{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T03:52:16Z","timestamp":1784260336670,"version":"3.55.0"},"publisher-location":"Cham","reference-count":24,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030622299","type":"print"},{"value":"9783030622305","type":"electronic"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-62230-5_10","type":"book-chapter","created":{"date-parts":[[2020,11,7]],"date-time":"2020-11-07T10:03:04Z","timestamp":1604743384000},"page":"186-197","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Contextualisation of Data Flow Diagrams for Security Analysis"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2859-1143","authenticated-orcid":false,"given":"Shamal","family":"Faily","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Riccardo","family":"Scandariato","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Adam","family":"Shostack","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8126-4491","authenticated-orcid":false,"given":"Laurens","family":"Sion","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8114-2737","authenticated-orcid":false,"given":"Duncan","family":"Ki-Aries","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2020,11,8]]},"reference":[{"key":"10_CR1","doi-asserted-by":"crossref","unstructured":"Antignac, T., Scandariato, R., Schneider, G.: Privacy compliance via model transformations. In: Proceedings of the 2018 IEEE European Symposium on Security and Privacy Workshops, pp. 120\u2013126, April 2018","DOI":"10.1109\/EuroSPW.2018.00024"},{"key":"10_CR2","doi-asserted-by":"crossref","unstructured":"Coles, J., Faily, S., Ki-Aries, D.: Tool-supporting data protection impact assessments with CAIRIS. In: Proceedings of the 5th International Workshop on Evolving Security & Privacy Requirements Engineering, pp. 21\u201327 (2018)","DOI":"10.1109\/ESPRE.2018.00010"},{"key":"10_CR3","volume-title":"About Face: The Essentials of Interaction Design","author":"A Cooper","year":"2014","unstructured":"Cooper, A., Reimann, R., Cronin, D., Noessel, C.: About Face: The Essentials of Interaction Design. John Wiley & Sons, Hoboken (2014)"},{"issue":"5","key":"10_CR4","doi-asserted-by":"publisher","first-page":"236","DOI":"10.1145\/360051.360056","volume":"19","author":"DE Denning","year":"1976","unstructured":"Denning, D.E.: A lattice model of secure information flow. Commun. ACM 19(5), 236\u2013243 (1976)","journal-title":"Commun. ACM"},{"key":"10_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"483","DOI":"10.1007\/3-540-45848-4_57","volume-title":"Graph Drawing","author":"J Ellson","year":"2002","unstructured":"Ellson, J., Gansner, E., Koutsofios, L., North, S.C., Woodhull, G.: Graphviz\u2014 open source graph drawing tools. In: Mutzel, P., J\u00fcnger, M., Leipert, S. (eds.) GD 2001. LNCS, vol. 2265, pp. 483\u2013484. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-45848-4_57"},{"key":"10_CR6","unstructured":"Faily, S.: CAIRIS web site. https:\/\/cairis.org (April 2018)"},{"key":"10_CR7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-75493-2","volume-title":"Designing Usable and Secure Software with IRIS and CAIRIS","author":"S Faily","year":"2018","unstructured":"Faily, S.: Designing Usable and Secure Software with IRIS and CAIRIS. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-75493-2"},{"key":"10_CR8","doi-asserted-by":"crossref","unstructured":"Faily, S., Fl\u00e9chais, I.: Barry is not the weakest link: eliciting secure system requirements with personas. In: Proceedings of the 24th BCS Interaction Specialist Group Conference, pp. 124\u2013132. BCS 2010, British Computer Society (2010)","DOI":"10.14236\/ewic\/HCI2010.17"},{"issue":"3","key":"10_CR9","doi-asserted-by":"publisher","first-page":"56","DOI":"10.4018\/jsse.2010070104","volume":"1","author":"S Faily","year":"2010","unstructured":"Faily, S., Fl\u00e9chais, I.: Towards tool-support for usable secure requirements engineering with CAIRIS. Int. J. Secure Softw. Eng. 1(3), 56\u201370 (2010)","journal-title":"Int. J. Secure Softw. Eng."},{"key":"10_CR10","volume-title":"Risk Management for Computer Security: Protecting your Network and Information Assets","author":"A Jones","year":"2005","unstructured":"Jones, A., Ashenden, D.: Risk Management for Computer Security: Protecting your Network and Information Assets. Elsevier, Oxford (2005)"},{"key":"10_CR11","doi-asserted-by":"crossref","unstructured":"Ki-Aries, D., Faily, S., Dogan, H., Williams, C.: Assessing system of systems security risk and requirements with OASoSIS. In: Proceedings of the 5th International Workshop on Evolving Security & Privacy Requirements Engineering, pp. 14\u201320 (2018)","DOI":"10.1109\/ESPRE.2018.00009"},{"key":"10_CR12","unstructured":"van Lamsweerde, A.: Requirements Engineering: from system goals to UML models to software specifications. John Wiley & Sons (2009)"},{"key":"10_CR13","doi-asserted-by":"crossref","unstructured":"Van der Linden, M.A.: Testing Code Security. Auerbach Pub, Boca Raton (2007)","DOI":"10.1201\/9781420013795"},{"key":"10_CR14","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1007\/978-3-319-61717-6_12","volume-title":"Fundamentals of Secure System Modelling","author":"R Matulevi\u010dius","year":"2017","unstructured":"Matulevi\u010dius, R.: Secure system development. Fundamentals of Secure System Modelling, pp. 199\u2013207. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-61717-6_12"},{"key":"10_CR15","volume-title":"Threat Modeling: Designing for Security","author":"A Shostack","year":"2014","unstructured":"Shostack, A.: Threat Modeling: Designing for Security. John Wiley & Sons, Indianapolis (2014)"},{"issue":"4","key":"10_CR16","first-page":"493","volume":"69","author":"HA Simon","year":"1979","unstructured":"Simon, H.A.: Rational decision making in business organizations. Am. Econ. Rev. 69(4), 493\u2013513 (1979)","journal-title":"Am. Econ. Rev."},{"key":"10_CR17","doi-asserted-by":"crossref","unstructured":"Sion, L., Yskout, K., Van Landuyt, D., van den Berghe, A., Joosen, W.: Security threat modeling: are data flow diagrams enough? In: Proceedings of IEEE\/ACM 42nd International Conference on Software Engineering Workshops (ICSEW 2020). IEEE (2020). to Appear","DOI":"10.1145\/3387940.3392221"},{"key":"10_CR18","series-title":"IFIP International Federation for Information Processing","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1007\/978-0-387-75462-8_6","volume-title":"Critical Infrastructure Protection","author":"J Slay","year":"2008","unstructured":"Slay, J., Miller, M.: Lessons learned from the maroochy water breach. In: Goetz, E., Shenoi, S. (eds.) ICCIP 2007. IIFIP, vol. 253, pp. 73\u201382. Springer, Boston, MA (2008). https:\/\/doi.org\/10.1007\/978-0-387-75462-8_6"},{"key":"10_CR19","doi-asserted-by":"crossref","unstructured":"Tuma, K., Scandariato, R., Balliu, M.: Flaws in flows: unveiling design flaws via information flow analysis. In: Proceedings of the 2019 IEEE International Conference on Software Architecture (ICSA), pp. 191\u2013200 (2019)","DOI":"10.1109\/ICSA.2019.00028"},{"key":"10_CR20","doi-asserted-by":"publisher","first-page":"275","DOI":"10.1016\/j.jss.2018.06.073","volume":"144","author":"K Tuma","year":"2018","unstructured":"Tuma, K., Kalikli, G., Scandariato, R.: Threat analysis of software systems: a systematic literature review. J. Syst. Softw. 144, 275\u2013294 (2018)","journal-title":"J. Syst. Softw."},{"key":"10_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"47","DOI":"10.1007\/978-3-319-72817-9_4","volume-title":"Computer Security","author":"K Tuma","year":"2018","unstructured":"Tuma, K., Scandariato, R., Widman, M., Sandberg, C.: Towards security threats that matter. In: Katsikas, S.K., Cuppens, F., Cuppens, N., Lambrinoudakis, C., Kalloniatis, C., Mylopoulos, J., Ant\u00f3n, A., Gritzalis, S. (eds.) CyberICPS\/SECPRE -2017. LNCS, vol. 10683, pp. 47\u201362. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-72817-9_4"},{"key":"10_CR22","unstructured":"Woodcock, J., Davies, J.: Using Z: Specification, Refinement, and Proof. Prentice Hall (1996)"},{"key":"10_CR23","doi-asserted-by":"crossref","unstructured":"Yin, H., Song, D., Egele, M., Kruegel, C., Kirda, E.: Panorama: capturing system-wide information flow for malware detection and analysis. In: Proceedings of the 14th ACM Conference on Computer and Communications Security, pp. 116\u2013127. Association for Computing Machinery (2007)","DOI":"10.1145\/1315245.1315261"},{"key":"10_CR24","volume-title":"Structured design: Fundamentals of a Discipline of Computer Program and Systems Design","author":"E Yourdon","year":"1979","unstructured":"Yourdon, E., Constantine, L.L.: Structured design: Fundamentals of a Discipline of Computer Program and Systems Design. Prentice Hall, USA (1979)"}],"container-title":["Lecture Notes in Computer Science","Graphical Models for Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-62230-5_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,4,24]],"date-time":"2021-04-24T10:45:16Z","timestamp":1619261116000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-62230-5_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030622299","9783030622305"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-62230-5_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"8 November 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"GraMSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Workshop on Graphical Models for Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Boston, MA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2020","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 June 2020","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 June 2020","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"gramsec2020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.gramsec.uni.lu\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"14","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"50% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"The workshop was held virtually due to the COVID-19 pandemic","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}