{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T07:39:39Z","timestamp":1742974779504,"version":"3.40.3"},"publisher-location":"Boston, MA","reference-count":93,"publisher":"Springer US","isbn-type":[{"type":"print","value":"9780387887746"},{"type":"electronic","value":"9780387887753"}],"license":[{"start":{"date-parts":[[2009,1,1]],"date-time":"2009-01-01T00:00:00Z","timestamp":1230768000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2009,1,1]],"date-time":"2009-01-01T00:00:00Z","timestamp":1230768000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009]]},"DOI":"10.1007\/978-0-387-88775-3_2","type":"book-chapter","created":{"date-parts":[[2009,4,18]],"date-time":"2009-04-18T17:55:18Z","timestamp":1240077318000},"page":"21-36","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Security and Dependability Engineering"],"prefix":"10.1007","author":[{"given":"Jan","family":"J&rjens","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2009,3,31]]},"reference":[{"key":"2_CR1_2","unstructured":"Agreiter B, Alam M, Hafner M, Seifert J-P, and Zhang X (2007). Model driven configuration of secure operating systems for mobile applications in healthcare. In Sztipanovits et al. [83]."},{"key":"2_CR2_2","doi-asserted-by":"crossref","unstructured":"Alam M, Hafner M, and Breu R (2007). Model-driven security engineering for trust management in SECTET. Journal of Software, 2(1).","DOI":"10.4304\/jsw.2.1.47-59"},{"key":"2_CR3_2","unstructured":"Alam M, Hafner M, Memon M, and Hung P (2007). Modeling and enforcing advanced access control policies in healthcare systems with SECTET. In Sztipanovits et al. [83]."},{"key":"2_CR4_2","volume-title":"Security Engineering: A Guide to Building Dependable Distributed Systems","author":"R Anderson","year":"2001","unstructured":"Anderson R (2001). Security Engineering: A Guide to Building Dependable Distributed Systems. John Wiley & Sons, New York."},{"issue":"4","key":"2_CR5_2","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1109\/MSP.2005.103","volume":"3","author":"A Apvrille","year":"2005","unstructured":"Apvrille A and Pourzandi M (2005). Secure software development by example. IEEE Security & Privacy, 3(4):10\u201317.","journal-title":"IEEE Security & Privacy"},{"key":"2_CR6_2","doi-asserted-by":"crossref","unstructured":"Arenas A, Aziz B, Bicarregui J, Matthews B, and Yang EY (2008). Modelling security properties in a grid-based operating system with anti-goals. In ARES [42]: 1429\u20131436.","DOI":"10.1109\/ARES.2008.159"},{"key":"2_CR7_2","doi-asserted-by":"crossref","unstructured":"Basin DA, Clavel M, Doser J, Egea M (2007). A Metamodel-Based Approach for Analyzing Security-Design Models. MoDELS 2007: 420\u2013435.","DOI":"10.1007\/978-3-540-75209-7_29"},{"key":"2_CR8_2","unstructured":"Breu R, Burger K, Hafner M, J\u00fcrjens J, Popp G, Wimmel G, Lotz V (2003). Key Issues of a Formally Based Process Model for Security Engineering. In Sixteenth Intern. Conference on Software & Systems Engineering & their Applications (ICSSEA 2003)."},{"issue":"4","key":"2_CR9_2","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1007\/s10550-006-0097-7","volume":"24","author":"A Baldwin","year":"2006","unstructured":"Baldwin A, Beres Y, Shiu S, and Kearney P (2006). A model based approach to trust, security and assurance. BT Technology Journal, 24(4):53\u201368.","journal-title":"BT Technology Journal"},{"issue":"1","key":"2_CR10_2","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1145\/1125808.1125810","volume":"15","author":"DA Basin","year":"2006","unstructured":"Basin DA, Doser J, and Lodderstedt T (2006). Model driven security: From UML models to access control infrastructures. ACM Trans. Softw. Eng. Methodol., 15(1): 39\u201391.","journal-title":"ACM Trans. Softw. Eng. Methodol"},{"key":"2_CR11_2","unstructured":"Bauer A and J\u00fcrjens J (2008). Security protocols, properties, and their monitoring. In Bart De Win, Seok-Won Lee, and Mattia Monga, editors, SESS: 33\u201340. ACM."},{"key":"2_CR12_2","doi-asserted-by":"crossref","unstructured":"Best B, J\u00fcrjens J, and Nuseibeh B (2007). Model-based security engineering of distributed information systems using UMLsec. In ICSE. ACM.","DOI":"10.1109\/ICSE.2007.55"},{"key":"2_CR13_2","doi-asserted-by":"crossref","unstructured":"Bhargavan K, Fournet C, Gordon AD, and Tse S (2006). Verified interoperable implementations of security protocols. In CSFW: 139\u2013152. IEEE Computer Society.","DOI":"10.1007\/11841197_6"},{"issue":"8","key":"2_CR14_2","doi-asserted-by":"publisher","first-page":"597","DOI":"10.1016\/j.ijmedinf.2005.08.010","volume":"75","author":"B Blobel","year":"2006","unstructured":"Blobel B, Nordberg R, Davis JM, and Pharow P (2006). Modelling privilege management and access control. International Journal of Medical Informatics, 75(8): 597\u2013623.","journal-title":"International Journal of Medical Informatics"},{"issue":"2\u20133","key":"2_CR15_2","doi-asserted-by":"publisher","first-page":"169","DOI":"10.1016\/j.ijmedinf.2006.05.044","volume":"76","author":"B Blobel","year":"2007","unstructured":"Blobel B and Pharow P (2007). A model-driven approach for the german health telematics architectural framework and security infrastructure. International Journal of Medical Informatics, 76(2\u20133): 169\u2013175.","journal-title":"International Journal of Medical Informatics"},{"key":"2_CR16_2","volume-title":"Software Engineering Economics","author":"BW Boehm","year":"1981","unstructured":"Boehm BW (1981). Software Engineering Economics. Prentice Hall, Englewood Cliffs, NJ."},{"key":"2_CR17_2","doi-asserted-by":"crossref","unstructured":"Brucker AD, Doser J, and Wolff B (2006). A model transformation semantics and analysis methodology for SecureUML. In MoDELS 2006, volume 4199 of LNCS: 306\u2013320. Springer.","DOI":"10.1007\/11880240_22"},{"key":"2_CR18_2","doi-asserted-by":"crossref","unstructured":"Buchholtz M, Gilmore S, Haenel V, and Montangero C (2005). End-to-end integrated security and performance analysis on the DEGAS Choreographer Platform. In FM 2005, volume 3582 of LNCS: 286\u2013301. Springer.","DOI":"10.1007\/11526841_20"},{"key":"2_CR19_2","unstructured":"Crook R, Ince DC, Lin L, and Nuseibeh B (2002). Security requirements engineering: When anti-requirements hit the fan. In RE 2002: 203\u2013205. IEEE."},{"key":"2_CR20_2","doi-asserted-by":"crossref","unstructured":"Daskala B and Maghiros I (2007). Digital Territories \u2013 Towards the protection of public and private space in a digital and Ambient Intelligence environment. Institute for Prospective Technological Studies (IPTS).","DOI":"10.1049\/cp:20060698"},{"key":"2_CR21_2","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1145\/1035167.1035185","volume":"2004","author":"M Deubler","year":"2004","unstructured":"Deubler M, Gr\u00fcnbauer J, J\u00fcrjens J, and Wimmel G (2004). Sound development of secure service-based systems. In ICSOC 2004: 115\u2013124. ACM.","journal-title":"In ICSOC"},{"key":"2_CR22_2","doi-asserted-by":"crossref","unstructured":"Devanbu P and Stubblebine S (2000). Software engineering for security: a roadmap. In The Future of Software Engineering (ICSE 2000): 227\u2013239.","DOI":"10.1145\/336512.336559"},{"key":"2_CR23_2","doi-asserted-by":"crossref","unstructured":"Dimitrakos T, Ritchie B, Raptis D, Aagedal J\u00d8, den Braber F, St\u00f8len K, and Houmb SH (2002). Integrating model-based security risk management into ebusiness systems development: The CORAS approach. In Second IFIP Conference on E-Commerce, E-Business, E-Government (I3E 2002): 159\u2013175. Kluwer.","DOI":"10.1007\/978-0-387-35617-4_11"},{"key":"2_CR24_2","doi-asserted-by":"crossref","unstructured":"Eckert C and Marek D (1997). Developing secure applications: A systematic approach. In 13th International Conference on Information Security (SEC 1998): 267\u2013279.","DOI":"10.1007\/978-0-387-35259-6_21"},{"key":"2_CR25_2","doi-asserted-by":"crossref","unstructured":"Elahi G and Yu E (2007). A goal oriented approach for modeling and analyzing security trade-offs. In ER 2007, volume 4801 of LNCS: 375\u2013390. Springer.","DOI":"10.1007\/978-3-540-75563-0_26"},{"key":"2_CR26_2","doi-asserted-by":"crossref","unstructured":"Fernandez EB and Hawkins JC (1997). Determining role rights from use cases. In Workshop on Role-Based Access Control: 121\u2013125. ACM.","DOI":"10.1145\/266741.266767"},{"key":"2_CR27_2","doi-asserted-by":"crossref","unstructured":"Fernandez EB, Larrondo-Petrie MM, Sorgente T, and VanHilst M (2006). A methodology to develop secure systems using patterns. In H Mouratidis and P Giorgini, editors, Integrating security and software engineering: Advances and future vision, chapter 5: 107\u2013126. IDEA Press.","DOI":"10.4018\/978-1-59904-147-6.ch005"},{"key":"2_CR28_2","doi-asserted-by":"crossref","unstructured":"Fern\u00e1ndez-Medina E and Piattini M (2004). Extending OCL for secure database development. In UML 2004, LNCS: 380\u2013394. Springer.","DOI":"10.1007\/978-3-540-30187-5_27"},{"issue":"1","key":"2_CR29_2","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1504\/IJESDF.2007.013589","volume":"1","author":"I Flechais","year":"2007","unstructured":"Flechais I, Mascolo C, and Sasse MA (2007). Integrating security and usability into the requirements and design process. International Journal of Electronic Security and Digital Forensics, 1(1):12\u201326.","journal-title":"International Journal of Electronic Security and Digital Forensics"},{"key":"2_CR30_2","unstructured":"Model-driven security: Enabling a real-time, adaptive security infrastructure. Gartner Briefing G00151498, 21 Sep. 2007."},{"key":"2_CR31_2","doi-asserted-by":"crossref","unstructured":"Gilmore S, Haenel V, Kloul L, and Maidl M (2005). Choreographing security and performance analysis for web services. In EPEW\/WS-FM 2005, volume 3670 of LNCS: 200\u2013214. Springer.","DOI":"10.1007\/11549970_15"},{"key":"2_CR32_2","doi-asserted-by":"crossref","unstructured":"Giorgini P, Massacci F, and Mylopoulos J (2003). Requirement engineering meets security: A case study on modelling secure electronic transactions by VISA and Mastercard. In I.-Y. Song, S. W. Liddle, T. W. Ling, and P Scheuermann, editors, 22nd International Conference on Conceptual Modeling (ER 2003), volume 2813 of LNCS: 263\u2013276. Springer.","DOI":"10.1007\/978-3-540-39648-2_22"},{"key":"2_CR33_2","doi-asserted-by":"crossref","unstructured":"Giorgini P, Massacci F, Mylopoulos J, and Zannone N (2005). Modeling security requirements through ownership, permission and delegation. In RE: 167\u2013176. IEEE Computer Society.","DOI":"10.1109\/RE.2005.43"},{"key":"2_CR34_2","doi-asserted-by":"crossref","unstructured":"Gollmann D (2000). On the verification of cryptographic protocols \u2013 a tale of two committees. In S Schneider and P Ryan, editors, Workshop on Security Architectures and Information Flow, volume 32 of ENTCS. Elsevier.","DOI":"10.1016\/S1571-0661(04)00094-5"},{"key":"2_CR35_2","doi-asserted-by":"crossref","unstructured":"Goubault-Larrecq J and Parrennes F (2005). Cryptographic protocol analysis on real c code. In VMCAI'05, LNCS. Springer.","DOI":"10.1007\/978-3-540-30579-8_24"},{"key":"2_CR36_2","unstructured":"G\u00fcrgens S and Peralta R (2000). Validation of cryptographic protocols by efficient automated testing. In James N. Etheredge and Bill Z. Manaris, editors, FLAIRS Conference: 7\u201312. AAAI Press."},{"issue":"1","key":"2_CR37_2","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1109\/TSE.2007.70754","volume":"34","author":"CB Haley","year":"2008","unstructured":"Haley CB, Laney RC, Moffett JD, and Nuseibeh B (2008). Security requirements engineering: A framework for representation and analysis. IEEE Trans. Software Eng., 34(1):133\u2013153.","journal-title":"Software Eng"},{"key":"2_CR38_2","doi-asserted-by":"crossref","unstructured":"Haneberg D, Reif W, and Stenzel K (2002). A method for secure smartcard applications. In H\u00e9l\u00e8ne Kirchner and Christophe Ringeissen, editors, AMAST, volume 2422 of Lecture Notes in Computer Science: 319\u2013333. Springer.","DOI":"10.1007\/3-540-45719-4_22"},{"key":"2_CR39_2","doi-asserted-by":"crossref","unstructured":"Heldal R and Hultin F (2003). Bridging model-based and language-based security. In E Snekkenes and D Gollmann, editors, 8th European Symposium on Research in Computer Security (ESORICS 2003), volume 2808 of LNCS: 235\u2013252. Springer.","DOI":"10.1007\/978-3-540-39650-5_14"},{"key":"2_CR40_2","doi-asserted-by":"crossref","unstructured":"H\u00f6hn S and J\u00fcrjens J (2008). Rubacon: automated support for model-based compliance engineering. In Robby, editor, ICSE: 875\u2013878. ACM.","DOI":"10.1145\/1368088.1368228"},{"key":"2_CR41_2","unstructured":"Houmb SH, Georg G, France RB, Bieman JM, and J\u00fcrjens J (2005). Cost-benefit trade-off analysis using BBN for aspect-oriented risk-driven development. In ICECCS: 195\u2013204. IEEE Computer Society."},{"key":"2_CR42_2","unstructured":"IEEE. 3rd Int Conference on Availability, Reliability and Security (ARES 2008), 2008."},{"key":"2_CR43_2","unstructured":"Jayaram KR and Mathur A (2005). Software engineering for secure software \u2013 state of the art: A survey. Technical Report CERIAS-TR-2005-67, SERC-TR-279, CERIAS, Purdue."},{"key":"2_CR44_2","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens J (2000). Secure information flow for concurrent processes. In C Palamidessi, editor, CONCUR 2000 (11th International Conference on Concurrency Theory), volume 1877 of LNCS: 395\u2013409. Springer.","DOI":"10.1007\/3-540-44618-4_29"},{"key":"2_CR45_2","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens J (2001). Secrecy-preserving refinement. In International Symposium on Formal Methods Europe (FME), volume 2021 of LNCS: 135\u2013152. Springer.","DOI":"10.1007\/3-540-45251-6_8"},{"key":"2_CR46_2","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens J (2001). Towards development of secure systems using UMLsec. In H Hu\u00dfmann, editor, 4th International Conference on Fundamental Approaches to Software Engineering (FASE), volume 2029 of LNCS: 187\u2013200. Springer. Also Oxford University Computing Laboratory TR-9-00 (November 2000), http:\/\/web.comlab.ox.ac.uk\/oucl\/publications\/tr\/tr-9-00.html","DOI":"10.1007\/3-540-45314-8_14"},{"key":"2_CR47_2","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens J (2002). UMLsec: Extending UML for secure systems development. In 5th Int Conf on the Unified Modeling Language (UML), LNCS. Springer.","DOI":"10.1145\/508791.508990"},{"key":"2_CR48_2","doi-asserted-by":"crossref","first-page":"29","DOI":"10.1007\/978-0-387-35496-5_4","volume-title":"Formal Methods for Open Object-Based Distributed Systems (FMOODS 2002)","author":"J J\u00fcrjens","year":"2002","unstructured":"J\u00fcrjens J (2002). Formal Semantics for Interacting UML subsystems. In Formal Methods for Open Object-Based Distributed Systems (FMOODS 2002), IFIP, Kluwer: 29\u201343."},{"key":"2_CR49_2","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens J, Shabalin P (2004). Automated Verification of UMLsec Models for Security Requirements. In 7th Intern. Conference on The Unified Modeling Language (UML 2004), Lecture Notes in Computer Science: 142\u2013155. Springer.","DOI":"10.1007\/978-3-540-30187-5_26"},{"key":"2_CR50_2","unstructured":"J\u00fcrjens J (2005). Secure Systems Development with UML. Springer."},{"key":"2_CR51_2","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens J (2005). Sound methods and effective tools for model-based security engineering with UML. In 27th Int Conf on Softw Engineering. IEEE.","DOI":"10.1145\/1062455.1062519"},{"key":"2_CR52_2","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens J (2006). Security analysis of crypto-based Java programs using automated theorem provers. In S Easterbrook and S Uchitel, editors, 21st IEEE\/ACM International Conference on Automated Software Engineering (ASE 2006). ACM.","DOI":"10.1109\/ASE.2006.60"},{"key":"2_CR53_2","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens J (2009). A domain-specific language for cryptographic protocols based on streams. To appear, Journal of Logic and Algebraic Programming (JLAP): 54\u201373.","DOI":"10.1016\/j.jlap.2008.08.006"},{"key":"2_CR54_2","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens J and Rumm R (2008). Model-based security analysis of the German Health Card architecture. Methods of Information in Medicine, vol. 47, 5: 409\u2013416. Special section on Model-based Development of Trustworthy Health Information Systems.","DOI":"10.3414\/ME9122"},{"key":"2_CR55_2","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens J and Shabalin P (2007). Tools for secure systems development with UML. Intern. Journal on Software Tools for Technology Transfer, 9(5\u20136):527\u2013544. Invited submission to the special issue for FASE 2004\/05.","DOI":"10.1007\/s10009-007-0048-8"},{"key":"2_CR56_2","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens J, Wimmel G (2001). Security Modelling for Electronic Commerce: The Common Electronic Purse Specifications. In Towards the E-Society: E-Commerce, E-Business, and E-Government. Intern. Federation for Information Processing (IFIP), Kluwer Academic Publishers: 489\u2013506. First IFIP Conference on E-Commerce, E-Business, and E-Government (I3E 2001).","DOI":"10.1007\/0-306-47009-8_36"},{"key":"2_CR57_2","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens J and Yampolskiy M (2005). Code security analysis with assertions. In D.F. Redmiles, T Ellman, and A Zisman, editors, 20th IEEE\/ACM International Conference on Automated Software Engineering (ASE 2005): 392\u2013395. ACM.","DOI":"10.1145\/1101908.1101978"},{"key":"2_CR58_2","doi-asserted-by":"crossref","unstructured":"Kearney P and Br\u00fcgger L (2007). A risk-driven security analysis method and modelling language. BT Technology Journal, 25(1).","DOI":"10.1007\/s10550-007-0016-6"},{"issue":"4","key":"2_CR59_2","doi-asserted-by":"publisher","first-page":"429","DOI":"10.1007\/s10270-006-0030-z","volume":"5","author":"M Koch","year":"2006","unstructured":"Koch M and Parisi-Presicce F (2006). UML specification of access control policies and their formal verification. Software and System Modeling, 5(4):429\u2013447.","journal-title":"Software and System Modeling"},{"key":"2_CR60_2","doi-asserted-by":"crossref","unstructured":"Kolarczyk S, Koch M, L\u00f6hr K-P , and Pauls K (2006). SecTOOL \u2013 supporting requirements engineering for access control. In G\u00fcnter M\u00fcller, editor, ETRICS, volume 3995 of Lecture Notes in Computer Science: 254\u2013267. Springer.","DOI":"10.1007\/11766155_18"},{"issue":"1","key":"2_CR61_2","doi-asserted-by":"crossref","first-page":"31","DOI":"10.3233\/JCS-1997-5103","volume":"5","author":"V Lotz","year":"1997","unstructured":"Lotz V (1997). Threat scenarios as a means to formally develop secure systems. Journal of Computer Security, 5(1):31\u201368.","journal-title":"Journal of Computer Security"},{"key":"2_CR62_2","doi-asserted-by":"crossref","unstructured":"Ma\u00f1a A, Montenegro JA, Rudolph C, and Vivas JL (2003). A business process-driven approach to security engineering. In DEXA Workshops: 477\u2013481. IEEE Computer Society.","DOI":"10.1109\/DEXA.2003.1232069"},{"key":"2_CR63_2","doi-asserted-by":"crossref","unstructured":"Ma\u00f1a A, Rudolph C, Spanoudakis G, Lotz V, Massacci F, Melideo M, and L\u00f3pez-Cobo J-M (2006). Security engineering for Ambient Intelligence: A manifesto. In H Mouratidis, editor, Integrating Security and Software Engineering: Advances and Future Vision. Idea Group.","DOI":"10.4018\/978-1-59904-147-6.ch011"},{"issue":"3","key":"2_CR64_2","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1007\/s10515-007-0013-5","volume":"14","author":"F Massacci","year":"2007","unstructured":"Massacci F, Mylopoulos J, and Zannone N (2007). Computer-aided support for secure tropos. Autom. Softw. Eng., 14(3):341\u2013364.","journal-title":"Autom. Softw. Eng"},{"key":"2_CR65_2","unstructured":"Mathe J, Duncavage S, Werner J, Malin B, Ledeczi A, and Sztipanovits J (2007). Implementing a model-based design environment for clinical information systems. In Sztipanovits et al. [83]."},{"key":"2_CR66_2","doi-asserted-by":"crossref","unstructured":"McGraw G (2006). Software Security: Building Security In. Addison Wesley.","DOI":"10.1109\/ISSRE.2006.43"},{"issue":"8","key":"2_CR67_2","first-page":"1073","volume":"13","author":"D M\u00e9ry","year":"2007","unstructured":"M\u00e9ry D and Merz S (2007). Specification and refinement of access control. J. UCS, 13(8):1073\u20131093.","journal-title":"J. UCS"},{"key":"2_CR68_2","doi-asserted-by":"crossref","unstructured":"Moebius N, Haneberg D, Reif W, and Schellhorn G (2007). A modeling framework for the development of provably secure e-commerce applications. In ICSEA: 8. IEEE Computer Society.","DOI":"10.1109\/ICSEA.2007.7"},{"key":"2_CR69_2","doi-asserted-by":"crossref","unstructured":"Mouratidis H, Giorgini P, and Manson GA (2003). Integrating security and systems engineering: Towards the modelling of secure information systems. In J Eder and M Missikoff, editors, 15th International Conference on Advanced Information Systems Engineering (CAiSE 2003), volume 2681 of LNCS: 63\u201378. Springer.","DOI":"10.1007\/3-540-45017-3_7"},{"key":"2_CR70_2","doi-asserted-by":"crossref","unstructured":"Mouratidis H, J\u00fcrjens J, and Fox J (2006). Towards a comprehensive framework for secure systems development. In 18th International Conference on Advanced Information Systems Engineering (CAiSE 2006), LNCS. Springer.","DOI":"10.1007\/11767138_5"},{"key":"2_CR71_2","first-page":"72","volume":"2008","author":"A Pironti","year":"2008","unstructured":"Pironti A, Sisto R (2008). Soundness Conditions for Message Encoding Abstractions in Formal Security Protocol Models. In ARES 2008: 72\u201379.","journal-title":"In ARES"},{"issue":"9","key":"2_CR72_2","doi-asserted-by":"publisher","first-page":"575","DOI":"10.1016\/j.infsof.2003.10.007","volume":"46","author":"I Ray","year":"2004","unstructured":"Ray I, France RB, Li N, and Georg G (2004). An aspect-based approach to modeling access control concerns. Information & Software Technology, 46(9):575\u2013587.","journal-title":"Information & Software Technology"},{"key":"2_CR73_2","unstructured":"Redwine S (2007). Introduction to modeling tools for software security. In: Build Security In \u2013 Setting a Higher Standard for Software Assurance. Software Engineering Institute (SEI), Carnegie Mellon University. Available at https:\/\/buildsecurityin.us-cert.gov\/daisy\/bsi\/articles\/tools\/modeling\/698-BSI.html"},{"key":"2_CR74_2","doi-asserted-by":"crossref","unstructured":"Rosado DG, Fern\u00e1ndez-Medina E, Piattini M, and Guti\u00e9rrez C (2006). A study of security architectural patterns. In ARES: 358\u2013365. IEEE Computer Society.","DOI":"10.1109\/ARES.2006.18"},{"issue":"9","key":"2_CR75_2","doi-asserted-by":"publisher","first-page":"1278","DOI":"10.1109\/PROC.1975.9939","volume":"63","author":"J Saltzer","year":"1975","unstructured":"Saltzer J and Schroeder M (1975). The protection of information in computer systems. Proceedings of the IEEE, 63(9):1278\u20131308.","journal-title":"Proceedings of the IEEE"},{"key":"2_CR76_2","doi-asserted-by":"crossref","unstructured":"Santen T (2006). Stepwise development of secure systems. In Janusz G\u00f3rski, editor, SAFE-COMP, volume 4166 of Lecture Notes in Computer Science: 142\u2013155. Springer.","DOI":"10.1007\/11875567_11"},{"key":"2_CR77_2","doi-asserted-by":"crossref","unstructured":"Santen T, Heisel M, and Pfitzmann A (2002). Confidentiality-preserving refinement is compositional \u2013 sometimes. In Dieter Gollmann, G\u00fcnter Karjoth, and Michael Waidner, editors, ESORICS, volume 2502 of Lecture Notes in Computer Science: 194\u2013211. Springer.","DOI":"10.1007\/3-540-45853-0_12"},{"key":"2_CR78_2","unstructured":"Schneider F, editor (1999). Trust in Cyberspace. National Academy Press, Washington, DC. Available at http:\/\/www.nap.edu\/readingroom\/books\/trust"},{"key":"2_CR79_2","doi-asserted-by":"crossref","unstructured":"Seehusen F and St\u00f8len K (2006). Information flow property preserving transformation of UML interaction diagrams. In David F. Ferraiolo and Indrakshi Ray, editors, SACMAT: 150\u2013159. ACM.","DOI":"10.1145\/1133058.1133080"},{"issue":"1","key":"2_CR80_2","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/s00766-004-0194-4","volume":"10","author":"G Sindre","year":"2005","unstructured":"Sindre G and Opdahl AL (2005). Eliciting security requirements with misuse cases. Requir. Eng., 10(1):34\u201344.","journal-title":"Requir. Eng"},{"key":"2_CR81_2","doi-asserted-by":"crossref","unstructured":"Siveroni I, Zisman A, and Spanoudakis G (2008). Property specification and static verification of UML models. In 3rd International Conference on Availability, Reliability, and Security (ARES'08).","DOI":"10.1109\/ARES.2008.194"},{"key":"2_CR82_2","doi-asserted-by":"crossref","unstructured":"Spanoudakis G, Kloukinas C, and Androutsopoulos K (2007). Towards security monitoring patterns. In SAC: 1518\u20131525. ACM.","DOI":"10.1145\/1244002.1244327"},{"key":"2_CR83_2","unstructured":"Sztipanovits J, Breu R, Ammenwerth E, Bajcsy R, Mitchell JC, and Pretschner A, editors (2007). Workshop on Model-based Trustworthy Health Information Systems (MOTHIS@Models)."},{"key":"2_CR84_2","unstructured":"UMLsec group. Security analysis tool, 2004. http:\/\/www.umlsec.org"},{"key":"2_CR85_2","doi-asserted-by":"crossref","unstructured":"Whittle J, Wijesekera D, and Hartong M (2008). Executable misuse cases for modeling security concerns. In ICSE 2008.","DOI":"10.1145\/1368088.1368106"},{"key":"2_CR86_2","unstructured":"Whyte B and Harrison J (2008). Secure software development - a white paper. Knowledge Transfer Network on Cyber Security, UK. Available at http:\/\/www.ktn.qinetiq-tim.net\/content\/files\/groups\/securesoft\/SSDSIG_softwareSecurityFailures.pdf"},{"key":"2_CR87_2","doi-asserted-by":"crossref","unstructured":"Wimmel G and J\u00fcrjens J (2002). Specification-based test generation for security-critical systems using mutations. In International Conference on Formal Engineering Methods (ICFEM), volume 2495 of LNCS: 471\u2013482. Springer.","DOI":"10.1007\/3-540-36103-0_48"},{"key":"2_CR88_2","unstructured":"Wirsing M (2008). Software engineering for secure software-intensive systems. Consultation meeting on \u201cEngineering Secure Software Systems\u201d in the context of the preparation of the EU FP7 ICT work programme 2009\u20132010, Brussels. Presentation available at ftp:\/\/ftp.cordis.europa.eu\/pub\/fp7\/ict\/docs\/security\/20080423-martin-wirsing-lmu-munich_en.pdf."},{"key":"2_CR89_2","first-page":"56","volume":"1","author":"M Woodside","year":"2008","unstructured":"Woodside M, Petriu DC, Petriu DB, Xu J, Israr T, Georg G, France R, Bieman JM, Houmb SH, and J\u00fcrjens J (2008). Performance analysis of security aspects by weaving scenarios from UML models. Journal of Systems and Software, vol. 82, 1: 56\u201374.","journal-title":"Journal of Systems and Software, vol. 82"},{"key":"2_CR90_2","unstructured":"Yoshioka N, Honiden S, and Finkelstein A (2004). Security patterns: A method for constructing secure and efficient inter-company coordination systems. In EDOC: 84\u201397."},{"key":"2_CR91_2","doi-asserted-by":"crossref","unstructured":"Yskout K, Scandariato R, De Win B, and Joosen W (2008). Transforming security requirements into architecture. In ARES [42]: 1421\u20131428.","DOI":"10.1109\/ARES.2008.47"},{"key":"2_CR92_2","doi-asserted-by":"crossref","unstructured":"Yu Y, J\u00fcrjens J, and Mylopoulos J (2008). Traceability for the maintenance of secure software. In 24th International Conference on Software Maintenance (ICSM). IEEE.","DOI":"10.1109\/ICSM.2008.4658078"},{"key":"2_CR93_2","unstructured":"Zhang G, Baumeister H, Koch N, and Knapp A (2005). Aspect-oriented modeling of access control in web applications. In 6th International Workshop on Aspect-Oriented Modeling."}],"container-title":["Advances in Information Security","Security and Dependability for Ambient Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-0-387-88775-3_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,20]],"date-time":"2024-03-20T09:24:48Z","timestamp":1710926688000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-0-387-88775-3_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009]]},"ISBN":["9780387887746","9780387887753"],"references-count":93,"URL":"https:\/\/doi.org\/10.1007\/978-0-387-88775-3_2","relation":{},"ISSN":["1568-2633"],"issn-type":[{"type":"print","value":"1568-2633"}],"subject":[],"published":{"date-parts":[[2009]]},"assertion":[{"value":"31 March 2009","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}