{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T14:47:16Z","timestamp":1776782836120,"version":"3.51.2"},"publisher-location":"Berlin, Heidelberg","reference-count":39,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"value":"9783642141911","type":"print"},{"value":"9783642141928","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-3-642-14192-8_24","type":"book-chapter","created":{"date-parts":[[2010,6,15]],"date-time":"2010-06-15T13:34:08Z","timestamp":1276608848000},"page":"262-275","source":"Crossref","is-referenced-by-count":18,"title":["Visualizing Cyber Attacks with Misuse Case Maps"],"prefix":"10.1007","author":[{"given":"Peter","family":"Karpati","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guttorm","family":"Sindre","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andreas L.","family":"Opdahl","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"24_CR1","unstructured":"Barnum, S., Sethi, A.: Attack Patterns as a Knowledge Resource for Building Secure Software. In: OMG Software Assurance Workshop (2007)"},{"key":"24_CR2","volume-title":"The shellcoder\u2019s handbook: discovering and exploiting security holes","author":"J. Koziol","year":"2004","unstructured":"Koziol, J., et al.: The shellcoder\u2019s handbook: discovering and exploiting security holes. John Wiley & Sons, Chichester (2004)"},{"key":"24_CR3","volume-title":"Exploiting Software: How to Break Code","author":"G. Hoglund","year":"2004","unstructured":"Hoglund, G., McGraw, G.: Exploiting Software: How to Break Code. Addison-Wesley, Boston (2004)"},{"key":"24_CR4","unstructured":"Amyot, D.: Use Case Maps Quick Tutorial (1999), http:\/\/www.usecasemaps.org\/pub\/UCMtutorial\/UCMtutorial.pdf"},{"key":"24_CR5","volume-title":"Use case maps for object-oriented systems","author":"R. Buhr","year":"1995","unstructured":"Buhr, R., Casselman, R.: Use case maps for object-oriented systems. Prentice-Hall, Inc., Upper Saddle River (1995)"},{"key":"24_CR6","volume-title":"The art of intrusion: the real stories behind the exploits of hackers, intruders & deceivers","author":"K.D. Mitnick","year":"2005","unstructured":"Mitnick, K.D., Simon, W.L.: The art of intrusion: the real stories behind the exploits of hackers, intruders & deceivers. Wiley, Chichester (2005)"},{"key":"24_CR7","volume-title":"Secrets & lies: digital security in a networked world","author":"B. Schneier","year":"2000","unstructured":"Schneier, B.: Secrets & lies: digital security in a networked world. John Wiley & Sons, Chichester (2000)"},{"key":"24_CR8","volume-title":"Fundamentals of computer security technology","author":"E.G. Amoroso","year":"1994","unstructured":"Amoroso, E.G.: Fundamentals of computer security technology. Prentice-Hall, Inc., Upper Saddle River (1994)"},{"key":"24_CR9","doi-asserted-by":"crossref","unstructured":"Liu, L., Yu, E., Mylopoulos, J.: Security and privacy requirements analysis within a social setting. In: Proc. RE 2003, vol.\u00a03, pp. 151\u2013161 (2003)","DOI":"10.1109\/ICRE.2003.1232746"},{"key":"24_CR10","unstructured":"Lin, L., et al.: Using abuse frames to bound the scope of security problems (2004)"},{"key":"24_CR11","unstructured":"McDermott, J., Fox, C.: Using abuse case models for security requirements analysis (1999)"},{"issue":"1","key":"24_CR12","doi-asserted-by":"publisher","first-page":"34","DOI":"10.1007\/s00766-004-0194-4","volume":"10","author":"G. Sindre","year":"2005","unstructured":"Sindre, G., Opdahl, A.L.: Eliciting security requirements with misuse cases. Requirements Engineering\u00a010(1), 34\u201344 (2005)","journal-title":"Requirements Engineering"},{"key":"24_CR13","doi-asserted-by":"crossref","unstructured":"Firesmith, D.J.: Security use cases. Technology\u00a02(3) (2003)","DOI":"10.5381\/jot.2003.2.3.c6"},{"key":"24_CR14","doi-asserted-by":"crossref","unstructured":"Giorgini, P., et al.: Modeling security requirements through ownership, permission and delegation. In: Proc. of RE, vol.\u00a05, pp. 167\u2013176 (2005)","DOI":"10.1109\/RE.2005.43"},{"key":"24_CR15","unstructured":"Van Lamsweerde, A., et al.: From system goals to intruder anti-goals: attack generation and resolution for security requirements engineering. In: Requirements Engineering for High Assurance Systems (RHAS 2003), vol.\u00a02003, p. 49 (2003)"},{"key":"24_CR16","first-page":"159","volume-title":"Proc. 2nd Conference on E-Commerce, E-Business, E-Government (I3E 2002)","author":"T. Dimitrakos","year":"2002","unstructured":"Dimitrakos, T., et al.: Integrating model-based security risk management into eBusiness systems development: The CORAS approach. In: Monteiro, J.L., Swatman, P.M.C., Tavares, L.V. (eds.) Proc. 2nd Conference on E-Commerce, E-Business, E-Government (I3E 2002), pp. 159\u2013175. Kluwer, Lisbon (2002)"},{"key":"24_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"412","DOI":"10.1007\/3-540-45800-X_32","volume-title":"\u00abUML\u00bb 2002 - The Unified Modeling Language. Model Engineering, Concepts, and Tools","author":"J. Jurjens","year":"2002","unstructured":"Jurjens, J.: UMLsec: Extending UML for secure systems development. In: J\u00e9z\u00e9quel, J.-M., Hussmann, H., Cook, S. (eds.) UML 2002. LNCS, vol.\u00a02460, pp. 412\u2013425. Springer, Heidelberg (2002)"},{"key":"24_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"426","DOI":"10.1007\/3-540-45800-X_33","volume-title":"\u00abUML\u00bb 2002 - The Unified Modeling Language. Model Engineering, Concepts, and Tools","author":"T. Lodderstedt","year":"2002","unstructured":"Lodderstedt, T., et al.: SecureUML: A UML-based modeling language for model-driven security. In: J\u00e9z\u00e9quel, J.-M., Hussmann, H., Cook, S., et al. (eds.) UML 2002. LNCS, vol.\u00a02460, pp. 426\u2013441. Springer, Heidelberg (2002)"},{"key":"24_CR19","doi-asserted-by":"crossref","unstructured":"Rodriguez, A., Fernandez-Medina, E., Piattini, M.: Towards an integration of security requirements into business process modeling. In: Proc. of WOSIS, vol.\u00a05, pp. 287\u2013297 (2005)","DOI":"10.5220\/0002579402870297"},{"key":"24_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1007\/11908883_6","volume-title":"Advances in Conceptual Modeling - Theory and Practice","author":"A. Rodriguez","year":"2006","unstructured":"Rodriguez, A., Fernandez-Medina, E., Piattini, M.: Capturing Security Requirements in Business Processes Through a UML 2.0 Activity Diagrams Profile. In: Roddick, J., Benjamins, V.R., Si-said Cherfi, S., Chiang, R., Claramunt, C., Elmasri, R.A., Grandi, F., Han, H., Hepp, M., Lytras, M.D., Mi\u0161i\u0107, V.B., Poels, G., Song, I.-Y., Trujillo, J., Vangenot, C. (eds.) ER Workshops 2006. LNCS, vol.\u00a04231, pp. 32\u201342. Springer, Heidelberg (2006)"},{"key":"24_CR21","volume-title":"Security Patterns: Integrating Security and Systems Engineering","author":"M. Schumacher","year":"2005","unstructured":"Schumacher, M., et al.: Security Patterns: Integrating Security and Systems Engineering. Wiley, Chichester (2005)"},{"issue":"2","key":"24_CR22","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1109\/32.345822","volume":"21","author":"A. Boswell","year":"1995","unstructured":"Boswell, A.: Specification and validation of a security policy model. IEEE Transactions on Software Engineering\u00a021(2), 63\u201368 (1995)","journal-title":"IEEE Transactions on Software Engineering"},{"key":"24_CR23","doi-asserted-by":"crossref","unstructured":"Hall, A., Chapman, R.: Correctness by construction: Developing a commercial secure system. IEEE Software, 18\u201325 (2002)","DOI":"10.1109\/52.976937"},{"key":"24_CR24","doi-asserted-by":"crossref","unstructured":"Buhr, R.J.A.: Use case maps for attributing behaviour to system architecture. In: 4th International Workshop of Parallel and Distributed Real-Time Systems (1996)","DOI":"10.1109\/WPDRTS.1996.557425"},{"issue":"12","key":"24_CR25","doi-asserted-by":"publisher","first-page":"1131","DOI":"10.1109\/32.738343","volume":"24","author":"R.J.A. Buhr","year":"1998","unstructured":"Buhr, R.J.A.: Use case maps as architectural entities for complex systems. IEEE Transactions on Software Engineering\u00a024(12), 1131\u20131155 (1998)","journal-title":"IEEE Transactions on Software Engineering"},{"key":"24_CR26","doi-asserted-by":"crossref","unstructured":"Woodside, M., Petriu, D., Siddiqui, K.: Performance-related completions for software specifications. In: 24th International Conference on Software Engineering (2002)","DOI":"10.1145\/581344.581346"},{"key":"24_CR27","doi-asserted-by":"crossref","unstructured":"Liu, X., Peyton, L., Kuziemsky, C.: A Requirement Engineering Framework for Electronic Data Sharing of Health Care Data Between Organizations. In: MCETECH (2009)","DOI":"10.1007\/978-3-642-01187-0_24"},{"key":"24_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1007\/978-3-540-75162-5_5","volume-title":"Transactions on Aspect-Oriented Software Development III","author":"G. Mussbacher","year":"2007","unstructured":"Mussbacher, G., Amyot, D., Weiss, M.: Visualizing Early Aspects with Use Case Maps. In: Rashid, A., Aksit, M. (eds.) Transactions on AOSD III. LNCS, vol.\u00a04620, pp. 105\u2013143. Springer, Heidelberg (2007)"},{"key":"24_CR29","unstructured":"Wu, W., Kelly, T.P.: Deriving safety requirements as part of system architecture definition. In: Proceedings of the 24th International System Safety Conference, Albuquerque (2006)"},{"key":"24_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1007\/11921998_9","volume-title":"Quality of Software Architectures","author":"W. Wu","year":"2006","unstructured":"Wu, W., Kelly, T.: Managing Architectural Design Decisions for Safety-Critical Software Systems. In: Hofmeister, C., Crnkovi\u0107, I., Reussner, R. (eds.) QoSA 2006. LNCS, vol.\u00a04214, pp. 59\u201377. Springer, Heidelberg (2006)"},{"issue":"1","key":"24_CR31","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1109\/MS.2003.1159030","volume":"20","author":"I. Alexander","year":"2003","unstructured":"Alexander, I.: Misuse cases: Use cases with hostile intent. IEEE Software\u00a020(1), 58\u201366 (2003)","journal-title":"IEEE Software"},{"key":"24_CR32","doi-asserted-by":"crossref","unstructured":"Sindre, G.: A look at misuse cases for safety concerns. International Federation for Information Processing Publications - IFIP, vol.\u00a0244, p. 252 (2007)","DOI":"10.1007\/978-0-387-73947-2_20"},{"key":"24_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"423","DOI":"10.1007\/978-3-540-75563-0_29","volume-title":"Conceptual Modeling - ER 2007","author":"T. St\u00e5lhane","year":"2007","unstructured":"St\u00e5lhane, T., Sindre, G.: A comparison of two approaches to safety analysis based on use cases. In: Parent, C., Schewe, K.-D., Storey, V.C., Thalheim, B. (eds.) ER 2007. LNCS, vol.\u00a04801, pp. 423\u2013437. Springer, Heidelberg (2007)"},{"key":"24_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"721","DOI":"10.1007\/978-3-540-87875-9_50","volume-title":"Model Driven Engineering Languages and Systems","author":"T. St\u00e5lhane","year":"2008","unstructured":"St\u00e5lhane, T., Sindre, G.: Safety Hazard Identification by Misuse Cases: Experimental Comparison of Text and Diagrams. In: Czarnecki, K., Ober, I., Bruel, J.-M., Uhl, A., V\u00f6lter, M. (eds.) MODELS 2008. LNCS, vol.\u00a05301, pp. 721\u2013735. Springer, Heidelberg (2008)"},{"issue":"2","key":"24_CR35","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1080\/2333696X.2008.10855837","volume":"4","author":"G. Sindre","year":"2008","unstructured":"Sindre, G., Opdahl, A.L.: Misuse Cases for Identifying System Dependability Threats. Journal of Information Privacy and Security\u00a04(2), 3\u201322 (2008)","journal-title":"Journal of Information Privacy and Security"},{"key":"24_CR36","unstructured":"Diallo, M.H., et al.: A comparative evaluation of three approaches to specifying security requirements. In: Proc. REFSQ 2006, Luxembourg (2006)"},{"issue":"5","key":"24_CR37","doi-asserted-by":"publisher","first-page":"916","DOI":"10.1016\/j.infsof.2008.05.013","volume":"51","author":"A.L. Opdahl","year":"2009","unstructured":"Opdahl, A.L., Sindre, G.: Experimental comparison of attack trees and misuse cases for security threat identification. Information and Software Technology\u00a051(5), 916\u2013932 (2009)","journal-title":"Information and Software Technology"},{"issue":"3","key":"24_CR38","doi-asserted-by":"publisher","first-page":"319","DOI":"10.2307\/249008","volume":"13","author":"F.D. Davis","year":"1989","unstructured":"Davis, F.D.: Perceived usefulness, perceived ease of use, and user acceptance of information technology. MIS quarterly\u00a013(3), 319\u2013340 (1989)","journal-title":"MIS quarterly"},{"key":"24_CR39","doi-asserted-by":"crossref","unstructured":"Lindqvist, U., Cheung, S., Valdez, R.: Correlated Attack Modeling, CAM (2003)","DOI":"10.21236\/ADA419251"}],"container-title":["Lecture Notes in Computer Science","Requirements Engineering: Foundation for Software Quality"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-14192-8_24.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T23:59:22Z","timestamp":1740182362000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-14192-8_24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9783642141911","9783642141928"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-14192-8_24","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2010]]}}}