{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T06:49:52Z","timestamp":1757314192925,"version":"3.40.3"},"publisher-location":"Cham","reference-count":35,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030839024"},{"type":"electronic","value":"9783030839031"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-83903-1_7","type":"book-chapter","created":{"date-parts":[[2021,8,24]],"date-time":"2021-08-24T23:05:04Z","timestamp":1629846304000},"page":"101-114","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Automating the Assembly of Security Assurance Case Fragments"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3284-1969","authenticated-orcid":false,"given":"Baoluo","family":"Meng","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1792-9858","authenticated-orcid":false,"given":"Saswata","family":"Paul","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Abha","family":"Moitra","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kit","family":"Siu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Durling","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,8,25]]},"reference":[{"unstructured":"Common Attack Pattern Enumeration and Classification (CAPEC) (2017). https:\/\/capec.mitre.org","key":"7_CR1"},{"unstructured":"Security and Privacy Controls for Information Systems and Organizations (2017)","key":"7_CR2"},{"doi-asserted-by":"crossref","unstructured":"Agudo, I., Vivas, J.L., L\u00f3pez, J.: Security assurance during the software development cycle. In: Proceedings of the International Conference on Computer Systems and Technologies and Workshop for PhD Students in Computing, pp. 1\u20136 (2009)","key":"7_CR3","DOI":"10.1145\/1731740.1731763"},{"key":"7_CR4","volume-title":"Security Assurance Cases: Motivation and the State of the Art","author":"R Alexander","year":"2011","unstructured":"Alexander, R., Hawkins, R., Kelly, T.: Security Assurance Cases: Motivation and the State of the Art. The University of York, York (2011)"},{"doi-asserted-by":"crossref","unstructured":"Bagheri, H., Kang, E., Mansoor, N.: Synthesis of assurance cases for software certification. In: Proceedings of the International Conference on Software Engineering (2020)","key":"7_CR5","DOI":"10.1145\/3377816.3381728"},{"key":"7_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"68","DOI":"10.1007\/978-3-642-15651-9_6","volume-title":"Computer Safety, Reliability, and Security","author":"N Basir","year":"2010","unstructured":"Basir, N., Denney, E., Fischer, B.: Deriving safety cases for hierarchical structure in model-based development. In: Schoitsch, E. (ed.) SAFECOMP 2010. LNCS, vol. 6351, pp. 68\u201381. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-15651-9_6"},{"doi-asserted-by":"crossref","unstructured":"Bloomfield, R., Netkachova, K.: Building blocks for assurance cases. In: 2014 IEEE International Symposium on Software Reliability Engineering Workshops, pp. 186\u2013191. IEEE (2014)","key":"7_CR7","DOI":"10.1109\/ISSREW.2014.72"},{"unstructured":"Bloomfield, R., Rushby, J.: Assurance 2.0: A manifesto (2020)","key":"7_CR8"},{"key":"7_CR9","doi-asserted-by":"publisher","first-page":"360","DOI":"10.1016\/j.cose.2018.04.008","volume":"77","author":"M Cheah","year":"2018","unstructured":"Cheah, M., Shaikh, S.A., Bryans, J., Wooderson, P.: Building an automotive security assurance case using systematic security evaluations. Comput. Secur. 77, 360\u2013379 (2018)","journal-title":"Comput. Secur."},{"issue":"03","key":"7_CR10","doi-asserted-by":"publisher","first-page":"215","DOI":"10.1142\/S1793351X13500025","volume":"7","author":"A Crapo","year":"2013","unstructured":"Crapo, A., Moitra, A.: Toward a unified English-like representation of semantic models, data, and graph patterns for subject matter experts. Int. J. Semant. Comput. 7(03), 215\u2013236 (2013)","journal-title":"Int. J. Semant. Comput."},{"unstructured":"De La Vara, J., Parra, E., Ruiz, A., Gallina, B.: The amass tool platform: an innovative solution for assurance and certification of cyber-physical systems. In: Joint 26th International Conference on Requirements Engineering: Foundation for Software Quality Workshops, Pisa, Italy, vol. 2584. CEUR-WS (2020)","key":"7_CR11"},{"unstructured":"Denney, E., Pai, G.: A methodology for the development of assurance arguments for unmanned aircraft systems. In: 33rd International System Safety Conference (ISSC 2015) (2015)","key":"7_CR12"},{"issue":"4","key":"7_CR13","doi-asserted-by":"publisher","first-page":"830","DOI":"10.1109\/TR.2014.2335995","volume":"63","author":"E Denney","year":"2014","unstructured":"Denney, E., Pai, G.: Automating the assembly of aviation safety cases. IEEE Trans. Reliab. 63(4), 830\u2013849 (2014)","journal-title":"IEEE Trans. Reliab."},{"issue":"3","key":"7_CR14","doi-asserted-by":"publisher","first-page":"435","DOI":"10.1007\/s10515-017-0230-5","volume":"25","author":"E Denney","year":"2017","unstructured":"Denney, E., Pai, G.: Tool support for assurance case development. Autom. Softw. Eng. 25(3), 435\u2013499 (2017). https:\/\/doi.org\/10.1007\/s10515-017-0230-5","journal-title":"Autom. Softw. Eng."},{"key":"7_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1007\/978-3-642-33675-1_2","volume-title":"Computer Safety, Reliability, and Security","author":"E Denney","year":"2012","unstructured":"Denney, E., Pai, G., Pohl, J.: AdvoCATE: an assurance case automation toolset. In: Ortmeier, F., Daniel, P. (eds.) SAFECOMP 2012. LNCS, vol. 7613, pp. 8\u201321. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-33675-1_2"},{"unstructured":"Feiler, P.: The Open Source AADL Tool Environment (OSATE). Technical report, Carnegie Mellon University (2019)","key":"7_CR16"},{"unstructured":"Feiler, P.H., Gluch, D.P.: Model-Based Engineering with AADL: An Introduction to the SAE Architecture Analysis & Design Language. Addison-Wesley, Boston (2012)","key":"7_CR17"},{"doi-asserted-by":"crossref","unstructured":"Feiler, P.H., Gluch, D.P., Hudak, J.J.: The architecture analysis & design language (AADL): An introduction. Technical report, Carnegie Mellon University (2006)","key":"7_CR18","DOI":"10.21236\/ADA455842"},{"issue":"3","key":"7_CR19","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1145\/2692956.2663177","volume":"34","author":"A Gacek","year":"2014","unstructured":"Gacek, A., Backes, J., Cofer, D., Slind, K., Whalen, M.: Resolute: an assurance case language for architecture models. ACM SIGAda Ada Lett. 34(3), 19\u201328 (2014)","journal-title":"ACM SIGAda Ada Lett."},{"doi-asserted-by":"crossref","unstructured":"Graydon, P.J.: Formal assurance arguments: a solution in search of a problem? In: 2015 45th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, pp. 517\u2013528. IEEE (2015)","key":"7_CR20","DOI":"10.1109\/DSN.2015.28"},{"unstructured":"Guerra, S., Sheridan, D.: Compliance with standards or claim-based justification? The interplay and complementarity of the approaches for nuclear software-based systems. In: Proceedings of the Twenty-Second Safety-Critical Systems Symposium, Brighton, UK (2014)","key":"7_CR21"},{"key":"7_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1007\/978-3-642-24270-0_14","volume-title":"Computer Safety, Reliability, and Security","author":"R Hawkins","year":"2011","unstructured":"Hawkins, R., Clegg, K., Alexander, R., Kelly, T.: Using a software safety argument pattern catalogue: two case studies. In: Flammini, F., Bologna, S., Vittorini, V. (eds.) SAFECOMP 2011. LNCS, vol. 6894, pp. 185\u2013198. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-24270-0_14"},{"unstructured":"Kelly, T., Weaver, R.: The goal structuring notation-a safety argument notation. In: Proceedings of the Dependable Systems and Networks 2004 Workshop on Assurance Cases, p. 6. Citeseer (2004)","key":"7_CR23"},{"key":"7_CR24","series-title":"Communications in Computer and Information Science","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1007\/978-981-10-7850-7_2","volume-title":"Mobile Internet Security","author":"N Kobayashi","year":"2018","unstructured":"Kobayashi, N., Morisaki, S., Yamamoto, S.: Mobile security assurance for automotive software through ArchiMate. In: You, I., Leu, F.-Y., Chen, H.-C., Kotenko, I. (eds.) MobiSec 2016. CCIS, vol. 797, pp. 10\u201320. Springer, Singapore (2018). https:\/\/doi.org\/10.1007\/978-981-10-7850-7_2"},{"doi-asserted-by":"publisher","unstructured":"Meng, B., et al.: Towards developing formalized assurance cases. In: 2020 AIAA\/IEEE 39th Digital Avionics Systems Conference (DASC), pp. 1\u20139 (2020). https:\/\/doi.org\/10.1109\/DASC50938.2020.9256740","key":"7_CR25","DOI":"10.1109\/DASC50938.2020.9256740"},{"doi-asserted-by":"publisher","unstructured":"Meng, B., et al.: VERDICT: a language and framework for engineering cyber resilient and safe system. Syst. 9(1) (2021). https:\/\/doi.org\/10.3390\/systems9010018. https:\/\/www.mdpi.com\/2079-8954\/9\/1\/18","key":"7_CR26","DOI":"10.3390\/systems9010018"},{"doi-asserted-by":"publisher","unstructured":"Meng, B., Smith, W., Durling, M.: Security threat modeling and automated analysis for system design. SAE Int. J. Transp. Cyber Privacy 4 (2021). https:\/\/doi.org\/10.4271\/11-04-01-0001","key":"7_CR27","DOI":"10.4271\/11-04-01-0001"},{"doi-asserted-by":"crossref","unstructured":"Moitra, A., Prince, D., Siu, K., Durling, M., Herencia-Zapana, H.: Threat identification and defense control selection for embedded systems. SAE Int. J. Transp. Cyber. Privacy 3 (2020)","key":"7_CR28","DOI":"10.4271\/11-03-02-0005"},{"key":"7_CR29","doi-asserted-by":"publisher","first-page":"499","DOI":"10.1016\/j.procs.2011.08.092","volume":"6","author":"BR Poreddy","year":"2011","unstructured":"Poreddy, B.R., Corns, S.: Arguing security of generic avionic mission control computer system (MCC) using assurance cases. Proc. Comput. Sci. 6, 499\u2013504 (2011)","journal-title":"Proc. Comput. Sci."},{"unstructured":"RTCA-DO: 178c: Software considerations in airborne systems and equipment certification (2011)","key":"7_CR30"},{"doi-asserted-by":"crossref","unstructured":"Siu, K., Herencia-Zapana, H., Prince, D., Moitra, A.: A model-based framework for analyzing the security of system architectures. In: 2020 Annual Reliability and Maintainability Symposium (RAMS), pp. 1\u20136. IEEE (2020)","key":"7_CR31","DOI":"10.1109\/RAMS48030.2020.9153607"},{"doi-asserted-by":"crossref","unstructured":"Siu, K., et al.: Architectural and behavioral analysis for cyber security. In: 2019 IEEE\/AIAA 38th Digital Avionics Systems Conference (DASC), pp. 1\u201310. IEEE (2019)","key":"7_CR32","DOI":"10.1109\/DASC43569.2019.9081652"},{"unstructured":"Sommerville, I.: Software Engineering (2011). ISBN-10 137035152, 18","key":"7_CR33"},{"issue":"1","key":"7_CR34","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1007\/s00766-010-0114-8","volume":"16","author":"JL Vivas","year":"2011","unstructured":"Vivas, J.L., Agudo, I., L\u00f3pez, J.: A methodology for security assurance-driven system development. Requir. Eng. 16(1), 55\u201373 (2011)","journal-title":"Requir. Eng."},{"key":"7_CR35","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1016\/j.jss.2019.05.013","volume":"154","author":"R Wei","year":"2019","unstructured":"Wei, R., Kelly, T.P., Dai, X., Zhao, S., Hawkins, R.: Model based system assurance using the structured assurance case metamodel. J. Syst. Softw. 154, 211\u2013233 (2019)","journal-title":"J. Syst. Softw."}],"container-title":["Lecture Notes in Computer Science","Computer Safety, Reliability, and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-83903-1_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,13]],"date-time":"2024-03-13T17:50:13Z","timestamp":1710352213000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-83903-1_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030839024","9783030839031"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-83903-1_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"25 August 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SAFECOMP","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Computer Safety, Reliability, and Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"York","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"United Kingdom","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 September 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 September 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"40","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"safecomp2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/safecomp2021.hosted.york.ac.uk\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"76","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"17","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"22% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4.2","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"From the workshops 26 full and 4 short papers were accepted for publication.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}