{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,4]],"date-time":"2025-09-04T14:22:02Z","timestamp":1756995722231},"publisher-location":"Berlin, Heidelberg","reference-count":24,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783662452301"},{"type":"electronic","value":"9783662452318"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-662-45231-8_24","type":"book-chapter","created":{"date-parts":[[2014,9,26]],"date-time":"2014-09-26T15:42:39Z","timestamp":1411746159000},"page":"337-352","source":"Crossref","is-referenced-by-count":11,"title":["Risk-Based Vulnerability Testing Using Security Test Patterns"],"prefix":"10.1007","author":[{"given":"Julien","family":"Botella","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bruno","family":"Legeard","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fabien","family":"Peureux","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alexandre","family":"Vernotte","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"24_CR1","unstructured":"Wichers, D.: Owasp top 10 (October 2013), \n                    \n                      https:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_Project\n                    \n                    \n                   (last visited: February 2014)"},{"key":"24_CR2","unstructured":"MITRE: Common weakness enumeration (October 2013), \n                    \n                      http:\/\/cwe.mitre.org\/\n                    \n                    \n                   (last visited: February 2014)"},{"key":"24_CR3","unstructured":"Whitehat: Website security statistics report (October 2013), \n                    \n                      https:\/\/www.whitehatsec.com\/assets\/WPstatsReport_052013.pdf\n                    \n                    \n                   (last visited: February 2014)"},{"key":"24_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1007\/978-3-642-14215-4_7","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"A. Doup\u00e9","year":"2010","unstructured":"Doup\u00e9, A., Cova, M., Vigna, G.: Why Johnny can\u2019t pentest: An analysis of black-box web vulnerability scanners. In: Kreibich, C., Jahnke, M. (eds.) DIMVA 2010. LNCS, vol.\u00a06201, pp. 111\u2013131. Springer, Heidelberg (2010)"},{"key":"24_CR5","unstructured":"Finifter, M., Wagner, D.: Exploring the relationship between web application development tools and security. In: Proc. of the 2nd USENIX Conference on Web Application Development (WebApps 2011), Portland, OR, USA, pp. 99\u2013111. USENIX Association (June 2011)"},{"key":"24_CR6","volume-title":"Practical Model-Based Testing - A tools approach","author":"M. Utting","year":"2006","unstructured":"Utting, M., Legeard, B.: Practical Model-Based Testing - A tools approach. Morgan Kaufmann, San Francisco (2006)"},{"key":"24_CR7","doi-asserted-by":"crossref","unstructured":"Dias-Neto, A., Travassos, G.: A Picture from the Model-Based Testing Area: Concepts, Techniques, and Challenges. Advances in Computers\u00a080, 45\u2013120 (2010), ISSN: 0065-2458","DOI":"10.1016\/S0065-2458(10)80002-6"},{"key":"24_CR8","doi-asserted-by":"crossref","unstructured":"Lebeau, F., Legeard, B., Peureux, F., Vernotte, A.: Model-Based Vulnerability Testing for Web Applications. In: Proc. of the 4th Int. Workshop on Security Testing (SECTEST 2013), Luxembourg, pp. 445\u2013452. IEEE CS Press (March 2013)","DOI":"10.1109\/ICSTW.2013.58"},{"key":"24_CR9","doi-asserted-by":"crossref","unstructured":"Bouquet, F., Grandpierre, C., Legeard, B., Peureux, F.: A test generation solution to automate software testing. In: Proc. of the 3rd Int. Workshop on Automation of Software Test (AST 2008), Leipzig, Germany, pp. 45\u201348. ACM Press (May 2008)","DOI":"10.1145\/1370042.1370052"},{"key":"24_CR10","doi-asserted-by":"crossref","unstructured":"Bouquet, F., Grandpierre, C., Legeard, B., Peureux, F., Vacelet, N., Utting, M.: A subset of precise UML for model-based testing. In: Proc. of the 3rd Int. Workshop on Advances in Model-Based Testing (AMOST 2007), London, UK, pp. 95\u2013104. ACM Press (July 2007)","DOI":"10.1145\/1291535.1291545"},{"key":"24_CR11","doi-asserted-by":"crossref","unstructured":"Botella, J., Bouquet, F., Capuron, J.F., Lebeau, F., Legeard, B., Schadle, F.: Model-Based Testing of Cryptographic Components \u2013 Lessons Learned from Experience. In: Proc. of the 6th Int. Conference on Software Testing, Verification and Validation (ICST 2013), Luxembourg, pp. 192\u2013201. IEEE CS (March 2013)","DOI":"10.1109\/ICST.2013.42"},{"issue":"6","key":"24_CR12","first-page":"113","volume":"32","author":"J. Bach","year":"1999","unstructured":"Bach, J.: Risk and Requirements-Based Testing. Computer\u00a032(6), 113\u2013114 (1999)","journal-title":"Computer"},{"key":"24_CR13","doi-asserted-by":"crossref","unstructured":"Lund, M.S., Solhaug, B., St\u00f8len, K.: Model-Driven Risk Analysis: The CORAS Approach, 1st edn. Springer Publishing Company, Incorporated (2010)","DOI":"10.1007\/978-3-642-12323-8"},{"key":"24_CR14","unstructured":"Vouffo\u00a0Feudjio, A.G.: Initial Security Test Pattern Catalog. Public Deliverable D3.WP4.T1, Diamonds Project, Berlin, Germany (June 2012) \n                    \n                      http:\/\/publica.fraunhofer.de\/documents\/N-212439.html\n                    \n                    \n                   (last visited: February 2014)"},{"key":"24_CR15","doi-asserted-by":"crossref","unstructured":"Bau, J., Bursztein, E., Gupta, D., Mitchell, J.: State of the Art: Automated Black-Box Web Application Vulnerability Testing. In: Proc. of the 31st Int. Symp. on Security and Privacy (SP 2010), Oakland, CA, USA, pp. 332\u2013345. IEEE CS (May 2010)","DOI":"10.1109\/SP.2010.27"},{"key":"24_CR16","unstructured":"Allan, D.: Web application security: automated scanning versus manual penetration testing. IBM White Paper (2008) \n                    \n                      ftp:\/\/ftp.software.ibm.com\/software\/rational\/web\/whitepapers\/r_wp_autoscan.pdf\n                    \n                    \n                   (last visited: February 2014)"},{"key":"24_CR17","unstructured":"SecToolMarket: Price and Feature Comparison of Web Application Scanners (February 2014), \n                    \n                      http:\/\/www.sectoolmarket.com\/\n                    \n                    \n                   (last visited: February 2014)"},{"key":"24_CR18","doi-asserted-by":"crossref","unstructured":"Schieferdecker, I., Grossmann, J., Schneider, M.: Model-based security testing. In: Proc. of the 7th Int. Workshop on Model-Based Testing (MBT 2012), Tallinn, Estonia. EPTCS, vol.\u00a080, pp. 1\u201312. Open Publishing Association (March 2012)","DOI":"10.4204\/EPTCS.80.1"},{"key":"24_CR19","doi-asserted-by":"crossref","unstructured":"Dadeau, F., H\u00e9am, P.-C.: Kheddam, R.: Mutation-Based Test Generation from Security Protocols in HLPSL. In: Proc. of the 4th Int. Conf. on Software Testing, Verification and Validation, Berlin, Germany, pp. 240\u2013248. IEEE CS (March 2011)","DOI":"10.1109\/ICST.2011.42"},{"issue":"1","key":"24_CR20","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1016\/j.entcs.2008.11.008","volume":"220","author":"J. J\u00fcrjens","year":"2008","unstructured":"J\u00fcrjens, J.: Model-based Security Testing Using UMLsec: A Case Study. The Journal of Electronic Notes in Theoretical Computer Science (ENTCS)\u00a0220(1), 93\u2013104 (2008)","journal-title":"The Journal of Electronic Notes in Theoretical Computer Science (ENTCS)"},{"key":"24_CR21","doi-asserted-by":"crossref","unstructured":"Buchler, M., Oudinet, J., Pretschner, A.: Semi-Automatic Security Testing of Web Applications from a Secure Model. In: Proc. of the 6th Int. Conference on Software Security and Reliability (SERE 2012), Gaithersburg, MD, USA, pp. 253\u2013262. IEEE CS (June 2012)","DOI":"10.1109\/SERE.2012.38"},{"key":"24_CR22","volume-title":"Fuzzing for Software Security Testing and Quality Assurance","author":"A. Takanen","year":"2008","unstructured":"Takanen, A., De Mott, J., Miller, C.: Fuzzing for Software Security Testing and Quality Assurance. Artech House, Inc., Norwood (2008)"},{"key":"24_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"88","DOI":"10.1007\/978-3-642-36757-1_6","volume-title":"System Analysis and Modeling: Theory and Practice","author":"M. Schneider","year":"2013","unstructured":"Schneider, M., Gro\u00dfmann, J., Tcholtchev, N., Schieferdecker, I., Pietschker, A.: Behavioral Fuzzing Operators for UML Sequence Diagrams. In: Haugen, \u00d8., Reed, R., Gotzhein, R. (eds.) SAM 2012. LNCS, vol.\u00a07744, pp. 88\u2013104. Springer, Heidelberg (2013)"},{"key":"24_CR24","doi-asserted-by":"crossref","unstructured":"Wang, L., Wong, E., Xu, D.: A threat model driven approach for security testing. In: Proc. of the 3rd Int. Workshop on Software Engineering for Secure Systems (SESS 2007), Minneapolis, MN, USA. IEEE CS (May 2007)","DOI":"10.1109\/SESS.2007.2"}],"container-title":["Lecture Notes in Computer Science","Leveraging Applications of Formal Methods, Verification and Validation. Specialized Techniques and Applications"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-662-45231-8_24","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,5,28]],"date-time":"2019-05-28T00:44:49Z","timestamp":1559004289000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-662-45231-8_24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783662452301","9783662452318"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-3-662-45231-8_24","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2014]]}}}