{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T00:45:42Z","timestamp":1780533942588,"version":"3.54.1"},"reference-count":50,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2011,11,9]],"date-time":"2011-11-09T00:00:00Z","timestamp":1320796800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Softw Syst Model"],"published-print":{"date-parts":[[2013,5]]},"DOI":"10.1007\/s10270-011-0218-8","type":"journal-article","created":{"date-parts":[[2011,11,8]],"date-time":"2011-11-08T08:27:19Z","timestamp":1320740839000},"page":"331-348","source":"Crossref","is-referenced-by-count":7,"title":["Least privilege analysis in software architectures"],"prefix":"10.1007","volume":"12","author":[{"given":"Koen","family":"Buyens","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Riccardo","family":"Scandariato","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wouter","family":"Joosen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2011,11,9]]},"reference":[{"key":"218_CR1","unstructured":"Alexandrov, A.D., Ibel, M., Schauser, K.E., Scheiman, C.J.: Extending the operating system at the user level: the Ufo global file system. In: 1997 Annual Technical Conference on UNIX and Advanced Computing Systems (USENIX\u201997) (1997)"},{"key":"218_CR2","unstructured":"Alexandrov, A., Kmiec, P., Schauser, K.: Consh: a confined execution environment for internet computations. In: USENIX Annual Technical Conference (1999)"},{"key":"218_CR3","unstructured":"Acharya, A., Raje, M.: Mapbox: using parameterized behavior classes to confine applications. Technical report, Santa Barbara, CA, USA (1999)"},{"key":"218_CR4","doi-asserted-by":"crossref","unstructured":"Barkley, J.: Comparing simple role based access control models and access control lists. In: ACM Workshop on Role Based Access Control (RBAC) (1997)","DOI":"10.1145\/266741.266769"},{"key":"218_CR5","doi-asserted-by":"crossref","unstructured":"Basin, D., Burri, S.J., Karjoth, G.: Dynamic enforcement of abstract separation of duty constraints. In: European Conference on Research in Computer Security (ESORICS) (2009)","DOI":"10.1007\/978-3-642-04444-1_16"},{"key":"218_CR6","unstructured":"Berman, A., Bourassa, V., Selberg, E.: TRON: process-specific file protection for the UNIX operating system. In: Proceedings of the USENIX 1995 Technical Conference Proceedings on USENIX 1995 Technical Conference Proceedings, p. 14. USENIX Association (1995)"},{"key":"218_CR7","doi-asserted-by":"crossref","unstructured":"Buyens, K., De Win, B., Joosen, W.: Resolving least privilege violations in software architectures. In: Workshop on Software Engineering for Secure Systems (SESS) (2009)","DOI":"10.1109\/IWSESS.2009.5068453"},{"key":"218_CR8","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J.: Some thoughts on security after ten years of qmail 1.0. In: CSAW \u201907, pp. 1\u201310. ACM, New York (2007)","DOI":"10.1145\/1314466.1314467"},{"key":"218_CR9","unstructured":"Brumley, D., Song, D.: Privtrans: automatically partitioning programs for privilege separation. In: USENIX (2004)"},{"key":"218_CR10","doi-asserted-by":"crossref","unstructured":"Buyens, K., Scandariato, R., Joosen, W.: Process activities supporting security principles. In: International Workshop on Security in Software Engineering (IWSSE) (2007)","DOI":"10.1109\/COMPSAC.2007.170"},{"key":"218_CR11","unstructured":"Buyens, K.: Security principle tool. http:\/\/people.cs.kuleuven.be\/~koen.buyens\/securityprinciples\/ (2011)"},{"issue":"2","key":"218_CR12","doi-asserted-by":"crossref","first-page":"173","DOI":"10.1145\/762476.762477","volume":"6","author":"S.N. Chari","year":"2003","unstructured":"Chari S.N., Cheng P.-C.: Bluebox: a policy-driven, host-based intrusion detection system. ACM Trans. Inf. Syst. Secur. 6(2), 173\u2013200 (2003)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"218_CR13","doi-asserted-by":"crossref","unstructured":"Crampton, J.: Specifying and enforcing constraints in role-based access control. In: ACM Symposium on Access Control Models and Technologies (SACMAT) (2003)","DOI":"10.1145\/775412.775419"},{"key":"218_CR14","doi-asserted-by":"crossref","unstructured":"Dashofy, E., Asuncion, H., Hendrickson, S., Suryanarayana, G., Georgas, J., Taylor, R.: Archstudio 4: an architecture-based meta-modeling environment. In: ICSE Companion (2007)","DOI":"10.1109\/ICSECOMPANION.2007.21"},{"key":"218_CR15","unstructured":"Debie, E., De Ryck, P.: Non-repudiation middleware for web-based architectures. Master\u2019s thesis, Katholieke Universiteit Leuven (2009)"},{"key":"218_CR16","unstructured":"Evans, C.: Comments on the Overall Architecture of Vsftpd, from a Security Standpoint. Internet, February 2001"},{"key":"218_CR17","doi-asserted-by":"crossref","unstructured":"Fernandez, E.B., Hawkins, J.C.: Determining role rights from use cases. In: Proceedings of the Second ACM workshop on Role-based Access Control, pp. 121\u2013125. ACM, New York (1997)","DOI":"10.1145\/266741.266767"},{"key":"218_CR18","doi-asserted-by":"crossref","unstructured":"Giorgini, P., Massacci, F., Mylopoulos, J., Zannone, N.: Requirements engineering meets trust management. In: Jensen, C., Poslad, S., Dimitrakos, T. (eds.) Trust Management. Lecture Notes in Computer Science, vol. 2995, pp. 176\u2013190. Springer, Berlin (2004)","DOI":"10.1007\/978-3-540-24747-0_14"},{"key":"218_CR19","doi-asserted-by":"crossref","unstructured":"H\u00f6hn, S., J\u00fcrjens, J.: Rubacon: automated support for model-based compliance engineering. In: ICSE (2008)","DOI":"10.1145\/1368088.1368228"},{"key":"218_CR20","unstructured":"Howard, M., Lipner, S.: The Security Development Lifecycle. Microsoft Press (2006)"},{"key":"218_CR21","volume-title":"Secure Systems Development with UML","author":"J. J\u00fcrjens","year":"2005","unstructured":"J\u00fcrjens J.: Secure Systems Development with UML. Springer, Berlin (2005)"},{"key":"218_CR22","unstructured":"Jordan, D., Evdemon, J.: WS-BPEL 2.0. Oasis (2007)"},{"key":"218_CR23","unstructured":"Jain, K., Sekar, R.: User-level infrastructure for system call interposition: a platform for intrusion detection and confinement. (2000)"},{"key":"218_CR24","doi-asserted-by":"crossref","unstructured":"Karger, P.A.: Limiting the damage potential of discretionary Trojan horses. In: Proceedings of the 1987 Symposium on Security and Privacy, pp. 32\u201337 (1987)","DOI":"10.1109\/SP.1987.10011"},{"key":"218_CR25","doi-asserted-by":"crossref","unstructured":"Li, N., Tripunitara, M.V., Bizri, Z.: On mutually exclusive roles and separation-of-duty. ACM Trans. Inf. Syst. Secur. (TISSEC) 10(2) (2007)","DOI":"10.1145\/1237500.1237501"},{"key":"218_CR26","unstructured":"Liu, L., Yu, E., Mylopoulos, J.: Security and privacy requirements analysis within a social setting"},{"key":"218_CR27","unstructured":"Microsoft. Msdn library\u2014access control lists. http:\/\/msdn.microsoft.com (2010)"},{"key":"218_CR28","doi-asserted-by":"crossref","unstructured":"Mazieres, D., Kaashoek, M.F.: Secure applications need flexible operating systems. In: Workshop on Hot Topics in Operating Systems (1997)","DOI":"10.1109\/HOTOS.1997.595183"},{"key":"218_CR29","unstructured":"Morandini, M., Nguyen, D.C., Perini, A., Siena, A., Susi, A.: Tool-supported development with Tropos: the conference management system case study. In: Workshop on Agent Oriented Software Engineering (AOSE) (2008)"},{"key":"218_CR30","unstructured":"Nash, M.J., Poland, K.R.: Transaction control expressions for separation of duties. In: Annual Computer Security Applications Conference (ACSAC) (1988)"},{"key":"218_CR31","doi-asserted-by":"crossref","unstructured":"Nash, M.J., Poland, K.R.: Some conundrums concerning separation of duty. In: IEEE Symposium on Research in Security and Privacy (1990)","DOI":"10.1109\/RISP.1990.63851"},{"key":"218_CR32","first-page":"325","volume":"10","author":"G. Peterson","year":"2005","unstructured":"Peterson G.: Service oriented security architecture. Inf. Secur. Bull. 10, 325\u2013330 (2005)","journal-title":"Inf. Secur. Bull."},{"key":"218_CR33","unstructured":"Provos, N.: Systrace\u2014interactive policy generation for system calls"},{"key":"218_CR34","unstructured":"Provos, N.: Preventing privilege escalation. In: In Proceedings of the 12th USENIX Security Symposium (2003)"},{"key":"218_CR35","doi-asserted-by":"crossref","unstructured":"Raza, A., Vogel, G., Plodereder, E.: Bauhaus\u2014a tool suite for program analysis and reverse engineering. In: Ada Europe (2006)","DOI":"10.1007\/11767077_6"},{"key":"218_CR36","unstructured":"Ren, J.: A connector-centric approach to architectural access control. PhD thesis, University of California Irvine (2006)"},{"key":"218_CR37","volume-title":"Mastering the Requirements Process","author":"S. Robertson","year":"1999","unstructured":"Robertson S., Robertson J.: Mastering the Requirements Process. Addison-Wesley, Boston (1999)"},{"key":"218_CR38","volume-title":"Software Systems Architecture: Working with Stakeholders Using Viewpoints and Perspectives","author":"N. Rozanski","year":"2005","unstructured":"Rozanski N., Woods E.: Software Systems Architecture: Working with Stakeholders Using Viewpoints and Perspectives. Addison-Wesley Professional, Boston (2005)"},{"issue":"2","key":"218_CR39","doi-asserted-by":"crossref","first-page":"38","DOI":"10.1109\/2.485845","volume":"29","author":"R.S. Sandhu","year":"1996","unstructured":"Sandhu R.S., Coyne E.J., Feinstein H.L., Youman C.E.: The protection of information in computer systems. IEEE Comput. 29(2), 38\u201347 (1996)","journal-title":"IEEE Comput."},{"issue":"2","key":"218_CR40","doi-asserted-by":"crossref","first-page":"38","DOI":"10.1109\/2.485845","volume":"29","author":"R.S. Sandhu","year":"1996","unstructured":"Sandhu R.S., Coyne E.J., Feinstein H.L., Youman C.E.: Role-based access control models. Computer 29(2), 38\u201347 (1996)","journal-title":"Computer"},{"issue":"1","key":"218_CR41","doi-asserted-by":"crossref","first-page":"30","DOI":"10.1145\/353323.353382","volume":"3","author":"F.B. Schneider","year":"2000","unstructured":"Schneider F.B.: Enforceable security policies. ACM Trans. Inf. Syst. Secur. 3(1), 30\u201350 (2000)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"218_CR42","unstructured":"Spitz, B.: Architecture recovery for security. K.U. Leuven Master Thesis (2011)"},{"issue":"9","key":"218_CR43","doi-asserted-by":"crossref","first-page":"1278","DOI":"10.1109\/PROC.1975.9939","volume":"63","author":"J.H. Saltzer","year":"1975","unstructured":"Saltzer J.H., Schroeder M.D.: The protection of information in computer systems. Proc. IEEE 63(9), 1278\u20131308 (1975)","journal-title":"Proc. IEEE"},{"key":"218_CR44","unstructured":"Van Landuyt, D., Gr\u00e9goire, J., Michiels, S., Truyen, E., Joosen, W.: Architectural design of a digital publishing system. Technical Report CW465, Katholieke Universiteit Leuven (2006)"},{"key":"218_CR45","unstructured":"Venema, W.Z.: Postfix home page"},{"key":"218_CR46","volume-title":"Building Secure Software","author":"J. Viega","year":"2002","unstructured":"Viega J., McGraw G.: Building Secure Software. Addison- Wesley, Boston (2002)"},{"key":"218_CR47","unstructured":"Wagner, D.A.: Janus: an approach for confinement of untrusted applications. Technical Report CSD-99-1056, 12 (1999)"},{"key":"218_CR48","unstructured":"Walker, K.M., Sterne, D.F., Lee Badger, M., Petkac, M.J., Sherman, D.L., Oostendorp, K.A.: Confining root programs with domain and type enforcement (dte). In: SSYM\u201996: Proceedings of the 6th Conference on USENIX Security Symposium, Focusing on Applications of Cryptography, pp. 3\u20133, Berkeley, CA, USA, 1996. USENIX Association"},{"key":"218_CR49","doi-asserted-by":"crossref","unstructured":"Yu, E.S.K.: Towards modeling and reasoning support for early-phase requirements engineering. In: Proceedings of RE, p. 226 (1997)","DOI":"10.1109\/ISRE.1997.566873"},{"issue":"3","key":"218_CR50","doi-asserted-by":"crossref","first-page":"283","DOI":"10.1145\/566340.566343","volume":"20","author":"S. Zdancewic","year":"2002","unstructured":"Zdancewic S., Zheng L., Nystrom N., Myers A.C.: Secure program partitioning. ACM Trans. Comput. Syst. (TOCS) 20(3), 283\u2013328 (2002)","journal-title":"ACM Trans. Comput. Syst. (TOCS)"}],"container-title":["Software &amp; Systems Modeling"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10270-011-0218-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10270-011-0218-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10270-011-0218-8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,13]],"date-time":"2025-03-13T22:02:33Z","timestamp":1741903353000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10270-011-0218-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,11,9]]},"references-count":50,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2013,5]]}},"alternative-id":["218"],"URL":"https:\/\/doi.org\/10.1007\/s10270-011-0218-8","relation":{},"ISSN":["1619-1366","1619-1374"],"issn-type":[{"value":"1619-1366","type":"print"},{"value":"1619-1374","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,11,9]]}}}