{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,25]],"date-time":"2025-04-25T12:28:50Z","timestamp":1745584130973,"version":"3.40.3"},"publisher-location":"Cham","reference-count":94,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030002619"},{"type":"electronic","value":"9783030002626"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-00262-6_12","type":"book-chapter","created":{"date-parts":[[2019,2,11]],"date-time":"2019-02-11T10:02:09Z","timestamp":1549879329000},"page":"445-489","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Security and Software Engineering"],"prefix":"10.1007","author":[{"given":"Sam","family":"Malek","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hamid","family":"Bagheri","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Joshua","family":"Garcia","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alireza","family":"Sadeghi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,2,12]]},"reference":[{"key":"12_CR1","unstructured":"Andoni, A., Daniliuc, D., Khurshid, S.: Evaluating the small scope hypothesis. Technical report, MIT, 2003"},{"issue":"6","key":"12_CR2","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1145\/2666356.2594299","volume":"49","author":"Steven Arzt","year":"2014","unstructured":"Arzt, S., Rasthofer, S., Fritz, C., Bodden, E., Bartel, A., Klein, J., Le Traon, Y., Octeau, D., McDaniel, P.: Flowdroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps. In: ACM SIGPLAN Notices, vol. 49, pp. 259\u2013269. ACM, New York (2014)","journal-title":"ACM SIGPLAN Notices"},{"key":"12_CR3","unstructured":"Avgerinos, T., Kil, C.S., Hao, B.L.T., David, B.: AEG: automatic exploit generation. In: Network and Distributed System Security Symposium (2011)"},{"key":"12_CR4","doi-asserted-by":"crossref","unstructured":"Bagheri, H., Sullivan, K.: Bottom-up model-driven development. In: Proceedings of the International Conference on Software Engineering (ICSE), pp. 1221\u20131224 (2013)","DOI":"10.1109\/ICSE.2013.6606683"},{"issue":"3","key":"12_CR5","doi-asserted-by":"publisher","first-page":"441","DOI":"10.1007\/s00165-016-0360-8","volume":"28","author":"H Bagheri","year":"2016","unstructured":"Bagheri, H., Sullivan, K.: Model-driven synthesis of formally precise stylized software architectures. Form. Asp. Comput. 28(3), 441\u2013467 (2016)","journal-title":"Form. Asp. Comput."},{"key":"12_CR6","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1007\/978-3-319-19249-9_6","volume-title":"FM 2015: Formal Methods","author":"Hamid Bagheri","year":"2015","unstructured":"Bagheri, H., Kang, E., Malek, S., Jackson, D.: Detection of design flaws in the android permission protocol through bounded verification. In: FM 2015: Formal Methods. Lecture Notes in Computer Science, vol. 9109, pp. 73\u201389. Springer, Berlin (2015)"},{"issue":"9","key":"12_CR7","doi-asserted-by":"publisher","first-page":"866","DOI":"10.1109\/TSE.2015.2419611","volume":"41","author":"H Bagheri","year":"2015","unstructured":"Bagheri, H., Sadeghi, A., Garcia, J., Malek, S.: Covert: compositional analysis of android inter-app permission leakage. IEEE Trans. Softw. Eng. 41(9), 866\u2013886 (2015)","journal-title":"IEEE Trans. Softw. Eng."},{"key":"12_CR8","doi-asserted-by":"crossref","unstructured":"Bagheri, H., Sadeghi, A., Jabbarvand, R., Malek, S.: Practical, formal synthesis and automatic enforcement of security policies for android. In: Proceedings of the 46th IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 514\u2013525 (2016)","DOI":"10.1109\/DSN.2016.53"},{"issue":"7","key":"12_CR9","doi-asserted-by":"publisher","first-page":"68","DOI":"10.1145\/1965724.1965743","volume":"54","author":"T Ball","year":"2011","unstructured":"Ball, T., Levin, V., Rajamani, S.K.: A decade of software model checking with slam. Commun. ACM 54(7), 68\u201376 (2011)","journal-title":"Commun. ACM"},{"issue":"5","key":"12_CR10","doi-asserted-by":"publisher","first-page":"507","DOI":"10.1109\/TSE.2014.2372785","volume":"41","author":"E Barr","year":"2015","unstructured":"Barr, E., Harman, M., McMinn, P., Shahbaz, M., Yoo, S.: The Oracle problem in software testing: a survey. IEEE Trans. Softw. Eng. 41(5), 507\u2013525 (2015)","journal-title":"IEEE Trans. Softw. Eng."},{"issue":"5","key":"12_CR11","doi-asserted-by":"publisher","first-page":"505","DOI":"10.1007\/s10009-007-0044-z","volume":"9","author":"D Beyer","year":"2007","unstructured":"Beyer, D., Henzinger, T.A., Jhala, R., Majumdar, R.: The software model checker blast: applications to software engineering. Int. J. Softw. Tools Technol. Transf. 9(5), 505\u2013525 (2007)","journal-title":"Int. J. Softw. Tools Technol. Transf."},{"key":"12_CR12","doi-asserted-by":"crossref","unstructured":"Binkley, D.: Source code analysis: a road map. In: International Conference on Software Engineering, Minneapolis, May 2007, pp. 104\u2013119","DOI":"10.1109\/FOSE.2007.27"},{"key":"12_CR13","doi-asserted-by":"crossref","unstructured":"Brumley, D., Hartwig, C., Liang, Z., Newsome, J., Song, D., Yin, H.: Automatically identifying trigger-based behavior in Malware. In: Botnet Detection: Countering the Largest Security Threat, pp. 65\u201388. Springer, Boston (2008)","DOI":"10.1007\/978-0-387-68768-1_4"},{"key":"12_CR14","doi-asserted-by":"crossref","unstructured":"Brumley, D., Poosankam, P., Song, D., Zheng, J.: Automatic patch-based exploit generation is possible: techniques and implications. In: IEEE Symposium on Security and Privacy, SP 2008, pp. 143\u2013157. IEEE, Piscataway (2008)","DOI":"10.1109\/SP.2008.17"},{"key":"12_CR15","doi-asserted-by":"crossref","unstructured":"CanforaHarman, G., Di Penta, M.: New frontiers of reverse engineering. In: 2007 Future of Software Engineering, pp. 326\u2013341. IEEE Computer Society, Los Alamitos (2007)","DOI":"10.1109\/FOSE.2007.15"},{"key":"12_CR16","doi-asserted-by":"crossref","unstructured":"Cha, S.K., Avgerinos, T., Rebert, A., Brumley, D.: Unleashing mayhem on binary code. In: 2012 IEEE Symposium on Security and Privacy, May 2012, pp. 380\u2013394","DOI":"10.1109\/SP.2012.31"},{"key":"12_CR17","doi-asserted-by":"crossref","unstructured":"Cheng, S.-W., Garlan, D., Schmerl, B.: Evaluating the effectiveness of the rainbow self-adaptive system. In: ICSE Workshop on Software Engineering for Adaptive and Self-managing Systems, SEAMS \u201909, May 2009, pp. 132\u2013141","DOI":"10.1007\/978-3-642-02161-9"},{"key":"12_CR18","doi-asserted-by":"publisher","first-page":"359","DOI":"10.1007\/3-540-45657-0_29","volume-title":"Computer Aided Verification","author":"Alessandro Cimatti","year":"2002","unstructured":"Cimatti, A., Clarke, E., Giunchiglia, E., Giunchiglia, F., Pistore, M., Roveri, M., Sebastiani, R., Tacchella, A.: Nusmv 2: an opensource tool for symbolic model checking. In: Computer Aided Verification. Lecture Notes in Computer Science, vol. 2404, pp. 359\u2013364. Springer, Berlin (2002)"},{"key":"12_CR19","doi-asserted-by":"crossref","unstructured":"Clarke, E., Emerson, E.: Design and synthesis of synchronisation skeletons using branching time temporal logic. In: Logic of Programs, Proceedings of Workshop. Lecture Notes in Computer Science, vol. 131, pp. 52\u201371. Springer, Berlin (1981)","DOI":"10.1007\/BFb0025774"},{"key":"12_CR20","doi-asserted-by":"crossref","unstructured":"Clarke, E., Emerson, E., Sistla, A.: Automatic verification of finite state concurrent system using temporal logic specifications: a practical approach. In: Proceedings of the 10th ACM SIGACT-SIGPLAN Symposium on Principles of Programming Languages (POPL\u201983), pp. 117\u2013126. ACM Press, New York (1983)","DOI":"10.1145\/567067.567080"},{"key":"12_CR21","volume-title":"Model Checking","author":"E Clarke","year":"1999","unstructured":"Clarke, E., Grumberg, O., Peled, D.: Model Checking. MIT Press, Cambridge (1999)"},{"key":"12_CR22","doi-asserted-by":"crossref","unstructured":"Clarke, E., Kroening, D., Yorav, K.: Behavioral consistency of c and verilog programs using bounded model checking. In: DAC, pp. 368\u2013371 (2003)","DOI":"10.21236\/ADA461052"},{"key":"12_CR23","unstructured":"Coverity: Coverity code advisor. www.coverity.com\/products\/code-advisor"},{"key":"12_CR24","doi-asserted-by":"crossref","unstructured":"De Moura, L., Bj\u00f8rner, N.: Z3: an efficient SMT solver. In: Tools and Algorithms for the Construction and Analysis of Systems, pp. 337\u2013340. Springer, Berlin (2008)","DOI":"10.1007\/978-3-540-78800-3_24"},{"key":"12_CR25","unstructured":"Dennis, G.: A relational framework for bounded program verification. PhD thesis, Massachusetts Institute of Technology (2009)"},{"key":"12_CR26","unstructured":"Dolby, J., Fink, S.J., Sridharan, M.: T.J. Watson Libraries for Analysis (WALA). https:\/\/www.wala.sf.net"},{"key":"12_CR27","doi-asserted-by":"crossref","unstructured":"Dwyer, M.B., Avrunin, G.S., Corbett, J.C.: Patterns in property specifications for finite-state verification. In: Proceedings of the 21st International Conference on Software Engineering, ICSE \u201999, pp. 411\u2013420. ACM, New York (1999)","DOI":"10.1145\/302405.302672"},{"key":"12_CR28","first-page":"2","volume":"2","author":"W Enck","year":"2011","unstructured":"Enck, W., Octeau, D., McDaniel, P., Chaudhuri, S.: A study of android application security. In: USENIX Security Symposium, vol. 2, p. 2 (2011)","journal-title":"In: USENIX Security Symposium"},{"issue":"2","key":"12_CR29","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1145\/2619091","volume":"32","author":"W Enck","year":"2014","unstructured":"Enck, W., Gilbert, P., Han, S., Tendulkar, V., Chun, B.-G., Cox, L.P., Jung, J., McDaniel, P., Sheth, A.N.: Taintdroid: an information-flow tracking system for realtime privacy monitoring on smartphones. ACM Trans. Comput. Syst. 32(2), 5 (2014)","journal-title":"ACM Trans. Comput. Syst."},{"key":"12_CR30","doi-asserted-by":"crossref","unstructured":"Ernst, M.D.: Invited talk static and dynamic analysis: synergy and duality. In: Proceedings of the 5th ACM SIGPLAN-SIGSOFT Workshop on Program Analysis for Software Tools and Engineering, PASTE \u201904, pp. 35\u201335. ACM, New York (2004)","DOI":"10.1145\/996821.996823"},{"key":"12_CR31","unstructured":"Foo, B., Wu, Y.-S., Mao, Y.-C., Bagchi, S., Spafford, E.: ADEPTS: adaptive intrusion response using attack graphs in an e-commerce environment. In: International Conference on Dependable Systems and Networks, DSN 2005. Proceedings, July 2005, pp. 508\u2013517"},{"issue":"2","key":"12_CR32","doi-asserted-by":"publisher","first-page":"278","DOI":"10.1109\/TSE.2011.93","volume":"38","author":"G Fraser","year":"2012","unstructured":"Fraser, G., Zeller, A.: Mutation-driven generation of unit tests and oracles. IEEE Trans. Softw. Eng. 38(2), 278\u2013292 (2012)","journal-title":"IEEE Trans. Softw. Eng."},{"issue":"10","key":"12_CR33","doi-asserted-by":"publisher","first-page":"46","DOI":"10.1109\/MC.2004.175","volume":"37","author":"D Garlan","year":"2004","unstructured":"Garlan, D., Cheng, S.W., Huang, A.C., Schmerl, B., Steenkiste, P.: Rainbow: architecture-based self-adaptation with reusable infrastructure. Computer 37(10), 46\u201354 (2004)","journal-title":"Computer"},{"key":"12_CR34","unstructured":"Gennari, J., Garlan, D.: Measuring attack surface in software architecture. Technical report CMU-ISR-11-121, Institute for Software Research, School of Computer Science, Carnegie Mellon University, 2011"},{"issue":"6","key":"12_CR35","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1145\/1064978.1065036","volume":"40","author":"P Godefroid","year":"2005","unstructured":"Godefroid, P., Klarlund, N., Sen, K.: Dart: directed automated random testing. SIGPLAN Not. 40(6), 213\u2013223 (2005)","journal-title":"SIGPLAN Not."},{"issue":"1","key":"12_CR36","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1145\/2090147.2094081","volume":"10","author":"Patrice Godefroid","year":"2012","unstructured":"Godefroid, P., Levin, M.Y., Molnar, D.: Sage: Whitebox fuzzing for security testing. Queue 10(1), 20:20\u201320:27 (2012)","journal-title":"Queue"},{"key":"12_CR37","doi-asserted-by":"crossref","unstructured":"Gupta, R., Harrold, M.J., Soffa, M.L.: An approach to regression testing using slicing. In: Conference on Software Maintenance. Proceedings, pp. 299\u2013308. IEEE, Piscataway (1992)","DOI":"10.1109\/ICSM.1992.242531"},{"issue":"10","key":"12_CR38","doi-asserted-by":"publisher","first-page":"576","DOI":"10.1145\/363235.363259","volume":"12","author":"C Hoare","year":"1969","unstructured":"Hoare, C.: An axiomatic basis for computer programming. Commun. ACM 12(10), 576\u2013585 (1969)","journal-title":"Commun. ACM"},{"key":"12_CR39","volume-title":"The SPIN Model Checker: Primer and Reference Manual","author":"GJ Holzmann","year":"2003","unstructured":"Holzmann, G.J.: The SPIN Model Checker: Primer and Reference Manual. Addison-Wesley, Boston (2003)"},{"issue":"12","key":"12_CR40","doi-asserted-by":"publisher","first-page":"92","DOI":"10.1145\/1052883.1052895","volume":"39","author":"D Hovemeyer","year":"2004","unstructured":"Hovemeyer, D., Pugh, W.: Finding bugs is easy. ACM Sigplan Not. 39(12), 92\u2013106 (2004)","journal-title":"ACM Sigplan Not."},{"key":"12_CR41","unstructured":"HP Enterprise Security: Fortify static code analysis tool: static application security testing \u2014 micro focus. https:\/\/software.microfocus.com\/en-us\/products\/static-code-analysis-sast\/overview"},{"key":"12_CR42","doi-asserted-by":"crossref","unstructured":"Huang, Y., Kintala, C., Kolettis, N., Fulton, N.: Software rejuvenation: analysis, module and applications. In: Twenty-Fifth International Symposium on Fault-Tolerant Computing, FTCS-25. Digest of Papers, June 1995, pp. 381\u2013390","DOI":"10.1109\/FTCS.1995.466961"},{"key":"12_CR43","unstructured":"IBM: IBM security appscan. www-03.ibm.com\/software\/products\/en\/appscan"},{"key":"12_CR44","volume-title":"Software Abstractions","author":"D Jackson","year":"2012","unstructured":"Jackson, D.: Software Abstractions, 2nd edn. MIT Press, Cambridge (2012)","edition":"2"},{"key":"12_CR45","unstructured":"Jlint: Find bugs in java programs. https:\/\/www.jlint.sourceforge.net"},{"key":"12_CR46","doi-asserted-by":"crossref","unstructured":"Jones, J.A., Harrold, M.J.: Empirical evaluation of the tarantula automatic fault-localization technique. In: Proceedings of the 20th IEEE\/ACM International Conference on Automated Software Engineering, pp. 273\u2013282. ACM, New York (2005)","DOI":"10.1145\/1101908.1101949"},{"key":"12_CR47","doi-asserted-by":"crossref","unstructured":"Kaufmann, M., Strother Moore, J.: ACL2: an industrial strength version of Nqthm. In: Proceedings of the Annual Conference on Computer Assurance (COMPASS), pp. 23\u201334 (1996)","DOI":"10.1109\/CMPASS.1996.507872"},{"issue":"1","key":"12_CR48","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1109\/MC.2003.1160055","volume":"36","author":"JO Kephart","year":"2003","unstructured":"Kephart, J.O., Chess, D.M.: The vision of autonomic computing. Computer 36(1), 41\u201350 (2003)","journal-title":"Computer"},{"key":"12_CR49","volume-title":"Finding Software Bugs with the Clang Static Analyzer","author":"T Kremenek","year":"2008","unstructured":"Kremenek, T.: Finding Software Bugs with the Clang Static Analyzer. Apple Inc., California (2008)"},{"key":"12_CR50","unstructured":"Lint4j: Lint4j overview. www.jutils.com"},{"key":"12_CR51","unstructured":"Livshits, V.B., Lam, M.S.: Finding security vulnerabilities in java applications with static analysis. In: Usenix Security, vol. 2013 (2005)"},{"key":"12_CR52","doi-asserted-by":"crossref","unstructured":"Marcus, A., Maletic, J.I.: Identification of high-level concept clones in source code. In: 16th Annual International Conference on Automated Software Engineering, ASE 2001. Proceedings, pp. 107\u2013114. IEEE, Piscataway (2001)","DOI":"10.1109\/ASE.2001.989796"},{"issue":"12","key":"12_CR53","doi-asserted-by":"publisher","first-page":"108","DOI":"10.1109\/MC.2008.514","volume":"41","author":"G McGraw","year":"2008","unstructured":"McGraw, G.: Automated code review tools for security. Computer 41(12), 108\u2013111 (2008)","journal-title":"Computer"},{"key":"12_CR54","volume-title":"Improving Web Application Security: Threats and Countermeasures","author":"J Meier","year":"2003","unstructured":"Meier, J., Mackman, A., Vasireddy, S., Dunner, M., Escamila, R., Murukan, A.: Improving Web Application Security: Threats and Countermeasures. Microsoft Corporation, Redmond (2003)"},{"key":"12_CR55","doi-asserted-by":"crossref","unstructured":"Morrisett, G., Tan, G., Tassarotti, J., Tristan, J.-B., Gan, E.: RockSalt: Better, faster, stronger SFI for the x86. In: Proceedings of the 33rd ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI \u201912, pp. 395\u2013404. ACM, New York (2012)","DOI":"10.1145\/2254064.2254111"},{"key":"12_CR56","doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., Kirda, E.: Exploring multiple execution paths for malware analysis. In: IEEE Symposium on Security and Privacy, SP\u201907, pp. 231\u2013245. IEEE, Piscataway (2007)","DOI":"10.1109\/SP.2007.17"},{"key":"12_CR57","doi-asserted-by":"crossref","unstructured":"Nagarajan, A., Nguyen, Q., Banks, R., Sood, A.: Combining intrusion detection and recovery for enhancing system dependability. In: 2011 IEEE\/IFIP 41st International Conference on Dependable Systems and Networks Workshops (DSN-W), June 2011, pp. 25\u201330","DOI":"10.1109\/DSNW.2011.5958859"},{"key":"12_CR58","unstructured":"National vulnerability database. https:\/\/nvd.nist.gov\/ . Accessed 22 Apr 2016"},{"key":"12_CR59","doi-asserted-by":"crossref","unstructured":"Necula, G.C.: Proof-carrying code. In: Proceedings of the 24th ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages, POPL \u201997, pp. 106\u2013119. ACM, New York (1997)","DOI":"10.1145\/263699.263712"},{"issue":"6","key":"12_CR60","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1145\/1273442.1250746","volume":"42","author":"Nicholas Nethercote","year":"2007","unstructured":"Nethercote, N., Seward, J.: Valgrind: a framework for heavyweight dynamic binary instrumentation. In: ACM Sigplan Notices, vol. 42, pp. 89\u2013100. ACM, New York (2007)","journal-title":"ACM SIGPLAN Notices"},{"key":"12_CR61","unstructured":"Newsome, J., Song, D.: Dynamic taint analysis for automatic detection, analysis, and signature generation of exploits on commodity software. In: Network and Distributed System Security Symposium (2005)"},{"issue":"1","key":"12_CR62","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1016\/j.ijcip.2012.01.002","volume":"5","author":"H Okhravi","year":"2012","unstructured":"Okhravi, H., Comella, A., Robinson, E., Haines, J.: Creating a cyber moving target for critical infrastructure applications using platform diversity. Int. J. Crit. Infrastruct. Prot. 5(1), 30\u201339 (2012)","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"12_CR63","doi-asserted-by":"crossref","unstructured":"Oreizy, P., Medvidovic, N., Taylor, R.N.: Architecture-based runtime software evolution. In: Proceedings of the 20th International Conference on Software Engineering, ICSE \u201998, pp. 177\u2013186. IEEE Computer Society, Washington (1998)","DOI":"10.1109\/ICSE.1998.671114"},{"key":"12_CR64","doi-asserted-by":"publisher","first-page":"691","DOI":"10.1007\/s00607-015-0445-x","volume":"97","author":"S Ouchani","year":"2015","unstructured":"Ouchani, S., Debbabi, M.: Specification, verification, and quantification of security in model-based systems. Computing 97, 691\u2013711 (2015)","journal-title":"Computing"},{"key":"12_CR65","unstructured":"Ouimet, M.: Formal software verification: model checking and theorem proving. Technical report ESL-TIK-00214, MIT, 2005"},{"key":"12_CR66","unstructured":"OWASP.org. Cross-site scripting (XSS) - OWASP. https:\/\/www.owasp.org\/index.php\/Cross-site_Scripting_(XSS)"},{"key":"12_CR67","unstructured":"OWASP.org. Owasp top ten project. https:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_Project"},{"key":"12_CR68","first-page":"748","volume-title":"Automated DeductionCADE-11. Lecture Notes in Computer Science","author":"S Owre","year":"1992","unstructured":"Owre, S., Rushby, J.M., Shankar, N.: PVS: a prototype verification system. In: Kapur, D. (ed.) Automated DeductionCADE-11. Lecture Notes in Computer Science, vol. 607, pp. 748\u2013752. Springer, Berlin (1992) https:\/\/doi.org\/10.1007\/3-540-55602-8_217"},{"key":"12_CR69","doi-asserted-by":"crossref","unstructured":"Pastore, F., Mariani, L., Fraser, G.: CrowdOracles: can the crowd solve the oracle problem? In: 2013 IEEE Sixth International Conference on Software Testing, Verification and Validation (ICST), March 2013, pp. 342\u2013351","DOI":"10.1109\/ICST.2013.13"},{"key":"12_CR70","doi-asserted-by":"crossref","unstructured":"Paulson, L.: Isabelle: A Generic Theorem Prover. Lecture Notes in Computer Science, vol. 828. Springer, Berlin (1994)","DOI":"10.1007\/BFb0030541"},{"key":"12_CR71","unstructured":"PMD: Source code analyzer. https:\/\/www.pmd.sourceforge.net"},{"key":"12_CR72","doi-asserted-by":"crossref","unstructured":"Pnueli, A.: The temporal logic of programs. In: Proceedings of the 18th Annual Symposium on Foundations of Computer Science (FOCS), pp. 46\u201357 (1977)","DOI":"10.1109\/SFCS.1977.32"},{"issue":"1","key":"12_CR73","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1007\/s00165-007-0058-z","volume":"20","author":"T Ramananandro","year":"2008","unstructured":"Ramananandro, T.: Mondex, an electronic purse: specification and refinement checks with the alloy model-finding method. Formal Asp. Comput. 20(1), 21\u201339 (2008)","journal-title":"Formal Asp. Comput."},{"key":"12_CR74","unstructured":"Ren, J.: A Connector-Centric Approach to Architectural Access Control. PhD thesis, University of California, Irvine (2006)"},{"key":"12_CR75","unstructured":"Ren, J., Taylor, R.: A secure software architecture description language. In: Workshop on Software Security Assurance Tools, Techniques, and Metrics, SSATTM\u201905 (2005)"},{"key":"12_CR76","doi-asserted-by":"crossref","unstructured":"Sen, K.: Concolic testing. In: Proceedings of the Twenty-Second IEEE\/ACM International Conference on Automated Software Engineering, ASE \u201907, pp. 571\u2013572. ACM, New York (2007)","DOI":"10.1145\/1321631.1321746"},{"key":"12_CR77","doi-asserted-by":"crossref","unstructured":"Sen, K., Marinov, D., Agha, G.: Cute: a concolic unit testing engine for c. In: Proceedings of the 10th European Software Engineering Conference Held Jointly with 13th ACM SIGSOFT International Symposium on Foundations of Software Engineering, ESEC\/FSE-13, pp. 263\u2013272. ACM, New York (2005)","DOI":"10.1145\/1081706.1081750"},{"issue":"4","key":"12_CR78","doi-asserted-by":"publisher","first-page":"452","DOI":"10.1109\/TPDS.2009.83","volume":"21","author":"P Sousa","year":"2010","unstructured":"Sousa, P., Bessani, A., Correia, M., Neves, N., Verissimo, P.: Highly available intrusion-tolerant services with proactive-reactive recovery. IEEE Trans. Parallel Distrib. Syst. 21(4), 452\u2013465 (2010)","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"12_CR79","doi-asserted-by":"crossref","unstructured":"Suryanarayana, G., Diallo, M., Erenkrantz, J., Taylor, R.N.: Architectural support for trust models in decentralized applications. In: 28th International Conference on Software Engineering, ICSE\u201906, May 2006","DOI":"10.1145\/1134285.1134295"},{"key":"12_CR80","volume-title":"Fuzzing for Software Security Testing and Quality Assurance","author":"A Takanen","year":"2008","unstructured":"Takanen, A., DeMott, J., Miller, C.: Fuzzing for Software Security Testing and Quality Assurance, 1st edn. Artech House, Inc., Norwood (2008)","edition":"1"},{"key":"12_CR81","doi-asserted-by":"crossref","unstructured":"Tam, K., Khan, S.J., Fattori, A., Cavallaro, L.: Copperdroid: automatic reconstruction of android malware behaviors. In: Network and Distributed System Security Symposium (2015)","DOI":"10.14722\/ndss.2015.23145"},{"key":"12_CR82","volume-title":"Software Architecture: Foundations, Theory, and Practice","author":"RN Taylor","year":"2009","unstructured":"Taylor, R.N., Medvidovic, N., Dashofy, E.M.: Software Architecture: Foundations, Theory, and Practice. Wiley, New York (2009)"},{"key":"12_CR83","unstructured":"The Coq Development Team: The Coq proof assistant reference manual. Technical report version 8.2, LogiCal Project, 2008"},{"key":"12_CR84","unstructured":"Vall\u00e9e-Rai, R., Co, P., Gagnon, E., Hendren, L., Lam, P., Sundaresan, V.: Soot-a java bytecode optimization framework. In: Proceedings of the 1999 Conference of the Centre for Advanced Studies on Collaborative Research, p. 13. IBM Press, Toronto (1999)"},{"issue":"2","key":"12_CR85","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1023\/A:1022920129859","volume":"10","author":"W Visser","year":"2003","unstructured":"Visser, W., Havelund, K., Brat, G., Park, S., Lerda, F.: Model checking programs. Autom. Softw. Eng. 10(2), 203\u2013232 (2003)","journal-title":"Autom. Softw. Eng."},{"key":"12_CR86","unstructured":"Wang, F., Jou, F., Gong, F., Sargor, C., Goseva-Popstojanova, K., Trivedi, K.: SITAR: a scalable intrusion-tolerant architecture for distributed services. In: Foundations of Intrusion Tolerant Systems, pp. 359\u2013367. IEEE Computer Society, New York (2003)"},{"key":"12_CR87","doi-asserted-by":"crossref","unstructured":"Wang, T., Wei, T., Gu, G., Zou, W.: Taintscope: a checksum-aware directed fuzzing tool for automatic software vulnerability detection. In: 2010 IEEE Symposium on Security and Privacy, May 2010, pp. 497\u2013512","DOI":"10.1109\/SP.2010.37"},{"key":"12_CR88","doi-asserted-by":"crossref","unstructured":"Xie, Y., Aiken, A.: Scalable error detection using boolean satisfiability. In: Proceedings of the 32nd ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages (POPL), pp. 351\u2013363 (2005)","DOI":"10.1145\/1040305.1040334"},{"key":"12_CR89","doi-asserted-by":"crossref","unstructured":"Xie, T., Tillmann, N., de Halleux, J., Schulte, W.: Fitness-guided path exploration in dynamic symbolic execution. In: 2009 IEEE\/IFIP International Conference on Dependable Systems Networks, June 2009, pp. 359\u2013368","DOI":"10.1109\/DSN.2009.5270315"},{"key":"12_CR90","unstructured":"Yan, L.K., Yin, H.: Droidscope: seamlessly reconstructing the os and dalvik semantic views for dynamic android malware analysis. Presented as part of the 21st USENIX Security Symposium (USENIX Security 12), pp. 569\u2013584 (2012)"},{"key":"12_CR91","doi-asserted-by":"crossref","unstructured":"Yuan, E., Malek, S., Schmerl, B., Garlan, D., Gennari, J.: Architecture-based self-protecting software systems. In: QoSA \u201913 (2013)","DOI":"10.1145\/2465478.2465479"},{"issue":"4","key":"12_CR92","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2555611","volume":"8","author":"Eric Yuan","year":"2014","unstructured":"Yuan, E., Esfahani, N., Malek, S.: A systematic survey of self-protecting software systems. ACM Trans. Auton. Adapt. Syst. 8(4), 17:1\u201317:41 (2014)","journal-title":"ACM Transactions on Autonomous and Adaptive Systems"},{"key":"12_CR93","doi-asserted-by":"crossref","unstructured":"Zaeem, R., Prasad, M., Khurshid, S.: Automated generation of oracles for testing user-interaction features of mobile apps. In: 2014 IEEE Seventh International Conference on Software Testing, Verification and Validation (ICST), March 2014, pp. 183\u2013192","DOI":"10.1109\/ICST.2014.31"},{"key":"12_CR94","doi-asserted-by":"crossref","unstructured":"Zhu, M., Yu, M., Xia, M., Li, B., Yu, P., Gao, S., Qi, Z., Liu, L., Chen, Y., Guan, H.: VASP: virtualization assisted security monitor for cross-platform protection. In: Proceedings of the 2011 ACM Symposium on Applied Computing, pp. 554\u2013559 (2011)","DOI":"10.1145\/1982185.1982305"}],"container-title":["Handbook of Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-00262-6_12","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,11,16]],"date-time":"2019-11-16T11:57:06Z","timestamp":1573905426000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-00262-6_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030002619","9783030002626"],"references-count":94,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-00262-6_12","relation":{},"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"12 February 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}