{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,7]],"date-time":"2024-09-07T09:13:55Z","timestamp":1725700435840},"publisher-location":"Berlin, Heidelberg","reference-count":23,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642324970"},{"type":"electronic","value":"9783642324987"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012]]},"DOI":"10.1007\/978-3-642-32498-7_7","type":"book-chapter","created":{"date-parts":[[2012,8,14]],"date-time":"2012-08-14T14:04:28Z","timestamp":1344953068000},"page":"85-92","source":"Crossref","is-referenced-by-count":12,"title":["Hunting for Aardvarks: Can Software Security Be Measured?"],"prefix":"10.1007","author":[{"given":"Martin Gilje","family":"Jaatun","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"unstructured":"CVE: Common Vulnerabilities and Exposures (CVE), http:\/\/cve.mitre.org\/","key":"7_CR1"},{"unstructured":"NVD: National Vulnerability Database Home, http:\/\/nvd.nist.gov","key":"7_CR2"},{"unstructured":"Clemens, S.L.: Notes on \u2019innocents abroad\u2019: Paragraph 20 (2010) (There are three kinds of lies: lies, damned lies, and statistics - Attributed to Disraeli), http:\/\/marktwainproject.org","key":"7_CR3"},{"unstructured":"Brooks, F.P.: The Mythical Man-Month. Addison-Wesley (1995)","key":"7_CR4"},{"key":"7_CR5","volume-title":"Proceedings of the 15th Conference on USENIX Security Symposium, USENIX-SS 2006","author":"A. Ozment","year":"2006","unstructured":"Ozment, A., Schechter, S.E.: Milk or wine: does software security improve with age? In: Proceedings of the 15th Conference on USENIX Security Symposium, USENIX-SS 2006, vol.\u00a015. USENIX Association, Berkeley (2006)"},{"unstructured":"Geer, D.: MetriCon 1.0 Digest (2006), http:\/\/www.securitymetrics.org\/content\/Wiki.jsp?page=Metricon1.0","key":"7_CR6"},{"unstructured":"Geer, D.: MetriCon 2.0 Digest (2007), http:\/\/www.securitymetrics.org\/content\/Wiki.jsp?page=Metricon2.0","key":"7_CR7"},{"unstructured":"Geer, D.: MetriCon 4.0 Digest (2009), http:\/\/www.securitymetrics.org\/content\/Wiki.jsp?page=Metricon4.0","key":"7_CR8"},{"unstructured":"Conway, D.: MetriCon 3.0 Digest (2008), http:\/\/www.securitymetrics.org\/content\/Wiki.jsp?page=Metricon3.0","key":"7_CR9"},{"unstructured":"ISO\/IEC 15408-1: Evaluation criteria for it security part 1: Introduction and general model (2005)","key":"7_CR10"},{"unstructured":"Eberlein, A., do Prado Leite, J.C.S.: Agile requirements definition: A view from requirements engineering. In: Proceedings of the International Workshop on Time-Constrained Requirements Engineering (TCRE 2002) (2002)","key":"7_CR11"},{"unstructured":"Beznosov, K.: eXtreme Security Engineering: On Employing XP Practices to Achieve \u201dGood Enough Security\u201d without Defining It. In: Proceedings of the First ACM Workshop on Business Driven Security Engineering, BizSec (2003)","key":"7_CR12"},{"key":"7_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1007\/978-3-540-27777-4_12","volume-title":"Extreme Programming and Agile Methods - XP\/Agile Universe 2004","author":"J. W\u00e4yrynen","year":"2004","unstructured":"W\u00e4yrynen, J., Bod\u00e9n, M., Bostr\u00f6m, G.: Security Engineering and eXtreme Programming: An Impossible Marriage? In: Zannier, C., Erdogmus, H., Lindstrom, L. (eds.) XP\/Agile Universe 2004. LNCS, vol.\u00a03134, pp. 117\u2013128. Springer, Heidelberg (2004)"},{"unstructured":"Beznosov, K., Kruchten, P.: Towards agile security assurance. In: Proceedings of New Security Paradigms Workshop, Nova Scotia, Canada (2004)","key":"7_CR14"},{"unstructured":"Siponen, M., Baskerville, R., Kuivalainen, T.: Integrating security into agile development methods. In: Proceedings of Hawaii International Conference on System Sciences (2005)","key":"7_CR15"},{"key":"7_CR16","first-page":"12","volume":"15","author":"M. Poppendieck","year":"2002","unstructured":"Poppendieck, M., Morsicato, R.: XP in a Safety-Critical Environment. Cutter IT Journal\u00a015, 12\u201316 (2002)","journal-title":"Cutter IT Journal"},{"key":"7_CR17","doi-asserted-by":"publisher","first-page":"805","DOI":"10.1145\/1176617.1176727","volume-title":"Companion to the 21st ACM SIGPLAN Symposium on Object-Oriented Programming Systems, Languages, and Applications, OOPSLA 2006","author":"V. Kongsli","year":"2006","unstructured":"Kongsli, V.: Towards agile security in web applications. In: Companion to the 21st ACM SIGPLAN Symposium on Object-Oriented Programming Systems, Languages, and Applications, OOPSLA 2006, pp. 805\u2013808. ACM, New York (2006)"},{"unstructured":"McGraw, G., Steven, J.: Software [In]security: Comparing Apples, Oranges, and Aardvarks (or, All Static Analysis Tools Are Not Created Equal) (2011)","key":"7_CR18"},{"doi-asserted-by":"crossref","unstructured":"Jensen, J.: A Novel Testbed for Detection of Malicious Software Functionality. In: Proceedings of Third International Conference on Availability, Security, and Reliability (ARES 2008), pp. 292\u2013301 (2008)","key":"7_CR19","DOI":"10.1109\/ARES.2008.113"},{"issue":"12","key":"7_CR20","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1145\/96267.96279","volume":"33","author":"Barton P. Miller","year":"1990","unstructured":"Miller, B., Fredriksen, L., So, B.: An empirical study of the reliability of unix utilities. Communications of the ACM\u00a033(12) (1990)","journal-title":"Communications of the ACM"},{"unstructured":"McGraw, G., Chess, B., Migues, S.: Building Security In Maturity Model (BSIMM 3) (2011)","key":"7_CR21"},{"unstructured":"Doyle, A.C.: Memoirs of Sherlock Holmes, http:\/\/www.gutenberg.org\/files\/834\/834-h\/834-h.htm","key":"7_CR22"},{"doi-asserted-by":"crossref","unstructured":"McGraw, G.: Software Security: Building Security. Addison-Wesley (2006)","key":"7_CR23","DOI":"10.1109\/ISSRE.2006.43"}],"container-title":["Lecture Notes in Computer Science","Multidisciplinary Research and Practice for Information Systems"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-32498-7_7.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,24]],"date-time":"2020-11-24T03:09:58Z","timestamp":1606187398000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-32498-7_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012]]},"ISBN":["9783642324970","9783642324987"],"references-count":23,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-32498-7_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2012]]}}}