{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T14:47:18Z","timestamp":1776782838562,"version":"3.51.2"},"reference-count":34,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2019,1,19]],"date-time":"2019-01-19T00:00:00Z","timestamp":1547856000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Software Qual J"],"published-print":{"date-parts":[[2019,6]]},"DOI":"10.1007\/s11219-018-9438-2","type":"journal-article","created":{"date-parts":[[2019,1,19]],"date-time":"2019-01-19T01:02:28Z","timestamp":1547859748000},"page":"675-701","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["An approach for guiding developers in the choice of security solutions and in the generation of concrete test cases"],"prefix":"10.1007","volume":"27","author":[{"given":"S\u00e9bastien","family":"Salva","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Loukmen","family":"Regainia","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,1,19]]},"reference":[{"key":"9438_CR1","unstructured":"Aleem, A.K., & Zulkernine, M. (2012). A comparative study of software security pattern classifications seventh international conference on availability. Reliability and Security, 582\u2013589."},{"key":"9438_CR2","unstructured":"Bozic, J., Simos, D.E., Wotawa, F. (2014). Attack pattern-based combinatorial testing. In Proceedings of the 9th international workshop on automation of software test. AST 2014 (pp. 1\u20137). New York: ACM."},{"key":"9438_CR3","unstructured":"Daun, M, H\u00fcbscher, C, Weyer, T. (2017). Controlled experiments with student participants in software engineering: preliminary results from a systematic mapping study. CoRR, arXiv: 1708.04662 ."},{"key":"9438_CR4","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.scico.2014.12.004","volume":"102","author":"M del Pilar Salas-Z\u00e1rate","year":"2015","unstructured":"del Pilar Salas-Z\u00e1rate, M., Alor-Hern\u00e1ndez, G., Valencia-Garc\u00eda, R., Rodr\u00edguez-Mazahua, L., Rodr\u00edguez-Gonz\u00e1lez, A., Cuadrado, J.L.L. (2015). Analyzing best practices on web development frameworks: the lift approach. Science of Computer Programming, 102, 1\u201319.","journal-title":"Science of Computer Programming"},{"issue":"3","key":"9438_CR5","doi-asserted-by":"publisher","first-page":"274","DOI":"10.1016\/j.infsof.2009.10.001","volume":"52","author":"J Dong","year":"2010","unstructured":"Dong, J., Peng, T., Zhao, Y. (2010). Automated verification of security pattern compositions. Information and Software Technology, 52(3), 274\u2013295.","journal-title":"Information and Software Technology"},{"key":"9438_CR6","unstructured":"El Ariss, O., & Xu, D. (2011). Modeling security attacks with statecharts. In Proceedings of the Joint ACM SIGSOFT conference \u2013 QoSA and ACM SIGSOFT symposium \u2013 ISARCS on quality of software architectures \u2013 QoSA and architecting critical systems \u2013 ISARCS. QoSA-ISARCS \u201911 (pp. 123\u2013132). New York: ACM."},{"key":"9438_CR7","doi-asserted-by":"crossref","unstructured":"Fernandez, E.B., Washizaki, H., Yoshioka, N., Kubo, A., Fukazawa, Y. (2008). Classifying security patterns. In Lecture notes in computer science (including subseries lecture notes in artificial intelligence and lecture notes in bioinformatics) (Vol. 4976 LNCS, pp. 342\u2013347).","DOI":"10.1007\/978-3-540-78849-2_35"},{"key":"9438_CR8","unstructured":"Hamid, B., Percebois, C., Gouteux, D. (2012). A methodology for integration of patterns with validation purpose. In Proceedings of the 17th European conference on pattern languages of programs. EuroPLoP \u201912 (pp. 8:1\u20138:14). New York: ACM."},{"key":"9438_CR9","unstructured":"Howard, M., & LeBlanc, D. (2003). Writing secure code."},{"key":"9438_CR10","doi-asserted-by":"crossref","unstructured":"Jhawar, R., Kordy, B., Mauw, S., Radomirovi\u0107, S., Trujillo-Rasua, R. (2015). Attack trees with sequential conjunction. In IFIP International information security conference (pp. 339\u2013353). Springer.","DOI":"10.1007\/978-3-319-18467-8_23"},{"key":"9438_CR11","doi-asserted-by":"crossref","unstructured":"Kobashi, T., Yoshizawa, M., Washizaki, H., Fukazawa, Y., Yoshioka, N., Okubo, T., Kaiya, H. (2015). TESEM: a tool for verifying security design pattern applications by model testing. In 2015 IEEE 8th International conference on software testing, verification and validation (ICST) (pp. 1\u20138).","DOI":"10.1109\/ICST.2015.7102633"},{"key":"9438_CR12","unstructured":"Kordy, B., Mauw, S., Radomirovi\u0107, S, Schweitzer, P. (2012). Attack\u2013defense trees. Journal of Logic and Computation p exs029."},{"key":"9438_CR13","doi-asserted-by":"crossref","unstructured":"Kordy, B., Kordy, P., Mauw, S., Schweitzer, P. (2013). ADTool: security analysis with attack\u2013defense trees. In International conference on quantitative evaluation of systems (pp. 173\u2013176). Springer.","DOI":"10.1007\/978-3-642-40196-1_15"},{"key":"9438_CR14","doi-asserted-by":"crossref","unstructured":"Marback, A., Do, H., He, K., Kondamarri, S., Xu, D. (2009). Security test generation using threat trees. In 2009 ICSE Workshop on automation of software test (pp. 62\u201369).","DOI":"10.1109\/IWAST.2009.5069042"},{"issue":"2","key":"9438_CR15","doi-asserted-by":"publisher","first-page":"241","DOI":"10.1002\/spe.2111","volume":"43","author":"A Marback","year":"2013","unstructured":"Marback, A., Do, H., He, K., Kondamarri, S., Xu, D. (2013). A threat model-based approach to security testing. Softw Pract Exper, 43(2), 241\u2013258.","journal-title":"Softw Pract Exper"},{"key":"9438_CR16","unstructured":"Mitre corporation. (2015). Common attack pattern enumeration and classification. https:\/\/capec.mitre.org\/ ."},{"key":"9438_CR17","doi-asserted-by":"crossref","unstructured":"Morais, A., Martins, E., Cavalli, A., Jimenez, W. (2009). Security protocol testing using attack trees. In 2009 International conference on computational science and engineering (Vol. 2, pp. 690\u2013697).","DOI":"10.1109\/CSE.2009.206"},{"key":"9438_CR18","unstructured":"Offensive Security. (2017). Exploit database archive. https:\/\/capec.mitre.org\/ ."},{"key":"9438_CR19","unstructured":"OWASP. (2016). Owasp testing guide v3.0 project. http:\/\/www.owasp.org\/index.php\/Category:OWASP_Testing_Project#OWASP_Testing_Guide ."},{"key":"9438_CR20","unstructured":"Regaigna, L., Bouhours, C., Salva, S. (2016). A systematic approach to assist designers in security pattern integration. In Second international conference on advances and trends in software engineering (SOFTENG 2016). Lisbon."},{"key":"9438_CR21","unstructured":"Regainia, L., & Salva, S. (2017). Security pattern classification, companion site. http:\/\/regainia.com\/research\/companion.html ."},{"key":"9438_CR22","unstructured":"Rojas, J.M., Fraser, G., Arcuri, A. (2015). Automated unit test generation during software development: a controlled experiment and think-aloud observations. In Proceedings of the 2015 international symposium on software testing and analysis. ISSTA 2015 (pp. 338\u2013349). New York: ACM."},{"key":"9438_CR23","doi-asserted-by":"crossref","unstructured":"Salva, S., & Regainia, L. (2017a). Using data integration for security testing. In Testing software and systems - 29th IFIP WG 6.1 international conference, ICTSS 2017, St. Petersburg, Russia, October 9-11, 2017, Proceedings (pp. 178\u2013194).","DOI":"10.1007\/978-3-319-67549-7_11"},{"key":"9438_CR24","doi-asserted-by":"crossref","unstructured":"Salva, S., & Regainia, L. (2017b). Using data integration to help design more secure applications. In Proceedings of the 12th international conference on risks and security of internet and systems. Dinard: Springer.","DOI":"10.1007\/978-3-319-76687-4_6"},{"key":"9438_CR25","doi-asserted-by":"crossref","unstructured":"Schieferdecker, I., Grossmann, J., Schneider, M.A. (2012). Model-based security testing. In Proceedings 7th workshop on model-based testing, MBT 2012, Tallinn, Estonia, 25 March 2012 (pp. 1\u201312).","DOI":"10.4204\/EPTCS.80.1"},{"key":"9438_CR26","doi-asserted-by":"publisher","DOI":"10.1007\/b11930","volume-title":"Security engineering with patterns: origins, theoretical models, and new applications","author":"M Schumacher","year":"2003","unstructured":"Schumacher, M. (2003). Security engineering with patterns: origins, theoretical models, and new applications. Secaucus: Springer-Verlag New York, Inc."},{"issue":"9","key":"9438_CR27","doi-asserted-by":"publisher","first-page":"997","DOI":"10.1016\/j.infsof.2012.03.004","volume":"54","author":"N Shahmehri","year":"2012","unstructured":"Shahmehri, N., Mammar, A., Montes De Oca, E., Byers, D., Cavalli, A., Ardi, S., Jimenez, W. (2012). An advanced approach for modeling and detecting software vulnerabilities. Information and Software Technology, 54(9), 997\u20131013.","journal-title":"Information and Software Technology"},{"key":"9438_CR28","unstructured":"Slavin, R., & Niu, J. (2017). Security patterns repository. http:\/\/sefm.cs.utsa.edu\/repository\/ ."},{"issue":"5","key":"9438_CR29","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1109\/MSP.2005.119","volume":"3","author":"P Torr","year":"2005","unstructured":"Torr, P. (2005). Demystifying the threat modeling process. IEEE Security Privacy, 3(5), 66\u201370.","journal-title":"IEEE Security Privacy"},{"issue":"4","key":"9438_CR30","doi-asserted-by":"publisher","first-page":"526","DOI":"10.1109\/TDSC.2012.24","volume":"9","author":"D Xu","year":"2012","unstructured":"Xu, D., Tu, M., Sanford, M., Thomas, L., Woodraska, D., Xu, W. (2012). Automated security test generation with formal threat models. IEEE Transactions on Dependable and Secure Computing, 9(4), 526\u2013540.","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"issue":"51","key":"9438_CR31","first-page":"31","volume":"1997","author":"J Yoder","year":"1998","unstructured":"Yoder, J., Yoder, J., Barcalow, J., Barcalow, J. (1998). Architectural patterns for enabling application security. Proceedings of PLoP, 1997(51), 31.","journal-title":"Proceedings of PLoP"},{"key":"9438_CR32","doi-asserted-by":"crossref","unstructured":"Yoshizawa, M., Kobashi, T., Washizaki, H., Fukazawa, Y., Okubo, T., Kaiya, H., Yoshioka, N. (2014). Verifying implementation of security design patterns using a test template. In 2014 Ninth international conference on availability, reliability and security (pp. 178\u2013183).","DOI":"10.1109\/ARES.2014.31"},{"key":"9438_CR33","unstructured":"Yskout, K., Heyman, T., Scandariato, R., Joosen, W. (2006). A system of security patterns."},{"key":"9438_CR34","unstructured":"Yskout, K., Scandariato, R., Joosen, W. (2015). Do security patterns really help designers?. In Proceedings of the 37th international conference on software engineering. ICSE \u201915, (Vol. 1 pp. 292\u2013302). Piscataway: IEEE Press."}],"container-title":["Software Quality Journal"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11219-018-9438-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11219-018-9438-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11219-018-9438-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,10]],"date-time":"2022-09-10T17:32:56Z","timestamp":1662831176000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11219-018-9438-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,1,19]]},"references-count":34,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2019,6]]}},"alternative-id":["9438"],"URL":"https:\/\/doi.org\/10.1007\/s11219-018-9438-2","relation":{},"ISSN":["0963-9314","1573-1367"],"issn-type":[{"value":"0963-9314","type":"print"},{"value":"1573-1367","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,1,19]]},"assertion":[{"value":"19 January 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}