{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T21:03:55Z","timestamp":1779829435342,"version":"3.53.1"},"reference-count":61,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,3,24]],"date-time":"2026-03-24T00:00:00Z","timestamp":1774310400000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001659","name":"German Research Foundation","doi-asserted-by":"publisher","award":["435878599"],"award-info":[{"award-number":["435878599"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004063","name":"Knut och Alice Wallenbergs Stiftelse","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004063","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100022771","name":"Hilti Aktiengesellschaft","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100022771","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002428","name":"Austrian Science Fund","doi-asserted-by":"publisher","award":["I 4701-N"],"award-info":[{"award-number":["I 4701-N"]}],"id":[{"id":"10.13039\/501100002428","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Journal of Systems and Software"],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1016\/j.jss.2026.112865","type":"journal-article","created":{"date-parts":[[2026,3,27]],"date-time":"2026-03-27T16:51:03Z","timestamp":1774630263000},"page":"112865","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Bridging safety and security in complex systems: A model-based approach with SAFT-GT toolchain"],"prefix":"10.1016","volume":"238","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0706-3202","authenticated-orcid":false,"given":"Irdin","family":"Pekaric","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Raffaela","family":"Groner","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6088-8393","authenticated-orcid":false,"given":"Alexander","family":"Raschke","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thomas","family":"Witte","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5494-3958","authenticated-orcid":false,"given":"Jubril","family":"Gbolahan Adigun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Felderer","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Matthias","family":"Tichy","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.jss.2026.112865_bib0001","series-title":"2019 19th International Conference on Application of Concurrency to System Design (ACSD)","first-page":"33","article-title":"Parametric analyses of attack-fault trees","author":"Andr\u00e9","year":"2019"},{"key":"10.1016\/j.jss.2026.112865_bib0002","article-title":"NLP-based techniques for cyber threat intelligence","volume":"abs\/2311.08807","author":"Arazzi","year":"2023","journal-title":"CoRR"},{"key":"10.1016\/j.jss.2026.112865_bib0003","series-title":"2015 IEEE\/ACM 10th International Symposium on Software Engineering for Adaptive and Self-Managing Systems","first-page":"13","article-title":"Modeling and analyzing MAPE-k feedback loops for self-adaptation","author":"Arcaini","year":"2015"},{"key":"10.1016\/j.jss.2026.112865_bib0004","series-title":"Proceedings of the 12th International Symposium on Software Engineering for Adaptive and Self-Managing Systems","first-page":"24-30","article-title":"Lotus@runtime: a tool for runtime monitoring and verification of self-adaptive systems","author":"Barbosa","year":"2017"},{"key":"10.1016\/j.jss.2026.112865_bib0005","series-title":"Proceedings of the 2012 ACM Conference on Computer and Communications Security","first-page":"833-844","article-title":"Before we knew it: an empirical study of zero-day attacks in the real world","author":"Bilge","year":"2012"},{"key":"10.1016\/j.jss.2026.112865_bib0006","series-title":"International Workshop on Software Engineering for Resilient Systems","first-page":"17","article-title":"Security-informed safety: if it\u2019s not secure, it\u2019s not safe","author":"Bloomfield","year":"2013"},{"key":"10.1016\/j.jss.2026.112865_bib0007","series-title":"Proceedings of the 39th ACM\/SIGAPP Symposium on Applied Computing","first-page":"1596","article-title":"Understanding the process of data labeling in cybersecurity","author":"Braun","year":"2024"},{"key":"10.1016\/j.jss.2026.112865_bib0008","series-title":"Quantitative Evaluation of Systems","first-page":"457","article-title":"Attack trees vs. fault trees: two sides of the same coin from different currencies","author":"Budde","year":"2021"},{"key":"10.1016\/j.jss.2026.112865_bib0009","series-title":"2023 IEEE\/ACM 18th Symposium on Software Engineering for Adaptive and Self-Managing Systems (SEAMS)","first-page":"104","article-title":"Runtime verification of self-adaptive systems with changing requirements","author":"Carwehl","year":"2023"},{"key":"10.1016\/j.jss.2026.112865_bib0010","doi-asserted-by":"crossref","first-page":"44952","DOI":"10.1109\/ACCESS.2023.3272979","article-title":"Evaluating object (mis) detection from a safety and reliability perspective: discussion and measures","volume":"11","author":"Ceccarelli","year":"2023","journal-title":"IEEE Access"},{"key":"10.1016\/j.jss.2026.112865_bib0011","series-title":"Proceedings of the 22nd International Conference on Software Engineering","first-page":"750-753","article-title":"Galileo: a tool built from mass-market applications","author":"Coppit","year":"2000"},{"key":"10.1016\/j.jss.2026.112865_bib0012","series-title":"Formal Modeling and Analysis of Timed Systems","first-page":"80","article-title":"Statistical model checking for networks of priced timed automata","author":"David","year":"2011"},{"issue":"4","key":"10.1016\/j.jss.2026.112865_bib0013","doi-asserted-by":"crossref","first-page":"397","DOI":"10.1007\/s10009-014-0361-y","article-title":"Uppaal SMC tutorial","volume":"17","author":"David","year":"2015","journal-title":"Int. J. Softw. Tool. Technol. Trans."},{"issue":"3","key":"10.1016\/j.jss.2026.112865_bib0014","doi-asserted-by":"crossref","first-page":"363","DOI":"10.1109\/24.159800","article-title":"Dynamic fault-tree models for fault-tolerant computer systems","volume":"41","author":"Dugan","year":"1992","journal-title":"IEEE Trans. Reliab."},{"key":"10.1016\/j.jss.2026.112865_bib0015","series-title":"Computer Safety, Reliability, and Security","first-page":"99","article-title":"Quantification of priority-OR gates in temporal fault trees","author":"Edifor","year":"2012"},{"key":"10.1016\/j.jss.2026.112865_bib0016","series-title":"Security and quality in cyber-physical systems engineering","first-page":"357","author":"Fournaris","year":"2019"},{"issue":"9","key":"10.1016\/j.jss.2026.112865_bib0017","doi-asserted-by":"crossref","first-page":"1394","DOI":"10.1016\/j.ress.2009.02.020","article-title":"Integrating cyber attacks within fault trees","volume":"94","author":"Fovino","year":"2009","journal-title":"Reliab. Eng. Syst. Safe."},{"key":"10.1016\/j.jss.2026.112865_bib0018","unstructured":"Gherardi, L., 2013. Variability modeling and resolution in component-based robotics systems. Ph. D. Thesis."},{"key":"10.1016\/j.jss.2026.112865_bib0019","series-title":"Computer Safety, Reliability, and Security","first-page":"156","article-title":"Component-based hazard analysis: optimal designs, product lines, and online-reconfiguration","author":"Giese","year":"2006"},{"key":"10.1016\/j.jss.2026.112865_bib0020","series-title":"Computer Safety, Reliability, and Security (SAFECOMP)","first-page":"107","article-title":"Model-based generation of attack-fault trees","author":"Groner","year":"2023"},{"key":"10.1016\/j.jss.2026.112865_bib0021","series-title":"Proceedings of the 2022 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems","first-page":"13-20","article-title":"Generating cyber-physical system risk overlays for attack and fault trees using systems theory","author":"Jablonski","year":"2022"},{"issue":"3","key":"10.1016\/j.jss.2026.112865_bib0022","article-title":"Exploit prediction scoring system (EPSS)","volume":"2","author":"Jacobs","year":"2021","journal-title":"Digit. Threat."},{"key":"10.1016\/j.jss.2026.112865_bib0023","series-title":"2016 46th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN)","first-page":"299","article-title":"Uncovering dynamic fault trees","author":"Junges","year":"2016"},{"key":"10.1016\/j.jss.2026.112865_bib0024","series-title":"Proceedings of the Sixteenth ACM Conference on Data and Application Security and Privacy (CODASPY)","article-title":"Security Barriers to Trustworthy AI-Driven Cyber Threat Intelligence in Finance: Evidence from Practitioners","author":"Karaosman","year":"2026"},{"issue":"1","key":"10.1016\/j.jss.2026.112865_bib0025","first-page":"41","article-title":"The vision of autonomic computing","volume":"36","author":"Kephart","year":"2003","journal-title":"Comput. (Long Beach Calif.)"},{"key":"10.1016\/j.jss.2026.112865_bib0026","doi-asserted-by":"crossref","first-page":"28","DOI":"10.1016\/j.sysarc.2018.03.004","article-title":"Comprehensible and dependable self-learning self-adaptive systems","volume":"85\u201386","author":"Kl\u00f6s","year":"2018","journal-title":"J. Syst. Archit."},{"key":"10.1016\/j.jss.2026.112865_bib0027","series-title":"2013 5th International Conference on Cyber Conflict (CYCON 2013)","first-page":"1","article-title":"A cyber attack modeling and impact assessment framework","author":"Kotenko","year":"2013"},{"key":"10.1016\/j.jss.2026.112865_bib0028","doi-asserted-by":"crossref","first-page":"p.156","DOI":"10.1016\/j.ress.2015.02.008","article-title":"A survey of approaches combining safety and security for industrial control systems","volume":"138","author":"Kriaa","year":"2015","journal-title":"Reliab. Eng. Syst. Safe."},{"key":"10.1016\/j.jss.2026.112865_bib0029","series-title":"2017 IEEE 18th International Symposium on High Assurance Systems Engineering (HASE)","first-page":"25","article-title":"Quantitative security and safety analysis with attack-fault trees","author":"Kumar","year":"2017"},{"key":"10.1016\/j.jss.2026.112865_bib0030","doi-asserted-by":"crossref","DOI":"10.1016\/j.cosrev.2019.100219","article-title":"A review of attack graph and attack tree visual syntax in cyber security","volume":"35","author":"Lallie","year":"2020","journal-title":"Comput. Sci. Rev."},{"key":"10.1016\/j.jss.2026.112865_bib0031","series-title":"Secure IT Systems","first-page":"199","article-title":"Attacker profiling in quantitative security assessment based on attack trees","author":"Lenin","year":"2014"},{"issue":"66","key":"10.1016\/j.jss.2026.112865_bib0032","article-title":"Robot operating system 2: design, architecture, and uses in the wild","volume":"7","author":"Macenski","year":"2022","journal-title":"Sci. Rob."},{"key":"10.1016\/j.jss.2026.112865_bib0033","series-title":"Information Security and Cryptology - ICISC 2005","first-page":"186","article-title":"Foundations of attack trees","author":"Mauw","year":"2006"},{"key":"10.1016\/j.jss.2026.112865_bib0034","doi-asserted-by":"crossref","first-page":"125","DOI":"10.1016\/j.entcs.2005.10.021","article-title":"A taxonomy of model transformation","volume":"152","author":"Mens","year":"2006","journal-title":"Electron. Note. Theor. Comput. Sci."},{"key":"10.1016\/j.jss.2026.112865_bib0035","doi-asserted-by":"crossref","first-page":"6365","DOI":"10.1109\/ACCESS.2024.3350444","article-title":"Unveiling vulnerabilities of web attacks considering man in the middle attack and session hijacking","volume":"12","author":"Muzammil","year":"2024","journal-title":"IEEE Access"},{"issue":"9","key":"10.1016\/j.jss.2026.112865_bib0036","doi-asserted-by":"crossref","first-page":"1394","DOI":"10.1016\/j.ress.2009.02.020","article-title":"Integrating cyber attacks within fault trees","volume":"94","author":"Nai Fovino","year":"2009","journal-title":"Reliab. Eng. Syst. Safe."},{"key":"10.1016\/j.jss.2026.112865_bib0037","series-title":"Proceedings of the 13th ACM Conference on Computer and Communications Security","first-page":"336-345","article-title":"A scalable approach to attack graph generation","author":"Ou","year":"2006"},{"key":"10.1016\/j.jss.2026.112865_bib0038","series-title":"2020 International Conference on Control, Automation and Diagnosis (ICCAD)","first-page":"1","article-title":"A review of combined safety and security risk analysis approaches: application and classification","author":"Oueidat","year":"2020"},{"key":"10.1016\/j.jss.2026.112865_bib0039","series-title":"13th International Symposium on Software Reliability Engineering, 2002. Proceedings.","first-page":"243","article-title":"Automatic synthesis of dynamic fault trees from UML system models","author":"Pai","year":"2002"},{"key":"10.1016\/j.jss.2026.112865_bib0040","series-title":"54th Hawaii International Conference on System Sciences, HICSS 2021, Kauai, Hawaii, USA, January 5, 2021","first-page":"1","article-title":"VULNERLIZER: cross-analysis between vulnerabilities and software libraries","author":"Pekaric","year":"2021"},{"key":"10.1016\/j.jss.2026.112865_bib0041","series-title":"57th Hawaii International Conference on System Sciences, HICSS 2024, Hilton Hawaiian Village Waikiki Beach Resort, Hawaii, USA, January 3\u20136, 2024","first-page":"7447","article-title":"Streamlining attack tree generation: a fragment-based approach","author":"Pekaric","year":"2024"},{"key":"10.1016\/j.jss.2026.112865_bib0042","doi-asserted-by":"crossref","DOI":"10.1016\/j.jss.2023.111716","article-title":"A systematic review on security and safety of self-adaptive systems","volume":"203","author":"Pekaric","year":"2023","journal-title":"J. Syst. Softw."},{"key":"10.1016\/j.jss.2026.112865_bib0043","doi-asserted-by":"crossref","DOI":"10.1016\/j.csi.2021.103539","article-title":"A taxonomy of attack mechanisms in the automotive domain","volume":"78","author":"Pekaric","year":"2021","journal-title":"Comput. Stand. Interface."},{"key":"10.1016\/j.jss.2026.112865_bib0044","series-title":"Computer Safety, Reliability, and Security","first-page":"70","article-title":"Towards combined safety and security constraints analysis","author":"Pereira","year":"2017"},{"key":"10.1016\/j.jss.2026.112865_bib0045","series-title":"2025 APWG Symposium on Electronic Crime Research (eCrime)","first-page":"1","article-title":"Department-Specific Security Awareness Campaigns: A Cross-Organizational Study of HR and Accounting","author":"Pfister","year":"2025"},{"key":"10.1016\/j.jss.2026.112865_bib0046","series-title":"2020 IEEE Workshop on Formal Requirements (FORMREQ)","first-page":"8","article-title":"Formalizing security and safety requirements by mapping attack-fault trees on obstacle models with constraint programming semantics","author":"Ponsard","year":"2020"},{"key":"10.1016\/j.jss.2026.112865_bib0047","series-title":"Proceedings of the 26th ACM International Systems and Software Product Line Conference - Volume B","first-page":"224-228","article-title":"Challenges of testing self-adaptive systems","author":"Prikler","year":"2022"},{"key":"10.1016\/j.jss.2026.112865_bib0048","series-title":"International Conference on Dependable Systems and Networks, 2004","first-page":"659","article-title":"Repairable fault tree for the automatic evaluation of repair policies","author":"Raiteri","year":"2004"},{"key":"10.1016\/j.jss.2026.112865_bib0049","doi-asserted-by":"crossref","first-page":"29","DOI":"10.1016\/j.cosrev.2015.03.001","article-title":"Fault tree analysis: a survey of the state-of-the-art in modeling, analysis and tools","volume":"15\u201316","author":"Ruijters","year":"2015","journal-title":"Comput. Sci. Rev."},{"issue":"3","key":"10.1016\/j.jss.2026.112865_bib0050","article-title":"The CIA strikes back: redefining confidentiality, integrity and availability in security","volume":"10","author":"Samonas","year":"2014","journal-title":"J. Inform. Syst. Secur."},{"key":"10.1016\/j.jss.2026.112865_bib0051","doi-asserted-by":"crossref","first-page":"140","DOI":"10.1016\/j.cose.2018.12.011","article-title":"An analysis and classification of public information security data sources used in research and practice","volume":"82","author":"Sauerwein","year":"2019","journal-title":"Computers & Security"},{"issue":"12","key":"10.1016\/j.jss.2026.112865_bib0052","article-title":"Modeling security threats","volume":"24","author":"Schneier","year":"1999","journal-title":"Dr. Dobb\u2019s J."},{"key":"10.1016\/j.jss.2026.112865_bib0053","series-title":"Workshop DECS (ERCIM\/EWICS Workshop on Dependable Embedded and Cyber-physical Systems) of the 32nd International Conference on Computer Safety (SAFECOMP)","article-title":"Combination of safety and security analysis - finding security problems that threaten the safety of a system","author":"Steiner","year":"2013"},{"key":"10.1016\/j.jss.2026.112865_bib0054","series-title":"Proceedings DARPA Information Survivability Conference and Exposition II. DISCEX\u201901","first-page":"307","article-title":"Computer-attack graph generation tool","volume":"Vol. 2","author":"Swiler","year":"2001"},{"key":"10.1016\/j.jss.2026.112865_bib0055","series-title":"Software Engineering for Self-Adaptive Systems 2","first-page":"116","article-title":"Towards practical runtime verification and validation of self-Adaptive software systems","volume":"Vol. 7475","author":"Tamura","year":"2012"},{"key":"10.1016\/j.jss.2026.112865_bib0056","series-title":"Technical Report","article-title":"Fault tree handbook","author":"Vesely","year":"1981"},{"key":"10.1016\/j.jss.2026.112865_bib0057","series-title":"Proceedings of the 6th International Symposium on Software Engineering for Adaptive and Self-Managing Systems","first-page":"80-89","article-title":"A framework for evaluating quality-driven self-adaptive software systems","author":"Villegas","year":"2011"},{"issue":"2","key":"10.1016\/j.jss.2026.112865_bib0058","doi-asserted-by":"crossref","DOI":"10.1145\/3589227","article-title":"Self-adaptation in industry: a survey","volume":"18","author":"Weyns","year":"2023","journal-title":"ACM Trans. Auton. Adapt. Syst."},{"key":"10.1016\/j.jss.2026.112865_bib0059","series-title":"Software Engineering for Self-Adaptive Systems II. Lecture Notes in Computer Science","first-page":"76","volume":"Vol. 7475","author":"Weyns","year":"2013"},{"key":"10.1016\/j.jss.2026.112865_bib0060","series-title":"Proceedings of the 17th Symposium on Software Engineering for Adaptive and Self-Managing Systems","first-page":"106-112","article-title":"Towards model co-evolution across self-adaptation steps for combined safety and security analysis","author":"Witte","year":"2022"},{"issue":"2","key":"10.1016\/j.jss.2026.112865_bib0061","doi-asserted-by":"crossref","first-page":"31","DOI":"10.1145\/2556938","article-title":"An integrated approach to safety and security based on systems theory","volume":"57","author":"Young","year":"2014","journal-title":"Commun. ACM"}],"container-title":["Journal of Systems and Software"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0164121226000981?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0164121226000981?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T20:27:25Z","timestamp":1779827245000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0164121226000981"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8]]},"references-count":61,"alternative-id":["S0164121226000981"],"URL":"https:\/\/doi.org\/10.1016\/j.jss.2026.112865","relation":{},"ISSN":["0164-1212"],"issn-type":[{"value":"0164-1212","type":"print"}],"subject":[],"published":{"date-parts":[[2026,8]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Bridging safety and security in complex systems: A model-based approach with SAFT-GT toolchain","name":"articletitle","label":"Article Title"},{"value":"Journal of Systems and Software","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.jss.2026.112865","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Author(s). Published by Elsevier Inc.","name":"copyright","label":"Copyright"}],"article-number":"112865"}}