{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T05:44:55Z","timestamp":1773639895850,"version":"3.50.1"},"reference-count":73,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2015,8,6]],"date-time":"2015-08-06T00:00:00Z","timestamp":1438819200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Softw Syst Model"],"published-print":{"date-parts":[[2017,7]]},"DOI":"10.1007\/s10270-015-0486-9","type":"journal-article","created":{"date-parts":[[2015,8,5]],"date-time":"2015-08-05T01:19:15Z","timestamp":1438737555000},"page":"809-831","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":32,"title":["Design notations for secure software: a systematic literature review"],"prefix":"10.1007","volume":"16","author":[{"given":"Alexander","family":"van\u00a0den\u00a0Berghe","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Riccardo","family":"Scandariato","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Koen","family":"Yskout","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wouter","family":"Joosen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2015,8,6]]},"reference":[{"issue":"3","key":"486_CR1","doi-asserted-by":"crossref","first-page":"299","DOI":"10.1016\/j.cose.2012.01.004","volume":"31","author":"J Abramov","year":"2012","unstructured":"Abramov, J., Anson, O., Dahan, M., Shoval, P., Sturm, A.: A methodology for integrating access control policies within database development. Comput. Secur. 31(3), 299\u2013314 (2012)","journal-title":"Comput. Secur."},{"issue":"9","key":"486_CR2","doi-asserted-by":"crossref","first-page":"1029","DOI":"10.1016\/j.infsof.2012.04.001","volume":"54","author":"J Abramov","year":"2012","unstructured":"Abramov, J., Sturm, A., Shoval, P.: Evaluation of the pattern-based method for secure development (PbSD): a controlled experiment. Inf. Softw. Technol. 54(9), 1029\u20131043 (2012)","journal-title":"Inf. Softw. Technol."},{"issue":"11","key":"486_CR3","doi-asserted-by":"crossref","first-page":"649","DOI":"10.1016\/S0950-5849(02)00092-7","volume":"44","author":"G-J Ahn","year":"2002","unstructured":"Ahn, G.-J., Hong, S.-P., Shin, M.E.: Reconstructing a formal security model. Inf. Softw. Technol. 44(11), 649\u2013657 (2002)","journal-title":"Inf. Softw. Technol."},{"issue":"1","key":"486_CR4","doi-asserted-by":"crossref","first-page":"47","DOI":"10.4304\/jsw.2.1.47-59","volume":"2","author":"M Alam","year":"2007","unstructured":"Alam, M., Breu, R., Hafner, M.: Model-driven security engineering for trust management in SECTET. J. Softw. 2(1), 47\u201359 (2007)","journal-title":"J. Softw."},{"issue":"1","key":"486_CR5","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1109\/TDSC.2004.2","volume":"1","author":"A Avizienis","year":"2004","unstructured":"Avizienis, A., Laprie, J.-C., Randell, B., Landwehr, C.: Basic concepts and taxonomy of dependable and secure computing. IEEE Trans. Dependable Secure Comput. 1(1), 11\u201333 (2004)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"issue":"5","key":"486_CR6","doi-asserted-by":"crossref","first-page":"815","DOI":"10.1016\/j.infsof.2008.05.011","volume":"51","author":"D Basin","year":"2009","unstructured":"Basin, D., Clavel, M., Doser, J., Egea, M.: Automated analysis of security-design models. Inf. Softw. Technol. 51(5), 815\u2013831 (2009)","journal-title":"Inf. Softw. Technol."},{"issue":"1","key":"486_CR7","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1145\/1125808.1125810","volume":"15","author":"D Basin","year":"2006","unstructured":"Basin, D., Doser, J., Lodderstedt, T.: Model driven security: from UML models to access control infrastructures. ACM Trans. Softw. Eng. Methodol. 15(1), 39\u201391 (2006)","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"486_CR8","doi-asserted-by":"crossref","unstructured":"Best, B., J\u00fcrjens, J., Nuseibeh, B.: Model-Based Security Engineering of Distributed Information Systems Using UMLsec. In: Proceedings of the 29th International Conference on Software Engineering, ICSE \u201907, pp. 581\u2013590. Washington, DC, USA (2007). IEEE Computer Society","DOI":"10.1109\/ICSE.2007.55"},{"issue":"2","key":"486_CR9","first-page":"1","volume":"12","author":"K Buyens","year":"2011","unstructured":"Buyens, K., Scandariato, R., Joosen, W.: Least privilege analysis in software architectures. Softw. Syst. Model. 12(2), 1\u201318 (2011)","journal-title":"Softw. Syst. Model."},{"issue":"1","key":"486_CR10","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1016\/j.scico.2005.11.006","volume":"61","author":"L Dai","year":"2006","unstructured":"Dai, L., Cooper, K.: Modeling and performance analysis for security aspects. Sci. Comput. Program. 61(1), 58\u201371 (2006)","journal-title":"Sci. Comput. Program."},{"issue":"2","key":"486_CR11","first-page":"187","volume":"5","author":"L Dai","year":"2007","unstructured":"Dai, L., Cooper, K.: A survey of modeling and analysis approaches for architecting secure software systems. Int. J. Netw. Secur. 5(2), 187\u2013198 (2007)","journal-title":"Int. J. Netw. Secur."},{"issue":"1","key":"486_CR12","doi-asserted-by":"crossref","first-page":"87","DOI":"10.1016\/j.scico.2006.10.010","volume":"66","author":"L Dai","year":"2007","unstructured":"Dai, L., Cooper, K.: Using FDAF to bridge the gap between enterprise and software architectures for security. Sci. Comput. Program. 66(1), 87\u2013102 (2007)","journal-title":"Sci. Comput. Program."},{"key":"486_CR13","unstructured":"Dehlinger, J., Subramanian, N.: Architecting Secure Software Systems Using an Aspect-Oriented Approach: A Survey of Current Research. In: Technical Report, Iowa State University (2006)"},{"issue":"1","key":"486_CR14","first-page":"187","volume":"16","author":"M Deng","year":"2012","unstructured":"Deng, M., Wuyts, K., Scandariato, R., Preneel, B., Joosen, W.: A privacy threat analysis framework: supporting the elicitation and fulfillment of privacy requirements. Requir. Eng. 16(1), 187\u2013198 (2012)","journal-title":"Requir. Eng."},{"key":"486_CR15","doi-asserted-by":"crossref","unstructured":"D\u00edaz, P., Aedo, I., Montero, S.: Ariadne, a development method for hypermedia. In: Mayr, H.C., Lazansky, J., Quirchmayr, G., Vogel, P. (eds.) Database and Expert Systems Applications. Lecture Notes in Computer Science, vol. 2113, pp. 764\u2013774. Springer, Berlin (2001)","DOI":"10.1007\/3-540-44759-8_74"},{"key":"486_CR16","doi-asserted-by":"crossref","unstructured":"D\u00edaz, P., Aedo, I., Sanz, D., Malizia, A.: A Model-Driven Approach for the Visual Specification of Role-Based Access Control Policies in Web Systems. In: IEEE Symposium on Visual Languages and Human-Centric Computing, 2008. VL\/HCC 2008. pp. 203\u2013210 (2008)","DOI":"10.1109\/VLHCC.2008.4639087"},{"issue":"7","key":"486_CR17","doi-asserted-by":"crossref","first-page":"463","DOI":"10.1016\/j.infsof.2004.09.013","volume":"47","author":"E Fern\u00e1ndez-Medina","year":"2005","unstructured":"Fern\u00e1ndez-Medina, E., Piattini, M.: Designing secure databases. Inf. Softw. Technol. 47(7), 463\u2013477 (2005)","journal-title":"Inf. Softw. Technol."},{"issue":"6","key":"486_CR18","doi-asserted-by":"crossref","first-page":"826","DOI":"10.1016\/j.is.2006.07.003","volume":"32","author":"E Fern\u00e1ndez-Medina","year":"2007","unstructured":"Fern\u00e1ndez-Medina, E., Trujillo, J., Villarroel, R., Piattini, M.: Developing secure data warehouses with a UML extension. Inf. Syst. 32(6), 826\u2013856 (2007)","journal-title":"Inf. Syst."},{"issue":"5","key":"486_CR19","doi-asserted-by":"crossref","first-page":"846","DOI":"10.1016\/j.infsof.2008.05.004","volume":"51","author":"G Georg","year":"2009","unstructured":"Georg, G., Ray, I., Anastasakis, K., Bordbar, B., Toahchoodee, M., Houmb, S.H.: An aspect-oriented methodology for designing secure applications. Inf. Softw. Technol. 51(5), 846\u2013864 (2009)","journal-title":"Inf. Softw. Technol."},{"key":"486_CR20","doi-asserted-by":"crossref","unstructured":"Georg, G., Ray, I., France, R.: Using Aspects to Design a Secure System. In: Proceedings of the Eighth International Conference on Engineering of Complex Computer Systems, ICECCS \u201902, p. 117. IEEE Computer Society, Washington (2002)","DOI":"10.1109\/ICECCS.2002.1181504"},{"issue":"1","key":"486_CR21","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1016\/j.jvlc.2009.11.002","volume":"21","author":"M Giordano","year":"2010","unstructured":"Giordano, M., Polese, G., Scanniello, G., Tortora, G.: A system for visual role-based policy modelling. J. Vis. Lang. Comput. 21(1), 41\u201364 (2010)","journal-title":"J. Vis. Lang. Comput."},{"key":"486_CR22","doi-asserted-by":"crossref","unstructured":"Gomaa, H., Eonsuk Shin, M.: Modelling Complex Systems by Separating Application and Security Concerns. In: Proceedings of Ninth IEEE International Conference on Engineering Complex Computer Systems, pp. 19\u201328 (2004)","DOI":"10.1109\/ICECCS.2004.1310900"},{"key":"486_CR23","doi-asserted-by":"crossref","unstructured":"Hafner, M., Breu, M., Breu, R., Nowak, A.: Modelling Inter-organizational Workflow Security in a Peer-to-Peer Environment. In: Proceedings of 2005 IEEE International Conference on Web Services, 2005. ICWS 2005. p. 540 (2005)","DOI":"10.1109\/ICWS.2005.83"},{"key":"486_CR24","doi-asserted-by":"publisher","unstructured":"Heldal, R., Hultin, F.: Bridging Model-Based and Language-Based Security. In: Snekkenes E., Gollmann D. (eds) Computer Security ESORICS 2003, volume 2808 of Lecture Notes in Computer Science, pp. 235\u2013252. Springer, Berlin (2003). doi: 10.1007\/978-3-540-39650-5_14","DOI":"10.1007\/978-3-540-39650-5_14"},{"key":"486_CR25","doi-asserted-by":"publisher","unstructured":"Hoisl, B., Sobernig, S., Strembeck, M.: Modeling and enforcing secure object flows in process-driven SOAs: an integrated model-driven approach. Softw. Syst. Model. 13(2), 513\u2013548 (2014). doi: 10.1007\/s10270-012-0263-y","DOI":"10.1007\/s10270-012-0263-y"},{"issue":"4","key":"486_CR26","doi-asserted-by":"crossref","first-page":"396","DOI":"10.1109\/TSMCC.2010.2047856","volume":"40","author":"H Hu","year":"2010","unstructured":"Hu, H., Ahn, G.-J.: Constructing authorization systems using assurance management framework. IEEE Trans. Syst. Man Cybern. Part C Appl. Rev. 40(4), 396\u2013405 (2010)","journal-title":"IEEE Trans. Syst. Man Cybern. Part C Appl. Rev."},{"issue":"4","key":"486_CR27","first-page":"642","volume":"3","author":"S Hussain","year":"2013","unstructured":"Hussain, S., Rasool, G., Atef, M., Shahid, A.K.: A review of approaches to model security into software systems. J. Basic Appl. Sci. Res. 3(4), 642\u2013647 (2013)","journal-title":"J. Basic Appl. Sci. Res."},{"key":"486_CR28","unstructured":"Jayaram, K.R., Mathur, A.P.: Software Engineering for Secure Software\u2014State of the Art: A Survey. In: Technical Report CERIAS 2005-67, Purdue University (2005)"},{"key":"486_CR29","doi-asserted-by":"crossref","unstructured":"Jensen, J., Jaatun, M.G.: Security in Model Driven Development: A Survey. In: 2011 Sixth International Conference on Availability, Reliability and Security (ARES), pp. 704\u2013709 (2011)","DOI":"10.1109\/ARES.2011.110"},{"key":"486_CR30","volume-title":"Secure Systems Development with UML","author":"J J\u00fcrjens","year":"2004","unstructured":"J\u00fcrjens, J.: Secure Systems Development with UML. Springer, Berlin (2004)"},{"key":"486_CR31","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens, J.: Sound Methods and Effective Tools for Model-Based Security Engineering with UML. In: Proceedings of the 27th International Conference on Software Engineering, ICSE \u201905, pp. 322\u2013331. ACM, New York (2005)","DOI":"10.1145\/1062455.1062519"},{"key":"486_CR32","doi-asserted-by":"crossref","first-page":"21","DOI":"10.1007\/978-0-387-88775-3_2","volume-title":"Security and Dependability for Ambient Intelligence, Volume 45 of Advances in Information Security","author":"J J\u00fcrjens","year":"2009","unstructured":"J\u00fcrjens, J.: Security and dependability engineering. In: Kokolakis, S., G\u00f3mez, A.M., Spanoudakis, G. (eds.) Security and Dependability for Ambient Intelligence, Volume 45 of Advances in Information Security, pp. 21\u201336. Springer, Berlin (2009)"},{"key":"486_CR33","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens, J., Lehrhuber, M., Wimmel, G.: Model-Based Design and Analysis of Permission-Based Security. In: Proceedings of 10th IEEE International Conference on Engineering of Complex Computer Systems, 2005. ICECCS 2005. pp. 224\u2013233 (2005)","DOI":"10.1109\/ICECCS.2005.61"},{"key":"486_CR34","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens, J., Schreck, J., Bartmann, P.: Model-Based Security Analysis for Mobile Communications. In: Proceedings of the 30th International Conference on Software Engineering, ICSE \u201908, pp. 683\u2013692. ACM, New York (2008)","DOI":"10.1145\/1368088.1368186"},{"key":"486_CR35","doi-asserted-by":"crossref","first-page":"527","DOI":"10.1007\/s10009-007-0048-8","volume":"9","author":"J J\u00fcrjens","year":"2007","unstructured":"J\u00fcrjens, J., Shabalin, P.: Tools for secure systems development with UML. Int. J. Softw. Tools Technol. Transf. 9, 527\u2013544 (2007)","journal-title":"Int. J. Softw. Tools Technol. Transf."},{"key":"486_CR36","doi-asserted-by":"crossref","unstructured":"Kasal, K., Heurix, J., Neubauer, T.: Model-Driven Development Meets Security: An Evaluation of Current Approaches. In: 2011 44th Hawaii International Conference on System Sciences (HICSS), pp. 1\u20139 (2011)","DOI":"10.1109\/HICSS.2011.310"},{"key":"486_CR37","doi-asserted-by":"crossref","unstructured":"Keller, F., Wendt, S.: FMC: An approach towards architecture-centric system development. In: Proceedings of 10th IEEE International Conference and Workshop on the Engineering of Computer-Based Systems, 2003, pp. 173\u2013182. IEEE (2003)","DOI":"10.1109\/ECBS.2003.1194797"},{"key":"486_CR38","unstructured":"Khan, M.U.A., Zulkernine, M.: A Survey on Requirements and Design Methods for Secure Software Development. In: Technical Report 2009-562, School of Computing, Queen\u2019s University, Kingston, Ontario, Canada (2009)"},{"issue":"5","key":"486_CR39","doi-asserted-by":"crossref","first-page":"581","DOI":"10.1142\/S0218194002001062","volume":"12","author":"AA Khwaja","year":"2002","unstructured":"Khwaja, A.A., Urban, J.E.: A synthesis of evaluation criteria for software specifications and specification techniques. Int. J. Softw. Eng. Knowl. Eng. 12(5), 581\u2013599 (2002)","journal-title":"Int. J. Softw. Eng. Knowl. Eng."},{"issue":"12","key":"486_CR40","doi-asserted-by":"crossref","first-page":"2035","DOI":"10.1016\/j.jss.2011.03.084","volume":"84","author":"S Kim","year":"2011","unstructured":"Kim, S., Kim, D.-K., Lu, L., Kim, S., Park, S.: A feature-based approach for modeling role-based access control systems. J. Syst. Softw. 84(12), 2035\u20132052 (2011)","journal-title":"J. Syst. Softw."},{"key":"486_CR41","unstructured":"Kitchenham, B., Charters, S.: Guidelines for Performing Systematic Literature Reviews in Software Engineering. In: Technical Report EBSE 2007-001, Keele University and Durham University Joint Report (2007)"},{"issue":"3","key":"486_CR42","doi-asserted-by":"crossref","first-page":"332","DOI":"10.1145\/545186.545191","volume":"5","author":"M Koch","year":"2002","unstructured":"Koch, M., Mancini, L.V., Parisi Presicce, F.: A graph-based formalism for RBAC. ACM Trans. Inf. Syst. Secur. 5(3), 332\u2013365 (2002)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"issue":"4","key":"486_CR43","doi-asserted-by":"crossref","first-page":"429","DOI":"10.1007\/s10270-006-0030-z","volume":"5","author":"M Koch","year":"2006","unstructured":"Koch, M., Parisi-Presicce, F.: UML specification of access control policies and their formal verification. Softw. Syst. Model. 5(4), 429\u2013447 (2006)","journal-title":"Softw. Syst. Model."},{"issue":"6","key":"486_CR44","doi-asserted-by":"crossref","first-page":"875","DOI":"10.1142\/S0218194010004980","volume":"20","author":"J Kong","year":"2010","unstructured":"Kong, J., Xu, D., Zeng, X.: UML-based modeling and analysis of security threats. Int. J. Softw. Eng. Knowl. Eng. 20(6), 875\u2013897 (2010)","journal-title":"Int. J. Softw. Eng. Knowl. Eng."},{"key":"486_CR45","doi-asserted-by":"crossref","unstructured":"L\u00facio, L., Zhang, Q., Nguyen, P.-H., Amrani, M., Klein, J., Vangheluwe, H., Le Traon, Y.: Advances in Model-Driven Security. Adv. Comput. 93, 103\u2013152 (2013)","DOI":"10.1016\/B978-0-12-800162-2.00003-8"},{"key":"486_CR46","unstructured":"Matulevi\u010dius, R., Dumas, M.: A Comparison of SecureUML and UMLsec for Role-Based Access Control. In: Databases and Information Systems, pp. 171\u2013185 (2010)"},{"key":"486_CR47","unstructured":"Mayer, P., Koch, N., Schroeder, A., Knapp, A.: The UML4SOA Profile. In: Technical report, LMU Muenchen (2010)"},{"key":"486_CR48","doi-asserted-by":"publisher","unstructured":"Memon, M., Menghwar, G., Depar, M., Jalbani, A., Mashwani, W.: Security modeling for service-oriented systems using security pattern refinement approach. Softw. Syst. Model. 13(2), 549\u2013572 (2014). doi: 10.1007\/s10270-012-0268-6","DOI":"10.1007\/s10270-012-0268-6"},{"key":"486_CR49","doi-asserted-by":"crossref","unstructured":"Menzel, M., Meinel, C.: A Security Meta-Model for Service-Oriented Architectures. In: IEEE International Conference on Services Computing, 2009. SCC \u201909. , pp. 251\u2013259 (2009)","DOI":"10.1109\/SCC.2009.57"},{"key":"486_CR50","doi-asserted-by":"crossref","unstructured":"Menzel, M., Meinel, C.: SecureSOA Modelling Security Requirements for Service-Oriented Architectures. In: 2010 IEEE International Conference on Services Computing (SCC), pp. 146\u2013153 (2010)","DOI":"10.1109\/SCC.2010.63"},{"key":"486_CR51","doi-asserted-by":"crossref","unstructured":"Nakamura, Y., Tatsubori, M., Imamura, T., Ono, K.: Model-Driven Security Based on a Web Services Security Architecture. In: 2005 IEEE International Conference on Services Computing, vol. 1, pp. 7\u201315 (2005)","DOI":"10.1109\/SCC.2005.66"},{"key":"486_CR52","doi-asserted-by":"crossref","unstructured":"Nguyen, P.-H., Klein, J., Le Traon, Y., Kramer, M.E.: A Systematic Review of Model-Driven Security. In: Software Engineering Conference (APSEC, 2013 20th Asia-Pacific), vol. 1, pp. 432\u2013441 (2013)","DOI":"10.1109\/APSEC.2013.64"},{"key":"486_CR53","unstructured":"OMG. OMG Unified Modeling Language (OMG UML), Infrastructure (2011). OMG. http:\/\/www.omg.org\/spec\/UML\/2.4.1\/Infrastructure\/PDF"},{"key":"486_CR54","unstructured":"OMG. OMG Unified Modeling Language (OMG UML), Superstructure (2011). OMG. http:\/\/www.omg.org\/spec\/UML\/2.4.1\/Superstructure\/PDF"},{"key":"486_CR55","unstructured":"OMG. OMG Object Constraint Language (OCL) (2012). OMG. http:\/\/www.omg.org\/spec\/OCL\/2.3.1\/PDF"},{"key":"486_CR56","unstructured":"OMG. Service Oriented architecture Modeling Language (SoaML) Specification (2012). OMG. http:\/\/www.omg.org\/spec\/SoaML\/1.0.1\/PDF"},{"issue":"3","key":"486_CR57","doi-asserted-by":"crossref","first-page":"350","DOI":"10.1016\/j.cose.2009.11.005","volume":"29","author":"JA Pavlich-Mariscal","year":"2010","unstructured":"Pavlich-Mariscal, J.A., Demurjian, S.A., Michel, L.D.: A framework of composable access control features: preserving separation of access control concerns from models to code. Comput. Secur. 29(3), 350\u2013379 (2010)","journal-title":"Comput. Secur."},{"issue":"9","key":"486_CR58","doi-asserted-by":"crossref","first-page":"575","DOI":"10.1016\/j.infsof.2003.10.007","volume":"46","author":"I Ray","year":"2004","unstructured":"Ray, I., France, R., Li, N., Georg, G.: An aspect-based approach to modeling access control concerns. Inf. Softw. Technol. 46(9), 575\u2013587 (2004)","journal-title":"Inf. Softw. Technol."},{"issue":"2","key":"486_CR59","doi-asserted-by":"crossref","first-page":"38","DOI":"10.1109\/2.485845","volume":"29","author":"RS Sandhu","year":"1996","unstructured":"Sandhu, R.S., Coyne, E.J., Feinstein, H.L., Youman, C.E.: Role-based access control models. Computer 29(2), 38\u201347 (1996)","journal-title":"Computer"},{"key":"486_CR60","doi-asserted-by":"crossref","unstructured":"Satoh, F., Nakamura, Y., Ono, K.: Adding Authentication to Model Driven Security. In: Proceedings of the IEEE International Conference on Web Services, ICWS \u201906, pp. 585\u2013594. IEEE Computer Society, Washington (2006)","DOI":"10.1109\/ICWS.2006.25"},{"key":"486_CR61","unstructured":"Shah, V., Hill, F.: An Aspect-Oriented Security Framework: Lessons Learned. In: AOSD Technology for Application-level Security (AOSDSEC) (2004)"},{"key":"486_CR62","doi-asserted-by":"crossref","unstructured":"Sohr, K., Ahn, G.-J., Gogolla, M., Migge, L.: Specification and Validation of Authorisation Constraints Using UML and OCL. In: de Capitani, S., di Vimercati, P., Syverson, D. Gollmann, (eds.) Computer Security ESORICS 2005. Lecture Notes in Computer Science, vol. 3679, pp. 64\u201379. Springer, Berlin Heidelberg (2005)","DOI":"10.1007\/11555827_5"},{"key":"486_CR63","unstructured":"Standard. The Common Criteria: Security functional components. https:\/\/www.commoncriteriaportal.org (2012)"},{"key":"486_CR64","unstructured":"Standard. WS-SecurityPolicy v1.3. OASIS Standard incorporating Approved Errata. http:\/\/docs.oasis-open.org\/ws-sx\/ws-securitypolicy\/v1.3\/errata01\/os\/ws-securitypolicy-1.3-errata01-os-complete.html (2012)"},{"key":"486_CR65","unstructured":"Standard. WS-Trust 1.4. OASIS Standard Incorporating Approved Errata. http:\/\/docs.oasis-open.org\/ws-sx\/ws-trust\/v1.4\/errata01\/os\/ws-trust-1.4-errata01-os-complete.html (2012)"},{"issue":"6","key":"486_CR66","doi-asserted-by":"crossref","first-page":"103","DOI":"10.5381\/jot.2009.8.6.a1","volume":"8","author":"C Talhi","year":"2009","unstructured":"Talhi, C., Mouheb, D., Lima, V., Debbabi, M., Wang, L., Pourzandi, M.: Usability of security specification approaches for UML design: a survey. J. Object Technol. 8(6), 103\u2013122 (2009)","journal-title":"J. Object Technol."},{"issue":"6","key":"486_CR67","doi-asserted-by":"crossref","first-page":"1033","DOI":"10.1016\/j.infsof.2008.12.003","volume":"51","author":"J Trujillo","year":"2009","unstructured":"Trujillo, J., Soler, E., Fern\u00e1ndez-Medina, E., Piattini, M.: An engineering process for developing secure data warehouses. Inf. Softw. Technol. 51(6), 1033\u20131051 (2009)","journal-title":"Inf. Softw. Technol."},{"issue":"20","key":"486_CR68","first-page":"2920","volume":"18","author":"AV Uzunov","year":"2012","unstructured":"Uzunov, A.V., Fernandez, E.B., Falkner, K.: Engineering security into distributed systems a survey of methodologies. J. Univ. Comput. Sci. 18(20), 2920\u20133006 (2012)","journal-title":"J. Univ. Comput. Sci."},{"issue":"4","key":"486_CR69","doi-asserted-by":"crossref","first-page":"899","DOI":"10.1016\/j.dss.2011.11.008","volume":"52","author":"B Vela","year":"2012","unstructured":"Vela, B., Blanco, C., Fern\u00e1ndez-Medina, E., Marcos, E.: A practical application of our MDD approach for modeling secure XML data warehouses. Decis. Support Syst. 52(4), 899\u2013925 (2012)","journal-title":"Decis. Support Syst."},{"issue":"4","key":"486_CR70","doi-asserted-by":"crossref","first-page":"308","DOI":"10.1016\/j.cose.2004.09.011","volume":"24","author":"R Villarroel","year":"2005","unstructured":"Villarroel, R., Fern\u00e1ndez-Medina, E., Piattini, M.: Secure information systems development\u2014a survey and comparison. Comput. Secur. 24(4), 308\u2013321 (2005)","journal-title":"Comput. Secur."},{"key":"486_CR71","unstructured":"Website. https:\/\/people.cs.kuleuven.be\/alexander.vandenberghe\/review\/overview.html"},{"issue":"4","key":"486_CR72","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1109\/TSE.2006.40","volume":"32","author":"D Xu","year":"2006","unstructured":"Xu, D., Nygard, K.E.: Threat-driven modeling and verification of secure software using aspect-oriented petri nets. IEEE Trans. Softw. Eng. 32(4), 265\u2013278 (2006)","journal-title":"IEEE Trans. Softw. Eng."},{"key":"486_CR73","doi-asserted-by":"crossref","unstructured":"Yu, L., France, R., Ray, Indrakshi, Ghosh, S.: A Rigorous Approach to Uncovering Security Policy Violations in UML Designs. In: 2009 14th IEEE International Conference on Engineering of Complex Computer Systems, pp. 126\u2013135 (2009)","DOI":"10.1109\/ICECCS.2009.16"}],"container-title":["Software &amp; Systems Modeling"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10270-015-0486-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10270-015-0486-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10270-015-0486-9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10270-015-0486-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,8,28]],"date-time":"2019-08-28T22:26:23Z","timestamp":1567031183000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10270-015-0486-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,8,6]]},"references-count":73,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2017,7]]}},"alternative-id":["486"],"URL":"https:\/\/doi.org\/10.1007\/s10270-015-0486-9","relation":{},"ISSN":["1619-1366","1619-1374"],"issn-type":[{"value":"1619-1366","type":"print"},{"value":"1619-1374","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,8,6]]}}}