{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T16:24:50Z","timestamp":1775838290719,"version":"3.50.1"},"reference-count":40,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"10","license":[{"start":{"date-parts":[[2014,10,1]],"date-time":"2014-10-01T00:00:00Z","timestamp":1412121600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"funder":[{"name":"EU FP7","award":["NESSoS"],"award-info":[{"award-number":["NESSoS"]}]},{"name":"Research Fund KU Leuven"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IIEEE Trans. Software Eng."],"published-print":{"date-parts":[[2014,10,1]]},"DOI":"10.1109\/tse.2014.2340398","type":"journal-article","created":{"date-parts":[[2014,7,18]],"date-time":"2014-07-18T18:23:40Z","timestamp":1405707820000},"page":"993-1006","source":"Crossref","is-referenced-by-count":285,"title":["Predicting Vulnerable Software Components via Text Mining"],"prefix":"10.1109","volume":"40","author":[{"given":"Riccardo","family":"Scandariato","sequence":"first","affiliation":[]},{"given":"James","family":"Walden","sequence":"additional","affiliation":[]},{"given":"Aram","family":"Hovsepyan","sequence":"additional","affiliation":[]},{"given":"Wouter","family":"Joosen","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","year":"0"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/2020390.2020395"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/1835804.1835821"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2010.5463340"},{"key":"ref31","article-title":"Vulnerability extrapolation: Assisted discovery of vulnerabilities using machine learning","author":"yamaguchi","year":"2011","journal-title":"Proc USENIX Workshop Offensive Technol"},{"key":"ref30","first-page":"229","article-title":"Peer code review to prevent security vulnerabilities: An empirical evaluation (extended abstract)","author":"bosu","year":"2013","journal-title":"Proc Int Conf Softw Security Rel"},{"key":"ref37","first-page":"1034","article-title":"On biases in estimating multi-valued attributes","author":"kononenko","year":"1995","journal-title":"Proc Int Joint Artif Intell Conf"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/2347736.2347755"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1996.8.7.1341"},{"key":"ref34","author":"scandariato","year":"0"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/1456362.1456372"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/1595696.1595713"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/1414004.1414065"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1016\/j.sysarc.2010.06.003"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2010.32"},{"key":"ref14","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1007\/978-3-642-00199-4_12","article-title":"Toward non-security failures as a predictor of security faults and failures","author":"gegick","year":"2009","journal-title":"Proc Symp Eng Secure Softw Syst"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/1853919.1853923"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2011.15"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/1853919.1853925"},{"key":"ref18","article-title":"Buying into the bias: Why vulnerability statistics suck","author":"martin","year":"0","journal-title":"Proc BlackHat USA"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2011.18"},{"key":"ref28","doi-asserted-by":"crossref","first-page":"181","DOI":"10.1109\/TSE.2007.70773","volume":"34","author":"kim","year":"0","journal-title":"IEEE Trans Softw Eng"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/280324.280335"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/1294948.1294954"},{"key":"ref3","article-title":"Software verification and validation: Its role in computer assurance and its relationship with software product management standards","author":"wallace","year":"0"},{"key":"ref6","first-page":"529","article-title":"Predicting vulnerable software components","author":"neuhaus","year":"2007","journal-title":"Proc ACM Conf Comput Commun Secur"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/1831708.1831723"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.81"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2008.10.027"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-009-9117-9"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1984.5010193"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-011-9190-8"},{"key":"ref1","year":"0"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.1"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICST.2009.36"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/1456362.1456370"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382218"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/1062455.1062558"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2007.29"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2006.38"}],"container-title":["IEEE Transactions on Software Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/32\/6919382\/06860243.pdf?arnumber=6860243","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T16:31:11Z","timestamp":1642005071000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6860243\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,10,1]]},"references-count":40,"journal-issue":{"issue":"10"},"URL":"https:\/\/doi.org\/10.1109\/tse.2014.2340398","relation":{},"ISSN":["0098-5589","1939-3520"],"issn-type":[{"value":"0098-5589","type":"print"},{"value":"1939-3520","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,10,1]]}}}