{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,8]],"date-time":"2024-09-08T23:19:51Z","timestamp":1725837591715},"publisher-location":"Cham","reference-count":20,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319264158"},{"type":"electronic","value":"9783319264165"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-319-26416-5_7","type":"book-chapter","created":{"date-parts":[[2015,11,12]],"date-time":"2015-11-12T05:50:46Z","timestamp":1447307446000},"page":"93-109","source":"Crossref","is-referenced-by-count":1,"title":["Risk-Driven Vulnerability Testing: Results from eHealth Experiments Using Patterns and Model-Based Approach"],"prefix":"10.1007","author":[{"given":"Alexandre","family":"Vernotte","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Cornel","family":"Botea","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bruno","family":"Legeard","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Arthur","family":"Molnar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fabien","family":"Peureux","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,11,13]]},"reference":[{"issue":"6","key":"7_CR1","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1145\/2184319.2184322","volume":"55","author":"J Hong","year":"2012","unstructured":"Hong, J., Linden, G.: Protecting against data breaches; living with mistakes. Commun. ACM 55(6), 10\u201311 (2012)","journal-title":"Commun. ACM"},{"key":"7_CR2","doi-asserted-by":"crossref","unstructured":"Oladimeji, E.A., Chung, L., Jung, H.T., Kim, J.: Managing security and privacy in ubiquitous ehealth information interchange. In: Ubiquitous Information Management and Communication, pp. 1\u201310. ACM, New York (2011)","DOI":"10.1145\/1968613.1968645"},{"key":"7_CR3","unstructured":"EU: GDP Regulation Draft (2012). \n                      http:\/\/ec.europa.eu\/justice\/data-protection\/document\/review2012\/com_2012_11_en.pdf\n                      \n                    . Accessed April 2015"},{"key":"7_CR4","volume-title":"Practical Model-Based Testing - A tools approach","author":"M Utting","year":"2006","unstructured":"Utting, M., Legeard, B.: Practical Model-Based Testing - A tools approach. Morgan Kaufmann, San Francisco (2006)"},{"key":"7_CR5","doi-asserted-by":"crossref","unstructured":"Dias-Neto, A., Travassos, G.: A Picture from the model-based testing area: concepts, techniques, and challenges. In: Advances in Computers, vol. 80, pp. 45\u2013120, July 2010. ISSN: 0065\u20132458","DOI":"10.1016\/S0065-2458(10)80002-6"},{"key":"7_CR6","unstructured":"Wichers, D.: Open web application security project (2013). \n                      https:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_Project\n                      \n                    . Accessed April 2015"},{"key":"7_CR7","unstructured":"MITRE: Common weakness enumeration, October 2013. \n                      http:\/\/cwe.mitre.org\/\n                      \n                    . Accessed April 2015"},{"key":"7_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/978-3-642-14215-4_7","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"A Doup\u00e9","year":"2010","unstructured":"Doup\u00e9, A., Cova, M., Vigna, G.: Why Johnny can\u2019t pentest: an analysis of black-box web vulnerability scanners. In: Kreibich, C., Jahnke, M. (eds.) DIMVA 2010. LNCS, vol. 6201, pp. 111\u2013131. Springer, Heidelberg (2010)"},{"issue":"6","key":"7_CR9","first-page":"113","volume":"32","author":"J Bach","year":"1999","unstructured":"Bach, J.: Risk and requirements-based testing. Computer 32(6), 113\u2013114 (1999). IEEE Press","journal-title":"Computer"},{"key":"7_CR10","doi-asserted-by":"crossref","unstructured":"Lund, M.S., Solhaug, B., St\u00f8len, K.: Model-Driven Risk Analysis: The CORAS Approach. 1st edn. Springer Publishing Company, Incorporated (2010)","DOI":"10.1007\/978-3-642-12323-8"},{"key":"7_CR11","doi-asserted-by":"crossref","unstructured":"Bouquet, F., Grandpierre, C., Legeard, B., Peureux, F.: A test generation solution to automate software testing. In: Proceedings of the 3rd International Workshop on Automation of Software Test (AST 2008), Leipzig, Germany, pp. 45\u201348. ACM Press, May 2008","DOI":"10.1145\/1370042.1370052"},{"key":"7_CR12","unstructured":"Fraunhofer FOKUS: Fuzzing library Fuzzino on Github (2013). \n                      https:\/\/github.com\/fraunhoferfokus\/Fuzzino\n                      \n                    . Accessed April 2015"},{"key":"7_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"337","DOI":"10.1007\/978-3-662-45231-8_24","volume-title":"Leveraging Applications of Formal Methods, Verification and Validation","author":"J Botella","year":"2014","unstructured":"Botella, J., Legeard, B., Peureux, F., Vernotte, A.: Risk-based vulnerability testing using security test patterns. In: Margaria, T., Steffen, B. (eds.) ISoLA 2014, Part II. LNCS, vol. 8803, pp. 337\u2013352. Springer, Heidelberg (2014)"},{"key":"7_CR14","unstructured":"Vouffo Feudjio, A.G.: Initial Security Test Pattern Catalog. Public Deliverable D3.WP4.T1, Diamonds Project, Berlin, Germany, June 2012. \n                      http:\/\/publica.fraunhofer.de\/documents\/N-212439.html\n                      \n                    . Accessed February 2014"},{"key":"7_CR15","doi-asserted-by":"crossref","unstructured":"Andrikopoulos, P.K., Belsis, P.: Towards effective organization of medical data. In: Proceedings of the 17th Panhellenic Conference on Informatics (PCI 2013), Thessaloniki, Greece, pp. 305\u2013310. ACM (2013)","DOI":"10.1145\/2491845.2491890"},{"issue":"4","key":"7_CR16","doi-asserted-by":"publisher","first-page":"277","DOI":"10.1145\/1118890.1118891","volume":"37","author":"M Eichelberg","year":"2005","unstructured":"Eichelberg, M., Aden, T., Riesmeier, J., Dogac, A., Laleci, G.B.: A survey and analysis of electronic healthcare record standards. ACM Comput. Surv. 37(4), 277\u2013315 (2005)","journal-title":"ACM Comput. Surv."},{"key":"7_CR17","unstructured":"Werner, F.: RASEN Deliverable D2.1.1 - Use Case Scenarios Definition, October 2013. \n                      http:\/\/www.rasenproject.eu\/downloads\/723\/\n                      \n                    . Accessed April 2015"},{"key":"7_CR18","unstructured":"IHE International: HIE security and privacy through IHE profiles. White paper, IHE IT Infrastructure, August 2008. \n                      http:\/\/www.ihe.net\/Technical_Framework\/upload\/IHE_ITI_Whitepaper_Security_and_Privacy_of_HIE_2008-08-22-2.pdf\n                      \n                    . Accessed March 2015"},{"key":"7_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"358","DOI":"10.1007\/978-3-319-13841-1_20","volume-title":"Information Systems Security","author":"A Vernotte","year":"2014","unstructured":"Vernotte, A., Dadeau, F., Lebeau, F., Legeard, B., Peureux, F., Piat, F.: Efficient detection of multi-step cross-site scripting vulnerabilities. In: Prakash, A., Shyamasundar, R. (eds.) ICISS 2014. LNCS, vol. 8880, pp. 358\u2013377. Springer, Heidelberg (2014)"},{"key":"7_CR20","unstructured":"Doup\u00e9, A., Cavedon, L., Kruegel, C., Vigna, G.: Enemy of the state: a state-aware black-box web vulnerability scanner. In: Proceedings of the 21st USENIX Conference on Security Symposium (Security 2012), Bellevue, WA, USA, pp. 523\u2013537. USENIX Association, August 2012"}],"container-title":["Lecture Notes in Computer Science","Risk Assessment and Risk-Driven Testing"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-26416-5_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,31]],"date-time":"2019-05-31T10:35:50Z","timestamp":1559298950000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-26416-5_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783319264158","9783319264165"],"references-count":20,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-26416-5_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2015]]}}}