOMP) | Springer | |
| Abstract: We present patterns for expressing dependability requirements, such as confidentiality, integrity, availability, and reliability. The paper considers random faults as well as certain attacks and therefore supports a combined safety and security engineering. The patterns - attached to functional requirements - are part of a pattern system that can be used to identify missing requirements. The approach is illustrated on a cooperative adaptive cruise control system. |
|||||
BibTeX:
@inproceedings{HH09b,
year = {2009},
title = {A Foundation for Requirements Analysis of Dependable Software},
booktitle = {Proceedings of the International Conference on Computer Safety, Reliability and Security (SAFECOMP)},
author = {Hatebur, Denis and Heisel, Maritta},
publisher = {Springer},
series = {LNCS 5775},
pages = {311--325},
url = {https://link.springer.com/}
}
|
|||||
| 2008 | A Systematic Account of Problem Frames | Côté, I., Hatebur, D., Heisel, M., Schmidt, H. & Wentzlaff, I. | Proceedings of the European Conference on Pattern Languages of Programs (EuroPLoP) | Universitätsverlag Konstanz | |
| Abstract: We give an enumeration of possible problem frames, based on domain characteristics, and comment on the usefulness of the obtained frames. In particular, we investigate problem domains and their characteristics in detail. This leads to fine-grained criteria for describing problem domains. As a result, we identify a new type of problem domain and come up with integrity conditions for developing useful problem frames. Taking a complete enumeration of possible problem frames (with at most three problem domains, of which only one is constrained) as a basis, we find 8 new problem frames, 7 of which we consider as useful in practical software development. |
|||||
BibTeX:
@inproceedings{europlop08,
year = {2008},
title = {A Systematic Account of Problem Frames},
booktitle = {Proceedings of the European Conference on Pattern Languages of Programs ({EuroPLoP})},
author = {C{\^{o}}t{\'{e}}, Isabelle and Hatebur, Denis and Heisel, Maritta and Schmidt, Holger and Wentzlaff, Ina},
publisher = {Universit{\"{a}}tsverlag Konstanz},
pages = {749--767},
url = {http://www.uvk.de/}
}
|
|||||
| 2008 | A Formal Metamodel for Problem Frames | Hatebur, D., Heisel, M. & Schmidt, H. | Proceedings of the International Conference on Model Driven Engineering Languages and Systems (MODELS) | ||
| Abstract: Problem frames are patterns for analyzing, structuring, and characterizing software development problems. This paper presents a formal metamodel for problem frames expressed in UML class diagrams and using the formal specification notation OCL. That metamodel clarifies the nature of the different syntactical elements of problem frames, as well as the relations between them. It provides a framework for syntactical analysis and semantic validation of newly defined problem frames, and it prepares the ground for tool support for the problem frame approach. |
|||||
BibTeX:
@techreport{HHS2008,
year = {2008},
title = {A Formal Metamodel for Problem Frames},
booktitle = {Proceedings of the International Conference on Model Driven Engineering Languages and Systems (MODELS)},
author = {Hatebur, Denis and Heisel, Maritta and Schmidt, Holger},
series = {LNCS 5301},
pages = {68--82},
url = {https://link.springer.com/}
}
|
|||||
| 2008 | Analysis and Component-based Realization of Security Requirements | Hatebur, D., Heisel, M. & Schmidt, H. | Proceedings of the International Conference on Availability, Reliability and Security (AReS) | IEEE Computer Society | |
| Abstract: We present a process to develop secure software with an extensive pattern-based security requirements engineering phase. It supports identifying and analyzing conflicts between different security requirements. In the design phase, we proceed by selecting security software components that achieve security requirements. The process enables software developers to systematically identify, analyze, and finally realize security requirements using security software components. We illustrate our approach by a lawyer agency software example. |
|||||
BibTeX:
@inproceedings{HHS2008b,
year = {2008},
title = {Analysis and Component-based Realization of Security Requirements},
booktitle = {Proceedings of the International Conference on Availability, Reliability and Security (AReS)},
author = {Hatebur, Denis and Heisel, Maritta and Schmidt, Holger},
publisher = {IEEE Computer Society},
series = {IEEE Transactions},
pages = {195--203},
url = {https://www.ieee.org}
}
|
|||||
| 2008 | Using UML Environment Models for Test Case Generation | Heisel, M., Hatebur, D., Santen, T. & Seifert, D. | Software Engineering 2008 - Workshopband | GI | |
| Abstract: We propose a new method for system validation by means of testing, which is based on environment models expressed as UML state machines. A sun blind control case study serves to illustrate the method. |
|||||
BibTeX:
@inproceedings{HHSS08a,
year = {2008},
title = {{U}sing {UML} {E}nvironment {M}odels for {T}est {C}ase {G}eneration},
booktitle = {Software Engineering 2008 - Workshopband},
author = {Heisel, Maritta and Hatebur, Denis and Santen, Thomas and Seifert, Dirk},
publisher = {GI},
pages = {399--406},
url = {https://gi.de/}
}
|
|||||
| 2008 | Testing Against Requirements using UML Environment Models | Heisel, M., Hatebur, D., Santen, T. & Seifert, D. | Proc. Fachgruppentreffen Requirements Engineering und Test, Analyse & Verifikation | GI | |
| Abstract: We propose a new method for system validation by means of testing, which is based on environment models expressed as UML state machines. A sun blind control case study serves to illustrate the method. |
|||||
BibTeX:
@inproceedings{HHSS08b,
year = {2008},
title = {Testing Against Requirements using {UML} Environment Models},
booktitle = {Proc. {Fachgruppentreffen} {Requirements} {Engineering} und {Test}, {Analyse} \& {Verifikation}},
author = {Heisel, Maritta and Hatebur, Denis and Santen, Thomas and Seifert, Dirk},
publisher = {GI},
pages = {28--31},
url = {https://gi.de/}
}
|
|||||
| 2007 | A Pattern System for Security Requirements Engineering | Hatebur, D., Heisel, M. & Schmidt, H. | Proceedings of the International Conference on Availability, Reliability and Security (AReS) | IEEE Computer Society | |
| Abstract: We present a pattern system for security requirements engineering, consisting of security problem frames and concretized security problem frames. These are special kinds of problem frames that serve to structure, characterize, analyze, and finally solve software development problems in the area of software and system security. We equip each frame with formal preconditions and postconditions. The analysis of these conditions results in a pattern system that explicitly shows the dependencies between the different frames. Moreover, we indicate related frames, which are commonly used together with the considered frame. Hence, our approach helps security engineers to avoid omissions and to cover all security requirements that are relevant for a given problem. |
|||||
BibTeX:
@inproceedings{HHS2007,
year = {2007},
title = {A Pattern System for Security Requirements Engineering},
booktitle = {Proceedings of the International Conference on Availability, Reliability and Security (AReS)},
author = {Hatebur, Denis and Heisel, Maritta and Schmidt, Holger},
publisher = {IEEE Computer Society},
series = {IEEE Transactions},
pages = {356--365},
url = {https://www.ieee.org}
}
|
|||||
| 2007 | A Security Engineering Process based on Patterns | Hatebur, D., Heisel, M. & Schmidt, H. | Proceedings of the International Workshop on Secure Systems Methodologies using Patterns (SPatterns) | IEEE Computer Society | |
| Abstract: We present a security engineering process based on security problem frames and concretized security problem frames. Both kinds of frames constitute patterns for analyzing security problems and associated solution approaches. They are arranged in a pattern system that makes dependencies between them explicit. We describe step-by-step how the pattern system can be used to analyze a given security problem and how solution approaches can be found. Further, we introduce a new frame that focuses on the privacy requirement anonymity. |
|||||
BibTeX:
@inproceedings{HHS2007a,
year = {2007},
title = {A Security Engineering Process based on Patterns},
booktitle = {Proceedings of the International Workshop on Secure Systems Methodologies using Patterns (SPatterns)},
author = {Hatebur, Denis and Heisel, Maritta and Schmidt, Holger},
publisher = {IEEE Computer Society},
url = {https://www.ieee.org}
}
|
|||||
| 2007 | Enhancing Dependability of Component-Based Systems | Lanoix, A., Hatebur, D., Heisel, M. & Souquières, J. | Reliable Software Technologies -- Ada Europe 2007 | Springer | |
| Abstract: We present an approach for enhancing dependability of component- based software. Functionality related to security, safety and reliability is encapsulated in specific components, allowing the method to be applied to off-the-shelf components. Any set of components can be extended with dependability features by wrapping them with special components, which monitor and filter input and outputs. This approach is supported by a rigorous development methodology based on UML and the B method and is introduced on the level of software architecture. |
|||||
BibTeX:
@inproceedings{LHH+2007,
year = {2007},
title = {Enhancing Dependability of Component-Based Systems},
booktitle = {Reliable Software Technologies -- Ada Europe 2007},
author = {Lanoix, Arnaud and Hatebur, Denis and Heisel, Maritta and Souqui{\`{e}}res, Jeanine},
publisher = {Springer},
series = {LNCS 4498},
pages = {41--54},
url = {https://link.springer.com/}
}
|
|||||
| 2006 | Component composition through architectural patterns for problem frames | Choppy, C., Hatebur, D. & Heisel, M. | Proc. XIII Asia Pacific Software Engineering Conference | IEEE Computer Society | |
| Abstract: In this paper, we present a pattern-based software development process using problem frames and corresponding architectural patterns. In decomposing a complex problem into simple subproblems, the relationships between the subproblems are recorded explicitly. Based on this information, we give guidelines on how to derive the software architecture for the overall problem from the software architectures of the simple subproblems. |
|||||
BibTeX:
@inproceedings{CHH2006,
year = {2006},
title = {Component composition through architectural patterns for problem frames},
booktitle = {Proc. XIII Asia Pacific Software Engineering Conference},
author = {Choppy, Christine and Hatebur, Denis and Heisel, Maritta},
publisher = {IEEE Computer Society},
pages = {27--34},
url = {https://www.ieee.org}
}
|
|||||
| 2006 | Security Engineering using Problem Frames | Hatebur, D., Heisel, M. & Schmidt, H. | Proceedings of the International Conference on Emerging Trends in Information and Communication Security (ETRICS) | Springer | |
| Abstract: We present a method for security engineering, which is based on two special kinds of problem frames that serve to structure, characterize, analyze, and finally solve software development problems in the area of software and system security. Both kinds of problem frames constitute patterns for representing security problems, variants of which occur frequently in practice.We present security problem frames, which are instantiated in the initial step of our method. They explicitly distinguish security problems from their solutions. To prepare the solution of the security problems in the next step, we employ concretized security problem frames capturing known approaches to achieve security. Finally, the last step of our method results in a specification of the system to be implemented given by concrete security mechanisms and instantiated generic sequence diagrams. We illustrate our approach by the example of a secure remote display system. |
|||||
BibTeX:
@inproceedings{HHS2006a,
year = {2006},
title = {Security Engineering using Problem Frames},
booktitle = {Proceedings of the International Conference on Emerging Trends in Information and Communication Security (ETRICS)},
author = {Hatebur, Denis and Heisel, Maritta and Schmidt, Holger},
publisher = {Springer},
volume = {3995/2006},
pages = {238--253},
url = {https://link.springer.com/}
}
|
|||||
| 2006 | A Method for Component-Based Software and System Development | Hatebur, D., Heisel, M. & Souquières, J. | Proc. 32nd Euromicro Conference on Software Engineering and Advanced Applications (SEAA) | IEEE Computer Society | |
| Abstract: In this paper, we present a pattern-based software development process using problem frames and corresponding architectural patterns. In decomposing a complex problem into simple subproblems, the relationships between the subproblems are recorded explicitly. Based on this information, we give guidelines on how to derive the software architecture for the overall problem from the software architectures of the simple subproblems. |
|||||
BibTeX:
@inproceedings{HHS2006b,
year = {2006},
title = {A Method for Component-Based Software and System Development},
booktitle = {Proc. 32nd Euromicro Conference on Software Engineering and Advanced Applications (SEAA)},
author = {Hatebur, Denis and Heisel, Maritta and Souqui{\`{e}}res, Jeanine},
publisher = {IEEE Computer Society},
pages = {72--80},
url = {https://www.ieee.org}
}
|
|||||
| 2005 | Architectural Patterns for Problem Frames | Choppy, C., Hatebur, D. & Heisel, M. | IEEE Proceedings -- Software, Special Issue on Relating Software Requirements and Architecture | ||
| Abstract: Problem frames provide a characterisation and classification of software development problems. Fitting a problem into an appropriate problem frame should not only help to understand it, but also to solve the problem (the idea being that, once the adequate problem frame is identified, then the associated development method should be available). We propose software architectural patterns corresponding to the different problem frames that may serve as a starting point for the construction of the software solving the given problem. These architectural patterns exactly reflect the properties of the problems fitting into a given frame, and they can be combined in a modular way to solve multi-frame problems. |
|||||
BibTeX:
@article{CHH2005a,
year = {2005},
title = {Architectural Patterns for Problem Frames},
author = {Choppy, Christine and Hatebur, Denis and Heisel, Maritta},
journal = {IEEE Proceedings -- Software, Special Issue on Relating Software Requirements and Architecture},
url = {https://www.ieee.org}
}
|
|||||
| 2005 | Composing architectures based on architectural patterns for problem frames | Choppy, C., Hatebur, D. & Heisel, M. | |||
| Abstract: to be inserted | |||||
BibTeX:
@techreport{ChoppyHateburHeisel05,
year = {2005},
title = {Composing architectures based on architectural patterns for problem frames},
author = {Choppy, Christine and Hatebur, Denis and Heisel, Maritta},
note = {\tt http://swe.uni-duisburg-essen.de/intern/comparch05.pdf}
}
|
|||||
| 2005 | Problem Frames and Architectures for Security Problems | Hatebur, D. & Heisel, M. | Proceedings of the 24th International Conference on Computer Safety, Reliability and Security (SAFECOMP) | Springer | |
| Abstract: Abstract: We present two (?) problem frames that serve to structure, characterize and analyze software development problems in the area of software and system security. These problem frames constitute patterns for representing security problems, variants of which occur frequently in practice. Solving such problems starts with the development of an appropriate software architecture. To support that process, we furthermore present architectural patterns associated with the problem frames. |
|||||
BibTeX:
@inproceedings{HH2005,
year = {2005},
title = {Problem Frames and Architectures for Security Problems},
booktitle = {Proceedings of the 24th International Conference on Computer Safety, Reliability and Security (SAFECOMP)},
author = {Hatebur, Denis and Heisel, Maritta},
publisher = {Springer},
series = {LNCS 3688},
pages = {390--404},
url = {https://link.springer.com/}
}
|
|||||
| 2005 | A Model-Based Development Process for Embedded Systems | Heisel, M. & Hatebur, D. | Proc. Workshop on Model-Based Development of Embedded Systems | ||
| Abstract: We present a development process for embedded systems which emerged from industrial practice. This process covers hardware and software components for systems engineering, but the main focus is on embedded software components and the modeling of problems, specications, tests and architectures. Each step of the process has validation conditions associated with it that help to detect errors as early as possible. |
|||||
BibTeX:
@inproceedings{HH2005a,
year = {2005},
title = {A Model-Based Development Process for Embedded Systems},
booktitle = {Proc. Workshop on Model-Based Development of Embedded Systems},
author = {Heisel, Maritta and Hatebur, Denis},
publisher = {Technical University of Braunschweig},
number = {TUBS-SSE-2005-01},
note = {Available at {\tt http://www.sse.cs.tu-bs.de/publications/MBEES-Tagungsband.pdf}}
}
|
|||||
| 2004 | Anbindung per Bluetooth [BibTeX] |
Hatebur, D., Hüntemann, C., Hülscher, F. & Rottke, T. | Computer & Automation | ||
BibTeX:
@article{ca04,
year = {2004},
title = {Anbindung per Bluetooth},
author = {Hatebur, Denis and H{\"{u}}ntemann, Christoph and H{\"{u}}lscher, Friedrich and Rottke, Thomas},
journal = {Computer & Automation},
volume = {5},
pages = {52-56},
url = {https://www.weka.de/}
}
|
|||||
| 2002 | A Problem-Oriented Approach to Common Criteria Certification | Rottke, T., Hatebur, D., Heisel, M. & Heiner, M. | Proceedings of the 21st International Conference on Computer Safety, Reliability and Security (SAFECOMP) | Springer | |
| Abstract: There is an increasing demand to certify the security of systems according to the Common Criteria (CC). The CC distinguish several evaluation assurance levels (EALs), level EAL7 being the highest and requiring the application of formal techniques. We present a method for requirements engineering and (semi-formal and formal) modeling of systems to be certified according to the higher evaluation assurance levels of the CC. The method is problem oriented, i.e. it is driven by the environment in which the system will operate and by a mission statement. We illustrate our approach by an industrial case study, namely an electronic purse card (EPC) to be implemented on a Java Smart Card. As a novelty, we treat the mutual asymmetric authentication of the card and the terminal into which the card is inserted. | |||||
BibTeX:
@inproceedings{RHH+2002,
year = {2002},
title = {A Problem-Oriented Approach to Common Criteria Certification},
booktitle = {Proceedings of the 21st International Conference on Computer Safety, Reliability and Security (SAFECOMP)},
author = {Rottke, Thomas and Hatebur, Denis and Heisel, Maritta and Heiner, Monika},
publisher = {Springer},
series = {LNCS 2434},
pages = {334--346},
url = {https://link.springer.com/}
}
|
|||||
| 2002 | Messen, Steuern und Regeln mit Windows CE [BibTeX] |
Swik, R., Hatebur, D. & Rottke, T. | Francis' Verlag | ||
BibTeX:
@book{SwikHateburRottke02,
year = {2002},
title = {Messen, Steuern und Regeln mit Windows CE},
author = {Swik, Rolf and Hatebur, Denis and Rottke, Thomas},
publisher = {Francis' Verlag},
url = {http://www.franzis.de/}
}
|
|||||
| 2001 | Windows CE versus Embedded Linux [BibTeX] |
Hatebur, D., Rottke, T. & Swik, R. | Electronic - Embedded Systeme | ||
BibTeX:
@article{HateburRottkeSwik01a,
year = {2001},
title = {Windows CE versus Embedded Linux},
author = {Hatebur, Denis and Rottke, Thomas and Swik, Rolf},
journal = {Electronic - Embedded Systeme},
volume = {Ausgabe 4},
url = {http://www.vogel.de/}
}
|
|||||
| 2001 | Der Vergleich - Windows CE für die Visualisierung, Linux zum Vernetzen [BibTeX] |
Hatebur, D., Rottke, T. & Swik, R. | Computer & Automation | ||
BibTeX:
@article{HateburRottkeSwik01b,
year = {2001},
title = {Der Vergleich - Windows CE f{\"{u}}r die Visualisierung, Linux zum Vernetzen},
author = {Hatebur, Denis and Rottke, Thomas and Swik, Rolf},
journal = {Computer \& Automation},
volume = {Ausgabe 4},
pages = {96-100},
url = {http://www.franzis.de/}
}
|
|||||
Created by JabRef on 11/09/2019.
Proposed Bachelor, Diploma and Master thesis
Information concerning final theses...
Already finished Bachelor, Diploma and Master thesis
| Year | Author | Title | Type |
|---|---|---|---|
| 2019 | Mostafa Mousa | Development of a Security Architecture in a Virtualized Environment | Master |
| 2019 | Milad Akhavanfar | Problems addressed by ISO 27001 Controls and Statement-of-Applicability Patterns | Master |
| 2018 | Christoph Kerscher | Development of a Structure for Consideration of the Environment in Hazard Analyses for Automotive Systems | Master |
| 2018 | Celil Uzunel | Methodisches Ableiten und Validieren einer Microservices-Architektur | Master |
| 2016 | Paul Parenko | Mapping from ISO 26262 (Functional Safety Standard) to ADIT | Master |
| 2014 | Hendrik Niechciol | Vergleich und Bewertung leichtgewichtiger Client-/Server-Kommunikationsprotokolle im JEE-Umfeld | Bachelor |
| 2014 | Celil Uzunel | Portalserver als Entwicklungsframework |
Bachelor |
| 2013 | Julija Wolf | Strukturiertes Requirements-Engineering für Virtual Reality Ein- und Ausgabegeräte unter Berücksichtigung von Qualitätsanforderungen | Diplom |
| 2012 | Sascha Voetee | Generation of Architectures based on Problem Descriptions by Interactive Model Transformation | Diplom |
| 2010 | Nazila Gol Mohammadi | Real-Time testing using UML Environment Models | Master |
| 2010 | Shamshad Naveed | Automatic validation of UML specifications based on UML environment models | Master |
| 2008 | Fengjie Sun | Test case generation based on UML environment models | Master |
| 2008 | Muhammad Iman Santoso | Tauglichkeit der Notationen SysML im Feld Maschinenbau und Logistik |
Master |
| 2007 | Rajitha Dandu | DePES/Fusion-based Development of a Mobile Data Logger for Nokia Multimedia Phones | Master |
| 2006 | Elisha Gama | Using the B-Method for Embedded Systems Development | Bachelor |
· Recherche
· Brainstorming
· LaTeX References
-
LaTeX for complete novices (Nicola Talbot)
LaTeX@TUC, Advanced LaTeX (Tim Love)
The LaTeX Beamer class homepage
-
MiKTeX
TeXnicCenter
InkScape
cygwin mit Xfig
Office hours by arrangment