{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,5]],"date-time":"2024-09-05T12:47:48Z","timestamp":1725540468767},"publisher-location":"Berlin, Heidelberg","reference-count":52,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642051500"},{"type":"electronic","value":"9783642051517"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009]]},"DOI":"10.1007\/978-3-642-05151-7_4","type":"book-chapter","created":{"date-parts":[[2009,11,6]],"date-time":"2009-11-06T11:08:42Z","timestamp":1257505722000},"page":"798-814","source":"Crossref","is-referenced-by-count":2,"title":["Moving from Requirements to Design Confronting Security Issues: A Case Study"],"prefix":"10.1007","author":[{"given":"Spyros T.","family":"Halkidis","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alexander","family":"Chatzigeorgiou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"George","family":"Stephanides","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"4_CR1","doi-asserted-by":"crossref","unstructured":"Alexander, I.: Misuse Cases: Use Cases with Hostile Intent. IEEE Software, 58\u201366 (January\/February 2003)","DOI":"10.1109\/MS.2003.1159030"},{"key":"4_CR2","volume-title":"Natural Language Understanding","author":"J. Allen","year":"1994","unstructured":"Allen, J.: Natural Language Understanding. Addison Wesley, Reading (1994)"},{"key":"4_CR3","doi-asserted-by":"crossref","unstructured":"Bikel, D.: Design of a Multi-lingual Parallel-Processing Statistical Parser Engine. In: Proceedings of Human Language Technology Conference, HLT 2002 (2002)","DOI":"10.3115\/1289189.1289191"},{"key":"4_CR4","unstructured":"Blakley, B., Heath, C., Members of the Open Group Security Forum: Security Design Patterns. Open Group Technical Guide (2004)"},{"key":"4_CR5","unstructured":"Braga, A., Rubira, C., Dahab, R.: Tropyc: A Pattern Language for Cryptographic Software. In: Proceedings of the 5th Conference on Pattern Languages of Programming, PLoP 1998 (1998)"},{"key":"4_CR6","doi-asserted-by":"crossref","unstructured":"Caldiera, G., Antoniol, G., Fiutem, R., Lokan, C.: A Definition and Experimental Evaluation of Function Points for Object-Oriented Systems. In: Proceedings of the Fifth International Symposium on Software Metrics-METRICS 1998, pp. 167\u2013178 (1998)","DOI":"10.1109\/METRIC.1998.731242"},{"key":"4_CR7","unstructured":"Cgisecurity.com, Cross Site Scripting questions and answers, http:\/\/www.cgisecurity.com\/articles\/xss-faq.shtml"},{"issue":"4","key":"4_CR8","first-page":"33","volume":"18","author":"E. Charniak","year":"1997","unstructured":"Charniak, E.: Statistical Techniques for Natural Language Parsing. AI Magazine\u00a018(4), 33\u201344 (1997)","journal-title":"AI Magazine"},{"key":"4_CR9","doi-asserted-by":"crossref","unstructured":"Chen, S.-J., Chen, S.-M.: Fuzzy Risk Analysis Based on Similarity Measures of General-ized Fuzzy Numbers. IEEE Transactions on Fuzzy Sets and Systems\u00a011(1) (2003)","DOI":"10.1109\/TFUZZ.2002.806316"},{"key":"4_CR10","doi-asserted-by":"crossref","unstructured":"Collins, M.: A New Statistical Parser Based on Bigram Lexical Dependencies. In: Proceedings of the 34th Annual Meeting of the Association for Computational Linguistics, pp. 184\u2013191 (1996)","DOI":"10.3115\/981863.981888"},{"key":"4_CR11","doi-asserted-by":"crossref","unstructured":"Costagliola, G., Ferruci, F., Tortora, G., Vitello, G.: Class Point: An Approach for the Size Estimation of Object Oriented Systems. IEEE Transactions on Software Engineering\u00a031(1) (January 2005)","DOI":"10.1109\/TSE.2005.5"},{"key":"4_CR12","unstructured":"Dra\u017ean, J.: Natural Language Processing of Textual Use Cases. M.Sc. Thesis, Department of Software Engineering, Faculty of Mathematics and Physics, Charles University in Prague (2005)"},{"key":"4_CR13","unstructured":"Fernandez, E.: Metadata and authorization patterns (2000), http:\/\/www.cse.fau.edu\/~ed\/MetadataPatterns.pdf"},{"key":"4_CR14","unstructured":"Friedl, S.: SQL Injection Attacks by Example, http:\/\/www.unixwiz.net\/techtips\/sql-injection.html"},{"key":"4_CR15","doi-asserted-by":"publisher","first-page":"846","DOI":"10.1016\/j.infsof.2008.05.004","volume":"51","author":"G. Georg","year":"2009","unstructured":"Georg, G., Ray, I., Anastasakis, K., Bordbar, B., Toachoodee, M., Humb, S.H.: An Aspect Oriented Methodology for Desigining Secure Applications. Information and Software Technology\u00a051, 846\u2013864 (2009)","journal-title":"Information and Software Technology"},{"issue":"3","key":"4_CR16","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1109\/TDSC.2007.70240","volume":"5","author":"S.T. Halkidis","year":"2008","unstructured":"Halkidis, S.T., Tsantalis, N., Chatzigeorgiou, A., Stephanides, G.: Architectural Risk Analysis of Software Systems Based on Security Patterns. IEEE Transactions on Depend-able and Secure Computing\u00a05(3), 129\u2013142 (2008)","journal-title":"IEEE Transactions on Depend-able and Secure Computing"},{"key":"4_CR17","doi-asserted-by":"crossref","unstructured":"Harmain, H.M., Gaizauskas, R.: CM-Builder: An Automated NL-based CASE Tool. In: Proceedings of the 15th IEEE International Conference on Automated Software Engineering, pp. 45\u201353 (2000)","DOI":"10.1109\/ASE.2000.873649"},{"key":"4_CR18","volume-title":"Exploiting Software, How to Break Code","author":"G. Hoglund","year":"2004","unstructured":"Hoglund, G., McGraw, G.: Exploiting Software, How to Break Code. Addison Wesley, Reading (2004)"},{"key":"4_CR19","volume-title":"Writing Secure Code","author":"M. Howard","year":"2002","unstructured":"Howard, M., LeBlanc, D.: Writing Secure Code. Microsoft Press, Redmond (2002)"},{"key":"4_CR20","unstructured":"Hu, D.: Preventing Cross-Site Scripting Vulnerability. SANS Institute whitepaper (2004)"},{"key":"4_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"392","DOI":"10.1007\/11428817_45","volume-title":"Natural Language Processing and Information Systems","author":"M.G. Ilieva","year":"2005","unstructured":"Ilieva, M.G., Ormanijeva, O.: Automatic Transition of Natural Language Software Requirements Specification into Formal Presentation. In: Montoyo, A., Mu\u0144oz, R., M\u00e9tais, E. (eds.) NLDB 2005. LNCS, vol.\u00a03513, pp. 392\u2013397. Springer, Heidelberg (2005)"},{"key":"4_CR22","volume-title":"Secure Systems Development with UML","author":"J. J\u0171rjens","year":"2005","unstructured":"J\u0171rjens, J.: Secure Systems Development with UML. Springer, Heidelberg (2005)"},{"key":"4_CR23","unstructured":"Kienzle, D., Elder, M.: Security Patterns for Web Application Development. Univ. of Virginia Technical Report (2002)"},{"key":"4_CR24","unstructured":"Klein, A.: Divide and Conquer., HTTP Response Splitting, Web Cache Poisoning Attacks and Related Topics, Sanctum whitepaper (2004)"},{"key":"4_CR25","volume-title":"The Rational Unified Process: An Introduction","author":"P. Kruchten","year":"2000","unstructured":"Kruchten, P.: The Rational Unified Process: An Introduction. Addison Wesley, Reading (2000)"},{"key":"4_CR26","doi-asserted-by":"crossref","unstructured":"van Lamsweerde, A.: Elaborating Security Requirements by Construction of Intentional Anti-Models. In: Proceedings of ICSE 2004, 26th International Conference on Software Engineering, Edinburgh, May 2004, pp. 148\u2013157. ACM-IEEE (2004)","DOI":"10.1109\/ICSE.2004.1317437"},{"key":"4_CR27","first-page":"196","volume-title":"NATO Security through Science Series - D: Information and Communication Security","author":"A. Lamsweerde van","year":"2007","unstructured":"van Lamsweerde, A.: Engineering Requirements for System Reliability and Security, in Software System Reliability and Security. In: Broy, M., Grunbauer, J., Hoare, C.A.R. (eds.) NATO Security through Science Series - D: Information and Communication Security, vol.\u00a09, pp. 196\u2013238. IOS Press, Amsterdam (2007)"},{"key":"4_CR28","volume-title":"Applying UML and Patterns: An Introduction to Object-Oriented Analysis and Design and the Unified Process","author":"C. Larman","year":"2002","unstructured":"Larman, C.: Applying UML and Patterns: An Introduction to Object-Oriented Analysis and Design and the Unified Process. Prentice-Hall, Englewood Cliffs (2002)"},{"key":"4_CR29","unstructured":"Lee Brown, F., Di Vietri, J., Diaz de Villegas, G., Fernandez, E.: The Authenticator Pattern. In: Proceedings of the 6th Conference on Pattern Languages of Programming, PLoP 1999 (1999)"},{"key":"4_CR30","unstructured":"Li, L.: A Semi-Automatic Approach to Translating Use Cases to Sequence Diagrams. In: Proceedings of Technology of Object Oriented Languages and Systems, pp. 184\u2013193 (1999)"},{"key":"4_CR31","series-title":"Lecture Notes in Artificial Intelligence","doi-asserted-by":"crossref","first-page":"295","DOI":"10.1007\/978-3-540-24677-0_31","volume-title":"Innovations in Applied Artificial Intelligence","author":"D. Liu","year":"2004","unstructured":"Liu, D., Subramaniam, K., Eberlein, A., Far, B.H.: Natural Language Requirements Analy-sis and Class Model Generation Using UCDA. In: Orchard, B., Yang, C., Ali, M. (eds.) IEA\/AIE 2004. LNCS (LNAI), vol.\u00a03029, pp. 295\u2013304. Springer, Heidelberg (2004)"},{"key":"4_CR32","unstructured":"Mahmoud, Q.: Security Policy: A Design Pattern for Mobile Java Code. In: Proceedings of the 7th Conference on Pattern Languages of Programming, PLoP 2000 (2000)"},{"key":"4_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"426","DOI":"10.1007\/3-540-45800-X_33","volume-title":"\u00abUML\u00bb 2002 - The Unified Modeling Language. Model Engineering, Concepts, and Tools","author":"T. Lodderstedt","year":"2002","unstructured":"Lodderstedt, T., Basin, D., Doser, J.: SecureUML: A UML-Based Modeling Language for Model Driven Security. In: J\u00e9z\u00e9quel, J.-M., Hussmann, H., Cook, S. (eds.) UML 2002. LNCS, vol.\u00a02460, pp. 426\u2013441. Springer, Heidelberg (2002)"},{"key":"4_CR34","doi-asserted-by":"crossref","unstructured":"Marcus, M., Kim, G., Marciniewicz, M.A., MacIntire, R., Bies, A., Ferguson, M., Katz, K., Schasberger, B.: The Penn Treebank: annotating predicate argument structure. In: Proceedings of the 1994 ARPA Human Language Technology Workshop (1994)","DOI":"10.3115\/1075812.1075835"},{"key":"4_CR35","volume-title":"Knapsack Problems: Algorithms and Computer Implementations","author":"X. Martello","year":"1990","unstructured":"Martello, X., Toth, P.: Knapsack Problems: Algorithms and Computer Implementations. John Wiley and Sons, Chichester (1990)"},{"key":"4_CR36","volume-title":"Software Security, Building Security","author":"G. McGraw","year":"2006","unstructured":"McGraw, G.: Software Security, Building Security. Addison Wesley, Reading (2006)"},{"key":"4_CR37","series-title":"Lecture Notes in Computer Science","volume-title":"Knowledge-Based Intelligent Information and Engineering Systems","author":"H. Mouratidis","year":"2003","unstructured":"Mouratidis, H., Giorgini, P., Manson, G.: An Ontology for Modelling Security: The Tro-pos Approach, in Knowledge-Based Intelligent Information and Engineering Systems. In: Palade, V., Howlett, R.J., Jain, L. (eds.) KES 2003. LNCS, vol.\u00a02773. Springer, Heidelberg (2003)"},{"key":"4_CR38","unstructured":"Mouratidis, H., Giorgini, P., Schumacher, M.: Security Patterns for Agent Systems. In: Proceedings of the Eighth European Conference on Pattern Languages of Programs, EuroPLoP 2003 (2003)"},{"key":"4_CR39","doi-asserted-by":"crossref","unstructured":"Overmyer, S.P., Lavoie, B., Owen, R.: Conceptual Modeling through Linguistic Analysis Using LIDA. In: Proceedings of the 23rd International Conference on Software Engineering, pp. 401\u2013410 (2001)","DOI":"10.1109\/ICSE.2001.919113"},{"key":"4_CR40","volume-title":"Proceedings of the International Conference on Information Technology: Coding and Computing (ITCC 2005)","author":"J.J. Pauli","year":"2005","unstructured":"Pauli, J.J., Xu, D.: Misuse Case Based Design and Analysis of Secure Software Architecture. In: Proceedings of the International Conference on Information Technology: Coding and Computing (ITCC 2005). IEEE, Los Alamitos (2005)"},{"key":"4_CR41","unstructured":"Romanosky, S.: Enterprise Security Patterns. Information Systems Security Association Journal (March 2003)"},{"key":"4_CR42","unstructured":"Rosenberg, D., Stephens, M.: Use Case Driven Modeling with UML: Theory and Practice. Apress (2007)"},{"key":"4_CR43","unstructured":"Sindre, G., Opdahl, A.L.: Capturing Security Requirements with Misuse Cases. In: Proceedings of the 14th annual Norwegian Informatics Conference, Norway (2001)"},{"key":"4_CR44","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/s00766-004-0194-4","volume":"10","author":"G. Sindre","year":"2005","unstructured":"Sindre, G., Opdahl, A.L.: Eliciting Security Requirements with Misuse Cases. Requirements Engineering\u00a010, 34\u201344 (2005)","journal-title":"Requirements Engineering"},{"key":"4_CR45","unstructured":"Sindre, G., Opdahl, A.L.: Templates for Misuse Case Description. In: Proceedings of the 7th International Workshop on Requirements Engineering, Foundations for Software Quality, REFSQ 2001 (2001)"},{"key":"4_CR46","unstructured":"Spett, K.: Cross-Site Scripting, Are your web applications vulnerable? SPI Labs whitepaper"},{"key":"4_CR47","unstructured":"SPI Labs, SQL Injection, Are Your Web Applications Vulnerable? SPI Labs whitepaper"},{"key":"4_CR48","volume-title":"Code Quality: The Open Source Perspective","author":"D. Spinellis","year":"2006","unstructured":"Spinellis, D.: Code Quality: The Open Source Perspective. Addison Wesley, Reading (2006)"},{"key":"4_CR49","volume-title":"Web Services and Identity Management","author":"C. Steel","year":"2006","unstructured":"Steel, C., Nagappan, R., Lai, R.: Core Security Patterns: Best Practices and Strategies for J2EE. In: Web Services and Identity Management. Prentice Hall, Englewood Cliffs (2006)"},{"key":"4_CR50","volume-title":"Building Secure Software, How to Avoid Security Problems the Right Way","author":"J. Viega","year":"2002","unstructured":"Viega, J., McGraw, G.: Building Secure Software, How to Avoid Security Problems the Right Way. Addison Wesley, Reading (2002)"},{"key":"4_CR51","unstructured":"Weiss, M.: Patterns for Web Applications. In: Proceedings of the 10th Conference on Pattern Languages of Programming, PLoP 2003 (2003)"},{"key":"4_CR52","unstructured":"Yoder, J., Barcalow, J.: Architectural Patterns for enabling application security. In: Proceedings of the 4th Conference on Pattern Languages of Programming, PLoP 1997 (1997)"}],"container-title":["Lecture Notes in Computer Science","On the Move to Meaningful Internet Systems: OTM 2009"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-05151-7_4.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,24]],"date-time":"2020-11-24T02:48:33Z","timestamp":1606186113000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-05151-7_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2009]]},"ISBN":["9783642051500","9783642051517"],"references-count":52,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-05151-7_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2009]]}}}