{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,31]],"date-time":"2026-01-31T22:28:35Z","timestamp":1769898515371,"version":"3.49.0"},"publisher-location":"Cham","reference-count":22,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030549961","type":"print"},{"value":"9783030549978","type":"electronic"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-54997-8_34","type":"book-chapter","created":{"date-parts":[[2020,8,10]],"date-time":"2020-08-10T20:11:50Z","timestamp":1597090310000},"page":"557-572","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["AuthCheck: Program-State Analysis for Access-Control Vulnerabilities"],"prefix":"10.1007","author":[{"given":"Goran","family":"Piskachev","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tobias","family":"Petrasch","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Johannes","family":"Sp\u00e4th","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eric","family":"Bodden","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,8,11]]},"reference":[{"key":"34_CR1","unstructured":"Spring framework, java spring. \nhttps:\/\/spring.io\/projects\n\n. Accessed 9 Mar 2019"},{"key":"34_CR2","unstructured":"Spring framework, java spring security. \nhttps:\/\/spring.io\/guides\/topicals\/spring-security-architecture\n\n. Accessed 9 Mar 2019"},{"key":"34_CR3","unstructured":"Spring framework, spring expression language. \nhttps:\/\/docs.spring.io\/spring\/docs\/5.0.5.RELEASE\/spring-framework-reference\/core.html\n\n. Accessed 12 Mar 2019"},{"key":"34_CR4","doi-asserted-by":"crossref","unstructured":"Alexander, P., Pike, L., Loscocco, P., Coker, G.: Model checking distributed mandatory access control policies. ACM Trans. Inf. Syst. Secur. 18(2), 6:1\u20136:25 (2015)","DOI":"10.1145\/2785966"},{"key":"34_CR5","doi-asserted-by":"crossref","unstructured":"Ball, T., Rajamani, S.K.: The slam project: debugging system software via static analysis. In: Proceedings of the 29th ACM SIGPLAN POPL, POPL 2002, pp. 1\u20133. ACM, New York (2002)","DOI":"10.1145\/565816.503274"},{"key":"34_CR6","unstructured":"Dalton, M., Kozyrakis, C., Zeldovich, N.: Nemesis: preventing authentication and access control vulnerabilities in web applications. In: Proceedings of USENIX, SSYM 2009, pp. 267\u2013282. USENIX Association, Berkeley (2009)"},{"key":"34_CR7","unstructured":"Enumeration, C.C.W.: Incorrect authorization. \nhttps:\/\/cwe.mitre.org\/data\/definitions\/863.html\n\n. Accessed 12 Mar 2019"},{"key":"34_CR8","unstructured":"Enumeration, C.C.W.: Missing authentication for critical function. \nhttps:\/\/cwe.mitre.org\/data\/definitions\/306.html\n\n. Accessed 12 Mar 2019"},{"key":"34_CR9","unstructured":"Enumeration, C.C.W.: Missing authorization. \nhttps:\/\/cwe.mitre.org\/data\/definitions\/862.html\n\n. Accessed 12 Mar 2019"},{"key":"34_CR10","unstructured":"Fielding, R.T.: Architectural styles and the design of network-based software architectures. Ph.D. thesis, University of California, Irvine (2000)"},{"key":"34_CR11","volume-title":"Design Patterns CD: Elements of Reusable Object-Oriented Software","author":"E Gamma","year":"1998","unstructured":"Gamma, E., Vlissides, J., Johnson, R., Helm, R.: Design Patterns CD: Elements of Reusable Object-Oriented Software. Addison-Wesley Longman Publishing Co. Inc., Boston (1998)"},{"key":"34_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1007\/3-540-44829-2_17","volume-title":"Model Checking Software","author":"TA Henzinger","year":"2003","unstructured":"Henzinger, T.A., Jhala, R., Majumdar, R., Sutre, G.: Software verification with BLAST. In: Ball, T., Rajamani, S.K. (eds.) SPIN 2003. LNCS, vol. 2648, pp. 235\u2013239. Springer, Heidelberg (2003). \nhttps:\/\/doi.org\/10.1007\/3-540-44829-2_17"},{"key":"34_CR13","doi-asserted-by":"crossref","unstructured":"Kr\u00fcger, S., Sp\u00e4th, J., Ali, K., Bodden, E., Mezini, M.: CrySL: an extensible approach to validating the correct usage of cryptographic APIs. In: ECOOP, pp. 10:1\u201310:27 (2018)","DOI":"10.1109\/TSE.2019.2948910"},{"key":"34_CR14","unstructured":"Lam, P., Bodden, E., Lhotak, O., Hendren, L.: The soot framework for java program analysis: a retrospective. In: Cetus Users and Compiler Infrastructure Workshop (CETUS 2011), October 2011"},{"key":"34_CR15","unstructured":"Marrero, W., Clarke, E., Jha, S.: A model checker for authentication protocols. In: Rutgers University (1997)"},{"issue":"3","key":"34_CR16","doi-asserted-by":"publisher","first-page":"292","DOI":"10.1145\/1178618.1178621","volume":"9","author":"M Murata","year":"2006","unstructured":"Murata, M., Tozawa, A., Kudo, M., Hada, S.: XML access control using static analysis. ACM Trans. Inf. Syst. Secur. 9(3), 292\u2013324 (2006)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"issue":"5","key":"34_CR17","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1022494.1022530","volume":"29","author":"G Naumovich","year":"2004","unstructured":"Naumovich, G., Centonze, P.: Static analysis of role-based access control in J2EE applications. SIGSOFT Softw. Eng. Notes 29(5), 1\u201310 (2004)","journal-title":"SIGSOFT Softw. Eng. Notes"},{"key":"34_CR18","unstructured":"Petrasch, T., Piskachev, G., Spaeth, J., Bodden, E.: Authcheck spring implementation. \nhttps:\/\/github.com\/secure-software-engineering\/authcheck\/"},{"key":"34_CR19","doi-asserted-by":"crossref","unstructured":"del Pilar Salas-Z\u00e1rate, M., Alor-Hern\u00e1ndez, G., Valencia-Garca, R., Rodr\u00edguez-Mazahua, L., Rodr\u00edguez-Gonz\u00e1lez, A., Cuadrado, J.L.L.: Analyzing best practices on web development frameworks: the lift approach. Sci. Comput. Program. 102, 1\u201319 (2015)","DOI":"10.1016\/j.scico.2014.12.004"},{"key":"34_CR20","doi-asserted-by":"crossref","unstructured":"Strom, R.E.: Mechanisms for compile-time enforcement of security. In: Proceedings of the 10th ACM SIGPLAN POPL, pp. 276\u2013284. ACM, New York (1983)","DOI":"10.1145\/567067.567093"},{"key":"34_CR21","unstructured":"Sun, F., Xu, L., Su, Z.: Static detection of access control vulnerabilities in web applications. In: Proceedings of USENIX. USENIX Association, Berkeley (2011)"},{"key":"34_CR22","unstructured":"Xu, Y., Xie, X.: Modeling and analysis of authentication protocols using colored petri nets. In: Proceedings of the 3rd ASID, ASID 2009. IEEE Press, Piscataway (2009)"}],"container-title":["Lecture Notes in Computer Science","Formal Methods. FM 2019 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-54997-8_34","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,8,10]],"date-time":"2020-08-10T20:21:52Z","timestamp":1597090912000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-54997-8_34"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030549961","9783030549978"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-54997-8_34","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"11 August 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"FM","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Formal Methods","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Porto","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Portugal","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 October 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 October 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"fm2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/formalmethods2019.inesctec.pt\/?page_id=84","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"129","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"44","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"34% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5,5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}