{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T10:19:59Z","timestamp":1783160399230,"version":"3.54.6"},"reference-count":66,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T00:00:00Z","timestamp":1778889600000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"DOI":"10.13039\/100019771","name":"European Commission Seventh Framework Programme for Research and Technological Development","doi-asserted-by":"publisher","award":["609734"],"award-info":[{"award-number":["609734"]}],"id":[{"id":"10.13039\/100019771","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000780","name":"European Commission","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100031478","name":"NextGenerationEU","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100031478","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100011102","name":"Seventh Framework Programme","doi-asserted-by":"publisher","award":["FP7\/2007-2013"],"award-info":[{"award-number":["FP7\/2007-2013"]}],"id":[{"id":"10.13039\/100011102","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computers &amp; Security"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.cose.2026.104959","type":"journal-article","created":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T15:24:05Z","timestamp":1778945045000},"page":"104959","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Automatic selection of protections to mitigate risks against software applications"],"prefix":"10.1016","volume":"168","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4265-7743","authenticated-orcid":false,"given":"Daniele","family":"Canavese","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9259-5157","authenticated-orcid":false,"given":"Leonardo","family":"Regano","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8016-1490","authenticated-orcid":false,"given":"Cataldo","family":"Basile","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0317-2089","authenticated-orcid":false,"given":"Bjorn","family":"De Sutter","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.cose.2026.104959_b1","series-title":"Proc. of the 6th Workshop on Software Security, Protection, and Reverse Engineering","first-page":"7:1","article-title":"Tightly-coupled self-debugging software protection","author":"Abrath","year":"2016"},{"key":"10.1016\/j.cose.2026.104959_b2","series-title":"Towards the prediction of performance degradation of obfuscated code","author":"Alberto","year":"2021"},{"key":"10.1016\/j.cose.2026.104959_b3","series-title":"Proc. 1st Int\u2019L Workshop on Software Protection","first-page":"52","article-title":"Automatic discovery of software attacks via backward reasoning","author":"Basile","year":"2015"},{"key":"10.1016\/j.cose.2026.104959_b4","series-title":"ASPIRE Validation","author":"Basile","year":"2016"},{"key":"10.1016\/j.cose.2026.104959_b5","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1016\/j.jss.2018.12.025","article-title":"A meta-model for software protections and reverse engineering attacks","volume":"150","author":"Basile","year":"2019","journal-title":"J. Syst. Softw."},{"key":"10.1016\/j.cose.2026.104959_b6","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103321","article-title":"Design, implementation, and automation of a risk management approach for man-at-the-end software protection","volume":"132","author":"Basile","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cose.2026.104959_b7","series-title":"ASPIRE Framework Report","author":"Basile","year":"2016"},{"key":"10.1016\/j.cose.2026.104959_b8","series-title":"Computer Chess Compendium","first-page":"123","article-title":"Tree-searching and tree-pruning techniques","author":"Birmingham","year":"1988"},{"key":"10.1016\/j.cose.2026.104959_b9","doi-asserted-by":"crossref","first-page":"97","DOI":"10.2307\/1906946","article-title":"La th\u00e9orie du jeu et les equation int\u00e9grales \u00e0 noyau sym\u00e9trique gauche.\u201d comptes rendus de l\u2019acad\u00e9mie des sciences, 173: 1304\u201308. Translated by lj savage in","volume":"21","author":"Borel","year":"1921","journal-title":"Econometrica"},{"key":"10.1016\/j.cose.2026.104959_b10","first-page":"199","article-title":"Information in transposition tables","volume":"8","author":"Breuker","year":"1997","journal-title":"Adv. Comput. Chess"},{"key":"10.1016\/j.cose.2026.104959_b11","doi-asserted-by":"crossref","first-page":"73","DOI":"10.1007\/s10207-020-00494-8","article-title":"Obfuscated integration of software protections","volume":"20","author":"Van den Broeck","year":"2021","journal-title":"Int\u2019L J. Inf. Secur."},{"key":"10.1016\/j.cose.2026.104959_b12","series-title":"Proceedings of the 3rd ACM Workshop on Software Protection","first-page":"41","article-title":"Epona and the obfuscation paradox: Transparent for users and developers, a pain for reversers","author":"Brunet","year":"2019"},{"key":"10.1016\/j.cose.2026.104959_b13","series-title":"Proc. of the 2nd ACM Workshop on Moving Target Defense","first-page":"95","article-title":"Software protection with code mobility","author":"Cabutto","year":"2015"},{"key":"10.1016\/j.cose.2026.104959_b14","series-title":"Security and Trust Management","first-page":"193","article-title":"Estimating software obfuscation potency with artificial neural networks","author":"Canavese","year":"2017"},{"key":"10.1016\/j.cose.2026.104959_b15","series-title":"ASPIRE Security Evaluation Methodology","author":"Ceccato","year":"2016"},{"key":"10.1016\/j.cose.2026.104959_b16","series-title":"7th IEEE Int\u2019L Working Conference on Source Code Analysis and Manipulation","first-page":"27","article-title":"Barrier slicing for remote software trusting","author":"Ceccato","year":"2007"},{"key":"10.1016\/j.cose.2026.104959_b17","series-title":"2017 IEEE\/ACM 25th International Conference on Program Comprehension","first-page":"154","article-title":"How professional hackers understand protected code while performing attack tasks","author":"Ceccato","year":"2017"},{"issue":"1","key":"10.1016\/j.cose.2026.104959_b18","doi-asserted-by":"crossref","first-page":"240","DOI":"10.1007\/s10664-018-9625-6","article-title":"Understanding the behaviour of hackers while performing attack tasks in a professional setting and in a public challenge","volume":"24","author":"Ceccato","year":"2019","journal-title":"Empir. Softw. Eng."},{"issue":"41","key":"10.1016\/j.cose.2026.104959_b19","first-page":"314","article-title":"Programming a computer for playing chess","volume":"7","author":"Claude","year":"1950","journal-title":"Philos. Mag. Ser"},{"key":"10.1016\/j.cose.2026.104959_b20","series-title":"A Taxonomy of Obfuscating Transformations","author":"Collberg","year":"1997"},{"issue":"4","key":"10.1016\/j.cose.2026.104959_b21","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2400682.2400683","article-title":"Feedback-driven binary code diversification","volume":"9","author":"Coppens","year":"2013","journal-title":"ACM Trans. Archit. Code Optim. (TACO)"},{"key":"10.1016\/j.cose.2026.104959_b22","series-title":"ASPIRE Open Source Manual","author":"Coppens","year":"2016"},{"issue":"2","key":"10.1016\/j.cose.2026.104959_b23","doi-asserted-by":"crossref","first-page":"96","DOI":"10.1109\/TSE.1979.234165","article-title":"Measuring the psychological complexity of software maintenance tasks with the Halstead and McCabe metrics","volume":"SE-5","author":"Curtis","year":"1979","journal-title":"IEEE Trans. Softw. Eng."},{"issue":"4","key":"10.1016\/j.cose.2026.104959_b24","doi-asserted-by":"crossref","DOI":"10.1145\/3702314","article-title":"Evaluation methodologies in software protection research","volume":"57","author":"De Sutter","year":"2024","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.cose.2026.104959_b25","series-title":"Requirements and Model for IDES \u2013 a Real-Time Intrusion-Detection Expert System","author":"Denning","year":"1985"},{"issue":"4","key":"10.1016\/j.cose.2026.104959_b26","doi-asserted-by":"crossref","first-page":"713","DOI":"10.1016\/j.eswa.2005.05.002","article-title":"An intelligent intrusion detection system (IDS) for anomaly and misuse detection in computer networks","volume":"29","author":"Depren","year":"2005","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.cose.2026.104959_b27","series-title":"Proceedings of the 2024 Workshop on Research on Offensive and Defensive Techniques in the Context of Man At the End (MATE) Attacks","first-page":"44","article-title":"Tools and models for software reverse engineering research","author":"Faingnaert","year":"2024"},{"issue":"2","key":"10.1016\/j.cose.2026.104959_b28","doi-asserted-by":"crossref","first-page":"24","DOI":"10.1109\/MS.2011.34","article-title":"Guest editors\u2019 introduction: Software protection","volume":"28","author":"Falcarin","year":"2011","journal-title":"IEEE Softw."},{"issue":"6","key":"10.1016\/j.cose.2026.104959_b29","doi-asserted-by":"crossref","first-page":"553","DOI":"10.1109\/TDSC.2014.2305990","article-title":"Pushing Java type obfuscation to the limit","volume":"11","author":"Foket","year":"2014","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"10.1016\/j.cose.2026.104959_b30","series-title":"Proceedings of the 27th ACM Conference on on Innovation and Technology in Computer Science Education Vol. 1","first-page":"477","article-title":"Towards understanding the skill gap in cybersecurity","author":"Goupil","year":"2022"},{"key":"10.1016\/j.cose.2026.104959_b31","series-title":"Elements of Software Science","author":"Halstead","year":"1977"},{"key":"10.1016\/j.cose.2026.104959_b32","series-title":"Information Security","first-page":"428","article-title":"The obfuscation executive","author":"Heffner","year":"2004"},{"issue":"2","key":"10.1016\/j.cose.2026.104959_b33","doi-asserted-by":"crossref","first-page":"75","DOI":"10.3233\/ICG-1998-21202","article-title":"Extended futility pruning","volume":"21","author":"Heinz","year":"1998","journal-title":"ICGA J."},{"key":"10.1016\/j.cose.2026.104959_b34","doi-asserted-by":"crossref","first-page":"75","DOI":"10.2307\/25148625","article-title":"Design science in information systems research","author":"Hevner","year":"2004","journal-title":"MIS Q."},{"key":"10.1016\/j.cose.2026.104959_b35","series-title":"Proceedings of the 9th National Computer Security Conference","first-page":"156","article-title":"Risk analysis and computer security: bridging the cultural gaps","author":"Hoffman","year":"1986"},{"key":"10.1016\/j.cose.2026.104959_b36","series-title":"Proceedings of the 7th Software Security, Protection, and Reverse Engineering \/ Software Security and Protection Workshop","article-title":"Evaluating optimal phase ordering in obfuscation executives","author":"Holder","year":"2017"},{"key":"10.1016\/j.cose.2026.104959_b37","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102609","article-title":"CRUSOE: A toolset for cyber situational awareness and decision support in incident handling","volume":"115","author":"Hus\u00e1k","year":"2022","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cose.2026.104959_b38","series-title":"SP 800-39. Managing Information Security Risk: Organization, Mission, and Information System View","author":"Initiative","year":"2011"},{"key":"10.1016\/j.cose.2026.104959_b39","series-title":"Proceedings of the IEEE\/ACM 1st International Workshop on Software Protection, SPRO\u201915, Firenze, Italy, May 19th, 2015","first-page":"3","article-title":"Obfuscator-LLVM \u2013 software protection for the masses","author":"Junod","year":"2015"},{"issue":"12","key":"10.1016\/j.cose.2026.104959_b40","doi-asserted-by":"crossref","first-page":"1225","DOI":"10.1109\/34.106996","article-title":"Minimax search algorithms with and without aspiration windows","volume":"13","author":"Kaindl","year":"1991","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.cose.2026.104959_b41","doi-asserted-by":"crossref","DOI":"10.1016\/j.inffus.2023.101804","article-title":"Artificial intelligence for cybersecurity: Literature review and future research directions","volume":"97","author":"Kaur","year":"2023","journal-title":"Inf. Fusion"},{"key":"10.1016\/j.cose.2026.104959_b42","series-title":"The Art of Computer Programming, Volume 4A: Combinatorial Algorithms, Part 1","author":"Knuth","year":"2011"},{"key":"10.1016\/j.cose.2026.104959_b43","article-title":"Obfuscating c++ programs via control flow flattening","volume":"30","author":"L\u00e1szl\u00f3","year":"2007","journal-title":"Ann. Univ. Sci. Budapest. Sect. Comput."},{"key":"10.1016\/j.cose.2026.104959_b44","series-title":"Proceedings of USENIX Annual Technical Conference","first-page":"285","article-title":"Glamdring: Automatic Application Partitioning for Intel SGX","author":"Lind","year":"2017"},{"key":"10.1016\/j.cose.2026.104959_b45","series-title":"Proceedings 10th ACM Conference on Computer and Communications Security","first-page":"290","article-title":"Obfuscation of executable code to improve resistance to static disassembly","author":"Linn","year":"2003"},{"key":"10.1016\/j.cose.2026.104959_b46","series-title":"Proc. 38th Int\u2019L Conference on Software Engineering Companion","first-page":"680","article-title":"Towards better program obfuscation: Optimization via language models","author":"Liu","year":"2016"},{"key":"10.1016\/j.cose.2026.104959_b47","series-title":"Proceedings of the 39th International Conference on Software Engineering","first-page":"221","article-title":"Stochastic optimization of program obfuscation","author":"Liu","year":"2017"},{"key":"10.1016\/j.cose.2026.104959_b48","series-title":"Advancing the Impact of Design Science: Moving from Theory To Practice","first-page":"321","article-title":"Instantiation validity in IS design research","author":"Lukyanenko","year":"2014"},{"key":"10.1016\/j.cose.2026.104959_b49","series-title":"31st USENIX Security Symposium (USENIX Security 22)","first-page":"2727","article-title":"RE-Mind: a first look inside the mind of a reverse engineer","author":"Mantovani","year":"2022"},{"issue":"4","key":"10.1016\/j.cose.2026.104959_b50","doi-asserted-by":"crossref","first-page":"308","DOI":"10.1109\/TSE.1976.233837","article-title":"A complexity measure","volume":"SE-2","author":"McCabe","year":"1976","journal-title":"IEEE Trans. Softw. Eng."},{"key":"10.1016\/j.cose.2026.104959_b51","series-title":"Surreptitious Software: Obfuscation, Watermarking, and Tamperproofing for Software Protection","author":"Nagra","year":"2009"},{"key":"10.1016\/j.cose.2026.104959_b52","series-title":"17th Int\u2019L Conf. on Tools with Artificial Intelligence","first-page":"672","article-title":"An integrated model of intrusion detection based on neural network and expert system","author":"Pan","year":"2005"},{"key":"10.1016\/j.cose.2026.104959_b53","series-title":"Proceedings of the 1998 Workshop on New Security Paradigms","first-page":"71","article-title":"A graph-based system for network-vulnerability analysis","author":"Phillips","year":"1998"},{"key":"10.1016\/j.cose.2026.104959_b54","series-title":"An Expert System for Automatic Software Protection","author":"Regano","year":"2019"},{"key":"10.1016\/j.cose.2026.104959_b55","series-title":"Proc. Int\u2019L Conf. on Software Quality, Reliability and Security","first-page":"374","article-title":"Towards optimally hiding protected assets in software applications","author":"Regano","year":"2017"},{"key":"10.1016\/j.cose.2026.104959_b56","series-title":"Information Security Theory and Practice","first-page":"120","article-title":"Towards automatic risk analysis and mitigation of software applications","author":"Regano","year":"2016"},{"key":"10.1016\/j.cose.2026.104959_b57","series-title":"Experiments in search and knowledge","author":"Schaeffer","year":"1986"},{"key":"10.1016\/j.cose.2026.104959_b58","series-title":"Proceedings of APLOS 2020: International Conference on Architectural Support for Programming Languages and Operating Systems","first-page":"955","article-title":"Occlum: Secure and Efficient Multitasking Inside a Single Enclave of Intel SGX","author":"Shen","year":"2020"},{"issue":"2","key":"10.1016\/j.cose.2026.104959_b59","doi-asserted-by":"crossref","first-page":"189","DOI":"10.1145\/321510.321511","article-title":"Experiments with some programs that search game trees","volume":"16","author":"Slagle","year":"1969","journal-title":"J. ACM"},{"key":"10.1016\/j.cose.2026.104959_b60","series-title":"Proc. Fifth IEEE Int\u2019L Symposium on Signal Processing and Information Technology","first-page":"7","article-title":"DIABLO: a reliable, retargetable and extensible link-time rewriting framework","author":"Van Put","year":"2005"},{"key":"10.1016\/j.cose.2026.104959_b61","series-title":"Proceedings of the 2016 ACM Workshop on Software PROtection","first-page":"73","article-title":"Reactive attestation: Automatic detection and reaction to software tampering attacks","author":"Viticchi\u00e9","year":"2016"},{"issue":"1","key":"10.1016\/j.cose.2026.104959_b62","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10664-019-09738-1","article-title":"Empirical assessment of the effort needed to attack programs protected with client\/server code splitting","volume":"25","author":"Viticchi\u00e9","year":"2020","journal-title":"Empir. Softw. Eng."},{"key":"10.1016\/j.cose.2026.104959_b63","series-title":"2016 IEEE 16th International Working Conference on Source Code Analysis and Manipulation","first-page":"11","article-title":"Assessment of source code obfuscation techniques","author":"Viticchi\u00e9","year":"2016"},{"key":"10.1016\/j.cose.2026.104959_b64","series-title":"Extended Abstracts of the 2019 CHI Conference on Human Factors in Computing Systems","article-title":"An observational investigation of reverse engineers\u2019 process and mental models","author":"Votipka","year":"2019"},{"key":"10.1016\/j.cose.2026.104959_b65","series-title":"Int\u2019L Conf. on High Performance Computing and Communications (HPCC) & Int\u2019L Conf. on Embedded and Ubiquitous Computing","first-page":"837","article-title":"Method to evaluate software protection based on attack modeling","author":"Wang","year":"2013"},{"key":"10.1016\/j.cose.2026.104959_b66","series-title":"Experimentation in Software Engineering - An Introduction","author":"Wohlin","year":"2000"}],"container-title":["Computers &amp; Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404826001355?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404826001355?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T10:11:29Z","timestamp":1783159889000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167404826001355"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":66,"alternative-id":["S0167404826001355"],"URL":"https:\/\/doi.org\/10.1016\/j.cose.2026.104959","relation":{},"ISSN":["0167-4048"],"issn-type":[{"value":"0167-4048","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Automatic selection of protections to mitigate risks against software applications","name":"articletitle","label":"Article Title"},{"value":"Computers & Security","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.cose.2026.104959","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Authors. Published by Elsevier Ltd.","name":"copyright","label":"Copyright"}],"article-number":"104959"}}