{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:41:44Z","timestamp":1750308104034,"version":"3.41.0"},"reference-count":22,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2005,5,15]],"date-time":"2005-05-15T00:00:00Z","timestamp":1116115200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGSOFT Softw. Eng. Notes"],"published-print":{"date-parts":[[2005,7]]},"abstract":"<jats:p>A key property of software component technology is predictability, which means that the properties of an overall system can be deduced from the properties of the individual components. One of the crucial building blocks in component technology is the notion of component contract. In order to leverage predictability for the construction of secure systems, security requirements and properties must be adequately supported by component contracts, which is currently a challenging and open problem. This paper provides an overview of the problem domain by presenting an initial taxonomy of security contracts and their representative security properties.<\/jats:p>","DOI":"10.1145\/1082983.1083204","type":"journal-article","created":{"date-parts":[[2005,11,7]],"date-time":"2005-11-07T19:28:32Z","timestamp":1131391712000},"page":"1-7","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Towards a unifying view on security contracts"],"prefix":"10.1145","volume":"30","author":[{"given":"Bart","family":"De Win","sequence":"first","affiliation":[{"name":"Katholieke Universiteit Leuven, Leuven, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Frank","family":"Piessens","sequence":"additional","affiliation":[{"name":"Katholieke Universiteit Leuven, Leuven, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jan","family":"Smans","sequence":"additional","affiliation":[{"name":"Katholieke Universiteit Leuven, Leuven, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wouter","family":"Joosen","sequence":"additional","affiliation":[{"name":"Katholieke Universiteit Leuven, Leuven, Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2005,5,15]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Common Criteria for Information Technology Security Evaluation Version 2.1 August 1999.  Common Criteria for Information Technology Security Evaluation Version 2.1 August 1999."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.5555\/646775.705734"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.21236\/ADA379930"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.774917"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.5555\/518169"},{"key":"e_1_2_1_6_1","volume-title":"Leuven","author":"De Win B.","year":"2004","unstructured":"B. De Win . Engineering application-level security through aspect-oriented software development. Phd, Department of Computer Science, K. U . Leuven , Leuven, Belgium , Mar. 2004 . 206+xiv pages. B. De Win. Engineering application-level security through aspect-oriented software development. Phd, Department of Computer Science, K. U. Leuven, Leuven, Belgium, Mar. 2004. 206+xiv pages."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-24851-4_21"},{"key":"e_1_2_1_8_1","unstructured":"L. G. a. DeMichiel. Enterprise JavaBeans Specification Version 2.1. http:\/\/java.sun.com\/products\/ejb\/docs.html June 2003.  L. G. a. DeMichiel. Enterprise JavaBeans Specification Version 2.1. http:\/\/java.sun.com\/products\/ejb\/docs.html June 2003."},{"key":"e_1_2_1_9_1","first-page":"11","volume-title":"Report of the AOSD2004 workshop on AOSD Technology for Application-level Security (AOSDSEC), CW387","author":"Franz E.","unstructured":"E. Franz and C. Pohl . Towards unified treatment of security and other non-functional properties . Report of the AOSD2004 workshop on AOSD Technology for Application-level Security (AOSDSEC), CW387 , pages 11 -- 16 , to appear. E. Franz and C. Pohl. Towards unified treatment of security and other non-functional properties. Report of the AOSD2004 workshop on AOSD Technology for Application-level Security (AOSDSEC), CW387, pages 11--16, to appear."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/976270.976281"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/WICSA.2001.948418"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/52.976939"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2004.17"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/263699.263712"},{"key":"e_1_2_1_15_1","volume-title":"Caesar: A proposed method for evaluating security in component-based distributed information systems. Master's thesis","author":"Peterson M.","year":"2004","unstructured":"M. Peterson . Caesar: A proposed method for evaluating security in component-based distributed information systems. Master's thesis , Link\u00f6ping University , 2004 . M. Peterson. Caesar: A proposed method for evaluating security in component-based distributed information systems. Master's thesis, Link\u00f6ping University, 2004."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2002.806121"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.241422"},{"key":"e_1_2_1_18_1","volume-title":"Static verification of code access security policy compliance of .net applications. Submitted to the 3rd International Conference on .NET Technologies","author":"Smans J.","year":"2005","unstructured":"J. Smans , B. Jacobs , and F. Piessens . Static verification of code access security policy compliance of .net applications. Submitted to the 3rd International Conference on .NET Technologies , 2005 . J. Smans, B. Jacobs, and F. Piessens. Static verification of code access security policy compliance of .net applications. Submitted to the 3rd International Conference on .NET Technologies, 2005."},{"key":"e_1_2_1_19_1","volume-title":"June","author":"The Object Management Group (OMG).","year":"2002","unstructured":"The Object Management Group (OMG). Corba components - version 3.0. formal\/02-06-65 , June 2002 . The Object Management Group (OMG). Corba components - version 3.0. formal\/02-06-65, June 2002."},{"key":"e_1_2_1_20_1","volume-title":"March","author":"The Object Management Group (OMG).","year":"2002","unstructured":"The Object Management Group (OMG). Corbaservices: Security service specification, version 1.8. formal\/02-03-11 , March 2002 . The Object Management Group (OMG). Corbaservices: Security service specification, version 1.8. formal\/02-03-11, March 2002."},{"key":"e_1_2_1_21_1","first-page":"42","volume-title":"Report of the AOSD2004 workshop on AOSD Technology for Application-level Security (AOSDSEC), CW387","author":"Verhanneman T.","unstructured":"T. Verhanneman , F. Piessens , B. De Win , and W. Joosen . View connectors for the integration of domain specific access control . Report of the AOSD2004 workshop on AOSD Technology for Application-level Security (AOSDSEC), CW387 , pages 42 -- 48 , to appear. T. Verhanneman, F. Piessens, B. De Win, and W. Joosen. View connectors for the integration of domain specific access control. Report of the AOSD2004 workshop on AOSD Technology for Application-level Security (AOSDSEC), CW387, pages 42--48, to appear."},{"key":"e_1_2_1_22_1","first-page":"94","volume-title":"SP '97: Proceedings of the 1997 IEEE Symposium on Security and Privacy","author":"Zakinthinos A.","unstructured":"A. Zakinthinos and E. S. Lee . A general theory of security properties . In SP '97: Proceedings of the 1997 IEEE Symposium on Security and Privacy , page 94 . IEEE Computer Society, 1997. A. Zakinthinos and E. S. Lee. A general theory of security properties. In SP '97: Proceedings of the 1997 IEEE Symposium on Security and Privacy, page 94. IEEE Computer Society, 1997."}],"container-title":["ACM SIGSOFT Software Engineering Notes"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1082983.1083204","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1082983.1083204","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:08:05Z","timestamp":1750262885000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1082983.1083204"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005,5,15]]},"references-count":22,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2005,7]]}},"alternative-id":["10.1145\/1082983.1083204"],"URL":"https:\/\/doi.org\/10.1145\/1082983.1083204","relation":{"is-identical-to":[{"id-type":"doi","id":"10.1145\/1083200.1083204","asserted-by":"subject"}]},"ISSN":["0163-5948"],"issn-type":[{"type":"print","value":"0163-5948"}],"subject":[],"published":{"date-parts":[[2005,5,15]]},"assertion":[{"value":"2005-05-15","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}