Network


Latest external collaboration on country level. Dive into details by clicking on the dots.

Hotspot


Dive into the research topics where Fredrik Vraalsen is active.

Publication


Featured researches published by Fredrik Vraalsen.


international conference on trust management | 2005

Specifying legal risk scenarios using the CORAS threat modelling language

Fredrik Vraalsen; Mass Soldal Lund; Tobias Mahler; Xavier Parent; Ketil Stølen

The paper makes two main contributions: (1) It presents experiences from using the CORAS language for security threat modelling to specify legal risk scenarios. These experiences are summarised in the form of requirements to a more expressive language providing specific support for the legal domain. (2) Its second main contribution is to present ideas towards the fulfilment of these requirements. More specifically, it extends the CORAS conceptual model for security risk analysis with legal concepts and associations. Moreover, based on this extended conceptual model, it introduces a number of promising language constructs addressing some of the identified deficiencies.


Journal of Cases on Information Technology | 2005

Experiences from Using the CORAS Methodology to Analyze a Web Application

Folker den Braber; Arne Bjørn Mildal; Jone Nes; Ketil Stølen; Fredrik Vraalsen

During a field trial performed at the Norwegian telecom company NetCom from May 2003 to July 2003, a methodology for model-based risk analysis was assessed. The chosen methodology was the CORAS methodology (CORAS, 2000), which has been developed in a European research project carried out by 11 European companies and research institutes partly funded by the European Union. The risk analysis and assessment were carried out by the Norwegian research institute SINTEF in cooperation with NetCom. NetCom (www.netcom.no) is one of the main mobile phone network providers in Norway. Their ‘MinSide’ application offers their customers access to their personal account information via the Internet, enabling them to view and change the properties of their mobile phone subscription. ‘MinSide’ deals with a lot of sensitive customer information that needs to be secure, while at the same time being easily available to the customer in order for the service to remain usable and competitive. The goal of the analysis was to identify risks in relation to the use of the ‘MinSide’ application and, where possible, suggest treatments for these risks. This was achieved through two model-driven brainstorming sessions based on system documentation in the form of UML sequence diagrams and data flow diagrams.


international conference on trust management | 2005

The CORAS tool for security risk analysis

Fredrik Vraalsen; Folker den Braber; Mass Soldal Lund; Ketil Stølen

The CORAS Tool for model-based security risk analysis supports documentation and reuse of risk analysis results through integration of different risk analysis and software development techniques and tools. Built-in consistency checking facilitates the maintenance of the results as the target of analysis and risk analysis results evolve.


working conference on virtual enterprises | 2005

Legal Risk Analysis with Respect to IPR in a Collaborative Engineering Virtual Organization

Tobias Mahler; Fredrik Vraalsen

Establishing and operating a virtual organization implies a number of challenges from many different perspectives, including socio-economic, organizational, legal and computational issues. This paper focuses on the legal aspects with a particular view on legal risks with respect to intellectual property rights. A risk analysis with respect to legal issues can either be based on abstract legal reasoning or it can focus on the business reality and the specific characterizations of the virtual organization. This paper follows the latter approach; it presents selected findings of a legal risk analysis of a business scenario in the collaborative engineering field. The legal risk analysis was performed in collaboration between lawyers and other professionals in order to highlight how different legal and non-legal aspects relate to each other. Graphical models of risks and treatments were utilized in order to reduce communicational barriers between experts in this multidisciplinary setting.


IFIP Working Conference on Mobile Information Systems | 2004

A Multimodal Context Aware Mobile Maintenance Terminal for Noisy Environments

Fredrik Vraalsen; Trym Holter; Ingrid Storruste Svagård; Øyvind Kvennås

Maintenance workers in the oil and process industry have typically had minimal IT support, relying on paper-based solutions both for the information they need to bring into the field and for data capture. This paper proposes a mobile context aware system for maintenance work based on electronically tagged equipment and handheld wireless terminals with a multimodal user interface. Particular attention has been given to voice interaction in noisy industrial scenarios, utilising the PARAT earplug. A proof-of-concept demonstrator of the system has been developed. The paper presents the demonstrator architecture and experiences gained through this work.


Bt Technology Journal | 2007

Model-based security analysis in seven steps --- a guided tour to the CORAS method

Folker den Braber; Ida Hogganvik; Mass Soldal Lund; Ketil Stølen; Fredrik Vraalsen


Archive | 2007

Assessing Enterprise Risk Level: The CORAS Approach

Fredrik Vraalsen; Tobias Mahler


encyclopedia of information science and technology | 2005

Integrating Security in the Development Process with UML

Folker den Braber; Mass Soldal Lund; Kentil Stolen; Fredrik Vraalsen


Lecture Notes in Computer Science | 2005

Specifying legal risk scenarios using the CORAS threat modelling language : Experiences and the way forward

Fredrik Vraalsen; Mass Soldal Lund; Tobias Mahler; Xavier Parent; Ketil Stølen


Archive | 2007

Legal Risk Management for an E-Learning Web Services Collaboration

Tobias Mahler; Fredrik Vraalsen

Collaboration


Dive into the Fredrik Vraalsen's collaboration.

Researchain Logo
Decentralizing Knowledge