
Traditional cloud sourcing frameworks provide high-level lifecycle guidance, but they rarely address how financial governance should be embedded into day-to-day cloud operations. This paper presents a model-driven FinOps framework that integrates the Inform, Optimize, and Operate pillars into the Cloud Sourcing Life Cycle of a large pharmaceutical enterprise running on AWS. We first analyze the organization’s “governance vacuum,” characterized by reactive spend visibility, disconnected financial authorization, and ambiguous ownership and decommissioning responsibilities. We then introduce a structural metamodel that links technical resources, financial entities, and governance artifacts, and derive executable BPMN workflows that operationalize FinOps pillars across provisioning, optimization, and retirement. An illustrative case study instantiation explores how automated guardrails, standardized approval paths, and role-specific responsibilities can be used to control expenditure requests, proposing a method to close critical governance gaps. This conceptual approach suggests that cloud cost governance can become an operational default rather than an after-the-fact reporting activity.
Enterprise information systems increasingly depend on distributed actors that must coordinate under uncertainty, partial observability, and dynamic role demands. A key open question is whether explicit, lightweight role-based orchestration can improve cooperative learning without replacing reward-based signals. This paper proposes and evaluates two orchestration mechanisms layered on top of the Multi-Agent Posthumous Credit Assignment (POCA) algorithm in the DungeonEscape cooperative environment. The first mechanism dynamically assigns temporary task roles to agents based on environment state. The second extends this with urgency-weighted confidence signals per role. Experiments across three random seeds show that task-based orchestration achieves the highest peak group reward (0.811), while baseline POCA remains the most stable across seeds (0.746), and confidence-aware orchestration underperforms on average (0.691). The results suggest that selective, lightweight coordination guidance can improve cooperative specialization, but overly expressive orchestration signals introduce optimization difficulty. These findings offer practical guidance for designing adaptive coordination mechanisms in actor-based business process systems.
Passwords are as old as computers and are indispensable for daily operations in all aspects of digital life. Despite reinforcements such as 2FA and MFA, the use of passwords in authentication and authorization is still essential. At the same time, password compromise is still one of the leading causes of successful cyber attacks, regardless of scale, target, and motive. One of the commonly used avenues for password compromise is the interception of its hashed form and subsequent usage of “rainbow tables” to recover the original password. Overall, “rainbow tables” have been systematically proven to be orders of magnitude more effective than pure bruteforce enumeration and all-combination dictionaries. The development of “rainbow tables” datasets/toolsets and of associated research works have seen some intense and fruitful developments in the early 2000s–2010s. Nevertheless, a few challenges persisted – the efforts largely remained scattered, some of them even went offline without any meaningful preservation efforts, overall the datasets and toolsets remained under-characterized, and the underlying knowledge is not systematized nor aggregated. Overall, the expertise to approach the “rainbow tables” research field remains a “black magic” type of knowledge that prevents more researchers from contributing to the field. This paper aims to bridge the gap in the characterization and systematization of knowledge and resources pertaining to publicly researched “rainbow tables” and associated tools. We hope that this condensed overview provides a useful reference point for cybersecurity practitioners, regardless of whether their work involves applying existing rainbow tables or advancing methodological and research directions in this area.
Large language models are widely used for vulnerability lookup and explanation, but their reliability in security-critical workflows is unclear. We evaluate ChatGPT using structured prompts based on CERT/CC vulnerability notes, CVE entries, and additional tests targeting non-standard failure modes. Across vulnerability records, the model generally produced correct core descriptions, with the most frequent issues being low-severity omissions of supporting metadata such as affected versions, vendors, and weakness classifications. For older vulnerability notes, performance declined and included high-severity errors, such as incorrect mappings between vulnerability identifiers. Additional testing revealed further risks: silent substitution of identifiers, overly long and weakly curated product lists that appear comprehensive but lack verification, and context-driven mismatches between vulnerability notes and identifiers. In a follow-up months later with a newer model, the system first rejected fake CVEs but then produced confident, entirely fabricated details, revealing instability between rejection and hallucination. Taken together, these results show that while ChatGPT can assist in vulnerability lookup and explanation, its outputs require human verification and cross-checking against authoritative sources. Practical safeguards—such as single-item prompting, structured output constraints, explicit repetition of identifiers, and rejection checks—can help reduce error propagation in operational settings.
Last-mile delivery processes often suffer from discrepancies between predicted and actual delivery locations, leading to inefficiencies and increased operational costs. Existing approaches mainly focus on improving routing or geocoding accuracy, but limited attention has been given to proactively predicting such discrepancies. This paper proposes a data-driven framework that integrates geospatial analysis with machine learning to identify deliveries at risk of spatial deviation. The approach combines geospatial distance computation with feature engineering based on address structure and contextual attributes and applies a Gradient Boosting model for predictive classification. The results demonstrate that the proposed framework achieves reliable predictive performance (AUC = 0.736) and enables the identification of high-risk deliveries at scale. The main contribution of this study lies in combining geospatial discrepancy quantification with predictive modeling into a unified operational framework. However, the approach is limited by the use of static features and a fixed spatial threshold. Future work will explore dynamic contextual data and adaptive thresholding.
The increasing use of unmanned aerial vehicles (UAVs) creates the need for reliable methods for monitoring, detection, and tracking. This paper considers drone tracking as a problem of heterogeneous time-series fusion under uncertainty, where noisy observations from different sensing modalities are combined to estimate the latent dynamic state of a moving object. A multimodal model for heterogeneous data integration is proposed, based on a linear state-space representation and sequential Kalman filter updates. The proposed approach is evaluated through simulation experiments and Monte Carlo analysis. The results show that recursive multisensor fusion improves positional accuracy and stability compared with direct sensor measurements and simple measurement-level averaging.
Modelling life-cycles is an important aspect of modelling. A State Machine Diagram, or (Status) Transition Diagram, is a popular way to model the potential life-cycle of an object, i.e., to specify the transitions allowed for such objects. A typical example is the status of an order, e.g., ‘Received’, ‘Open’, ‘In progress’, ‘Deferred’, ‘Completed’, ‘Checked’, and ‘Closed’. Research questions raised: What is the final role and position of state (machine) diagrams in modelling? Are they separate ingredients of the final system model (and implementation), say besides an activity diagram or business process model and a class diagram? How can the system guarantee that only allowed status changes occur? And how does this all fit together? Although status is usually an important property of an object, the state of an object is usually much more than only its status and will contain much other information as well. Therefore, we will talk about status and (status) transition diagram instead of state and state transition diagram. In UML, for instance, such Transition Diagrams are typically treated as State (Machine) Diagrams, a diagram type next to, e.g., Class Diagrams, which model the data on the objects. We consider such allowed (status) transitions as intrinsic parts of the data model itself. A corresponding transition diagram can be generated easily from the data model. With this approach, the State Machines can also be ‘dynamic’, that is, adaptable and immediately effective at runtime, without the need for structural adaptions (e.g., of the data model) or adaption of code.
The increasing use of unmanned aerial vehicles (UAVs), called “drones”, in civil and military missions increases the need to create reliable systems for their detection, recognition, tracking and, if necessary, blocking. Drone detection in practice can be achieved using active sensors (radar, LIDAR, ultrasound), passive sensors (camera, microphone, radio eavesdropping) or a combination of them. The paper proposes a model of a system for real-time detection and classification of drones in the presence of noise, interference, and similarly moving objects, using Doppler and micro-Doppler analysis. The model consists of several logically connected levels from which various information about the moving drone is obtained. The Doppler component is used to estimate the radial velocity of the drone, while the micro-Doppler components form a characteristic spectral signature associated with the movement of the rotor blades. These signatures are used to train machine learning algorithms to automatically detect and recognize drones.
Information can be defined as that what contributes to someone’s understanding of a situation. Information can also be defined as material signs representing something else. Both definitions have value, but they represent two different concepts of information. Information in the first sense is a mental phenomenon, hence not directly observable. It can originate from many sources, ranging from material signs via perception to memory. Material signs belong to sign systems such as natural language, pictorial language, formal language. Characteristics of the sign system determine what can be represented through it. Information in business processes is meant to contribute to a proper understanding of the ins and outs of the tasks to be performed. Different sign systems are involved in representing different kinds of business information: operational variables, business values and commitments, planning and coordination guidelines, et cetera. The rationale of a business information system is to provide the people and systems executing business processes with relevant information. In setting up such a system, all kinds of information – using various sign systems – need to be considered. The pragmatics of the working place, where information from heterogeneous sources must be integrated, requires special attention in developing such a system. Matching both the business situation and the mental world of the persons involved is required. This is key to a proper understanding and behaviour in the execution of business processes, hence to the effective and efficient fulfilment of business agreements. .
In process-aware information systems (PAIS), actor assignments are used to define the potential actors (owners) of a task. These actors may be absent for extended periods of time (e.g. due to illness or holiday). However, for urgent tasks, it is essential to ensure that potential actors are always available. Therefore, many applications require that it is possible to define a substitute for such an actor. Since tasks that are assigned to the same actor can realize totally different functions, it must be possible to define the substitutes depending on the current context (e.g. the task type, the concerned project). This is even more important if different applications (e.g. for personnel management and product development) are controlled by the same process management system (PMS). Nevertheless, the topic of substitutes has so far been insufficiently considered in commercial PMS, standards, and scientific literature, i.e. only very limited and inflexible solutions exist. This article presents multiple approaches for the definition of substitutes. Additionally, it proposes several strategies for defining when a substitution rule shall be applied, when indirect substitutes shall be included, and when a substitution shall be revoked. This enables process designers to select the required behavior with great flexibility.
Existing research on open data engagement has predominantly focused on the supply-side indicators or on the subjective demand-side evaluations, while objective-based analysis of the demand-side engagement remains underexplored. Drawing on the platform ecosystem perspective, this paper takes a different approach by examining open data platform engagement as an indicator of value creation through observable behavioral interactions, thereby positioning our study on the demand-side and within an objective-based evaluation. Through interviews with 15 open data platform stakeholders, we identify opportunities to measure engagement using behavioral indicators derived from platform use. Building on these findings, we develop a multi-layer framework of behavioral indicators to measure engagement with open data platforms. The framework consists of four layers which includes: system-level indicators, behavioral metrics, interactive signals, and contextual factors. We present a proof-of-concept implementation that operationalizes the proposed framework using platform logs, providing guidance for open data platform designers and policymakers to evaluate engagement. The paper contributes to the open data evaluation literature by reconceptualizing engagement as an observable, value-creating behavior in open data platforms. In this way, the demand-side is taken into account, and the actual behavior is measured, which data can complement the subjective data. Overall, the study demonstrates how integrating objective measures with subjective evaluation can support a more comprehensive and value-oriented engagement measurement of open data platforms.
Aspect-based sentiment analysis (ACSA) aims to extract fine-grained opinions about aspects or attributes of a specific product or service from a given natural-language task. Aspect Category Opinion Sentiment (ACOS) is an ACSA task, which requires identifying aspect terms, opinion terms, sentiment polarity, and aspect categories within a single sentence, making the task structurally complex. This paper introduces a multi-agent system for ACOS extraction that uses large language models (LLMs). By following the Gaia methodology, the system decomposes the task into specialized agents for aspect–opinion extraction, sentiment classification, and category prediction. We evaluated the approach on the Laptop-ACOS and Restaurant-ACOS benchmarks using three LLMs (GPT-4o, GPT-4o-mini, and DeepSeek-V3) under zero-shot and few-shot prompting. Few-shot prompting substantially improved extraction accuracy, and the modular pipeline consistently outperformed a single-prompt baseline. DeepSeek-V3 achieved performance comparable to GPT-4o while requiring substantially lower inference cost. These results show that modular agentic architectures can accurately extract ACOS without task-specific training, while improving interpretability and cost efficiency.
AI-driven search systems increasingly deliver answers directly within search interfaces, reducing user traffic to original web content providers. In a design science-oriented way, this paper proposes a layered compensation architecture to address the resulting value displacement and preserve the economic viability of content creation in an era of AI-mediated information retrieval. A literature review identifies existing knowledge on zero-click search, platform economics, and copyright compensation. Based on this foundation, a three-layered hybrid compensation architecture is designed and demonstrated that integrates market-based licensing, levy-based redistribution, and technical attribution mechanisms while accounting for the interests of content providers, AI search operators, and end users. The architecture is demonstrated through three illustrative scenarios and assessed analytically against five design objectives. Empirical validation is identified as the central limitation and main avenue for future work. This research contributes to the discourse on the economic sustainability of AI-based application systems by addressing the underexplored economic dimension of AI-driven content retrieval.
In this study, we conducted a thorough review of the cryptographic security and privacy schemes proposed to protect Automatic Dependent Surveillance Broadcast (ADS-B) systems, together with a structured mapping of potential attacks based on security requirements. We systematically select and analyze the 31 most relevant top-venue research papers that enhance ADS-B security and privacy, addressing key properties such as message confidentiality, integrity, authentication, and related aspects. Through a comparative analysis of the existing literature, we evaluate the strengths and limitations of the proposed schemes and their compatibility with the existing ADS-B infrastructure. In addition, this study identifies core security requirements and highlights corresponding vulnerabilities that can be exploited in ADS-B systems. We hope that our comprehensive review can help research and practitioner communities understand and improve ADS-B ecosystems with practical, interoperable, and state-of-the-art hardening solutions.
Due to the challenges of organizational adoption of Artificial Intelligence (AI), the prevalence of Shadow Information Technology (SIT) is growing. In particular with respect to small and medium enterprises, a comprehensive quantitative mapping of its intellectual structure and evolution is lacking. This study addresses this gap by presenting a bibliometric analysis of SIT research based on 188 peer-reviewed publications retrieved from Scopus and Web of Science covering the period from 2008 to 2026, screened according to the PRISMA protocol. Co-citation analysis, bibliographic coupling, and keyword co-occurrence with temporal overlay were performed using VOSviewer. The bibliometric findings were evaluated against two established systematic literature reviews (SLRs). The contribution of our study is threefold: First, it reveals a tripartite intellectual structure organized around behavioral compliance, organizational governance, and information security, with strong inter-group ties indicating substantive theoretical interconnection. Second, we delineate the evolution of SIT into four phases of foundation, exploration, expansion, and diversification, with preliminary evidence suggesting an ascending fifth phase driven by Shadow AI. Finally, our results align with previous SLRs and provide an up-to-date overview of their identified research gaps, while identifying IT governance in distributed work environments and Shadow AI as emerging subfields. The latter potentially marks a fundamental shift in the nature of unsanctioned IT use.
Data centres are becoming increasingly important digital infrastructure, but their growing energy use, emissions, water consumption, and lifecycle impacts create environmental and regulatory challenges. Prior research has addressed important sub-areas such as cooling efficiency, renewable energy integration, waste heat reuse, virtualisation, workload management, and sustainability indicators. However, this knowledge remains fragmented, and practitioners lack a high-level model that connects green data centre practices, enabling conditions, surrounding infrastructure, and measurable sustainability indicators into a single representation. This paper addresses the problem of how conventional data centres can be transformed into green data centres. Using a design science research approach, the study develops a high-level conceptual model informed by recent literature, policy and standards-related material, documentary evidence, stakeholder discussions, field observations, and a site visit. The original contribution is a practice-oriented conceptual artefact that integrates renewable energy use, efficient and free cooling, waste heat reuse, virtualisation, energy-conscious workload handling, monitoring and dynamic control, location and climate considerations, water-use awareness, and IT equipment lifecycle management. The model links these elements to four indicators: PUE, ERF, REF, and WUE. The model was evaluated through formative comparison with the evidence base and an illustrative comparison against three Finnish data centre implementations: Google Hamina, CSC LUMI in Kajaani, and the Telia–Helen district heating integration in Helsinki. The comparison suggests that the model is plausible and useful for planning, communication, and sustainability assessment. The study is limited by its high-level scope and Finnish validation context, and further work should test and refine the model in other climatic, regulatory, and infrastructural settings.
Developing information systems (in general) and software applications (in particular) often responds to needs for improvements as it concerns real-life (business) processes. Nevertheless, the particular trigger for such developments may differ; moreover, we observe “evolution” in time, in this regard: (i) Twenty years ago today it was common to develop software for the sake of automating “men-done” processes; (ii) Some years later, developers would mostly consider service-driven solutions to particular (functional) user needs; (iii) And what we observe to date is deploying technology in response to (non-functional) user “concerns”, that in turn asks for designing new (business) processes. As noted in previous works, all this is about bringing together enterprise modeling and software specification. Still, those differences are important and require explicit consideration. Not claiming exhaustiveness, we analyze those three approaches in the current paper, supported by three corresponding illustrative examples. We plan more elaboration, and also validation of our analysis as future work.
Small and medium-sized enterprises across the EU need a digital contracting infrastructure that is both legally enforceable under the eIDAS regulation and resilient to centralized points of failure. Existing systems address parts of this need—qualified signatures, blockchain anchoring, or self-sovereign identity—but no published architecture combines them. This position paper proposes a hybrid layered architecture in which an Identity Layer connects centralized trust services (OAuth 2.0 through a Qualified Trust Service Provider) with decentralized verifiable credentials managed via Hyperledger Aries, and a Smart Contract Layer on Hyperledger Besu anchors document hashes, signature references, and completion timestamps without placing sensitive content on chain. A verifiable-credential gate mediates entry into the contract layer through off-chain proof verification. We describe the architectural pattern and discuss limitations.
In this paper, we describe a public-key algorithm that constructs an n × n matrix and makes it public. An algorithm is given for translating a message into a sum of the integers stored in this matrix. The sum represents the encrypted message.
NOMIS (Normative Modelling of Information Systems) is a human-centred approach to information systems modelling and development centred on observable human actions. Previous work proposed a model-driven systems development direction for NOMIS, suggesting that its models, notation, and metamodel could support transformations towards software artefacts. However, such transformations require suitable target structures in the software system if NOMIS concepts are to remain explicit and traceable in implementation. This paper addresses this problem through an implemented case study: Vortex Combat, a web-based system for training management and student progression in a Jiu-Jitsu gym. The paper identifies design-oriented requirements for NOMIS operationalisation and proposes candidate mappings between selected NOMIS artefacts and software structures. The case suggests that Human Actions can be mapped to application-level use cases or services, while Environmental States can be mapped to explicit validation objects or Specifications. Other mappings remain more exploratory and require further refinement. The contribution does not define a general reference architecture or a complete code-generation framework. Instead, it provides implementation-based evidence, design lessons, and candidate transformation targets for future model-driven systems development direction for future NOMIS-MDSD.