{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,11]],"date-time":"2025-09-11T20:28:36Z","timestamp":1757622516994,"version":"3.44.0"},"publisher-location":"Cham","reference-count":42,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783032006233"},{"type":"electronic","value":"9783032006240"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-032-00624-0_14","type":"book-chapter","created":{"date-parts":[[2025,8,9]],"date-time":"2025-08-09T11:42:12Z","timestamp":1754739732000},"page":"278-300","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["In Specs We Trust? Conformance-Analysis of\u00a0Implementation to\u00a0Specifications in\u00a0Node-RED and\u00a0Associated Security Risks"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8605-615X","authenticated-orcid":false,"given":"Simon","family":"Schneider","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Komal","family":"Kashish","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7189-2817","authenticated-orcid":false,"given":"Katja","family":"Tuma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3591-7671","authenticated-orcid":false,"given":"Riccardo","family":"Scandariato","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,8,10]]},"reference":[{"key":"14_CR1","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2021.100365","volume":"14","author":"R Ahmad","year":"2021","unstructured":"Ahmad, R., Alsmadi, I.: Machine learning approaches to IoT security: a systematic literature review. Internet Things 14, 100365 (2021). https:\/\/doi.org\/10.1016\/j.iot.2021.100365","journal-title":"Internet Things"},{"doi-asserted-by":"publisher","unstructured":"Ahmadpanah, M.M., Balliu, M., Hedin, D., Olsson, L.E., Sabelfeld, A.: Securing Node-RED Applications, pp. 1\u201321. Springer (2021). https:\/\/doi.org\/10.1007\/978-3-030-91631-2_1","key":"14_CR2","DOI":"10.1007\/978-3-030-91631-2_1"},{"issue":"3","key":"14_CR3","doi-asserted-by":"publisher","first-page":"1646","DOI":"10.1109\/COMST.2020.2988293","volume":"22","author":"MA Al-Garadi","year":"2020","unstructured":"Al-Garadi, M.A., Mohamed, A., Al-Ali, A.K., Du, X., Ali, I., Guizani, M.: A survey of machine and deep learning methods for internet of things (IoT) security. IEEE Commun. Surv. Tutor. 22(3), 1646\u20131685 (2020). https:\/\/doi.org\/10.1109\/COMST.2020.2988293","journal-title":"IEEE Commun. Surv. Tutor."},{"unstructured":"Alfadel, M., Costa, D.E., Mkhallalati, M., Shihab, E., Adams, B.: On the threat of NPM vulnerable dependencies in node.js applications. CoRR abs\/2009.09019 (2020)","key":"14_CR4"},{"doi-asserted-by":"publisher","unstructured":"Ancona, D., Franceschini, L., Delzanno, G., Leotta, M., Ribaudo, M., Ricca, F.: Towards runtime monitoring of node.js and its application to the internet of things. Electron. Proc. Theoret. Comput. Sci. 264, 27\u201342 (2018). https:\/\/doi.org\/10.4204\/eptcs.264.4","key":"14_CR5","DOI":"10.4204\/eptcs.264.4"},{"unstructured":"Anonymous authors of this paper: Replication package of this paper (2025). https:\/\/anonymous.4open.science\/r\/replication_package_ARES-CC51\/","key":"14_CR6"},{"key":"14_CR7","doi-asserted-by":"publisher","first-page":"733","DOI":"10.1007\/s12599-021-00726-8","volume":"63","author":"AC Bock","year":"2021","unstructured":"Bock, A.C., Frank, U.: Low-code platform. Bus. Inf. Syst. Eng. 63, 733\u2013740 (2021)","journal-title":"Bus. Inf. Syst. Eng."},{"key":"14_CR8","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2022.100568","volume":"19","author":"A Chatterjee","year":"2022","unstructured":"Chatterjee, A., Ahmed, B.S.: IoT anomaly detection methods and applications: a survey. Internet Things 19, 100568 (2022). https:\/\/doi.org\/10.1016\/j.iot.2022.100568","journal-title":"Internet Things"},{"doi-asserted-by":"publisher","unstructured":"Chibotaru, V., Bichsel, B., Raychev, V., Vechev, M.: Scalable taint specification inference with big code. In: Proceedings of the 40th ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI 2019, pp. 760\u2013774. ACM (2019). https:\/\/doi.org\/10.1145\/3314221.3314648","key":"14_CR9","DOI":"10.1145\/3314221.3314648"},{"doi-asserted-by":"publisher","unstructured":"Clapp, L., Anand, S., Aiken, A.: ModelGEN: mining explicit information flow specifications from concrete executions. In: Proceedings of the 2015 International Symposium on Software Testing and Analysis, ISSTA 2015, pp. 129\u2013140. ACM (2015). https:\/\/doi.org\/10.1145\/2771783.2771810","key":"14_CR10","DOI":"10.1145\/2771783.2771810"},{"doi-asserted-by":"publisher","unstructured":"Clerissi, D., Leotta, M., Reggio, G., Ricca, F.: Towards an approach for developing and testing node-red IoT systems. In: Proceedings of the 1st ACM SIGSOFT International Workshop on Ensemble-Based Software Engineering, EnSEmble 2018, pp. 1\u20138. ACM (2018). https:\/\/doi.org\/10.1145\/3281022.3281023","key":"14_CR11","DOI":"10.1145\/3281022.3281023"},{"doi-asserted-by":"publisher","unstructured":"Decan, A., Mens, T., Constantinou, E.: On the impact of security vulnerabilities in the NPM package dependency network. In: Proceedings of the 15th International Conference on Mining Software Repositories, MSR 2018, pp. 181\u2013191. ACM (2018). https:\/\/doi.org\/10.1145\/3196398.3196401","key":"14_CR12","DOI":"10.1145\/3196398.3196401"},{"doi-asserted-by":"crossref","unstructured":"Dutta, S., Garbervetsky, D., Lahiri, S., Sch\u00e4fer, M.: InspectJS: leveraging code similarity and user-feedback for effective taint specification inference for JavaScript. arXiv preprint arXiv:2111.09625 (2021)","key":"14_CR13","DOI":"10.1145\/3510457.3513048"},{"doi-asserted-by":"publisher","unstructured":"Ferreira, G., Jia, L., Sunshine, J., K\u00e4stner, C.: Containing malicious package updates in NPM with a lightweight permission system. In: 2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE), pp. 1334\u20131346 (2021). https:\/\/doi.org\/10.1109\/ICSE43902.2021.00121","key":"14_CR14","DOI":"10.1109\/ICSE43902.2021.00121"},{"doi-asserted-by":"publisher","unstructured":"HaddadPajouh, H., Dehghantanha, A., M. Parizi, R., Aledhari, M., Karimipour, H.: A survey on internet of things security: Requirements, challenges, and solutions. Internet of Things 14, 100129 (2021). https:\/\/doi.org\/10.1016\/j.iot.2019.100129","key":"14_CR15","DOI":"10.1016\/j.iot.2019.100129"},{"unstructured":"Halfond, W.G., Viegas, J., Orso, A., et\u00a0al.: A classification of SQL injection attacks and countermeasures. In: ISSSE (2006)","key":"14_CR16"},{"key":"14_CR17","doi-asserted-by":"publisher","first-page":"82721","DOI":"10.1109\/ACCESS.2019.2924045","volume":"7","author":"V Hassija","year":"2019","unstructured":"Hassija, V., Chamola, V., Saxena, V., Jain, D., Goyal, P., Sikdar, B.: A survey on IoT security: application areas, security threats, and solution architectures. IEEE Access 7, 82721\u201382743 (2019). https:\/\/doi.org\/10.1109\/ACCESS.2019.2924045","journal-title":"IEEE Access"},{"unstructured":"Huawei Technologies\u00a0Co., L.: Global connectivity index. http:\/\/www.huawei.com\/minisite\/gci\/en\/index.html","key":"14_CR18"},{"doi-asserted-by":"publisher","unstructured":"Ioannidis, T., Bolgouras, V., Xenakis, C., Politis, I.: Securing the flow: security and privacy tools for flow-based programming. In: Proceedings of the 18th International Conference on Availability, Reliability and Security, ARES 2023. ACM (2023). https:\/\/doi.org\/10.1145\/3600160.3605089","key":"14_CR19","DOI":"10.1145\/3600160.3605089"},{"doi-asserted-by":"publisher","unstructured":"Krohn, M., et al.: Information flow control for standard OS abstractions. In: Proceedings of Twenty-First ACM SIGOPS Symposium on Operating Systems Principles, SOSP 2007, pp. 321\u2013334. ACM (2007). https:\/\/doi.org\/10.1145\/1294261.1294293","key":"14_CR20","DOI":"10.1145\/1294261.1294293"},{"doi-asserted-by":"publisher","unstructured":"Li, R., Liang, P., Soliman, M., Avgeriou, P.: Understanding software architecture erosion: a systematic mapping study. J. Softw. Evol. Process 34(3), e2423 (2022). https:\/\/doi.org\/10.1002\/smr.2423","key":"14_CR21","DOI":"10.1002\/smr.2423"},{"doi-asserted-by":"publisher","unstructured":"Livshits, B., Nori, A.V., Rajamani, S.K., Banerjee, A.: Merlin: specification inference for explicit information flow problems. In: 30th ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI 2009, pp. 75\u201386. ACM (2009). https:\/\/doi.org\/10.1145\/1542476.1542485","key":"14_CR22","DOI":"10.1145\/1542476.1542485"},{"doi-asserted-by":"publisher","unstructured":"Mahmoud, R., Yousuf, T., Aloul, F., Zualkernan, I.: Internet of things (IoT) security: current status, challenges and prospective measures. In: 2015 10th International Conference for Internet Technology and Secured Transactions (ICITST), pp. 336\u2013341 (2015). https:\/\/doi.org\/10.1109\/ICITST.2015.7412116","key":"14_CR23","DOI":"10.1109\/ICITST.2015.7412116"},{"doi-asserted-by":"publisher","unstructured":"Marchezan, L., Assun\u00e7\u00e3o, W.K.G., Herac, E., Keplinger, F., Egyed, A., Lauwerys, C.: Fulfilling industrial needs for consistency among engineering artifacts. In: 2023 IEEE\/ACM 45th International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP), pp. 246\u2013257 (2023). https:\/\/doi.org\/10.1109\/ICSE-SEIP58684.2023.00028","key":"14_CR24","DOI":"10.1109\/ICSE-SEIP58684.2023.00028"},{"doi-asserted-by":"publisher","unstructured":"binti Mohamad Noor, M., Hassan, W.H.: Current research on internet of things (IoT) security: a survey. Comput. Netw. 148, 283\u2013294 (2019). https:\/\/doi.org\/10.1016\/j.comnet.2018.11.025","key":"14_CR25","DOI":"10.1016\/j.comnet.2018.11.025"},{"issue":"4","key":"14_CR26","doi-asserted-by":"publisher","first-page":"364","DOI":"10.1109\/32.917525","volume":"27","author":"G Murphy","year":"2001","unstructured":"Murphy, G., Notkin, D., Sullivan, K.: Software reflexion models: bridging the gap between design and implementation. IEEE Trans. Software Eng. 27(4), 364\u2013380 (2001). https:\/\/doi.org\/10.1109\/32.917525","journal-title":"IEEE Trans. Software Eng."},{"doi-asserted-by":"crossref","unstructured":"Peldszus, S., Tuma, K., Str\u00fcber, D., J\u00fcrjens, J., Scandariato, R.: Secure data-flow compliance checks between models and code based on automated mappings. In: 2019 ACM\/IEEE 22nd International Conference on Model Driven Engineering Languages and Systems (MODELS), pp. 23\u201333. IEEE (2019)","key":"14_CR27","DOI":"10.1109\/MODELS.2019.00-18"},{"doi-asserted-by":"crossref","unstructured":"Rasthofer, S., Arzt, S., Bodden, E.: A machine-learning approach for classifying and categorizing android sources and sinks. In: NDSS, vol.\u00a014 (2014)","key":"14_CR28","DOI":"10.14722\/ndss.2014.23039"},{"doi-asserted-by":"crossref","unstructured":"Rokis, K., Kirikova, M.: Challenges of low-code\/no-code software development: a literature review. In: Perspectives in Business Informatics Research, pp. 3\u201317. Springer (2022)","key":"14_CR29","DOI":"10.1007\/978-3-031-16947-2_1"},{"doi-asserted-by":"publisher","unstructured":"Schwartz, E.J., Avgerinos, T., Brumley, D.: All you ever wanted to know about dynamic taint analysis and forward symbolic execution (but might have been afraid to ask). In: 2010 IEEE Symposium on Security and Privacy, pp. 317\u2013331 (2010). https:\/\/doi.org\/10.1109\/SP.2010.26","key":"14_CR30","DOI":"10.1109\/SP.2010.26"},{"doi-asserted-by":"crossref","unstructured":"Smith, B., Williams, L., Austin, A.: Idea: using system level testing for revealing SQL injection-related error message information leaks. In: Engineering Secure Software and Systems, pp. 192\u2013200. Springer (2010)","key":"14_CR31","DOI":"10.1007\/978-3-642-11747-3_15"},{"doi-asserted-by":"publisher","unstructured":"Staicu, C.A., Torp, M.T., Sch\u00e4fer, M., M\u00f8ller, A., Pradel, M.: Extracting taint specifications for JavaScript libraries. In: Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering, ICSE 2020, pp. 198\u2013209. ACM (2020). https:\/\/doi.org\/10.1145\/3377811.3380390","key":"14_CR32","DOI":"10.1145\/3377811.3380390"},{"issue":"3","key":"14_CR33","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3310353","volume":"18","author":"FM Tabrizi","year":"2019","unstructured":"Tabrizi, F.M., Pattabiraman, K.: Design-level and code-level security analysis of IoT devices. ACM Trans. Embed. Comput. Syst. 18(3), 1\u201325 (2019)","journal-title":"ACM Trans. Embed. Comput. Syst."},{"doi-asserted-by":"publisher","unstructured":"Tuma, K., Peldszus, S., Str\u00fcber, D., Scandariato, R., J\u00fcrjens, J.: Checking security compliance between models and code. Softw. Syst. Model., 1\u201324 (2022). https:\/\/doi.org\/10.1007\/s10270-022-00991-5","key":"14_CR34","DOI":"10.1007\/s10270-022-00991-5"},{"issue":"2","key":"14_CR35","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1049\/iet-cps.2017.0068","volume":"3","author":"IS Udoh","year":"2018","unstructured":"Udoh, I.S., Kotonya, G.: Developing IoT applications: challenges and frameworks. IET Cyber-Phys. Syst. Theory Appl. 3(2), 65\u201372 (2018). https:\/\/doi.org\/10.1049\/iet-cps.2017.0068","journal-title":"IET Cyber-Phys. Syst. Theory Appl."},{"doi-asserted-by":"publisher","unstructured":"Uzun, B., Tekinerdogan, B.: Architecture conformance analysis using model-based testing: a case study approach. Softw. Pract. Exp. 49(3), 423\u2013448 (2019). https:\/\/doi.org\/10.1002\/spe.2667","key":"14_CR36","DOI":"10.1002\/spe.2667"},{"key":"14_CR37","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2022.100564","volume":"19","author":"P Williams","year":"2022","unstructured":"Williams, P., Dutta, I.K., Daoud, H., Bayoumi, M.: A survey on security in internet of things with a focus on the impact of emerging technologies. Internet Things 19, 100564 (2022). https:\/\/doi.org\/10.1016\/j.iot.2022.100564","journal-title":"Internet Things"},{"issue":"5","key":"14_CR38","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1109\/MSP.2018.2825478","volume":"35","author":"L Xiao","year":"2018","unstructured":"Xiao, L., Wan, X., Lu, X., Zhang, Y., Wu, D.: IoT security techniques based on machine learning: How do IoT devices use AI to enhance security? IEEE Signal Process. Mag. 35(5), 41\u201349 (2018). https:\/\/doi.org\/10.1109\/MSP.2018.2825478","journal-title":"IEEE Signal Process. Mag."},{"doi-asserted-by":"publisher","unstructured":"Zahan, N., Zimmermann, T., Godefroid, P., Murphy, B., Maddila, C., Williams, L.: What are weak links in the NPM supply chain? In: Proceedings of the 44th International Conference on Software Engineering: Software Engineering in Practice, ICSE-SEIP 2022, pp. 331\u2013340. ACM (2022). https:\/\/doi.org\/10.1145\/3510457.3513044","key":"14_CR39","DOI":"10.1145\/3510457.3513044"},{"doi-asserted-by":"publisher","unstructured":"Zhang, Z.K., Cho, M.C.Y., Wang, C.W., Hsu, C.W., Chen, C.K., Shieh, S.: IoT security: ongoing challenges and research opportunities. In: 2014 IEEE 7th International Conference on Service-Oriented Computing and Applications, pp. 230\u2013234 (2014). https:\/\/doi.org\/10.1109\/SOCA.2014.58","key":"14_CR40","DOI":"10.1109\/SOCA.2014.58"},{"doi-asserted-by":"publisher","unstructured":"Zhong, C., et al.: DOMICO: checking conformance between domain models and implementations. Softw. Pract. Exp. (2023). https:\/\/doi.org\/10.1002\/spe.3272","key":"14_CR41","DOI":"10.1002\/spe.3272"},{"unstructured":"Zimmermann, M., Staicu, C.A., Tenny, C., Pradel, M.: Small world with high risks: a study of security threats in the NPM ecosystem. In: 28th USENIX Security Symposium, pp. 995\u20131010. USENIX Association (2019)","key":"14_CR42"}],"container-title":["Lecture Notes in Computer Science","Availability, Reliability and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-00624-0_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T19:54:29Z","timestamp":1757361269000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-00624-0_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783032006233","9783032006240"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-00624-0_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"10 August 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ARES","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Availability, Reliability and Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Ghent","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Belgium","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ares-12025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/2025.ares-conference.eu","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}