KIT | KIT-Bibliothek | Impressum | Datenschutz

Mitigation strategies for confidentiality violations in software architecture using ranked feature importance

Niehues, Nils ORCID iD icon 1; Hahner, Sebastian ORCID iD icon 1; Heinrich, Robert
1 Institut für Informationssicherheit und Verlässlichkeit (KASTEL), Karlsruher Institut für Technologie (KIT)

Abstract:

A quality attribute like confidentiality is critical to trustworthy software but unfortunately, very challenging to
ensure. This is because modern software systems are complex and interconnected. Architecture-based confiden-
tiality analysis enables the early detection of violations, helping to mitigate risks before deployment. However,
uncertainty in software systems and their environments complicates precise and comprehensive architectural
analysis. Additionally, the complexity of software models and the exponential growth of uncertainty scenarios
pose significant challenges for automated mitigation, often leaving software architects to resolve confidentiality
violations manually, a process that is both time-intensive and error-prone.
In this paper, we extend our machine-learning-based approach to mitigate confidentiality violations. Specif-
ically, we introduce a novel mitigation strategy inspired by TCP Congestion Control, as well as a strategy that
capitalizes on clustering techniques to dynamically adjust batch sizes. Our evaluation on three real-world soft-
ware architectures demonstrates that our extended approach can mitigate confidentiality violations while out-
... mehr


Verlagsausgabe §
DOI: 10.5445/IR/1000189764
Veröffentlicht am 20.01.2026
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Informationssicherheit und Verlässlichkeit (KASTEL)
Publikationstyp Zeitschriftenaufsatz
Publikationsmonat/-jahr 05.2026
Sprache Englisch
Identifikator ISSN: 0164-1212
KITopen-ID: 1000189764
Erschienen in Journal of Systems and Software
Verlag Elsevier
Band 235
Seiten Art.-Nr: 112761
Vorab online veröffentlicht am 26.12.2025
Nachgewiesen in Web of Science
OpenAlex
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page