{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T03:55:31Z","timestamp":1783569331590,"version":"3.55.0"},"reference-count":118,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2025,5,28]],"date-time":"2025-05-28T00:00:00Z","timestamp":1748390400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,5,28]],"date-time":"2025-05-28T00:00:00Z","timestamp":1748390400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["EXC 2092 CASA- 390781972"],"award-info":[{"award-number":["EXC 2092 CASA- 390781972"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["EXC 2092 CASA- 390781972"],"award-info":[{"award-number":["EXC 2092 CASA- 390781972"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["EXC 2092 CASA- 390781972"],"award-info":[{"award-number":["EXC 2092 CASA- 390781972"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["EXC 2092 CASA- 390781972"],"award-info":[{"award-number":["EXC 2092 CASA- 390781972"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2025,9]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Security must be considered in almost every software system. Unfortunately, selecting and implementing security features remains a challenge due to the wide variety of security threats and possible countermeasures. While security standards are intended to help developers, they are usually too abstract and vague to help implementing security features, or they merely help configuring such. A resource that describes security features at an abstraction level that lies between high-level (i.e., rather too general) and low-level (i.e., rather too specific) security standards could facilitate secure systems development. This resource should support the selection of appropriate security features to achieve high-level security goals, allow easy retrieval of relevant low-level details, and provide pointers to suitable ways to realize the security features. To realize security features, developers typically use external security libraries or frameworks, to minimize implementation mistakes. Even when using libraries, developers still make mistakes when writing code to integrate them, often resulting in security vulnerabilities. When security incidents occur or the system needs to be audited or maintained, it is essential to know what security features have been implemented and, more importantly, where they are located. This task, commonly referred to as feature location, is often tedious and error-prone. While dedicated feature location techniques exist, they require significant manual effort or adherence to strict development processes, preventing their use. Therefore, we have to support long-term tracking of implemented security features. We present a study of security features presented in the literature and their coverage in popular security frameworks. We contribute (1) a taxonomy of 68 functional implementation-level security features including a mapping to widely used security standards, (2) an examination of 21 popular security frameworks concerning which of these security features they provide, and (3) a discussion on the representation of security features in source code. Our taxonomy aims to aid developers in selecting appropriate security features and security frameworks, as well as relating them to security standards when they need to choose and implement security features for a software system.<\/jats:p>","DOI":"10.1007\/s10664-025-10649-7","type":"journal-article","created":{"date-parts":[[2025,5,28]],"date-time":"2025-05-28T06:05:08Z","timestamp":1748412308000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["A taxonomy of functional security features and how they can be located"],"prefix":"10.1007","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-6207-4045","authenticated-orcid":false,"given":"Kevin","family":"Hermann","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8605-615X","authenticated-orcid":false,"given":"Simon","family":"Schneider","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9916-4456","authenticated-orcid":false,"given":"Catherine","family":"Tony","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-6117-6581","authenticated-orcid":false,"given":"Asli","family":"Yardim","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2604-0487","authenticated-orcid":false,"given":"Sven","family":"Peldszus","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3870-5167","authenticated-orcid":false,"given":"Thorsten","family":"Berger","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3591-7671","authenticated-orcid":false,"given":"Riccardo","family":"Scandariato","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1823-5505","authenticated-orcid":false,"given":"M. Angela","family":"Sasse","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-1843-2027","authenticated-orcid":false,"given":"Alena","family":"Naiakshina","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,5,28]]},"reference":[{"key":"10649_CR1","unstructured":"Abbas A, Saddik AE, Miri A (2005) A State Of The Art Security Taxonomy Of Internet Security: Threats And Countermeasures. Computer Science"},{"key":"10649_CR2","doi-asserted-by":"publisher","unstructured":"Abukwaik H, Burger A, Andam BK, et\u00a0al (2018) Semi-Automated Feature Traceability With Embedded Annotations. In: International Conference on Software Maintenance and Evolution (ICSME), pp 529\u2013533, https:\/\/doi.org\/10.1109\/ICSME.2018.00049","DOI":"10.1109\/ICSME.2018.00049"},{"key":"10649_CR3","doi-asserted-by":"publisher","unstructured":"Acar Y, Backes M, Fahl S, et\u00a0al (2017) Comparing The Usability Of Cryptographic APIs. In: 2017 IEEE Symposium on Security and Privacy (S&P), pp 154\u201317https:\/\/doi.org\/10.1109\/SP.2017.52","DOI":"10.1109\/SP.2017.52"},{"issue":"3","key":"10649_CR4","doi-asserted-by":"publisher","first-page":"423","DOI":"10.1007\/s11235-017-0345-9","volume":"67","author":"V Adat","year":"2018","unstructured":"Adat V, Gupta BB (2018) Security In Internet Of Things: Issues, Challenges, Taxonomy. And Architecture. Telecommunication Systems 67(3):423\u201344. https:\/\/doi.org\/10.1007\/s11235-017-0345-9","journal-title":"And Architecture. Telecommunication Systems"},{"key":"10649_CR5","doi-asserted-by":"publisher","unstructured":"Ahmadian AS, Peldszus S, Ramadan Q, et\u00a0al (2017) Model-Based Privacy And Security Analysis With CARiSMA. In: Joint Meeting on Foundations of Software Engineering (ESEC\/FSE), pp 989\u2013993,https:\/\/doi.org\/10.1145\/3106237.3122823","DOI":"10.1145\/3106237.3122823"},{"key":"10649_CR6","doi-asserted-by":"publisher","unstructured":"Andam B, Burger A, Berger T, et\u00a0al (2017) FLOrIDA: Feature LOcatIon DAshboard for extracting and visualizing feature traces. In: International Workshop on Variability Modelling of Software-intensive Systems (VaMoS). ACM, pp 100\u201310https:\/\/doi.org\/10.1145\/3023956.3023967","DOI":"10.1145\/3023956.3023967"},{"key":"10649_CR7","doi-asserted-by":"publisher","unstructured":"Ardagna CA, Cremonini M, De\u00a0Capitani\u00a0di Vimercati S, et\u00a0al (2009) Access Control in Location-Based Services, Springer, pp 106\u2013126.https:\/\/doi.org\/10.1007\/978-3-642-03511-1_5","DOI":"10.1007\/978-3-642-03511-1_5"},{"key":"10649_CR8","doi-asserted-by":"crossref","unstructured":"Baitha AK, Vinod S (2018) Session Hijacking And Prevention Technique. International Journal of Engineering & Technology 7(2.6):193\u2013198","DOI":"10.14419\/ijet.v7i2.6.10566"},{"issue":"6","key":"10649_CR9","doi-asserted-by":"publisher","first-page":"355","DOI":"10.1109\/TSE.2004.23","volume":"30","author":"D Batory","year":"2004","unstructured":"Batory D, Sarvela JN, Rauschmayer A (2004) Scaling Step-Wise Refinement. IEEE Trans Software Eng 30(6):355\u2013371","journal-title":"IEEE Trans Software Eng"},{"key":"10649_CR10","volume-title":"Vulnerability Factors In New Web Applications: Audit Tools","author":"J Bau","year":"2012","unstructured":"Bau J, Wang F, Bursztein E et al (2012) Vulnerability Factors In New Web Applications: Audit Tools. Developer Selection & Languages, Stanford, Tech Rep"},{"key":"10649_CR11","unstructured":"BBC (2020) Police Launch Homicide Inquiry After German Hospital Hack. https:\/\/www.bbc.com\/news\/technology-54204356\/, [Online; accessed 04-December-2024]"},{"key":"10649_CR12","doi-asserted-by":"publisher","unstructured":"ben Othmane L, Chehrazi G, Bodden E, et\u00a0al (2015) Factors Impacting The Effort Required To Fix Security Vulnerabilities. In: Information Security, Lecture Notes in Computer Science, vol 9290. Springer, p 102\u20131https:\/\/doi.org\/10.1007\/978-3-319-23318-5_6","DOI":"10.1007\/978-3-319-23318-5_6"},{"key":"10649_CR13","doi-asserted-by":"publisher","unstructured":"ben Othmane L, Chehrazi G, Bodden E et al (2017) Time For Addressing Software Security Issues: Prediction Models And Impacting Factors. Data Science and Engineering 2(2):107\u2013124. https:\/\/doi.org\/10.1007\/s41019-016-0019-8","DOI":"10.1007\/s41019-016-0019-8"},{"key":"10649_CR14","doi-asserted-by":"publisher","unstructured":"Bergel A, Ghzouli R, Berger T, et\u00a0al (2021) FeatureVista: interactive feature visualization. In: ACM International Systems and Software Product Line Conference - Volume A. ACM, pp 196\u201320https:\/\/doi.org\/10.1145\/3461001.3471154","DOI":"10.1145\/3461001.3471154"},{"key":"10649_CR15","doi-asserted-by":"crossref","unstructured":"Berger T, Lettner D, Rubin J, et\u00a0al (2015) What Is a Feature? A Qualitative Study of Features in Industrial Software Product Lines. In: Systems and Software Product Line Conference","DOI":"10.1145\/2791060.2791108"},{"key":"10649_CR16","doi-asserted-by":"crossref","unstructured":"Bertino E, Ghinita G, Kamra A (2011) Access Control for Databases: Concepts and Systems. Now Foundations and Trends","DOI":"10.1561\/9781601984173"},{"issue":"4","key":"10649_CR17","doi-asserted-by":"publisher","first-page":"289","DOI":"10.14257\/ijsia.2015.9.4.27","volume":"9","author":"R Bhanot","year":"2015","unstructured":"Bhanot R, Hans R (2015) A Review and Comparative Analysis of Various Encryption Algorithms. International Journal of Security and Its Applications 9(4):289\u2013306","journal-title":"International Journal of Security and Its Applications"},{"issue":"6","key":"10649_CR18","doi-asserted-by":"publisher","first-page":"2558","DOI":"10.1007\/s11227-016-1945-y","volume":"73","author":"T Bhatia","year":"2017","unstructured":"Bhatia T, Verma AK (2017) Data Security in Mobile Cloud Computing Paradigm: A Survey, Taxonomy and Open Research Issues. Journal of Supercomputing 73(6):2558\u2013263. https:\/\/doi.org\/10.1007\/s11227-016-1945-y","journal-title":"Journal of Supercomputing"},{"issue":"5","key":"10649_CR19","doi-asserted-by":"publisher","first-page":"72","DOI":"10.1145\/175290.175300","volume":"37","author":"TJ Biggerstaff","year":"1994","unstructured":"Biggerstaff TJ, Mitbander BG, Webster DE (1994) Program Understanding and the Concept Assignment Problem. Commun ACM 37(5):72\u201382","journal-title":"Commun ACM"},{"key":"10649_CR20","doi-asserted-by":"publisher","unstructured":"Blythe JM, Sombatruang N, Johnson SD (2019) What Security Features and Crime Prevention Advice Is Communicated in Consumer Iot Device Manuals and Support Pages? Journal of Cybersecurity 5(1https:\/\/doi.org\/10.1093\/cybsec\/tyz005","DOI":"10.1093\/cybsec\/tyz005"},{"key":"10649_CR21","doi-asserted-by":"crossref","unstructured":"Bokhari MU, Shallal QM (2016) A Review on Symmetric Key Encryption Techniques in Cryptography. International journal of computer applications 147(10)","DOI":"10.5120\/ijca2016911203"},{"key":"10649_CR22","unstructured":"Bosch J (2000) Design & Use of Software Architectures-Adopting and Evolving a Product Line Approach. Pearson Education Ltd"},{"issue":"2","key":"10649_CR23","first-page":"233","volume":"9","author":"M Busch","year":"2015","unstructured":"Busch M, Wirsing M (2015) An Ontology for Secure Web Applications. International Journal of Software and Informatics 9(2):233\u2013258","journal-title":"International Journal of Software and Informatics"},{"key":"10649_CR24","doi-asserted-by":"crossref","unstructured":"Chen K, Zhang W, Zhao H, et\u00a0al (2005) An Approach to Constructing Feature Models Based on Requirements Clustering. In: International Conference on Requirements Engineering (RE), pp 31\u201340","DOI":"10.1109\/RE.2005.9"},{"key":"10649_CR25","doi-asserted-by":"publisher","unstructured":"Chung, Ferraiolo D, Kuhn D, et\u00a0al (2019) Guide to Attribute Based Access Control (ABAC) Definition and Considerations.https:\/\/doi.org\/10.6028\/NIST.SP.800-162","DOI":"10.6028\/NIST.SP.800-162"},{"key":"10649_CR26","unstructured":"Cornell D (2012) Remediation Statistics: What Does Fixing Application Vulnerabilities Cost. In: RSA Conference"},{"key":"10649_CR27","doi-asserted-by":"crossref","unstructured":"Denker G, Kagal L, Finin TW, et\u00a0al (2003) Security for DAML web services: Annotation and matchmaking. In: International Semantic Web Conference, Lecture Notes in Computer Science, vol 2870. Springer, pp 335\u2013350","DOI":"10.1007\/978-3-540-39718-2_22"},{"issue":"5","key":"10649_CR28","doi-asserted-by":"publisher","first-page":"236","DOI":"10.1145\/360051.360056","volume":"19","author":"DE Denning","year":"1976","unstructured":"Denning DE (1976) A Lattice Model of Secure Information Flow. Commun ACM 19(5):236\u201324. https:\/\/doi.org\/10.1145\/360051.360056","journal-title":"Commun ACM"},{"key":"10649_CR29","unstructured":"Dent AW (2004) Hybrid cryptography. Cryptology ePrint Archive, Paper 2004\/210, https:\/\/eprint.iacr.org\/2004\/210"},{"key":"10649_CR30","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1002\/smr.567","volume":"25","author":"B Dit","year":"2013","unstructured":"Dit B, Revelle M, Gethers M et al (2013) Feature Location in Source Code: A Taxonomy and Survey. J Softw Maint Evol Res Pract 25:53\u201395. https:\/\/doi.org\/10.1002\/smr.567","journal-title":"J Softw Maint Evol Res Pract"},{"key":"10649_CR31","doi-asserted-by":"publisher","unstructured":"Dougherty C, Sayre K, Seacord R, et\u00a0al (2009) Secure Design Patterns. Tech. Rep. CMU\/SEI-2009-TR-010, Carnegie Mellon University, Software Engineering Institute\u2019s Digital Librarhttps:\/\/doi.org\/10.1184\/R1\/6583640.v1","DOI":"10.1184\/R1\/6583640.v1"},{"key":"10649_CR32","doi-asserted-by":"crossref","unstructured":"Egele M, Brumley D, Fratantonio Y, et\u00a0al (2013) An Empirical Study of Cryptographic Misuse in Android Applications. In: ACM SIGSAC conference on Computer & communications security, ACM, pp 73\u201384","DOI":"10.1145\/2508859.2516693"},{"key":"10649_CR33","doi-asserted-by":"publisher","unstructured":"Entekhabi S, Solback A, Stegh\u00f6fer JP, et\u00a0al (2019) Visualization of Feature Locations With the Tool FeatureDashboard. In: International Systems and Software Product Line Conference volume B. ACM, pp 1\u20134,https:\/\/doi.org\/10.1145\/3307630.3342392","DOI":"10.1145\/3307630.3342392"},{"key":"10649_CR34","unstructured":"European Parliament and Council of the European Union (2017) Regulation (EU) 2017\/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, amending Directive 2001\/83\/EC, Regulation (EC) No 178\/2002 and Regulation (EC) No 1223\/2009 and repealing Council Directives 90\/385\/EEC and 93\/42\/EEC. URL https:\/\/eur-lex.europa.eu\/eli\/reg\/2017\/745\/oj, [Online; accessed 19-December-2024]"},{"key":"10649_CR35","doi-asserted-by":"crossref","unstructured":"Fahl S, Harbach M, Perl H, et\u00a0al (2013) Rethinking SSL development in an appified world. In: ACM SIGSAC conference on Computer & communications security, ACM, pp 49\u201360","DOI":"10.1145\/2508859.2516655"},{"key":"10649_CR36","doi-asserted-by":"publisher","unstructured":"Fang W, Miller BP, Kupsch JA (2012) Automated Tracing and Visualization of Software Security Structure and Properties. In: 9th International Symposium on Visualization for Cyber Security (VizSec). ACM, pp 9\u201316,https:\/\/doi.org\/10.1145\/2379690.2379692","DOI":"10.1145\/2379690.2379692"},{"key":"10649_CR37","unstructured":"Ferraiolo DF, Kuhn DR (2009) Role-Based Access Controls. ArXiv abs\/0903.2171"},{"key":"10649_CR38","doi-asserted-by":"publisher","unstructured":"Ghafir I, Prenosil V, Svoboda J, et\u00a0al (2016) A Survey on Network Security Monitoring Systems. In: 2016 IEEE 4th International Conference on Future Internet of Things and Cloud Workshops (FiCloudW), pp 77\u201382,https:\/\/doi.org\/10.1109\/W-FiCloud.2016.30","DOI":"10.1109\/W-FiCloud.2016.30"},{"key":"10649_CR39","unstructured":"Glaser B (1978) Theoretical Sensitivity: Advances in the Methodology of Grounded Theory. Advances in the methodology of grounded theory, Sociology Press"},{"key":"10649_CR40","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1186\/s40294-014-0005-9","volume":"2","author":"U Habiba","year":"2014","unstructured":"Habiba U, Masood R, Shibli MA et al (2014) Cloud identity management security issues & solutions: a taxonomy. Complex Adaptive Systems Modeling 2:5. https:\/\/doi.org\/10.1186\/s40294-014-0005-9","journal-title":"Complex Adaptive Systems Modeling"},{"key":"10649_CR41","doi-asserted-by":"crossref","unstructured":"Hakeem A, Shah M (2004) Ontology and taxonomy collaborated framework for meeting classification. In: International Conference on Pattern Recognition, IEEE, pp 219\u2013222","DOI":"10.1109\/ICPR.2004.1333743"},{"issue":"1","key":"10649_CR42","doi-asserted-by":"publisher","first-page":"325","DOI":"10.1007\/s11277-019-06405-y","volume":"108","author":"Y Harbi","year":"2019","unstructured":"Harbi Y, Aliouat Z, Harous S et al (2019) A Review of Security in Internet of Things. Wireless Pers Commun 108(1):325\u2013344. https:\/\/doi.org\/10.1007\/s11277-019-06405-y","journal-title":"Wireless Pers Commun"},{"key":"10649_CR43","unstructured":"Harzing A (2007) Publish or perish. URL https:\/\/harzing.com\/resources\/publish-or-perish, online; accessed 20-December-2023"},{"key":"10649_CR44","doi-asserted-by":"publisher","unstructured":"Hendre A, Joshi KP (2015) A Semantic Approach to Cloud Security and Compliance. In: Pu C, Mohindra A (eds) 8th IEEE International Conference on Cloud Computing (CLOUD). IEEE, pp 1081\u2013108https:\/\/doi.org\/10.1109\/CLOUD.2015.157","DOI":"10.1109\/CLOUD.2015.157"},{"key":"10649_CR45","doi-asserted-by":"crossref","unstructured":"Hermann K, Peldszus S, Stegh\u00f6fer JP, et\u00a0al (2025) An Exploratory Study on the Engineering of Security Features. In: International Conference on Software Engineering (ICSE)","DOI":"10.1109\/ICSE55347.2025.00184"},{"issue":"4","key":"10649_CR46","doi-asserted-by":"publisher","first-page":"1","DOI":"10.4018\/jisp.2007100101","volume":"1","author":"A Herzog","year":"2007","unstructured":"Herzog A, Shahmehri N, Duma C (2007) An Ontology of Information Security. Int J Inf Secur Priv 1(4):1\u201323. https:\/\/doi.org\/10.4018\/jisp.2007100101","journal-title":"Int J Inf Secur Priv"},{"key":"10649_CR47","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1007\/s10664-008-9064-x","volume":"14","author":"R Hewett","year":"2009","unstructured":"Hewett R, Kijsanayothin P (2009) On modeling software defect repair time. Empir Softw Eng 14:165\u201318. https:\/\/doi.org\/10.1007\/s10664-008-9064-x","journal-title":"Empir Softw Eng"},{"key":"10649_CR48","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/s00766-009-0093-9","volume":"15","author":"S Houmb","year":"2010","unstructured":"Houmb S, Islam S, Knauss E et al (2010) Eliciting security requirements and tracing them to design: An integration of Common Criteria, heuristics, and UMLsec. Requirements Eng 15:63\u20139. https:\/\/doi.org\/10.1007\/s00766-009-0093-9","journal-title":"Requirements Eng"},{"key":"10649_CR49","unstructured":"IBM (2023a) Discretionary access control (MAC). URL https:\/\/www.ibm.com\/docs\/en\/zos\/3.1.0?topic=controls-discretionary-access-control-dac, accessed: 2023-Dec-20"},{"key":"10649_CR50","unstructured":"IBM (2023b) IBM Engineering Requirements Management DOORS Family. URL https:\/\/www.ibm.com\/docs\/en\/engineering-lifecycle-management-suite\/doors\/9.7.2, online; accessed 20-December-2023"},{"key":"10649_CR51","unstructured":"IBM (2023c) Mandatory access control (MAC). URL https:\/\/www.ibm.com\/docs\/en\/zos\/3.1.0?topic=environment-mandatory-access-control-mac, accessed: 2023-Dec-20"},{"key":"10649_CR52","doi-asserted-by":"publisher","first-page":"369","DOI":"10.1007\/s10270-010-0154-z","volume":"10","author":"S Islam","year":"2011","unstructured":"Islam S, Mouratidis H, J\u00fcrjens J (2011) A framework to support alignment of secure software engineering with legal regulations. Software and System Modeling 10:369\u201339. https:\/\/doi.org\/10.1007\/s10270-010-0154-z","journal-title":"Software and System Modeling"},{"key":"10649_CR53","unstructured":"ISO\/IEC JTC 1\/SC 27 (2009) Common Criteria for Information Technology Security Evaluation. International Standard ISO\/IEC 15408, International Organization for Standardization (ISO)"},{"key":"10649_CR54","unstructured":"ISO\/TC 22\/SC 32 (2021) Road vehicles \u2013 Cybersecurity engineering. International Standard ISO\/SAE 21434, International Organization for Standardization (ISO)"},{"key":"10649_CR55","doi-asserted-by":"publisher","unstructured":"Jakobsen J, Orlandi C (2016) On the CCA (in)Security of MTProto. In: Workshop on Security and Privacy in Smartphones and Mobile Devices, p 113-116,https:\/\/doi.org\/10.1145\/2994459.2994468","DOI":"10.1145\/2994459.2994468"},{"key":"10649_CR56","doi-asserted-by":"publisher","unstructured":"Ji W, Berger T, Antkiewicz M, et\u00a0al (2015) Maintaining Feature Traceability with Embedded Annotations. In: International Conference on Software Product Line. ACM, pp 61\u20137https:\/\/doi.org\/10.1145\/2791060.2791107","DOI":"10.1145\/2791060.2791107"},{"key":"10649_CR57","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11432-018-9929-x","volume":"63","author":"L Jiao","year":"2020","unstructured":"Jiao L, Hao Y, Feng D (2020) Stream cipher designs: a review. SCIENCE CHINA Inf Sci 63:1\u201325","journal-title":"SCIENCE CHINA Inf Sci"},{"key":"10649_CR58","doi-asserted-by":"publisher","unstructured":"Jin X, Sandhu R, Krishnan R (2012) RABAC: Role-Centric Attribute-Based Access Control. In: International Conference on Mathematical Methods, Models, and Architectures for Computer Network Security (MMM-ACNS),https:\/\/doi.org\/10.1007\/978-3-642-33704-8_8","DOI":"10.1007\/978-3-642-33704-8_8"},{"key":"10649_CR59","doi-asserted-by":"publisher","unstructured":"Johns M, Braun B, Schrank M, et\u00a0al (2011) Reliable Protection against Session Fixation Attacks. In: ACM Symposium on Applied Computing. ACM, SAC \u201911, p 1531-153https:\/\/doi.org\/10.1145\/1982185.1982511","DOI":"10.1145\/1982185.1982511"},{"key":"10649_CR60","volume-title":"Secure Systems Development with UML","author":"J J\u00fcrjens","year":"2005","unstructured":"J\u00fcrjens J (2005) Secure Systems Development with UML. Springer"},{"key":"10649_CR61","doi-asserted-by":"crossref","unstructured":"Kamra A, Bertino E (2010) Privilege States Based Access Control for Fine-Grained Intrusion Response. In: International Conference on Recent Advances in Intrusion Detection. Springer-Verlag, Berlin, Heidelberg, RAID\u201910, p 402-421","DOI":"10.1007\/978-3-642-15512-3_21"},{"key":"10649_CR62","doi-asserted-by":"crossref","unstructured":"Kang K, Cohen S, Hess J, et\u00a0al (1990) Feature-Oriented Domain Analysis (FODA) Feasibility Study. Tech. Rep. CMU\/SEI-90-TR-021, Software Engineering Institute, Carnegie Mellon University, Pittsburgh, PA","DOI":"10.21236\/ADA235785"},{"key":"10649_CR63","doi-asserted-by":"publisher","unstructured":"Kang W, Liang Y (2013) A security ontology with MDA for software development. In: International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC). IEEE, pp 67\u20137https:\/\/doi.org\/10.1109\/CyberC.2013.20","DOI":"10.1109\/CyberC.2013.20"},{"key":"10649_CR64","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-27712-7","volume-title":"Digital signatures,","author":"J Katz","year":"2010","unstructured":"Katz J (2010) Digital signatures, vol 1. Springer"},{"key":"10649_CR65","doi-asserted-by":"publisher","unstructured":"Kaur R, Singh A, Singh S, et\u00a0al (2016) Security of software defined networks: Taxonomic modeling, key components and open research area. In: 2016 International Conference on Electrical, Electronics, and Optimization Techniques (ICEEOT), pp 2832\u2013283https:\/\/doi.org\/10.1109\/ICEEOT.2016.7755214","DOI":"10.1109\/ICEEOT.2016.7755214"},{"key":"10649_CR66","doi-asserted-by":"publisher","first-page":"219709","DOI":"10.1109\/ACCESS.2020.3037359","volume":"8","author":"S Khanam","year":"2020","unstructured":"Khanam S, Ahmedy IB, Idris MYIB et al (2020) A Survey of Security Challenges, Attacks Taxonomy and Advanced Countermeasures in the Internet of Things. IEEE Access 8:219709\u201321974. https:\/\/doi.org\/10.1109\/ACCESS.2020.3037359","journal-title":"IEEE Access"},{"key":"10649_CR67","doi-asserted-by":"publisher","unstructured":"Kim A, Luo J, Kang MH (2007) Security Ontology to Facilitate Web Service Description and Discovery. Journal on Data Semantics 9:167\u2013195. https:\/\/doi.org\/10.1007\/978-3-540-74987-5_6","DOI":"10.1007\/978-3-540-74987-5_6"},{"key":"10649_CR68","unstructured":"Kour J, Verma D (2014) Steganography techniques\u2013A review paper. International Journal of Emerging Research in Management &Technology ISSN pp 2278\u20139359"},{"key":"10649_CR69","unstructured":"Krombholz K, Mayer W, Schmiedecker M, et\u00a0al (2017) \"I Have No Idea What I\u2019m Doing\" - On the Usability of Deploying HTTPS. In: 26th USENIX Security Symposium. USENIX Association, pp 1339\u20131356"},{"key":"10649_CR70","doi-asserted-by":"publisher","unstructured":"Krueger J, Berger T, Leich T (2019) Software Engineering for Variability Intensive Systems, Auerbach Publications, pp 153\u2013172.https:\/\/doi.org\/10.1201\/9780429022067-7","DOI":"10.1201\/9780429022067-7"},{"key":"10649_CR71","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cosrev.2019.05.002","volume":"33","author":"R Kumar","year":"2019","unstructured":"Kumar R, Goyal R (2019) On cloud security requirements, threats, vulnerabilities and countermeasures: A survey. Computer Science Reviews 33:1\u20134. https:\/\/doi.org\/10.1016\/j.cosrev.2019.05.002","journal-title":"Computer Science Reviews"},{"key":"10649_CR72","doi-asserted-by":"crossref","unstructured":"Lazar D, Chen H, Wang X, et\u00a0al (2014) Why Does Cryptographic Software Fail?: A Case Study And Open Problems. In: Asia-Pacific Workshop on Systems, ACM, p\u00a07","DOI":"10.1145\/2637166.2637237"},{"key":"10649_CR73","doi-asserted-by":"publisher","unstructured":"L\u00f6hr H, Sadeghi AR, Winandy M (2010) Patterns for Secure Boot and Secure Storage in Computer Systems. In: 2010 International Conference on Availability, Reliability and Security (ARES), pp 569\u2013573,https:\/\/doi.org\/10.1109\/ARES.2010.110","DOI":"10.1109\/ARES.2010.110"},{"key":"10649_CR74","doi-asserted-by":"crossref","unstructured":"Mahapatra S, Singh B, Kumar V (2020) A survey on secure transmission in internet of things: Taxonomy, recent techniques, research requirements, and challenges. Arab Journal for Science and Engineering p 6211-6240","DOI":"10.1007\/s13369-020-04461-2"},{"key":"10649_CR75","doi-asserted-by":"publisher","unstructured":"Martinson J, Jansson H, Mukelabai M, et\u00a0al (2021) HAnS: IDE-based Editing Support for Embedded Feature Annotations. In: International Systems and Software Product Line Conference (SPLC), pp 28\u201331,https:\/\/doi.org\/10.1145\/3461002.3473072","DOI":"10.1145\/3461002.3473072"},{"key":"10649_CR76","doi-asserted-by":"publisher","unstructured":"McDonald N, Schoenebeck S, Forte A (2019) Reliability and Inter-rater Reliability in Qualitative Research: Norms and Guidelines for CSCW and HCI Practice. Proceedings of the ACM on Human-Computer Interaction 3(CSCW).https:\/\/doi.org\/10.1145\/3359174","DOI":"10.1145\/3359174"},{"issue":"2","key":"10649_CR77","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1109\/MSECP.2004.1281254","volume":"2","author":"G McGraw","year":"2004","unstructured":"McGraw G (2004) Software security. IEEE Security & Privacy 2(2):80\u201383. https:\/\/doi.org\/10.1109\/MSECP.2004.1281254","journal-title":"IEEE Security & Privacy"},{"issue":"2","key":"10649_CR78","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1145\/997150.997156","volume":"34","author":"J Mirkovic","year":"2004","unstructured":"Mirkovic J, Reiher P (2004) A Taxonomy of DDoS Attack and DDoS Defense Mechanisms. SIGCOMM Computer Communincation Reviews 34(2):39\u201353. https:\/\/doi.org\/10.1145\/997150.997156","journal-title":"SIGCOMM Computer Communincation Reviews"},{"issue":"12","key":"10649_CR79","doi-asserted-by":"publisher","first-page":"5060","DOI":"10.1109\/TSE.2023.3324719","volume":"49","author":"M Mukelabai","year":"2023","unstructured":"Mukelabai M, Hermann K, Berger T et al (2023) FeatRacer: Locating Features Through Assisted Traceability. IEEE Trans Software Eng 49(12):5060\u2013508. https:\/\/doi.org\/10.1109\/TSE.2023.3324719","journal-title":"IEEE Trans Software Eng"},{"key":"10649_CR80","doi-asserted-by":"crossref","unstructured":"Nadi S, Kr\u00fcger S, Mezini M, et\u00a0al (2016) Jumping Through Hoops: Why Do Java Developers Struggle With Cryptography APIs? In: International Conference on Software Engineering, ACM, pp 935\u2013946","DOI":"10.1145\/2884781.2884790"},{"key":"10649_CR81","doi-asserted-by":"publisher","unstructured":"Oyetoyan TD, Cruzes DS, Jaatun MG (2016) An Empirical Study on the Relationship between Software Security Skills, Usage and Training Needs in Agile Settings. In: 2016 11th International Conference on Availability, Reliability and Security (ARES), pp 548\u201355https:\/\/doi.org\/10.1109\/ARES.2016.103","DOI":"10.1109\/ARES.2016.103"},{"key":"10649_CR82","doi-asserted-by":"publisher","unstructured":"Oyetoyan TD, Jaatun MG, Cruzes DS (2019) Measuring Developers\u2019 Software Security Skills, Usage, and Training Needs. In: Exploring Security in Software Architecture and Design, pp 260\u2013286,https:\/\/doi.org\/10.4018\/978-1-5225-6313-6.ch011","DOI":"10.4018\/978-1-5225-6313-6.ch011"},{"key":"10649_CR83","unstructured":"Patnaik N, Hallett J, Rashid A (2019) Usability smells: An analysis of Developers\u2019 struggle with crypto libraries. In: Fifteenth Symposium on Usable Privacy and Security (SOUPS 2019). USENIX Association, pp 245\u2013257"},{"key":"10649_CR84","unstructured":"Peldszus S (2020) Development of Secure Software with GRaViTY. In: Workshop on Software-Reengineering & -Evolution"},{"key":"10649_CR85","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-658-37665-9_6","author":"S Peldszus","year":"2022","unstructured":"Peldszus S (2022) Security Compliance in Model-driven Development of Software Systems in Presence of Long-Term Evolution and Variants. Springer. https:\/\/doi.org\/10.1007\/978-3-658-37665-9_6","journal-title":"Springer"},{"key":"10649_CR86","doi-asserted-by":"publisher","unstructured":"Peldszus S, Tuma K, Str\u00fcber D, et\u00a0al (2019) Secure Data-Flow Compliance Checks between Models and Code based on Automated Mappings. In: International Conference on Model-driven Engineering Languages and Systems (MODELS). IEEE, pp 23\u20133https:\/\/doi.org\/10.1109\/MODELS.2019.00-18","DOI":"10.1109\/MODELS.2019.00-18"},{"key":"10649_CR87","doi-asserted-by":"publisher","unstructured":"Peldszus S, B\u00fcrger J, Kehrer T et al (2021) Ontology-Driven Evolution of Software Security. Data & Knowledge Engineering (DKE) 134:101907. https:\/\/doi.org\/10.1016\/j.datak.2021.101907","DOI":"10.1016\/j.datak.2021.101907"},{"key":"10649_CR88","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/TSE.2023.3326366","volume":"01","author":"S Peldszus","year":"2024","unstructured":"Peldszus S, Burger J, Jurjens J (2024) UMLsecRT: Reactive Security Monitoring of Java Applications with Round-Trip Engineering. IEEE Trans Software Eng 01:1\u20133. https:\/\/doi.org\/10.1109\/TSE.2023.3326366","journal-title":"IEEE Trans Software Eng"},{"issue":"5","key":"10649_CR89","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1109\/MSP.2004.84","volume":"2","author":"B Potter","year":"2004","unstructured":"Potter B, McGraw G (2004) Software security testing. IEEE Security & Privacy 2(5):81\u20138. https:\/\/doi.org\/10.1109\/MSP.2004.84","journal-title":"IEEE Security & Privacy"},{"key":"10649_CR90","unstructured":"Ralph P, bin Ali N, Baltes S, et\u00a0al (2021) Empirical Standards for Software Engineering Research. 2010.03525"},{"key":"10649_CR91","doi-asserted-by":"publisher","first-page":"10360","DOI":"10.1016\/j.jisa.2023.103607","volume":"78","author":"S Rana","year":"2023","unstructured":"Rana S, Parast FK, Kelly B et al (2023) A comprehensive survey of cryptography key management systems. Journal of Information Security and Applications 78:10360. https:\/\/doi.org\/10.1016\/j.jisa.2023.103607","journal-title":"Journal of Information Security and Applications"},{"key":"10649_CR92","unstructured":"Replication Package (2025) Replication Package. https:\/\/doi.org\/10.5281\/zenodo.11091429"},{"key":"10649_CR93","doi-asserted-by":"publisher","unstructured":"Revelle M, Broadbent T, Coppit D (2005) Understanding Concerns in Software: Insights Gained from Two Case Studies. In: 13th International Workshop on Program Comprehension (IWPC). IEEE, pp 23\u20133https:\/\/doi.org\/10.1109\/WPC.2005.43","DOI":"10.1109\/WPC.2005.43"},{"key":"10649_CR94","doi-asserted-by":"crossref","unstructured":"Riebisch M (2003) Towards a More Precise Definition of Feature Models. In: Modeling Variability for Object-Oriented Product Lines","DOI":"10.1007\/978-3-540-25934-3_16"},{"key":"10649_CR95","doi-asserted-by":"publisher","unstructured":"Rivest RL (1990) CHAPTER 13 - Cryptography. In: van Leeuwen J (ed) Algorithms and Complexity. Handbook of Theoretical Computer Science, Elsevier, p 717\u2013755,https:\/\/doi.org\/10.1016\/B978-0-444-88071-0.50018-7","DOI":"10.1016\/B978-0-444-88071-0.50018-7"},{"issue":"1","key":"10649_CR96","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1145\/1189748.1189751","volume":"16","author":"MP Robillard","year":"2007","unstructured":"Robillard MP, Murphy GC (2007) Representing concerns in source code. ACM Transactions on Software Engineering and Methodology 16(1):3. https:\/\/doi.org\/10.1145\/1189748.1189751","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"10649_CR97","unstructured":"Robshaw M (1995) Block ciphers"},{"key":"10649_CR98","doi-asserted-by":"publisher","unstructured":"Roth S, Gr\u00f6ber L, Backes M, et\u00a0al (2021) 12 Angry Developers - A Qualitative Study on Developers\u2019 Struggles with CSP. In: Conference on Computer and Communications Security (CCS). ACM, p 3085-3103,https:\/\/doi.org\/10.1145\/3460120.3484780","DOI":"10.1145\/3460120.3484780"},{"key":"10649_CR99","doi-asserted-by":"crossref","unstructured":"Rubin J, Chechik M (2013) A Survey of Feature Location Techniques. In: Domain Engineering, Product Lines, Languages, and Conceptual Models","DOI":"10.1007\/978-3-642-36654-3_2"},{"key":"10649_CR100","doi-asserted-by":"publisher","unstructured":"Russo ER, Di\u00a0Sorbo A, Visaggio CA, et\u00a0al (2019) Summarizing Vulnerabilities\u2019 Descriptions to Support Experts during Vulnerability Assessment Activities. Journal of Systems and Software 156(C):84-9https:\/\/doi.org\/10.1016\/j.jss.2019.06.001","DOI":"10.1016\/j.jss.2019.06.001"},{"key":"10649_CR101","doi-asserted-by":"crossref","unstructured":"Santos JC, Tarrit K, Mirakhorli M (2017) A Catalog of Security Architecture Weaknesses. In: 2017 IEEE International Conference on Software Architecture Workshops (ICSAW), IEEE, pp 220\u2013223","DOI":"10.1109\/ICSAW.2017.25"},{"key":"10649_CR102","doi-asserted-by":"publisher","first-page":"263","DOI":"10.1016\/j.jss.2018.10.030","volume":"149","author":"JC Santos","year":"2019","unstructured":"Santos JC, Tarrit K, Sejfia A et al (2019) An Empirical Study of Tactical Vulnerabilities. J Syst Softw 149:263\u2013284. https:\/\/doi.org\/10.1016\/j.jss.2018.10.030","journal-title":"J Syst Softw"},{"key":"10649_CR103","doi-asserted-by":"publisher","unstructured":"Schindler W (2009) Random Number Generators for Cryptographic Applications, Springer, pp 5\u20132https:\/\/doi.org\/10.1007\/978-0-387-71817-0_2","DOI":"10.1007\/978-0-387-71817-0_2"},{"key":"10649_CR104","doi-asserted-by":"publisher","unstructured":"Schwarz T, Mahmood W, Berger T (2020) A Common Notation and Tool Support for Embedded Feature Annotations. In: ACM International Systems and Software Product Line Conference - Volume B. ACM, pp 5\u20138,https:\/\/doi.org\/10.1145\/3382026.3431253","DOI":"10.1145\/3382026.3431253"},{"key":"10649_CR105","doi-asserted-by":"crossref","unstructured":"Seiler M, Paech B (2017) Using Tags to Support Feature Management Across Issue Tracking Systems and Version Control Systems. In: Requirements Engineering: Foundation for Software Quality. Springer, pp 174\u2013180","DOI":"10.1007\/978-3-319-54045-0_13"},{"issue":"3","key":"10649_CR106","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1109\/MC.2012.283","volume":"46","author":"LK Shar","year":"2013","unstructured":"Shar LK, Tan HBK (2013) Defeating SQL Injection. Computer 46(3):69\u201377. https:\/\/doi.org\/10.1109\/MC.2012.283","journal-title":"Computer"},{"key":"10649_CR107","unstructured":"Sparxsystems (2023) Enterprise Architect. URL https:\/\/www.sparxsystems.eu\/, accessed: 2023-Dec-20"},{"key":"10649_CR108","unstructured":"Stack\u00a0Exchange I (2022) Stack Exchange API. URL https:\/\/api.stackexchange.com\/, online; accessed 20-December-2023"},{"key":"10649_CR109","doi-asserted-by":"publisher","first-page":"422","DOI":"10.1016\/j.comnet.2015.03.010","volume":"83","author":"VN Talooki","year":"2015","unstructured":"Talooki VN, Bassoli R, Lucani DE et al (2015) Security concerns and countermeasures in network coding based communication systems: A survey. Comput Netw 83:422\u201344. https:\/\/doi.org\/10.1016\/j.comnet.2015.03.010","journal-title":"Comput Netw"},{"key":"10649_CR110","unstructured":"The Apache Software Foundation (2010) Apache Shiro - Simple. Java. Security. https:\/\/shiro.apache.org\/, [Online; accessed 20-December-2023]"},{"issue":"6","key":"10649_CR111","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1109\/MSP.2005.159","volume":"3","author":"K Tsipenyuk","year":"2005","unstructured":"Tsipenyuk K, Chess B, McGraw G (2005) Seven Pernicious Kingdoms: A Taxonomy of Software Security Errors. IEEE Security & Privacy 3(6):81\u201384. https:\/\/doi.org\/10.1109\/MSP.2005.159","journal-title":"IEEE Security & Privacy"},{"key":"10649_CR112","doi-asserted-by":"publisher","DOI":"10.1007\/s10270-022-00991-5","author":"K Tuma","year":"2022","unstructured":"Tuma K, Peldszus S, Str\u00fcber D et al (2022) Checking Security Compliance between Models and Code. International Journal on Software and Systems Modeli. https:\/\/doi.org\/10.1007\/s10270-022-00991-5","journal-title":"International Journal on Software and Systems Modeli"},{"key":"10649_CR113","unstructured":"United States Congress (1996) Health insurance portability and accountability act of 1996 (public law 104-191). URL https:\/\/www.govinfo.gov\/content\/pkg\/PLAW-104publ191\/pdf\/PLAW-104publ191.pdf, [Online; accessed 19-December-2024]"},{"key":"10649_CR114","doi-asserted-by":"publisher","unstructured":"Valente A, Holanda M, Mariano AM, et\u00a0al (2022) Analysis of Academic Databases for Literature Review in the Computer Science Education Field. In: 2022 IEEE Frontiers in Education Conference (FIE), pp 1\u20137,https:\/\/doi.org\/10.1109\/FIE56618.2022.9962393","DOI":"10.1109\/FIE56618.2022.9962393"},{"key":"10649_CR115","doi-asserted-by":"publisher","unstructured":"Venter HS, Eloff JHP (2003) A taxonomy for information security technologies. Computers % Security 22(4):299\u201330https:\/\/doi.org\/10.1016\/S0167-4048(03)00406-1","DOI":"10.1016\/S0167-4048(03)00406-1"},{"key":"10649_CR116","unstructured":"Vorobiev A, Bekmamedova N (2010) An Ontology-Driven Approach Applied to Information Security. Journal of Research and Practice in Information Technology 42"},{"issue":"6","key":"10649_CR117","doi-asserted-by":"publisher","first-page":"3149","DOI":"10.1007\/s10664-017-9514-4","volume":"22","author":"X Xia","year":"2017","unstructured":"Xia X, Bao L, Lo D et al (2017) What do developers search for on the web? Empir Softw Eng 22(6):3149\u20133185. https:\/\/doi.org\/10.1007\/s10664-017-9514-4","journal-title":"Empir Softw Eng"},{"key":"10649_CR118","doi-asserted-by":"publisher","unstructured":"Yassein MB, Aljawarneh S, Qawasmeh E, et\u00a0al (2017) Comprehensive Study of Symmetric Key and Asymmetric Key Encryption Algorithms. In: 2017 International Conference on Engineering and Technology (ICET), pp 1\u20137,https:\/\/doi.org\/10.1109\/ICEngTechnol.2017.8308215","DOI":"10.1109\/ICEngTechnol.2017.8308215"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-025-10649-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-025-10649-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-025-10649-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,27]],"date-time":"2025-11-27T06:24:29Z","timestamp":1764224669000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-025-10649-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,28]]},"references-count":118,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2025,9]]}},"alternative-id":["10649"],"URL":"https:\/\/doi.org\/10.1007\/s10664-025-10649-7","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,28]]},"assertion":[{"value":"25 March 2025","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 May 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"117"}}