-
Simon Tjoa and Stefan Jakoubi and Gernot Goluch and Gerhard Kitzler and Sigrun Goluch and Gerald Quirchmayr, "A Formal Approach Enabling Risk-aware Business Process Modeling and Simulation,"
IEEE Transactions on Services Computing, 2010.
BibTeX |
PDF
@ARTICLE{Tjoa2010a,
Author = {Simon Tjoa and Stefan Jakoubi and Gernot Goluch and Gerhard Kitzler and Sigrun Goluch and Gerald Quirchmayr},
title = {A Formal Approach Enabling Risk-aware Business Process Modeling and Simulation},
journal = {IEEE Transactions on Services Computing},
year = {2010},
month = {4},
pdf = {Tjoa_TSC2010.pdf},
}
-
Gernot Goluch and Simon Tjoa and Thomas Neubauer and Stefan Jakoubi and Martin Wisser, "A Process Model for RFID based Business Process Analysis," in
APSCC, 2009.
BibTeX
@INPROCEEDINGS{Neubauer_ProcessModelRFID_2009,
Author = {Gernot Goluch and Simon Tjoa and Thomas Neubauer and Stefan Jakoubi and Martin Wisser},
title = {A Process Model for RFID based Business Process Analysis},
booktitle = {APSCC},
year = {2009},
month = {1},
}
-
Gerald Quirchmayr and Gernot Goluch and Simon Tjoa and Stefan Jakoubi, "A Survey of Scientific Approaches Considering the Integration of Security and Risk Aspects into Business Process Management," in
International Workshop on Database and Expert Systems Applications, 2009, pp. 127-132.
BibTeX |
PDF
@INPROCEEDINGS{Jakoubi_SurveyofScientific_2009,
Author = {Gerald Quirchmayr and Gernot Goluch and Simon Tjoa and Stefan Jakoubi},
title = {A Survey of Scientific Approaches Considering the Integration of Security and Risk Aspects into Business Process Management},
booktitle = {International Workshop on Database and Expert Systems Applications},
year = {2009},
month = {1},
pdf = {Jakoubi_SurveyofScientific_2009.pdf},
pages = {127-132},
publisher = {IEEE Computer Society},
}
-
Gerald Quirchmayr and Gernot Goluch and Simon Tjoa and Stefan Jakoubi, "Extension of a Methodology for Risk-Aware Business Process Modeling and Simulation Enabling Process-Oriented Incident Handling Support," in
The 22st International Conference on Advanced Information Networking and Applications, 2008.
BibTeX
@INPROCEEDINGS{Tjoa_ExtensionofMethodology_2008,
Author = {Gerald Quirchmayr and Gernot Goluch and Simon Tjoa and Stefan Jakoubi},
title = {Extension of a Methodology for Risk-Aware Business Process Modeling and Simulation Enabling Process-Oriented Incident Handling Support},
booktitle = {The 22st International Conference on Advanced Information Networking and Applications},
year = {2008},
month = {1},
abstract = {Increasingly, companies face the challenges to perform their business processes effectively as well as efficiently and to simultaneously assure the continuity of these processes. As the majority of companies rely on IT, it is essential to establish effective incident handling. In this paper, we introduce new extensions of the risk-aware business process management framework ROPE (Risk- Oriented Process Evaluation) in order to support the improvement of the management and execution of business processes. We further discuss the advantages of those extensions and how they can support the implementation of standards and best-practices such as the NIST SP800-61 (Computer Security Incident Handling Guide).},
publisher = {IEEE Society},
}
-
Stefan Fenz and Edgar R. Weippl and Andreas Ekelhart and Gernot Goluch and Markus Steinkellner, "XML Security – A comparative literature review,"
Journal of Systems and Software, vol. 81, pp. 1715-1724, 2008.
BibTeX |
PDF
@ARTICLE{Ekelhart_XMLSecurity_2008,
Author = {Stefan Fenz and {Edgar R.} Weippl and Andreas Ekelhart and Gernot Goluch and Markus Steinkellner},
sbahotlist = {true},
title = {XML Security - A comparative literature review},
journal = {Journal of Systems and Software},
year = {2008},
month = {1},
abstract = {Since the turn of the millenium, Working Groups of the W3C have been concentrating on the development of XML based security standards, which are paraphrased as XML Security. XML Security consists of three recommendations: XML (Digital) Signature, XML Encryption and XML Key Management Specification (XKMS), all of them published by the W3C. By means of a review of the available literature the authors draw several conclusions about the status quo of XML Security. Furthermore the current state and focuses of research as well as the existing challenges are derived. Trends to different application areas - e.g. use of XML Security for Mobile Computing - are also outlined. Based on this information the analyzed results are discussed and a future outlook is predicted.},
pdf = {2008 - Ekelhart - XML security -- A Comparative Literature Review.pdf},
volume = {81},
pages = {1715-1724},
note = {ISSN: 0164-1212},
}
-
Stefan Fenz and Andreas Ekelhart and Gernot Goluch and Simon Tjoa and Stefan Jakoubi and Thomas Mueck, "Integration of an Ontological Information Security Concept in Risk Aware Business Process Management," in
Proceedings of the 41st Hawaii International Conference on System Sciences, HICSS2008, 2008, pp. 377-385.
BibTeX |
PDF
@INPROCEEDINGS{Goluch_IntegrationofOntological_2008,
Author = {Stefan Fenz and Andreas Ekelhart and Gernot Goluch and Simon Tjoa and Stefan Jakoubi and Thomas Mueck},
sbahotlist = {true},
title = {Integration of an Ontological Information Security Concept in Risk Aware Business Process Management},
booktitle = {Proceedings of the 41st Hawaii International Conference on System Sciences, HICSS2008},
year = {2008},
month = {1},
pdf = {2008 - Goluch - Integration of an Ontological Information Security Concept in Risk-Aware Business Process Management.pdf},
pages = {377-385},
publisher = {IEEE Computer Society},
note = {978-0-7695-3075-8},
}
-
Gerald Quirchmayr and Gernot Goluch and Simon Tjoa and Stefan Jakoubi, "Deriving Resource Requirements Applying Risk-Aware Business Process Modeling and Simulation," in
Proceedings of the 16th European Conference on Information Systems (ECIS), 2008.
BibTeX
@INPROCEEDINGS{Jakoubi_DerivingResourceRequirements_2008,
Author = {Gerald Quirchmayr and Gernot Goluch and Simon Tjoa and Stefan Jakoubi},
sbahotlist = {true},
title = {Deriving Resource Requirements Applying Risk-Aware Business Process Modeling and Simulation},
booktitle = {Proceedings of the 16th European Conference on Information Systems (ECIS)},
year = {2008},
month = {1},
abstract = {Today, companies face the challenge to effectively and efficiently perform their business processes as well as to guarantee their continuous operation. To meet the economic requirements, companies often consult business process management experts. The robustness and continuity of operations is separately considered in other domains such as business continuity management and risk management. The shortcoming of this separation is that in most cases a common reasoning and information basis is missing. With the risk-aware process modeling and simulation methodology named ROPE we fill this gap and combine the strengths of the aforementioned domains. In this paper, we present new ROPE simulation capabilities focusing on the determination of resource requirements considering the impact of occurring threats on business processes. Furthermore, we introduce an example scenario to clarify how a company can benefit from applying these extensions.},
}
-
Stefan Fenz and Edgar R. Weippl and Markus Klemen and Andreas Ekelhart and Gernot Goluch, "Architectural approach for handling semi-structured data in an user-centered working environment,"
International Journal of Web Information Systems, vol. 3, iss. 3, pp. 198-211, 2007.
BibTeX |
PDF
@ARTICLE{Ekelhart_Architecturalapproachhandling_2007,
Author = {Stefan Fenz and {Edgar R.} Weippl and Markus Klemen and Andreas Ekelhart and Gernot Goluch},
title = {Architectural approach for handling semi-structured data in an user-centered working environment},
journal = {International Journal of Web Information Systems},
year = {2007},
month = {1},
abstract = {Purpose of this paper Today the amount of all kind of digital data (e.g., documents and e-mails), existing on every user's computer, is continuously growing. Users are faced with huge difficulties when it comes to handling the existing data pool and finding specific information respectively. We aim to discover new ways of searching and finding semi-structured data by integrating semantic metadata. Design/methodology/approach The proposed architecture allows cross border searches spanning various applications and operating system activities (e.g., file access and network traffic) and improves the human working process by offering context specific, automatically generated links that are created using ontologies. Findings The proposed semantic enrichment of automated gathered data is a useful approach to reflect the human way of thinking which is accomplished by remembering relations rather than keywords or tags. The proposed architecture supports the goals of supporting the human working process by managing and enriching personal data, e.g. by providing a database model which supports the semantic storage idea through a generic and flexible structure or the modular structure and composition of data collectors. Originality/value Available programs to manage personal data usually offer searches either via keywords or full text search. Each of these existing search methodologies has its shortcomings and apart from that, people tend to forget names of specific objects. It is often easier to remember the context of a situation in which e.g. a file was created or a website was visited. By proposing our architectural approach for handling semi-structured data we are able to offer sophisticated and more applicable search mechanism regarding the way of human thinking.},
pdf = {2007 - Ekelhart - Architectural Approach for Handling Semi-Structured Data in a User-Centered Working Environment.pdf},
volume = {3},
number = {3},
pages = {198-211},
note = {ISSN: 1744-0084},
}
-
Stefan Fenz and Andreas Ekelhart and Gernot Goluch and Simon Tjoa and Stefan Jakoubi and Bernhard Riedl, "CASSIS – Computer-based Academy for Security and Safety in Information Systems," in
Proceedings of the 2nd Conference on Availability, Reliability and Security, ARES2007, 2007, pp. 730-740.
BibTeX |
PDF
@INPROCEEDINGS{Goluch_CASSISComputerbased_2007,
Author = {Stefan Fenz and Andreas Ekelhart and Gernot Goluch and Simon Tjoa and Stefan Jakoubi and Bernhard Riedl},
title = {CASSIS - Computer-based Academy for Security and Safety in Information Systems},
booktitle = {Proceedings of the 2nd Conference on Availability, Reliability and Security, ARES2007},
year = {2007},
month = {4},
abstract = {Information technologies and society are highly interwoven nowadays, but in both, the private and business sector, users are often not aware of security issues or lack proper security skills. The branch of information technology security is growing constantly but attacks against the vocational sector as well as the personal sector still cause great losses each day. Considering that the end-user is the weakest link of the security chain we aim to raise awareness, regarding IT security, and train and educate IT security skills by establishing a European-wide initiative and framework.},
pdf = {2007 - Goluch - CASSIS.pdf},
pages = {730-740},
publisher = {IEEE Computer Society},
note = {978-0-7695-2775-8},
}
-
Stefan Fenz and Edgar R. Weippl and Andreas Ekelhart and Gernot Goluch and Bernhard Riedl, "Information Security Fortification by Ontological Mapping of the ISO IEC 27001 Standard," in
Proceedings of the 13th Pacific Rim International Symposium on Dependable Computing, PRDC2007, 2007, pp. 381-388.
BibTeX |
PDF
@INPROCEEDINGS{Fenz_InformationSecurityFortification_2007,
Author = {Stefan Fenz and {Edgar R.} Weippl and Andreas Ekelhart and Gernot Goluch and Bernhard Riedl},
title = {Information Security Fortification by Ontological Mapping of the ISO IEC 27001 Standard},
booktitle = {Proceedings of the 13th Pacific Rim International Symposium on Dependable Computing, PRDC2007},
year = {2007},
month = {12},
pdf = {2007 - Fenz - Information Security Fortification by Ontological Mapping of the ISOIEC 27001 Standard.pdf},
pages = {381-388},
publisher = {IEEE Computer Society},
note = {0-7695-3054-0},
}
-
Gernot Goluch and Thomas Neubauer and Bernhard Riedl and Oswald Boehm and Gert Reinauer and Alexander Krumboeck, "A secure architecture for the pseudonymization of medical data," in
Proceedings of the Second International Conference on Availability, Reliability and Security (ARES), 2007, pp. 318-324.
BibTeX
@INPROCEEDINGS{Riedl_securearchitecturepseudonymization_2007,
Author = {Gernot Goluch and Thomas Neubauer and Bernhard Riedl and Oswald Boehm and Gert Reinauer and Alexander Krumboeck},
title = {A secure architecture for the pseudonymization of medical data},
booktitle = {Proceedings of the Second International Conference on Availability, Reliability and Security (ARES)},
year = {2007},
month = {1},
pages = {318-324},
}
-
Edgar R. Weippl and Gernot Goluch and Bernhard Riedl and Stefan Poechlinger, "Comparative Literature Review on RFID Security and Privacy," in
Proceedings of The 9th International Conference on Information Integration and Web-based Applications and Services (iiWAS2007), 2007.
BibTeX
@INPROCEEDINGS{Riedl_ComparativeLiteratureReview_2007,
Author = {{Edgar R.} Weippl and Gernot Goluch and Bernhard Riedl and Stefan Poechlinger},
title = {Comparative Literature Review on RFID Security and Privacy},
booktitle = {Proceedings of The 9th International Conference on Information Integration and Web-based Applications and Services (iiWAS2007)},
year = {2007},
month = {1},
}
-
Stefan Fenz and Edgar R. Weippl and Andreas Ekelhart and Gernot Goluch, "Ontological Mapping of Common Criterias Security Assurance Requirements," in
New Approaches for Security, Privacy and Trust in Complex Environments, Proceedings of the IFIP TC 11 22nd International Information Security Conference, IFIPSEC2007, May 14-16, 2007, pp. 85-95.
BibTeX
@INPROCEEDINGS{Ekelhart_OntologicalMappingof_2007,
Author = {Stefan Fenz and {Edgar R.} Weippl and Andreas Ekelhart and Gernot Goluch},
title = {Ontological Mapping of Common Criterias Security Assurance Requirements},
booktitle = {New Approaches for Security, Privacy and Trust in Complex Environments, Proceedings of the IFIP TC 11 22nd International Information Security Conference, IFIPSEC2007, May 14-16},
year = {2007},
month = {5},
abstract = {The Common Criteria (CC) for Information Technology Security Evaluation provides comprehensive guidelines for the evaluation and certification of IT security regarding data security and data privacy. Due to the very complex and time-consuming certification process a lot of companies abstain from a CC certification. We created the CC Ontology tool, which is based on an ontological representation of the CC catalog, to support the evaluator at the certification process. Tasks such as the planning of an evaluation process, the review of relevant documents or the creating of reports are supported by the CC Ontology tool. With the development of this tool we reduce the time and costs needed to complete a certification.},
volume = {232_2007},
pages = {85-95},
publisher = {International Federation for Information Processing ,},
note = {978-0-387-72366-2},
}
-
Gernot Goluch and Thomas Neubauer and Bernhard Riedl, "A Research Agenda for Autonomous Business Process Management," in
Proceedings of the Second International Conference on Availability, Reliability and Security ARES, 2007.
BibTeX
@INPROCEEDINGS{Neubauer_ResearchAgendaAutonomous_2007,
Author = {Gernot Goluch and Thomas Neubauer and Bernhard Riedl},
title = {A Research Agenda for Autonomous Business Process Management},
booktitle = {{P}roceedings of the {S}econd {I}nternational {C}onference on {A}vailability, {R}eliability and {S}ecurity {ARES}},
year = {2007},
month = {1},
publisher = {IEEE Computer Society},
}
-
Edgar R. Weippl and Gernot Goluch, "Nichtabstreitbarkeit und Audits in ELearning," in
IRIS 2006, 2006.
BibTeX
@INPROCEEDINGS{Goluch_NichtabstreitbarkeitundAudits_2006,
Author = {{Edgar R.} Weippl and Gernot Goluch},
title = {Nichtabstreitbarkeit und Audits in ELearning},
booktitle = {IRIS 2006},
year = {2006},
month = {1},
}
-
Stefan Biffl and Gernot Goluch and Dietmar Winkler and Ramona Varvaroi, "An Empirical Study On Integrating Analytical Quality Assurance Into Pair Programming," in
Proceedings of 5th ACM-IEEE International Symposium on Empirical Software Engineering, 2006.
BibTeX
@INPROCEEDINGS{Winkler_EmpiricalStudyIntegrating_2006,
Author = {Stefan Biffl and Gernot Goluch and Dietmar Winkler and Ramona Varvaroi},
title = {An Empirical Study On Integrating Analytical Quality Assurance Into Pair Programming},
booktitle = {Proceedings of 5th ACM-IEEE International Symposium on Empirical Software Engineering},
year = {2006},
month = {1},
abstract = {The success of software projects depends on the ability of a human planner to understand the relationships of tasks and their temporal uncertainty and hence the visualization thereof. In this paper we report on an empirical study that compares the performance of two techniques to visualize task relationships and temporal uncertainties: traditional ``best-practice'' PERT charts and recently introduced PlanningLines. Main results of the study are: (a) while PERT charts are well suited for reading single attributes, PlanningLines better support users in judging temporal task uncertainty; (b) both experiment rounds shows consistent results regarding the strengths and limitations of the techniques. Overall, these results suggest that a combination of PERT charts and PlanningLines has the potential to significantly improve the planning support of project managers and software engineers.},
}
-
Stefan Biffl and Gernot Goluch and Silvia Miksch and Bettina Thurnher and Dietmar Winkler and Wolfgang Aigner, "An Empirical investigation on the Visualization of Temporal Uncertainties in Software Engineering Project Planning," in
Proceedings of 5th ACM-IEEE International Symposium on Empirical Software Engineering, 2005.
BibTeX
@INPROCEEDINGS{Biffl_EmpiricalinvestigationVisualization_2005,
Author = {Stefan Biffl and Gernot Goluch and Silvia Miksch and Bettina Thurnher and Dietmar Winkler and Wolfgang Aigner},
title = {An Empirical investigation on the Visualization of Temporal Uncertainties in Software Engineering Project Planning},
booktitle = {Proceedings of 5th ACM-IEEE International Symposium on Empirical Software Engineering},
year = {2005},
month = {1},
abstract = {The success of software projects depends on the ability of a human planner to understand the relationships of tasks and their temporal uncertainty and hence the visualization thereof. In this paper we report on an empirical study that compares the performance of two techniques to visualize task relationships and temporal uncertainties: traditional ``best-practice'' PERT charts and recently introduced PlanningLines. Main results of the study are: (a) while PERT charts are well suited for reading single attributes, PlanningLines better support users in judging temporal task uncertainty; (b) both experiment rounds shows consistent results regarding the strengths and limitations of the techniques. Overall, these results suggest that a combination of PERT charts and PlanningLines has the potential to significantly improve the planning support of project managers and software engineers.},
}
-
A Min Tjoa and Stefan Fenz and Edgar R. Weippl and Markus Klemen and Gernot Goluch and Manfred Linnert, "Semantic Storage: A Report on Performance and Flexibility," in
Database and Expert Systems Applications, 16th International Conference, DEXA 2005, 2005, pp. 586-595.
BibTeX |
PDF
@INPROCEEDINGS{Weippl_SemanticStorageReport_2005,
Author = {{A Min} Tjoa and Stefan Fenz and {Edgar R.} Weippl and Markus Klemen and Gernot Goluch and Manfred Linnert},
title = {Semantic Storage: A Report on Performance and Flexibility},
booktitle = {Database and Expert Systems Applications, 16th International Conference, DEXA 2005},
year = {2005},
month = {8},
abstract = {Desktop search tools are becoming more popular. They have to deal with increasing amounts of locally stored data. Another approach is to analyze the semantic relationship between collected data in order to preprocess the data semantically. The goal is to allow searches based on relationships between various objects instead of focusing on the name of objects. We introduce a database architecture based on an existing software prototype, which is capable of meeting the various demands for a semantic information manager. We describe the use of an association table which stores the relationships between events. It enables adding or removing data items easily without the need for schema modifications. Existing optimization techniques of RDBMS can still be used.},
pdf = {2005 - Weippl - Semantic Storage A Report on Performance and Flexibility:2005 - Weippl - Semantic Storage A Report on Performance and Flexibility.pdf},
volume = {3588_2005},
pages = {586-595},
publisher = {Springer Berlin Heidelberg},
}