{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,27]],"date-time":"2025-02-27T05:05:03Z","timestamp":1740632703164,"version":"3.38.0"},"publisher-location":"Berlin, Heidelberg","reference-count":27,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642162473"},{"type":"electronic","value":"9783642162480"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-3-642-16248-0_46","type":"book-chapter","created":{"date-parts":[[2010,10,1]],"date-time":"2010-10-01T02:21:24Z","timestamp":1285899684000},"page":"310-321","source":"Crossref","is-referenced-by-count":8,"title":["Review of Software Security Defects Taxonomy"],"prefix":"10.1007","author":[{"given":"Zhanwei","family":"Hui","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Song","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhengping","family":"Ren","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yi","family":"Yao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"issue":"2","key":"46_CR1","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1109\/MSECP.2004.1281254","volume":"2","author":"G. McGraw","year":"2004","unstructured":"McGraw, G.: Software Security. IEEE Security & Privacy\u00a02(2), 80\u201383 (2004)","journal-title":"IEEE Security & Privacy"},{"issue":"5","key":"46_CR2","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1109\/MSP.2004.84","volume":"2","author":"B. Potter","year":"2004","unstructured":"Potter, B., McGraw, G.: Software security testing. Security and Privacy Magazine IEEE\u00a02(5), 81\u201385 (2004)","journal-title":"Security and Privacy Magazine IEEE"},{"key":"46_CR3","unstructured":"Leveson, N., Turner, C.S.: An investigation of the Therac-25 accidents. UCI TR 92-108. Inf. and Comp. Sci. Dept., Univ. of Cal.-Irvine, Irvine, CA (1992)"},{"key":"46_CR4","doi-asserted-by":"publisher","first-page":"678","DOI":"10.1145\/63526.63527","volume":"32","author":"E.H. Spafford","year":"1989","unstructured":"Spafford, E.H.: Crisis and aftermath. Comm. ACM\u00a032, 678\u2013687 (1989)","journal-title":"Comm. ACM"},{"key":"46_CR5","unstructured":"Brehmer, C.L., Carl, J.R.: Incorporating IEEE Standard 1044 into your anomaly tracking process. CrossTalk. J. Defense Software Engineering\u00a06, 9\u201316 (1993); Chillarege, R."},{"issue":"11","key":"46_CR6","doi-asserted-by":"publisher","first-page":"943","DOI":"10.1109\/32.177364","volume":"18","author":"I.S. Bhandari","year":"1992","unstructured":"Bhandari, I.S., Chaar, J.K., Halliday, M.J., Moebus, D.S., Ray, B.K., Wong, M.-Y.: Orthogonal defect classification\u2014a concept for in-process measurements. IEEE Trans. on Software Engineering\u00a018(11), 943\u2013956 (1992)","journal-title":"IEEE Trans. on Software Engineering"},{"key":"46_CR7","unstructured":"IEEE Computer Society 1990. Standard glossary of software engineering terminology. ANSI\/IEEE Standard 610.12-1990. IEEE Press, New York (1990)"},{"key":"46_CR8","unstructured":"Landwehr, C.E.: Dependability: Basic Concepts and Terminology. Dependable Computing and Fault-Tolerant Systems, vol.\u00a06. Springer, New York (1992)"},{"key":"46_CR9","doi-asserted-by":"crossref","unstructured":"Davis, N., Humphrey, W., Zibulski, G., Mcgraw, G.: Processes for producing secure software. IEEE Security& Privacy (2004)","DOI":"10.1109\/MSP.2004.21"},{"key":"46_CR10","unstructured":"http:\/\/cwe.mitre.org\/"},{"issue":"3","key":"46_CR11","doi-asserted-by":"publisher","first-page":"247","DOI":"10.1145\/356850.356852","volume":"13","author":"C.E. Landwehr","year":"1981","unstructured":"Landwehr, C.E.: Formal models for computer security. ACM Computing Surveys\u00a013(3), 247\u2013278 (1981)","journal-title":"ACM Computing Surveys"},{"key":"46_CR12","doi-asserted-by":"crossref","unstructured":"Linde, R.R.: Operating system penetration. In: AFIPS National Computer Conference, pp. 361\u2013368 (1975)","DOI":"10.1145\/1499949.1500018"},{"key":"46_CR13","doi-asserted-by":"crossref","unstructured":"Bishop, M., Bailey, D.: A critical analysis of vulnerability taxonomies. Technical Report CSE-96-11, Department of Computer Science at the University of California at Davis (September 1996)","DOI":"10.21236\/ADA453251"},{"key":"46_CR14","unstructured":"Anderson, J.P.: Computer security technology planning study. Technical Report ESD\u2013TR\u201373\u201351, Vols. I, II, James P. Anderson and Co., Fort Washington, PA, USA, HQ Electronic Systems Division, Hanscom AFB, MA, USA (October 1972)"},{"key":"46_CR15","doi-asserted-by":"crossref","unstructured":"Lindquist, U., Jonsson, E.: How to systematically classify computer security intrusions. In: Proceedings of the IEEE Symposium on Security and Privacy, pp. 154\u2013163 (1997)","DOI":"10.1109\/SECPRI.1997.601330"},{"key":"46_CR16","unstructured":"Howard, J.D.: An Analysis of Security Incidents on the Internet 1989 - 1995. PhD thesis, Carnegie Mellon University (April 1997)"},{"key":"46_CR17","unstructured":"Wysopal, C., Nelson, L., Zovi, D.D., Dustin, E.: The Art of Software Security Testing. Symatec press"},{"key":"46_CR18","unstructured":"Aslam, T., Krsul, I., Spafford, E.H.: Use of a taxonomy of security faults. In: Proc. 19th NIST-NCSC National Information Systems Security Conference, pp. 551\u2013560 (1996)"},{"key":"46_CR19","doi-asserted-by":"crossref","unstructured":"Abbott, R.P., Chin, J.S., Donnelley, J.E., Konigsford, W.L., Tukubo, S., Webb, D.A.: Security analysis and enhancements of computer operating systems. NBSIR 76-1041, The RISOS Project, Lawrence Livermore Laboratory, Livermore, CA, USA (April 1976)","DOI":"10.6028\/NBS.IR.76-1041"},{"key":"46_CR20","unstructured":"Bisbey, R., Hollingworth, D.: Protection analysis: Final report. Technical Report ISI\/SR-78-13, Information Sciences Institute, University of Southern California, Marina del Rey, CA (May 1978)"},{"key":"46_CR21","unstructured":"Aslam, T.: A taxonomy of security faults in the UNIX operating system. Master\u2019s thesis, Purdue University (August 1995)"},{"key":"46_CR22","unstructured":"Bisbey, R.:Private communication (July 26, 1990)"},{"key":"46_CR23","doi-asserted-by":"crossref","unstructured":"Weber, S., Karger, P.A., Paradkar, A.: A Software Flaw Taxonomy: Aiming Tools At Security. In: Software Engineering for Secure Systems \u2013 Building Trustworthy Applications (SESS 2005), St. Louis, Missouri, USA (2005)","DOI":"10.1145\/1083200.1083209"},{"issue":"3","key":"46_CR24","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1145\/185403.185412","volume":"26","author":"C.E. Landwehr","year":"1994","unstructured":"Landwehr, C.E., Bull, A.R., McDermott, J.P., Choi, W.S.: A taxonomy of computer program security flaws. ACM Computer Surveys\u00a026(3), 211\u2013254 (1994)","journal-title":"ACM Computer Surveys"},{"key":"46_CR25","doi-asserted-by":"crossref","unstructured":"Ashcraft, K., Engler, D.: Using programmer-written compiler extensions to catch security holes. In: IEEE Symposium on Security and Privacy, Oakland, California (May 2002)","DOI":"10.1109\/SECPRI.2002.1004368"},{"key":"46_CR26","doi-asserted-by":"crossref","unstructured":"Weber, S., Karger, P.A., Paradkar, A.: A Software Flaw Taxonomy: Aiming Tools At Security. In: Software Engineering for Secure Systems \u2013 Building Trustworthy Applications (SESS 2005), St. Louis, Missouri, USA (2005)","DOI":"10.1145\/1083200.1083209"},{"key":"46_CR27","unstructured":"Hui, Z.: Research on the techniques of software security testing based on software security defects. Master thesis. PLA University of Science and Technology (2009)"}],"container-title":["Lecture Notes in Computer Science","Rough Set and Knowledge Technology"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-16248-0_46.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,26]],"date-time":"2025-02-26T04:30:27Z","timestamp":1740544227000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-16248-0_46"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9783642162473","9783642162480"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-16248-0_46","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2010]]}}}