{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T14:43:22Z","timestamp":1784213002048,"version":"3.55.0"},"reference-count":43,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2018,5,26]],"date-time":"2018-05-26T00:00:00Z","timestamp":1527292800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/501100004963","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["609734"],"award-info":[{"award-number":["609734"]}],"id":[{"id":"10.13039\/501100004963","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100011102","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["609734"],"award-info":[{"award-number":["609734"]}],"id":[{"id":"10.13039\/100011102","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100011102","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["609734"],"award-info":[{"award-number":["609734"]}],"id":[{"id":"10.13039\/100011102","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100011102","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["609734"],"award-info":[{"award-number":["609734"]}],"id":[{"id":"10.13039\/100011102","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100011102","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["609734"],"award-info":[{"award-number":["609734"]}],"id":[{"id":"10.13039\/100011102","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100011102","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["609734"],"award-info":[{"award-number":["609734"]}],"id":[{"id":"10.13039\/100011102","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100011102","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["609734"],"award-info":[{"award-number":["609734"]}],"id":[{"id":"10.13039\/100011102","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2019,2]]},"DOI":"10.1007\/s10664-018-9625-6","type":"journal-article","created":{"date-parts":[[2018,5,26]],"date-time":"2018-05-26T04:27:58Z","timestamp":1527308878000},"page":"240-286","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":29,"title":["Understanding the behaviour of hackers while performing attack tasks in a professional setting and in a public challenge"],"prefix":"10.1007","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7325-0316","authenticated-orcid":false,"given":"Mariano","family":"Ceccato","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Paolo","family":"Tonella","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cataldo","family":"Basile","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Paolo","family":"Falcarin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marco","family":"Torchiano","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bart","family":"Coppens","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bjorn","family":"De Sutter","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2018,5,26]]},"reference":[{"key":"9625_CR1","doi-asserted-by":"crossref","unstructured":"Abrath B, Coppens B, Volckaert S, Wijnant J, De Sutter B (2016) Tightly-coupled self-debugging software protection. In: Proceedings of the 6th workshop on software security, protection, and reverse engineering (SSPREW), pp 7:1\u20137:10","DOI":"10.1145\/3015135.3015142"},{"key":"9625_CR2","doi-asserted-by":"crossref","unstructured":"Anckaert B, Madou M, De Sutter B, De Bus B, De Bosschere K, Preneel B (2007) Program obfuscation: a quantitative approach. In: Proceedings of ACM workshop on quality of protection, pp 15\u201320","DOI":"10.1145\/1314257.1314263"},{"key":"9625_CR3","doi-asserted-by":"crossref","unstructured":"Andrews AA, Ghosh S, Choi EM (2002) A model for understanding software components. In: 18th international conference on software maintenance (ICSM 2002), maintaining distributed heterogeneous systems, 3\u20136 October 2002, Montreal, Quebec, Canada, p 359","DOI":"10.1109\/ICSM.2002.1167792"},{"key":"9625_CR4","doi-asserted-by":"publisher","unstructured":"Armknecht F, Sadeghi AR, Schulz S, Wachsmann C (2013) A security framework for the analysis and design of software attestation. In: Proceedings of the 2013 ACM SIGSAC conference on computer & communications security, CCS \u201913. ACM, New York, USA, pp 1\u201312. https:\/\/doi.org\/10.1145\/2508859.2516650","DOI":"10.1145\/2508859.2516650"},{"key":"9625_CR5","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/3-540-44647-8_2","volume":"2139","author":"B Barak","year":"2001","unstructured":"Barak B, Goldreich O, Impagliazzo R, Rudich S, Sahai A, Vadhan S, Yang K (2001) On the (im) possibility of obfuscating programs. Lect Notes Comput Sci 2139:19\u201323","journal-title":"Lect Notes Comput Sci"},{"issue":"2","key":"9625_CR6","doi-asserted-by":"publisher","first-page":"115","DOI":"10.1023\/A:1015297914742","volume":"7","author":"J Burkhardt","year":"2002","unstructured":"Burkhardt J, D\u00e9tienne F, Wiedenbeck S (2002) Object-oriented program comprehension: effect of expertise, task and phase. Empir Softw Eng 7(2):115\u2013156","journal-title":"Empir Softw Eng"},{"key":"9625_CR7","doi-asserted-by":"crossref","unstructured":"Cabutto A, Falcarin P, Abrath B, Coppens B, De Sutter B (2015) Software protection with code mobility. In: Proceedings of the second ACM workshop on moving target defense (MTD), pp 95\u2013103","DOI":"10.1145\/2808475.2808481"},{"key":"9625_CR8","doi-asserted-by":"crossref","unstructured":"Capiluppi A, Falcarin P, Boldyreff C (2012) Code defactoring: evaluating the effectiveness of java obfuscations. In: 2012 19th working conference on reverse engineering (WCRE). IEEE, pp 71\u201380","DOI":"10.1109\/WCRE.2012.17"},{"issue":"6","key":"9625_CR9","doi-asserted-by":"publisher","first-page":"1486","DOI":"10.1007\/s10664-014-9321-0","volume":"20","author":"M Ceccato","year":"2015","unstructured":"Ceccato M, Capiluppi A, Falcarin P, Boldyreff C (2015) A large study on the effect of code obfuscation on the quality of java code. Empir Softw Eng 20(6):1486\u20131524","journal-title":"Empir Softw Eng"},{"issue":"4","key":"9625_CR10","first-page":"1040","volume":"19","author":"M Ceccato","year":"2014","unstructured":"Ceccato M, Di Penta M, Falcarin P, Ricca F, Torchiano M, Tonella P (2014) A family of experiments to assess the effectiveness and efficiency of source code obfuscation techniques. Empir Softw Eng 19(4):1040\u20131074","journal-title":"Empir Softw Eng"},{"key":"9625_CR11","doi-asserted-by":"publisher","unstructured":"Ceccato M, Di Penta M, Nagra J, Falcarin P, Ricca F, Torchiano M, Tonella P (2009) The effectiveness of source code obfuscation: an experimental assessment. In: IEEE 17th international conference on program comprehension (ICPC), pp 178\u2013187. https:\/\/doi.org\/10.1109\/ICPC.2009.5090041","DOI":"10.1109\/ICPC.2009.5090041"},{"key":"9625_CR12","doi-asserted-by":"publisher","unstructured":"Ceccato M, Dalla Preda M, Nagra J, Collberg C, Tonella P (2007) Barrier slicing for remote software trusting. In: Proceedings of the seventh IEEE international working conference on source code analysis and manipulation, SCAM \u201907. IEEE Computer Society, Washington, pp 27\u201336. https:\/\/doi.org\/10.1109\/SCAM.2007.6 https:\/\/doi.org\/10.1109\/SCAM.2007.6","DOI":"10.1109\/SCAM.2007.6"},{"key":"9625_CR13","doi-asserted-by":"crossref","unstructured":"Ceccato M, Tonella P, Basile C, Coppens B, De Sutter B, Falcarin P, Torchiano M (2017) How professional hackers understand protected code while performing attack tasks. In: Proceedings of the 25th international conference on program comprehension (ICPC), pp 154\u2013164. ICPC best paper award and ACM Distinguished paper award","DOI":"10.1109\/ICPC.2017.2"},{"key":"9625_CR14","unstructured":"Collberg C, Thomborson C, Low D (1997) A taxonomy of obfuscating transformations. Technical Report 148, Dept. of Computer Science, The Univ. of Auckland"},{"key":"9625_CR15","unstructured":"Collberg C, Nagra J (2009) Surreptitious software: obfuscation, watermarking, and tamperproofing for software protection. Addison-wesley, London"},{"key":"9625_CR16","doi-asserted-by":"crossref","unstructured":"Demissie BF, Ceccato M, Tiella R (2015) Assessment of data obfuscation with residue number coding. In: Proceedings of the 1st international workshop on software protection, SPRO \u201915. IEEE Press, Piscataway, pp 38\u201344. http:\/\/dl.acm.org\/citation.cfm?id=2821429.2821440","DOI":"10.1109\/SPRO.2015.15"},{"key":"9625_CR17","doi-asserted-by":"crossref","unstructured":"Edmundson A, Holtkamp B, Rivera E, Finifter M, Mettler A, Wagner D (2013) An empirical study on the effectiveness of security code review. In: International symposium on engineering secure software and systems. Springer, pp 197\u2013212","DOI":"10.1007\/978-3-642-36563-8_14"},{"key":"9625_CR18","volume-title":"An introduction to qualitative research","author":"U Flick","year":"2009","unstructured":"Flick U (2009) An introduction to qualitative research, 4th edn. Sage, London, England, UK","edition":"4th edn."},{"key":"9625_CR19","volume-title":"The discovery of grounded theory","author":"BG Glaser","year":"1967","unstructured":"Glaser BG, Strauss AL (1967) The discovery of grounded theory. Aldine, Chicago, IL, USA"},{"key":"9625_CR20","doi-asserted-by":"publisher","unstructured":"Katipally R, Yang L, Liu A (2011) Attacker behavior analysis in multi-stage attack detection system. In: Proceedings of the seventh annual workshop on cyber security and information intelligence research, CSIIRW \u201911. ACM, New York, pp 63:1\u201363:1. https:\/\/doi.org\/10.1145\/2179298.2179369","DOI":"10.1145\/2179298.2179369"},{"issue":"4","key":"9625_CR21","doi-asserted-by":"publisher","first-page":"325","DOI":"10.1016\/0164-1212(87)90032-X","volume":"7","author":"S Letovsky","year":"1987","unstructured":"Letovsky S (1987) Cognitive processes in program comprehension. J Syst Softw 7(4):325\u2013339","journal-title":"J Syst Softw"},{"key":"9625_CR22","doi-asserted-by":"crossref","unstructured":"Linn C, Debray S (2003) Obfuscation of executable code to improve resistance to static disassembly. In: Proceedings of ACM conference on computer and communications security, pp 290\u2013299","DOI":"10.1145\/948109.948149"},{"issue":"4","key":"9625_CR23","doi-asserted-by":"publisher","first-page":"341","DOI":"10.1016\/0164-1212(87)90033-1","volume":"7","author":"DC Littman","year":"1987","unstructured":"Littman DC, Pinto J, Letovsky S, Soloway E (1987) Mental models and software maintenance. J Syst Softw 7(4):341\u2013355","journal-title":"J Syst Softw"},{"key":"9625_CR24","doi-asserted-by":"publisher","unstructured":"Mallikarjunan KN, Prabavathy S, Sundarakantham K, Shalinie SM (2015) Model for cyber attacker behavioral analysis. In: 2015 IEEE workshop on computational intelligence: theories, applications and future directions (WCI), pp 1\u20134. https:\/\/doi.org\/10.1109\/WCI.2015.7495520","DOI":"10.1109\/WCI.2015.7495520"},{"issue":"2","key":"9625_CR25","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1109\/TDSC.2005.24","volume":"2","author":"PC Oorschot van","year":"2005","unstructured":"van Oorschot PC, Somayaji A, Wurster G (2005) Hardware-assisted circumvention of self-hashing software tamper resistance. IEEE Trans Dependable Secur Comput 2(2):82\u201392. https:\/\/doi.org\/10.1109\/TDSC.2005.24 https:\/\/doi.org\/10.1109\/TDSC.2005.24","journal-title":"IEEE Trans Dependable Secur Comput"},{"issue":"3","key":"9625_CR26","doi-asserted-by":"publisher","first-page":"295","DOI":"10.1016\/0010-0285(87)90007-7","volume":"19","author":"N Pennington","year":"1987","unstructured":"Pennington N (1987) Stimulus structures and mental representations in expert comprehension of computer programs. Cogn Psychol 19(3):295\u2013341","journal-title":"Cogn Psychol"},{"key":"9625_CR27","doi-asserted-by":"crossref","unstructured":"Piorkowski DJ, Fleming SD, Kwan I, Burnett MM, Scaffidi C, Bellamy RK, Jordahl J (2013) The whats and hows of programmers\u2019 foraging diets. In: Proceedings of the SIGCHI conference on human factors in computing systems. ACM, New York, pp 3063\u20133072","DOI":"10.1145\/2470654.2466418"},{"key":"9625_CR28","doi-asserted-by":"crossref","unstructured":"Prechelt L, Schmeisky H, Zieris F (2016) Quality experience: a grounded theory of successful agile projects without dedicated testers. In: Proceedings of the 38th international conference on software engineering, ICSE 2016, Austin, TX, USA, May 14\u201322, 2016, pp 1017\u20131027","DOI":"10.1145\/2884781.2884789"},{"key":"9625_CR29","doi-asserted-by":"crossref","unstructured":"Sillito J, Murphy GC, Volder KD (2006) Questions programmers ask during software evolution tasks. In: Proceedings of the 14th ACM SIGSOFT international symposium on foundations of software engineering, FSE, pp 23\u201334","DOI":"10.1145\/1181775.1181779"},{"key":"9625_CR30","doi-asserted-by":"crossref","unstructured":"Stol K, Ralph P, Fitzgerald B (2016) Grounded theory in software engineering research: a critical review and guidelines. In: Proceedings of the 38th international conference on software engineering, ICSE 2016, Austin, TX, USA, May 14\u201322, 2016, pp 120\u2013131","DOI":"10.1145\/2884781.2884833"},{"key":"9625_CR31","volume-title":"Basics of qualitative research: grounded theory procedures and techniques","author":"A Strauss","year":"1990","unstructured":"Strauss A, Corbin J (1990) Basics of qualitative research: grounded theory procedures and techniques. Sage, London"},{"issue":"3","key":"9625_CR32","doi-asserted-by":"publisher","first-page":"221","DOI":"10.1016\/j.cose.2005.11.002","volume":"25","author":"I Sutherland","year":"2006","unstructured":"Sutherland I, Kalb GE, Blyth A, Mulley G (2006) An empirical examination of the reverse engineering process for binary files. Comput Secur 25(3):221\u2013228","journal-title":"Comput Secur"},{"key":"9625_CR33","doi-asserted-by":"publisher","unstructured":"Udupa SK, Debray SK, Madou M (2005) Deobfuscation: reverse engineering obfuscated code. In: Proceedings of the 12th working conference on reverse engineering. IEEE Computer Society, Washington, pp 45\u201354. https:\/\/doi.org\/10.1109\/WCRE.2005.13 . http:\/\/dl.acm.org\/citation.cfm?id=1107841.1108171","DOI":"10.1109\/WCRE.2005.13"},{"key":"9625_CR34","unstructured":"Vectra (2017) Attacker behavior industry report. https:\/\/info.vectra.ai\/attacker-behavior-industry-report-1q2017 https:\/\/info.vectra.ai\/attacker-behavior-industry-report-1q2017"},{"key":"9625_CR35","doi-asserted-by":"crossref","unstructured":"Viticchi\u00e9 A, Regano L, Torchiano M, Basile C, Ceccato M, Tonella P, Tiella R (2016) Assessment of source code obfuscation techniques. In: Proceedings of the 16th IEEE international working conference on source code analysis and manipulation, pp 11\u201320","DOI":"10.1109\/SCAM.2016.17"},{"key":"9625_CR36","doi-asserted-by":"crossref","unstructured":"von Mayrhauser A, Vans AM (1994) Comprehension processes during large scale maintenance. In: Proceedings of the 16th international conference on software engineering, Sorrento, Italy, May 16\u201321, pp 39\u201348","DOI":"10.1109\/ICSE.1994.296764"},{"issue":"5","key":"9625_CR37","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1049\/sej.1995.0023","volume":"10","author":"A von Mayrhauser","year":"1995","unstructured":"von Mayrhauser A, Vans AM (1995) Industrial experience with an integrated code comprehension model. Softw Eng J 10(5):171\u2013182","journal-title":"Softw Eng J"},{"key":"9625_CR38","doi-asserted-by":"crossref","unstructured":"von Mayrhauser A, Vans AM (1996a) Identification of dynamic comprehension processes during large scale maintenance. IEEE Trans Softw Eng 22(6):424\u2013437","DOI":"10.1109\/32.508315"},{"key":"9625_CR39","doi-asserted-by":"crossref","unstructured":"von Mayrhauser A, Vans AM (1996b) On the role of hypotheses during opportunistic understanding while porting large scale code. In: 4th international workshop on program comprehension (WPC \u201996), March 29\u201331, 1996, Berlin, Germany, pp 68\u201377","DOI":"10.1109\/WPC.1996.501122"},{"key":"9625_CR40","doi-asserted-by":"crossref","unstructured":"von Mayrhauser A, Vans AM (1997a) Hypothesis-driven understanding processes during corrective maintenance of large scale software. In: 1997 international conference on software maintenance (ICSM \u201997), 1\u20133 October 1997, Bari, Italy, Proceedings, pp 12\u201320","DOI":"10.1109\/ICSM.1997.624226"},{"key":"9625_CR41","doi-asserted-by":"crossref","unstructured":"von Mayrhauser A, Vans AM (1997b) Program understanding needs during corrective maintenance of large scale software. In: 21st intern. computer software and applications conference (COMPSAC\u201997), 1997, USA, pp 630\u2013637","DOI":"10.1109\/CMPSAC.1997.625084"},{"key":"9625_CR42","unstructured":"Wheeler DA (2001) More than a gigabuck: estimating gnu\/Linux\u2019s size. https:\/\/www.dwheeler.com\/sloc\/redhat71-v1\/redhat71sloc.html"},{"key":"9625_CR43","unstructured":"Wyseur B (2009) White-box cryptography. Ph.D. thesis, Katholieke Universiteit Leuven. https:\/\/www.cosic.esat.kuleuven.be\/publications\/thesis-152.pdf"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10664-018-9625-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-018-9625-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-018-9625-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,4]],"date-time":"2025-07-04T19:42:06Z","timestamp":1751658126000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10664-018-9625-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,5,26]]},"references-count":43,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2019,2]]}},"alternative-id":["9625"],"URL":"https:\/\/doi.org\/10.1007\/s10664-018-9625-6","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,5,26]]},"assertion":[{"value":"26 May 2018","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}