{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T18:52:04Z","timestamp":1725475924341},"publisher-location":"Berlin, Heidelberg","reference-count":38,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783540482697"},{"type":"electronic","value":"9783540482727"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2006]]},"DOI":"10.1007\/11915034_79","type":"book-chapter","created":{"date-parts":[[2006,11,29]],"date-time":"2006-11-29T23:40:30Z","timestamp":1164843630000},"page":"554-564","source":"Crossref","is-referenced-by-count":6,"title":["Quantitative Evaluation of Systems with Security Patterns Using a Fuzzy Approach"],"prefix":"10.1007","author":[{"given":"Spyros T.","family":"Halkidis","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alexander","family":"Chatzigeorgiou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"George","family":"Stephanides","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"79_CR1","volume-title":"Fundamentals of Computer Security Technology","author":"E. Amoroso","year":"1994","unstructured":"Amoroso, E.: Fundamentals of Computer Security Technology. Prentice-Hall, Englewood Cliffs (1994)"},{"key":"79_CR2","unstructured":"Anley, C.: Advanced SQL Injection in SQL Server Applications, NGSSoftware whitepaper (2002)"},{"key":"79_CR3","unstructured":"Berry, C.A., Carnell, J., Juric, M.B., Kunnumpurath, M.M., Nashi, N., Romanosky, S.: J2EE Design Patterns Applied, Wrox Press (2002)"},{"key":"79_CR4","unstructured":"Blakley, B., Heath, C. and Members of the Open Group Security Forum: Security Design Patterns, Open Group Technical Guide (2004)"},{"key":"79_CR5","unstructured":"Braga, A., Rubira, C., Dahab, R.: Tropyc: A Pattern Language for Cryptographic Software. In: Proceedings of the 5th Conference on Pattern Languages of Programming (PLoP 1998) (1998)"},{"issue":"3","key":"79_CR6","doi-asserted-by":"publisher","first-page":"256","DOI":"10.1016\/S0167-4048(03)00313-4","volume":"22","author":"P.J. Brooke","year":"2003","unstructured":"Brooke, P.J., Paige, R.F.: Fault Trees for Security System Design and Analysis. Computers and Security\u00a022(3), 256\u2013264 (2003)","journal-title":"Computers and Security"},{"key":"79_CR7","doi-asserted-by":"crossref","DOI":"10.1007\/978-1-4613-1403-5","volume-title":"Introduction to Fuzzy Reliability","author":"K.-Y. Cai","year":"1996","unstructured":"Cai, K.-Y.: Introduction to Fuzzy Reliability. Kluwer Academic Publishers, Dordrecht (1996)"},{"key":"79_CR8","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1016\/0165-0114(95)00385-1","volume":"83","author":"K.-Y. Cai","year":"1996","unstructured":"Cai, K.-Y.: System Failure Engineering and Fuzzy Methodology, An Introductory Overview. Fuzzy Sets and Systems\u00a083, 113\u2013133 (1996)","journal-title":"Fuzzy Sets and Systems"},{"key":"79_CR9","doi-asserted-by":"crossref","unstructured":"Chen, S.-J., Chen, S.-M.: Fuzzy Risk Analysis Based on Similarity Measures of Generalized Fuzzy Numbers. IEEE Transactions on Fuzzy Sets and Systems\u00a011(1) (2003)","DOI":"10.1109\/TFUZZ.2002.806316"},{"key":"79_CR10","unstructured":"Cgisecurity.com, Cross Site Scripting questions and answers, http:\/\/www.cgisecurity.com\/articles\/xss-faq.shtml"},{"key":"79_CR11","unstructured":"Fernandez, E.: Metadata and authorization patterns (2000), http:\/\/www.cse.fau.edu\/~ed\/MetadataPatterns.pdf"},{"key":"79_CR12","unstructured":"Friedl, S.: SQL Injection Attacks by Example, http:\/\/www.unixwiz.net\/techtips\/sql-injection.html"},{"key":"79_CR13","volume-title":"Design Patterns, Elements of Reusable Object-Oriented Software","author":"E. Gamma","year":"1995","unstructured":"Gamma, E., Helm, R., Johnson, R., Vlissides, J.: Design Patterns, Elements of Reusable Object-Oriented Software. Addison-Wesley, Reading (1995)"},{"key":"79_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30191-2_11","volume-title":"Information and Communications Security","author":"S.T. Halkidis","year":"2004","unstructured":"Halkidis, S.T., Chatzigeorgiou, A., Stephanides, G.: A Qualitative Evaluation of Security Patterns. In: L\u00f3pez, J., Qing, S., Okamoto, E. (eds.) ICICS 2004. LNCS, vol.\u00a03269, Springer, Heidelberg (2004)"},{"key":"79_CR15","volume-title":"Exploiting Software, How to Break Code","author":"G. Hoglund","year":"2004","unstructured":"Hoglund, G., McGraw, G.: Exploiting Software, How to Break Code. Addison-Wesley, Reading (2004)"},{"key":"79_CR16","unstructured":"Howard, M., LeBlanc, D.: Writing Secure Code. Microsoft Press (2002)"},{"key":"79_CR17","unstructured":"Hu, D.: Preventing Cross-Site Scripting Vulnerability, SANS Institute whitepaper (2004)"},{"key":"79_CR18","unstructured":"Kienzle, D., Elder, M.: Security Patterns for Web Application Development, Univ. of Virginia Technical Report (2002)"},{"key":"79_CR19","unstructured":"Klein, A.: Divide and Conquer. HTTP Response Splitting, Web Cache Poisoning Attacks and Related Topics, Sanctum whitepaper (2004)"},{"key":"79_CR20","unstructured":"Lee Brown, F., Di Vietri, J., Diaz de Villegas, G., Fernandez, E.: The Authenticator Pattern. In: Proceedings of the 6th Conference on Pattern Languages of Programming (PLoP 1999) (1999)"},{"key":"79_CR21","unstructured":"Livshits, B., Lam, M.S.: Proceedings of the 14th USENIX Security Symposium (2005)"},{"key":"79_CR22","unstructured":"Livshits, B., Lam, M.S.: Finding Security Vulnerabilities in Java Applications with Static Analysis, Stanford University Technical Report (2005)"},{"key":"79_CR23","unstructured":"Mahmoud, Q.: Security Policy: A Design Pattern for Mobile Java Code. In: Proceedings of the 7th Conference on Pattern Languages of Programming (PLoP 2000) (2000)"},{"key":"79_CR24","unstructured":"Mouratidis, H., Giorgini, P., Schumacher, M.: Security Patterns for Agent Systems. In: Proceedings of the Eighth European Conference on Pattern Languages of Programs (EuroPLoP 2003) (2003)"},{"key":"79_CR25","unstructured":"Pullum, L.L.: Software Fault Tolerance Techniques and Implementation. Artech House Publishers (2001)"},{"key":"79_CR26","volume-title":"Mastering Enterprise JavaBeans","author":"E. Roman","year":"2005","unstructured":"Roman, E., Sriganesh, R.P., Brose, G.: Mastering Enterprise JavaBeans, 3rd edn. Wiley, Chichester (2005)","edition":"3"},{"key":"79_CR27","unstructured":"Romanosky, S.: Enterprise Security Patterns (2002), http:\/\/www.romanosky.net\/papers\/EnterpriseSecurityPatterns.pdf"},{"key":"79_CR28","unstructured":"Ross, B., Jackson, C., Miyake, N., Boneh, D., Mitchell, J.C.: Stronger Password Authentication Using Browser Extensions. In: Proceedings of the 14th USENIX Security Symposium (2005)"},{"key":"79_CR29","volume-title":"Hacking Exposed Web Applications","author":"J. Scambray","year":"2002","unstructured":"Scambray, J., Shema, M.: Hacking Exposed Web Applications. McGraw-Hill, New York (2002)"},{"key":"79_CR30","unstructured":"Spett, K.: Cross-Site Scripting, Are your web applications vulnerable? SPI Labs whitepaper"},{"key":"79_CR31","unstructured":"SPI Labs, SQL Injection, Are Your Web Applications Vulnerable? SPI Labs whitepaper"},{"key":"79_CR32","volume-title":"Code Quality : The Open Source Perspective","author":"D. Spinnelis","year":"2006","unstructured":"Spinnelis, D.: Code Quality: The Open Source Perspective. Addison-Wesley, Reading (2006)"},{"key":"79_CR33","volume-title":"Core Security Patterns, Best Practices and Strategies for J2EE, Web Services, and Identity Management","author":"C. Steel","year":"2006","unstructured":"Steel, C., Nagappan, R., Lai, R.: Core Security Patterns, Best Practices and Strategies for J2EE, Web Services, and Identity Management. Prentice-Hall, Englewood Cliffs (2006)"},{"key":"79_CR34","volume-title":"Building Secure Software, How to Avoid Security Problems the Right Way","author":"J. Viega","year":"2002","unstructured":"Viega, J., McGraw, G.: Building Secure Software, How to Avoid Security Problems the Right Way. Addison-Wesley, Reading (2002)"},{"key":"79_CR35","unstructured":"Yoder, J., Barcalow, J.: Architectural Patterns for enabling application security. In: Proceedings of the 4th Conference on Pattern Languages of Programming (PLoP 1997) (1997)"},{"key":"79_CR36","unstructured":"Weiss, M.: Patterns for Web Applications. In: Proceedings of the 10th Conference on Pattern Languages of Programming (PLoP 2003) (2003)"},{"key":"79_CR37","unstructured":"Wu, T.: A Real-World Analysis of Kerberos Password Security. In: Proceedings of the 1999 Network and Distributed System Symposium (1999)"},{"key":"79_CR38","doi-asserted-by":"crossref","DOI":"10.1007\/978-94-015-8702-0","volume-title":"Fuzzy Set Theory and its Applications","author":"H.-J. Zimmerman","year":"1996","unstructured":"Zimmerman, H.-J.: Fuzzy Set Theory and its Applications, 3rd edn. Kluwer Academic, Dordrecht (1996)","edition":"3"}],"container-title":["Lecture Notes in Computer Science","On the Move to Meaningful Internet Systems 2006: OTM 2006 Workshops"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/11915034_79.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,27]],"date-time":"2021-04-27T07:41:13Z","timestamp":1619509273000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/11915034_79"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006]]},"ISBN":["9783540482697","9783540482727"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/11915034_79","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2006]]}}}