security

Designs, builds, and analyzes systems, protocols, controls, and processes that ensure the confidentiality, integrity, and availability of information and resources. This includes authentication and authorization mechanisms, cryptographic protections, secure coding and testing, threat modeling and vulnerability assessment, monitoring and incident response, and the policies and operational controls used to identify, mitigate, and manage security risks.

security

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
2.71
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$204K/year
Oct 01, 2026Oct 01, 2026

Recommended Survey Paper

Quick overview of the field
View more

Must-Read Papers

Most classic and influential ideas
View more

To address the challenges of complex security control configuration, difficult policy enforcement, and delayed response in networked systems, this paper proposes a Security Capability Model (SCM). The SCM establishes, for the first time, a computable abstract framework integrating information and data models, formally specifying rule semantics, policy parsing mechanisms, and data representations for filtering- and channel-protection–based controls. Leveraging UML/SysML modeling, Model-Driven Engineering (MDE), and a multi-granularity security control description language, the approach enables automated policy refinement, cross-heterogeneous-device (e.g., firewalls, encrypted gateways) configuration generation, and event-driven response. Experimental evaluation demonstrates a threefold improvement in policy deployment timeliness and a 40% increase in configuration accuracy, thereby filling a critical gap in the formal foundations for automated security policy enforcement.

OptimizationSecurity ControlsThreat Response

An Exploratory Study on the Engineering of Security Features

Jan 20, 2025
KH
Kevin Hermann
🏛️ Ruhr University Bochum | XITASO GmbH | Chalmers University of Technology | University of Gothenburg

Prior security development research lacks empirical grounding, particularly regarding engineers’ practical challenges in industrially engineering and maintaining security features (e.g., encryption, access control). Method: We conducted a qualitative study involving semi-structured interviews with 26 experienced practitioners, followed by thematic coding to empirically validate and refine four prevalent industry assumptions. Contribution/Results: We identify three core challenges: (1) ambiguous security trade-off decisions, (2) severe documentation deficits, and (3) excessive maintenance burden during system evolution. We further characterize recurring code patterns and maintenance bottlenecks associated with security features. This work fills a critical gap in empirical security engineering research and provides actionable, evidence-based insights for designing security tools, IDE plugins, and engineering guidelines—thereby bridging the theory–practice divide in secure software development.

Practical ApplicationSecurity FeaturesSoftware Developers

Verification and Attack Synthesis for Network Protocols

Nov 02, 2025
MV
Max von Hippel
🏛️ Northeastern University

Ensuring functional correctness and performance resilience of network protocols under component failures and adversarial attacks remains a significant challenge. Method: This paper proposes a synergistic analysis framework integrating formal verification with attack synthesis. It models protocol behavior using a formal specification language and employs logical predicates, trace analysis, and model checking to achieve closed-loop verification—simultaneously establishing correctness guarantees and automatically generating realistic attack scenarios. Contribution/Results: Diverging from conventional unidirectional verification, our approach innovatively embeds attack-path generation directly into the verification workflow, enabling reproducible and interpretable failure attribution. Experimental evaluation across multiple mainstream network protocols demonstrates substantial improvements in vulnerability detection rates and attack-surface characterization accuracy. The results validate the feasibility and practicality of formal methods for deep, security-critical analysis of complex network protocols.

Applying formal methods to analyze protocols under normal and attack conditionsSynthesizing attacks that prevent protocol requirement achievementVerifying network protocol functionality and performance requirements

This study addresses the automated selection of an optimal subset of security controls from large, standardized control catalogs (e.g., ITSG-33) under budget constraints, inter-control dependencies, and heterogeneous effectiveness. Method: We propose the first approach that algebraically models control dependencies within a zero-sum game framework, formalizing attacker–defender interaction as a single two-player zero-sum game to enable scalable, interpretable, and catalog-aware control selection. Contribution/Results: A Python-based prototype tool was developed and evaluated on a Canadian military system case study. Results demonstrate significant improvements in security objective attainment and budget utilization efficiency, while providing actionable, auditable decision support for critical information infrastructure protection.

Balancing budget, effectiveness, and dependencies among security controls.Selecting effective security controls from large standardized catalogues.Using game theory to guide decision-making for secure system development.

Automated Reasoning for Vulnerability Management by Design

Jul 08, 2025
AS
Avi Shaked
🏛️ University of Oxford | IRIT | CNRS | UT2

Existing vulnerability management approaches lack systematic reasoning capabilities for the vulnerability posture during system design, hindering proactive security control design. This paper introduces the first automated vulnerability reasoning mechanism tailored for the design phase, leveraging formal modeling and automated reasoning to support end-to-end vulnerability identification, mitigation option generation, and security control specification. The mechanism is deeply integrated into an open-source security design tool and validated in real-world industrial settings: it accurately identifies applicable vulnerabilities and significantly improves both the accuracy and efficiency of security control design, thereby shifting vulnerability management from reactive response to design-driven assurance. Its core contribution lies in establishing verifiable, formal relationships among design artifacts, vulnerabilities, and security controls—addressing a critical gap in automation-enabled security left-shifting.

Automated identification of design-specific vulnerabilitiesFormal specification of mitigation controls for vulnerabilitiesSystematic reasoning about system vulnerability postures

Latest Papers

What's happening recently
View more

This study addresses the challenge fintech firms face in effectively implementing ISO/IEC 27001:2022 requirements within high-intensity information environments due to the absence of actionable implementation pathways. By analyzing a real-world case in which an organization translated the standard’s clauses and Annex A controls into eight core operational procedures, this work proposes a multi-layered, procedural Information Security Management System (ISMS) framework. The framework integrates the CIA triad as a unified evaluation criterion, a twelve-step risk assessment methodology, and role-based accountability. Through structured process modeling, role-permission mapping, and root-cause analysis of non-conformities, it establishes a closed-loop governance mechanism that is executable, measurable, and clearly assigns responsibility. The findings indicate that a tightly integrated, hierarchically structured procedural system—equipped with quantifiable risk metrics and explicit accountability—is essential for effective ISMS implementation in fintech contexts.

Financial-Technology OrganisationInformation Security ManagementISMS Implementation

This work addresses the inadequacy of existing large language model (LLM) lifecycle frameworks, which predominantly emphasize operational efficiency while lacking explicit support for security-critical activities—such as data provenance, component signing, and access control—and failing to align governance requirements with specific lifecycle phases. The paper proposes the first security-oriented LLM system lifecycle model, structured not by workflow but by security boundaries, organizing 32 phases into four layered pipelines: data, model, distribution, and application, while integrating LLMOps and governance pillars. It uniquely identifies 13 distinct security-critical phases and exposes a structural imbalance wherein regulatory evidence is concentrated at deployment despite pivotal decisions occurring during development. By mapping key standards—including NIST AI RMF, the EU AI Act, and ISO/IEC 42001—the study establishes a phase-to-governance correspondence mechanism, yielding a comprehensive, lifecycle-spanning security analysis framework that offers structured guidance for compliance and secure design.

governance frameworklarge language modelsLLM systems

Tight coupling between security logic and business code in web applications degrades maintainability and weakens security assurance. Method: This paper proposes an aspect-oriented programming (AOP)-based modularization approach for security concerns, decoupling and encapsulating cross-cutting security mechanisms—including authentication, authorization, and input validation—into reusable aspects. We conduct a multi-scenario case study, complemented by ISO/IEC 25010–compliant code quality assessment, performance benchmarking (response time, throughput, memory consumption), and an empirical developer survey. Contribution/Results: Results demonstrate that AOP significantly improves cohesion and reusability of security modules, reduces code coupling, and enhances maintainability. The incurred runtime overhead is negligible (<2% across all metrics). This work establishes a reproducible, quantifiable AOP practice paradigm for security-driven software architecture, grounded in rigorous empirical evidence.

Comparing AOP and OOP approaches for security feature implementationEvaluating impact on code quality, performance, and maintainabilityModularizing cross-cutting security concerns in web applications

This work addresses the challenge of identifying and prioritizing multi-step attack paths in industrial control systems (ICS). The authors propose a semi-automated approach that integrates network topology and vulnerability data to construct a system model, and for the first time apply state-aware attack graph generation to a Siemens PCS7 water treatment plant blueprint. Leveraging a state-aware traversal algorithm, the method derives multi-step attack chains driven by CVEs and misconfigurations, enabling visualization of critical attack paths. Experimental results demonstrate that a single point of failure can compromise network segmentation, while remediation of key vulnerabilities effectively protects entire security zones. These findings offer actionable security insights for ICS risk mitigation.

attack pathscritical infrastructureIndustrial Control Systems

This study addresses the significant abstraction gap between security-by-design specifications—typically expressed in domain-specific languages (DSLs)—and code-level analyzers, which impedes the traceability of design intent to implementation vulnerabilities. It presents the first large-scale empirical investigation, examining 559 security checks across 36 analyzers and 66 security design DSLs. The authors introduce SecLan, a unified model that captures shared security concepts between these two layers, and validate its structure through expert evaluation involving 22 practitioners and qualitative interviews with 9 additional experts. The findings reveal a pronounced mismatch between security concepts at the design and implementation levels, with existing analyzer checks often relying on overly broad vulnerability descriptions, leading to ambiguous mappings. This work provides both an empirical foundation and a modeling framework to bridge the gap between security design and implementation.

abstraction gapcode analyzersdomain-specific languages