{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T23:11:49Z","timestamp":1778195509173,"version":"3.51.4"},"publisher-location":"Cham","reference-count":26,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030007607","type":"print"},{"value":"9783030007614","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-030-00761-4_23","type":"book-chapter","created":{"date-parts":[[2018,9,14]],"date-time":"2018-09-14T11:05:23Z","timestamp":1536923123000},"page":"347-363","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":24,"title":["Two Architectural Threat Analysis Techniques Compared"],"prefix":"10.1007","author":[{"given":"Katja","family":"Tuma","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Riccardo","family":"Scandariato","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,9,15]]},"reference":[{"key":"23_CR1","unstructured":"Empirical study: Threat modeling. https:\/\/sites.google.com\/site\/empiricalstudythreatanalysis\/ . Accessed 25 Aug 2017"},{"key":"23_CR2","doi-asserted-by":"crossref","unstructured":"Abe, T., Hayashi, S., Saeki, M.: Modeling security threat patterns to derive negative scenarios. In: 2013 20th Asia-Pacific Software Engineering Conference (APSEC), vol. 1, pp. 58\u201366. IEEE (2013)","DOI":"10.1109\/APSEC.2013.19"},{"key":"23_CR3","doi-asserted-by":"crossref","unstructured":"Carver, J., Jaccheri, L., Morasca, S., Shull, F.: Issues in using students in empirical studies in software engineering education. In: Proceedings of Ninth International Software Metrics Symposium, pp. 239\u2013249. IEEE (2003)","DOI":"10.1109\/METRIC.2003.1232471"},{"issue":"1","key":"23_CR4","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/s00766-010-0115-7","volume":"16","author":"M Deng","year":"2011","unstructured":"Deng, M., Wuyts, K., Scandariato, R., Preneel, B., Joosen, W.: A privacy threat analysis framework: supporting the elicitation and fulfillment of privacy requirements. Requir. Eng. 16(1), 3\u201332 (2011)","journal-title":"Requir. Eng."},{"key":"23_CR5","unstructured":"Diallo, M.H., Romero-Mariona, J., Sim, S.E., Alspaugh, T.A., Richardson, D.J.: A comparative evaluation of three approaches to specifying security requirements. In: 12th Working Conference on Requirements Engineering: Foundation for Software Quality, Luxembourg (2006)"},{"issue":"3","key":"23_CR6","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1023\/A:1026586415054","volume":"5","author":"M H\u00f6st","year":"2000","unstructured":"H\u00f6st, M., Regnell, B., Wohlin, C.: Using students as subjectsa comparative study of students and professionals in lead-time impact assessment. Empir. Softw. Eng. 5(3), 201\u2013214 (2000)","journal-title":"Empir. Softw. Eng."},{"key":"23_CR7","volume-title":"The Security Development Lifecycle","author":"M Howard","year":"2006","unstructured":"Howard, M., Lipner, S.: The Security Development Lifecycle, vol. 8. Microsoft Press, Redmond (2006)"},{"key":"23_CR8","doi-asserted-by":"crossref","unstructured":"Karpati, P., Opdahl, A.L., Sindre, G.: Experimental comparison of misuse case maps with misuse cases and system architecture diagrams for eliciting security vulnerabilities and mitigations. In: 2011 Sixth International Conference on Availability, Reliability and Security (ARES), pp. 507\u2013514. IEEE (2011)","DOI":"10.1109\/ARES.2011.77"},{"issue":"2","key":"23_CR9","doi-asserted-by":"publisher","first-page":"54","DOI":"10.4018\/jsse.2012040103","volume":"3","author":"P Karpati","year":"2012","unstructured":"Karpati, P., Sindre, G., Matulevicius, R.: Comparing misuse case and mal-activity diagrams for modelling social engineering attacks. Int. J. Secure Softw. Eng. (IJSSE) 3(2), 54\u201373 (2012)","journal-title":"Int. J. Secure Softw. Eng. (IJSSE)"},{"key":"23_CR10","doi-asserted-by":"crossref","unstructured":"Labunets, K., Massacci, F., Paci, F., et al.: An experimental comparison of two risk-based security methods. In: 2013 ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement, pp. 163\u2013172. IEEE (2013)","DOI":"10.1109\/ESEM.2013.29"},{"key":"23_CR11","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1007\/978-3-642-12323-8_3","volume-title":"Model-Driven Risk Analysis","author":"MS Lund","year":"2011","unstructured":"Lund, M.S., Solhaug, B., St\u00f8len, K.: A guided tour of the CORAS method. In: Lund, M.S., Solhaug, B., St\u00f8len, K. (eds.) Model-Driven Risk Analysis, pp. 23\u201343. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-12323-8_3"},{"key":"23_CR12","unstructured":"McGraw, G., Migues, S., West, J.: Building security in maturity model (BSIMM). https:\/\/www.bsimm.com . Accessed 25 Aug 2017"},{"key":"23_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"114","DOI":"10.1007\/978-3-642-11747-3_9","volume-title":"Engineering Secure Software and Systems","author":"PH Meland","year":"2010","unstructured":"Meland, P.H., T\u00f8ndel, I.A., Jensen, J.: Idea: reusability of threat models \u2013 two approaches with an experimental evaluation. In: Massacci, F., Wallach, D., Zannone, N. (eds.) ESSoS 2010. LNCS, vol. 5965, pp. 114\u2013122. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-11747-3_9"},{"issue":"5","key":"23_CR14","doi-asserted-by":"publisher","first-page":"916","DOI":"10.1016\/j.infsof.2008.05.013","volume":"51","author":"AL Opdahl","year":"2009","unstructured":"Opdahl, A.L., Sindre, G.: Experimental comparison of attack trees and misuse cases for security threat identification. Inf. Softw. Technol. 51(5), 916\u2013932 (2009)","journal-title":"Inf. Softw. Technol."},{"key":"23_CR15","unstructured":"Runeson, P.: Using students as experiment subjects-an analysis on graduate and freshmen student data. In: Proceedings of the 7th International Conference on Empirical Assessment in Software Engineering, pp. 95\u2013102 (2003)"},{"key":"23_CR16","unstructured":"Saitta, P., Larcom, B., Eddington, M.: Trike v. 1 methodology document [draft]. http:\/\/dymaxion.org\/trike\/Trike_v1_Methodology_Documentdraft.pdf"},{"key":"23_CR17","doi-asserted-by":"crossref","unstructured":"Salman, I., Misirli, A.T., Juristo, N.: Are students representatives of professionals in software engineering experiments? In: Proceedings of the 37th International Conference on Software Engineering, vol. 1, pp. 666\u2013676. IEEE Press (2015)","DOI":"10.1109\/ICSE.2015.82"},{"issue":"2","key":"23_CR18","doi-asserted-by":"publisher","first-page":"163","DOI":"10.1007\/s00766-013-0195-2","volume":"20","author":"R Scandariato","year":"2015","unstructured":"Scandariato, R., Wuyts, K., Joosen, W.: A descriptive study of microsofts threat modeling technique. Requir. Eng. 20(2), 163\u2013180 (2015)","journal-title":"Requir. Eng."},{"issue":"12","key":"23_CR19","first-page":"21","volume":"24","author":"B Schneier","year":"1999","unstructured":"Schneier, B.: Attack trees. Dr Dobb\u2019s J. 24(12), 21\u201329 (1999)","journal-title":"Dr Dobb\u2019s J."},{"key":"23_CR20","volume-title":"Threat Modeling: Designing for Security","author":"A Shostack","year":"2014","unstructured":"Shostack, A.: Threat Modeling: Designing for Security. Wiley, Hoboken (2014)"},{"key":"23_CR21","doi-asserted-by":"crossref","unstructured":"Stoneburner, G., Hayden, C., Feringa, A.: Engineering principles for information technology security (a baseline for achieving security). Technical report, Booz-Allen and Hamilton Inc., Mclean, VA (2001)","DOI":"10.6028\/NIST.SP.800-27"},{"issue":"5","key":"23_CR22","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1109\/MSP.2005.119","volume":"3","author":"P Torr","year":"2005","unstructured":"Torr, P.: Demystifying the threat modeling process. IEEE Secur. Priv. 3(5), 66\u201370 (2005)","journal-title":"IEEE Secur. Priv."},{"key":"23_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/978-3-319-72817-9_4","volume-title":"Computer Security","author":"K Tuma","year":"2018","unstructured":"Tuma, K., Scandariato, R., Widman, M., Sandberg, C.: Towards security threats that matter. In: Katsikas, S.K., et al. (eds.) CyberICPS\/SECPRE -2017. LNCS, vol. 10683, pp. 47\u201362. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-72817-9_4"},{"key":"23_CR24","doi-asserted-by":"publisher","DOI":"10.1002\/9781118988374","volume-title":"Risk Centric Threat Modeling: Process for Attack Simulation and Threat Analysis","author":"T UcedaVelez","year":"2015","unstructured":"UcedaVelez, T., Morana, M.M.: Risk Centric Threat Modeling: Process for Attack Simulation and Threat Analysis. Wiley, Hoboken (2015)"},{"key":"23_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"7","DOI":"10.1007\/978-3-540-45143-3_2","volume-title":"Empirical Methods and Studies in Software Engineering","author":"C Wohlin","year":"2003","unstructured":"Wohlin, C., H\u00f6st, M., Henningsson, K.: Empirical research methods in software engineering. In: Conradi, R., Wang, A.I. (eds.) Empirical Methods and Studies in Software Engineering. LNCS, vol. 2765, pp. 7\u201323. Springer, Heidelberg (2003). https:\/\/doi.org\/10.1007\/978-3-540-45143-3_2"},{"key":"23_CR26","doi-asserted-by":"publisher","first-page":"122","DOI":"10.1016\/j.jss.2014.05.075","volume":"96","author":"K Wuyts","year":"2014","unstructured":"Wuyts, K., Scandariato, R., Joosen, W.: Empirical evaluation of a privacy-focused threat modeling methodology. J. Syst. Softw. 96, 122\u2013138 (2014)","journal-title":"J. Syst. Softw."}],"container-title":["Lecture Notes in Computer Science","Software Architecture"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-00761-4_23","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T08:47:51Z","timestamp":1751878071000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-00761-4_23"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783030007607","9783030007614"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-00761-4_23","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"ECSA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Software Architecture","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Madrid","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Spain","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 September 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28 September 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ecsa2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eventos.upm.es\/12427\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}