Simon Hacks Senior Lecturer, Associate Professor

Contact

Name and title: Simon HacksSenior Lecturer, Associate Professor

Phone: +468161829

ORCID0000-0003-0478-9347 Länk till annan webbplats.

Workplace: Department of Computer and Systems Sciences Länk till annan webbplats.

Visiting address Nodhuset, Borgarfjordsgatan 12

Postal address Institutionen för data- och systemvetenskap164 25 Kista

Research group

About me

Simon Hacks is an associate professor at DSV, Stockholm University. His research interests lie in the quality of Enterprise Architecture (EA) and its models. Therefore, he has coined the term EA Debt as an extension of Technical Debt, which provides a holistic view of organizations beyond technical aspects. Moreover, he researches the reuse of different models for attack simulations. In line, he facilitates the Meta Attack Language (MAL) that allows providing domain-specific languages (DSL) tailored to the needs of different stakeholders. Finally, he aims to provide tooling around MAL to ensure the quality of the created MAL DSLs.

He received his Ph.D. in EA modeling from RWTH Aachen University, Germany, and supervised several theses related to EA and Threat Modeling/Attack simulations. His teaching covers Software Engineering, Enterprise Modeling, and Threat Modeling. Simon serves as PC in conferences such as ER - International Conference on Conceptual Modeling or EDOC – International Enterprise Computing Conference and is reviewing for Journals like EMISAJ – International Journal of Conceptual Modeling or SoSyM - International Journal on Software and Systems Modeling. He received his master’s degree in applied computer science from the Technical University Dortmund.


Simon's research activities cover three main areas: Enterprise Architecture, Threat Modeling, and Military Learning and Training. In Enterprise Architecture (EA), he investigates EA modeling, model quality, and EA Debt. In threat modeling, his research focuses on different aspects of the Meta Attack Language (MAL). His work on military learning and training explores how digital technologies and organizational arrangements can support continuous learning and adaptation through Train While You Fight and learning dominance.

Enterprise Architecture

Simon's research activities related to EA started with his Ph.D. studies within the research project EARTh – Integrated Enterprise Architecture Roundtrip Approach. The project aimed to develop means that provided development projects with models stored in the central EA repository and play their changes back. This includes contributions to how this integration can be realized, how contradictory information coming from the projects could be handled, and how the thinking of continuous delivery can support the process.

To address the human aspects of modeling quality, Simon elaborated on the quality aspects of EA models. He developed an extension for the open-source tool Archi that helps the modeler avoid adding an existing element to the EA repository.

Another stream of research is related to using the EA model, such as using the model as input to determine a possible optimal state of the EA concerning different objectives (e.g., minimal coupling or cost optimality) while considering various constraints (e.g., different implementation costs for changes or budgets allocated to different departments). Alternatively, the models can be used for a security certification or as input for a security assessment.

The quality of the EA plays a crucial role in the organization, especially in digitization. In this regard, IT is often seen as a driver for the necessary innovation, but often the opposite is the case. More specifically, IT structures, as have the associated processes, have grown over decades. This means organizations are generally no longer sufficiently flexible when changing these structures. This turns out to be a challenge for the intended digitalization efforts of many organizations. The information about shortcomings in the organizational structures is known to the employees. Still, it is regularly only externalized when estimating project expenses for small changes, which often turn out to be unexpectedly large. This makes it difficult to steer the organization effectively in a desired direction.

The notion of EA Debt was proposed to address these challenges. It is an extension of the term Technical Debt from the field of software engineering to all layers of the EA so that organizational aspects are also considered. Originally, Technical Debt described qualitative disadvantages in designing and implementing technical elements. The idea is to develop EA Debts that can be used to identify patterns that impact digitization, whether negative or positive, to help the organization with the transformation.

So far, the efforts in the field of EA Debt can be mainly differentiated into two streams of work: (1) research related to the technical aspects of EA Debt and (2) the elaboration on the socio-technical aspects of EA Debt.

Most of the research has been published on the technical aspects of EA Debt. As such, Simon was involved in the definition of EA Smell, which provides measures for the symptoms of an EA Debt to make it visible, but also a prototype that was able to identify some of the smells in ArchiMate models. To further ease the identification of these smells, a tool was enhanced to identify EA Smells automatized in EA models and expanded the identification from ArchiMate models to any EA model with a graph-based representation.

A process was proposed to provide a frame for the presented technical measures. EA Debts are identified, collected, assessed, prioritized, removed, or actively monitored. To provide a means to identify EA Debts and EA Smells that cannot be detected by solely relying on EA models, a workshop format can be used in which stakeholders are brought together to discuss (1) the notion of EA Debt; (2) organizational issues that they encounter; (3) possible causes for these issues.

Threat Modeling

The Meta Attack Language (MAL) was proposed as a framework for developing Domain Specific Languages (DSLs) that can be used to assess IT infrastructures' cyber-security. Therefore, the MAL uses attack graph simulations based on system architecture models. Within the domain of MAL, Simon is involved in developing different languages, supporting the language developers, and increasing the quality of the created languages.

Simon was actively involved in the development of vehicleLang, which is a language to simulate attack vectors for modern vehicles, coreLang, which is a basic language that provides the fundamentals of IT systems, as well as powerLang, which is a language designed to analyze weaknesses in the power grid.

MAL has become more adopted, leading to more languages covering a broader spectrum of different domains developed by a wide range of people with different backgrounds and competencies. Thus, the quality of the developed languages varies heavily. To raise the quality of the developed languages, it is possible to write tests to ensure that the developed language behaves as intended. However, at the moment, the language developers write tests more ad hoc than structured. Therefore, an extension to JUnit allows us to assess different coverages on the tested threat models. Moreover, the first step was taken to achieve full coverage of the test cases systematically.

Secondly, patterns and concepts recur in the newly developed languages leading to the design of coreLang that covers assets of general purpose in the IT infrastructures. coreLang is, thus, intended to be a starting point for new languages so that the developers are not forced to reinvent the core constructs of the language every time. As such, the basic component for an ecosystem of MAL-based languages should guide the relations between languages covering different domains, such as office environments or industrial control systems.

Thirdly, every language developer follows their own experience and vision to develop a language. Therefore, a development process guides language developers through the different phases of language development: purpose definition, language design, and evaluation. An important challenge is determining the probability distributions that describe the expected time to compromise a single attack step. This can be provided by a systematic approach to collect the necessary data and distill it into probability distributions and another approach to include information on the security behavior of persons in organizations.

Lastly, the manual creation of the used threat models for attack simulations is error-prone. Therefore, one can reuse existing models in the organization. These models can be, for example, business process models or enterprise architecture models. Furthermore, one can combine threat and multi-level modeling to guide non-security experts in designing secure systems. Finally, it is important to analyze the business impact of the detected vulnerabilities of the system.

Military Learning and Training

Simon's research on military learning and training focuses on Train While You Fight (TWYF), which addresses the need to maintain and adapt training during ongoing operations. This includes translating operational experience into relevant learning content and making it available despite constraints such as disrupted infrastructure, limited connectivity, and rapidly changing requirements.

In this area, Simon contributes to identifying the requirements for digital learning environments and relating them to suitable software-engineering approaches. His work addresses interoperability, resilience, security, scalability, and multilingual support. It examines approaches such as short, targeted learning content, personalized learning, on-demand content production, and digital learning ecosystems that support both connected and offline use.

To connect these technical considerations with organizational needs, Simon investigates TWYF through the lense of socio-technical systems. This perspective considers the relationships between participants, processes, information, and technologies, together with the responsibilities and coordination needed to develop and maintain a learning environment over time.

Building on this work, Simon's research interests extend to learning dominance: the organizational ability to recognize relevant changes, translate them into effective training, procedures, and capabilities faster than other actors, and assess their effects using reliable evidence.

A complete list of publications can be found on my google scholar profile.

Contact

Name and title: Simon HacksSenior Lecturer, Associate Professor

Phone: +468161829

ORCID0000-0003-0478-9347 Länk till annan webbplats.

Workplace: Department of Computer and Systems Sciences Länk till annan webbplats.

Visiting address Nodhuset, Borgarfjordsgatan 12

Postal address Institutionen för data- och systemvetenskap164 25 Kista

Research group