{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:03:41Z","timestamp":1777806221523,"version":"3.51.4"},"reference-count":57,"publisher":"SAGE Publications","issue":"4","license":[{"start":{"date-parts":[[2022,11,23]],"date-time":"2022-11-23T00:00:00Z","timestamp":1669161600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2023,8,14]]},"abstract":"<jats:p>There is an increasing number of cyber-systems (e.g., systems for payment, transportation, voting, critical infrastructures) whose security depends intrinsically on human users. In this paper, we introduce a novel approach for the formal and automated analysis of security ceremonies. A security ceremony expands a security protocol to include human nodes alongside computer nodes, with communication links that comprise user interfaces, human-to-human communication and transfers of physical objects that carry data, and thus a ceremony\u2019s security analysis should include, in particular, the mistakes that human users might make when participating actively in the ceremony. Our approach defines mutation rules that model possible behaviors of a human user, automatically generates mutations in the behavior of the other agents of the ceremony to match the human-induced mutations, and automatically propagates these mutations through the whole ceremony. This allows for the analysis of the original ceremony specification and its possible mutations, which may include the way in which the ceremony has actually been implemented or could be implemented. To automate our approach, we have developed the tool X-Men, which is a prototype that builds on top of Tamarin, one of the most common tools for the automatic unbounded verification of security protocols. As a proof of concept, we have applied our approach to three real-life case studies, uncovering a number of concrete vulnerabilities. Some of these vulnerabilities were so far unknown, whereas others had so far been discovered only by empirical observation of the actual ceremony execution or by directly formalizing alternative models of the ceremony by hand, but X-Men instead allowed us to find them automatically.<\/jats:p>","DOI":"10.3233\/jcs-210075","type":"journal-article","created":{"date-parts":[[2022,11,25]],"date-time":"2022-11-25T10:00:32Z","timestamp":1669370432000},"page":"293-364","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":6,"title":["A mutation-based approach for the formal and automated analysis of security ceremonies"],"prefix":"10.1177","volume":"31","author":[{"given":"Diego","family":"Sempreboni","sequence":"first","affiliation":[{"name":"Department of Informatics, King\u2019s College London, London, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Luca","family":"Vigan\u00f2","sequence":"additional","affiliation":[{"name":"Department of Informatics, King\u2019s College London, London, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2022,11,23]]},"reference":[{"key":"ref001","doi-asserted-by":"publisher","DOI":"10.1145\/360204.360213"},{"key":"ref002","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-25527-9_7"},{"key":"ref003","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-28756-5_19"},{"key":"ref004","doi-asserted-by":"publisher","DOI":"10.1145\/1456396.1456397"},{"key":"ref005","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2017.12"},{"key":"ref006","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2015.21"},{"key":"ref007","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2016.30"},{"key":"ref008","doi-asserted-by":"publisher","DOI":"10.1007\/11901433_4"},{"key":"ref009","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-30436-1_23"},{"key":"ref010","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-210059"},{"key":"ref011","doi-asserted-by":"publisher","DOI":"10.1007\/s13347-022-00552-0"},{"key":"ref012","doi-asserted-by":"publisher","DOI":"10.5220\/0007921501250136"},{"key":"ref013","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-26096-9_25"},{"key":"ref014","doi-asserted-by":"publisher","DOI":"10.1109\/CSFW.2001.930138"},{"key":"ref015","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-21768-5_6"},{"key":"ref016","doi-asserted-by":"publisher","DOI":"10.5220\/0004129704400445"},{"key":"ref017","unstructured":"N.\u00a0Courtois, K.\u00a0Nohl and S.\u00a0O\u2019Neil, Algebraic attacks on the crypto-1 stream cipher in MiFare classic and oyster cards, IACR Cryptology ePrint Archive, 166 (2008)."},{"key":"ref018","doi-asserted-by":"publisher","DOI":"10.1007\/s00165-007-0035-6"},{"key":"ref019","doi-asserted-by":"publisher","DOI":"10.1002\/stvr.1531"},{"key":"ref020","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-85893-5_20"},{"key":"ref021","unstructured":"R.A.\u00a0DeMillo, R.J.\u00a0Lipton and F.G.\u00a0Sayward, Program Mutation: A New Approach to Program Testing, Infotech State of the Art Report, Software Testing, 1979."},{"key":"ref022","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1983.1056650"},{"key":"ref023","first-page":"1","volume":"399","author":"Ellison C.M.","year":"2007","journal-title":"IACR Cryptology ePrint Archive"},{"key":"ref024","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03829-7_1"},{"key":"ref025","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-1999-72-304"},{"key":"ref026","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88313-5_7"},{"key":"ref027","doi-asserted-by":"publisher","DOI":"10.1109\/CSE-EUC-DCABES.2016.240"},{"key":"ref028","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.62"},{"key":"ref029","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-17016-9_18"},{"key":"ref030","doi-asserted-by":"publisher","DOI":"10.1145\/3373270"},{"key":"ref031","doi-asserted-by":"publisher","DOI":"10.1109\/CSE.2009.324"},{"key":"ref032","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-014-0253-x"},{"key":"ref033","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-39799-8_48"},{"key":"ref034","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04444-1_21"},{"key":"ref035","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03829-7_6"},{"key":"ref036","doi-asserted-by":"publisher","DOI":"10.1145\/2590296.2590330"},{"key":"ref037","unstructured":"T.\u00a0Parr, The Definitive ANTLR 4 Reference, Pragmatic Bookshelf, 2013."},{"key":"ref038","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-1998-61-205"},{"key":"ref039","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-28073-3_2"},{"key":"ref040","doi-asserted-by":"publisher","DOI":"10.1002\/stvr.1685"},{"key":"ref041","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/bxw066"},{"key":"ref042","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-21424-0_9"},{"key":"ref043","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2012.25"},{"issue":"2","key":"ref044","first-page":"105","volume":"26","author":"Semanc\u02d8\u00edk R.","year":"2007","journal-title":"Computing and Informatics"},{"key":"ref045","doi-asserted-by":"publisher","DOI":"10.5220\/0007924901610172"},{"key":"ref046","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00014"},{"key":"ref047","unstructured":"TfL (Transport for London), TfL Transparency strategy, https:\/\/tfl.gov.uk\/corporate\/publications-and-reports\/oyster-card."},{"key":"ref048","unstructured":"TfL (Transport for London), Incomplete journeys, https:\/\/tfl.gov.uk\/fares-and-payments\/oyster\/using-oyster\/incomplete-journeys."},{"key":"ref049","unstructured":"TfL (Transport for London), Card clash, https:\/\/tfl.gov.uk\/fares-and-payments\/oyster\/using-oyster\/card-clash."},{"key":"ref050","unstructured":"The Tamarin user manual, 2020, https:\/\/tamarin-prover.github.io\/manual\/tex\/tamarin-manual.pdf."},{"key":"ref051","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2013.75"},{"key":"ref052","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-42653-8_18"},{"key":"ref053","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-85623-6_3"},{"key":"ref054","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-08143-9_1"},{"key":"ref055","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-92690-8_30"},{"key":"ref056","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW51379.2020.00045"},{"key":"ref057","unstructured":"X-Men: A mutation-based approach for the formal analysis of security ceremonies, 2021, https:\/\/diegosempreboni.github.io\/X-Men\/."}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-210075","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-210075","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-210075","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:43Z","timestamp":1777495543000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-210075"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,23]]},"references-count":57,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,8,14]]}},"alternative-id":["10.3233\/JCS-210075"],"URL":"https:\/\/doi.org\/10.3233\/jcs-210075","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,23]]}}}