Fredrik Vraalsen
SINTEF
Network
Latest external collaboration on country level. Dive into details by clicking on the dots.
Publication
Featured researches published by Fredrik Vraalsen.
international conference on trust management | 2005
Fredrik Vraalsen; Mass Soldal Lund; Tobias Mahler; Xavier Parent; Ketil Stølen
The paper makes two main contributions: (1) It presents experiences from using the CORAS language for security threat modelling to specify legal risk scenarios. These experiences are summarised in the form of requirements to a more expressive language providing specific support for the legal domain. (2) Its second main contribution is to present ideas towards the fulfilment of these requirements. More specifically, it extends the CORAS conceptual model for security risk analysis with legal concepts and associations. Moreover, based on this extended conceptual model, it introduces a number of promising language constructs addressing some of the identified deficiencies.
Journal of Cases on Information Technology | 2005
Folker den Braber; Arne Bjørn Mildal; Jone Nes; Ketil Stølen; Fredrik Vraalsen
During a field trial performed at the Norwegian telecom company NetCom from May 2003 to July 2003, a methodology for model-based risk analysis was assessed. The chosen methodology was the CORAS methodology (CORAS, 2000), which has been developed in a European research project carried out by 11 European companies and research institutes partly funded by the European Union. The risk analysis and assessment were carried out by the Norwegian research institute SINTEF in cooperation with NetCom. NetCom (www.netcom.no) is one of the main mobile phone network providers in Norway. Their ‘MinSide’ application offers their customers access to their personal account information via the Internet, enabling them to view and change the properties of their mobile phone subscription. ‘MinSide’ deals with a lot of sensitive customer information that needs to be secure, while at the same time being easily available to the customer in order for the service to remain usable and competitive. The goal of the analysis was to identify risks in relation to the use of the ‘MinSide’ application and, where possible, suggest treatments for these risks. This was achieved through two model-driven brainstorming sessions based on system documentation in the form of UML sequence diagrams and data flow diagrams.
international conference on trust management | 2005
Fredrik Vraalsen; Folker den Braber; Mass Soldal Lund; Ketil Stølen
The CORAS Tool for model-based security risk analysis supports documentation and reuse of risk analysis results through integration of different risk analysis and software development techniques and tools. Built-in consistency checking facilitates the maintenance of the results as the target of analysis and risk analysis results evolve.
working conference on virtual enterprises | 2005
Tobias Mahler; Fredrik Vraalsen
Establishing and operating a virtual organization implies a number of challenges from many different perspectives, including socio-economic, organizational, legal and computational issues. This paper focuses on the legal aspects with a particular view on legal risks with respect to intellectual property rights. A risk analysis with respect to legal issues can either be based on abstract legal reasoning or it can focus on the business reality and the specific characterizations of the virtual organization. This paper follows the latter approach; it presents selected findings of a legal risk analysis of a business scenario in the collaborative engineering field. The legal risk analysis was performed in collaboration between lawyers and other professionals in order to highlight how different legal and non-legal aspects relate to each other. Graphical models of risks and treatments were utilized in order to reduce communicational barriers between experts in this multidisciplinary setting.
IFIP Working Conference on Mobile Information Systems | 2004
Fredrik Vraalsen; Trym Holter; Ingrid Storruste Svagård; Øyvind Kvennås
Maintenance workers in the oil and process industry have typically had minimal IT support, relying on paper-based solutions both for the information they need to bring into the field and for data capture. This paper proposes a mobile context aware system for maintenance work based on electronically tagged equipment and handheld wireless terminals with a multimodal user interface. Particular attention has been given to voice interaction in noisy industrial scenarios, utilising the PARAT earplug. A proof-of-concept demonstrator of the system has been developed. The paper presents the demonstrator architecture and experiences gained through this work.
Bt Technology Journal | 2007
Folker den Braber; Ida Hogganvik; Mass Soldal Lund; Ketil Stølen; Fredrik Vraalsen
Archive | 2007
Fredrik Vraalsen; Tobias Mahler
encyclopedia of information science and technology | 2005
Folker den Braber; Mass Soldal Lund; Kentil Stolen; Fredrik Vraalsen
Lecture Notes in Computer Science | 2005
Fredrik Vraalsen; Mass Soldal Lund; Tobias Mahler; Xavier Parent; Ketil Stølen
Archive | 2007
Tobias Mahler; Fredrik Vraalsen