{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,18]],"date-time":"2026-01-18T09:04:42Z","timestamp":1768727082814,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":23,"publisher":"ACM","license":[{"start":{"date-parts":[[2008,10,27]],"date-time":"2008-10-27T00:00:00Z","timestamp":1225065600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2008,10,27]]},"DOI":"10.1145\/1456362.1456370","type":"proceedings-article","created":{"date-parts":[[2008,11,6]],"date-time":"2008-11-06T13:49:50Z","timestamp":1225979390000},"page":"31-38","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":61,"title":["Prioritizing software security fortification throughcode-level metrics"],"prefix":"10.1145","author":[{"given":"Michael","family":"Gegick","sequence":"first","affiliation":[{"name":"North Carolina State University, Raleigh, NC, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Laurie","family":"Williams","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, NC, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jason","family":"Osborne","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, NC, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mladen","family":"Vouk","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, NC, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2008,10,27]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Design Principles,\" https:\/\/buildsecurityin.us--cert.gov\/portal\/article\/knowledge\/Principles","author":"Barnum S.","year":"2005","unstructured":"S. Barnum and M. Gegick , \" Design Principles,\" https:\/\/buildsecurityin.us--cert.gov\/portal\/article\/knowledge\/Principles , 2005 . S. Barnum and M. Gegick, \"Design Principles,\" https:\/\/buildsecurityin.us--cert.gov\/portal\/article\/knowledge\/Principles, 2005."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.544352"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2006.77"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/C-M.1978.218136"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/337180.337592"},{"key":"e_1_3_2_1_6_1","volume-title":"Structured Programming","author":"Dijkstra E.","year":"1970","unstructured":"E. Dijkstra , Structured Programming , Brussels, Belgium , 1970 . E. Dijkstra, Structured Programming, Brussels, Belgium, 1970."},{"key":"e_1_3_2_1_7_1","volume-title":"CA, July 1--6","author":"Gegick M.","year":"2007","unstructured":"M. Gegick and L. Williams , \" Toward the Use of Static Analysis Alerts for Early Identification of Vulnerability- and Attack-prone Components,\" First International Workshop on Systems Vulnerabilities (SYVUL'07) Santa Clara , CA, July 1--6 2007 . M. Gegick and L. Williams, \"Toward the Use of Static Analysis Alerts for Early Identification of Vulnerability- and Attack-prone Components,\" First International Workshop on Systems Vulnerabilities (SYVUL'07) Santa Clara, CA, July 1--6 2007."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"crossref","DOI":"10.1007\/978-0-387-21606-5","volume-title":"The Elements of Statistical Learning","author":"Hastie T.","year":"2001","unstructured":"T. Hastie , R. Tibshirani , and J. H. Friedman , The Elements of Statistical Learning , New York , Springer , 2001 . T. Hastie, R. Tibshirani, and J. H. Friedman, The Elements of Statistical Learning, New York, Springer, 2001."},{"key":"e_1_3_2_1_9_1","volume-title":"NC","author":"Heckman S.","year":"2006","unstructured":"S. Heckman and L. Williams , \" Automated adaptive ranking and filtering of static analysis alerts,\" Fast abstract at the International Symposium on Software Reliability Engineering, Raleigh , NC , November 2006 . S. Heckman and L. Williams, \"Automated adaptive ranking and filtering of static analysis alerts,\" Fast abstract at the International Symposium on Software Reliability Engineering, Raleigh, NC, November 2006."},{"key":"e_1_3_2_1_10_1","volume-title":"General Overview","author":"Information ISO","year":"1996","unstructured":"ISO , \"ISO\/IEC DIS 14598--1 Information Technology - Software Product Evaluation - Part 1 : General Overview ,\" October 28 1996 . ISO, \"ISO\/IEC DIS 14598--1 Information Technology - Software Product Evaluation - Part 1: General Overview,\" October 28 1996."},{"key":"e_1_3_2_1_11_1","unstructured":"ISO\/IEC 24765 \"Software and Systems Engineering Vocabulary \" 2006.  ISO\/IEC 24765 \"Software and Systems Engineering Vocabulary \" 2006."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.5555\/851020.856204"},{"key":"e_1_3_2_1_13_1","unstructured":"I. Krsul \"Software Vulnerability Analysis \" PhD Thesis in Computer Science at Purdue University West Lafayette 1998.   I. Krsul \"Software Vulnerability Analysis \" PhD Thesis in Computer Science at Purdue University West Lafayette 1998."},{"key":"e_1_3_2_1_14_1","first-page":"355","article-title":"The Status of Research on Program Mutation","author":"Lipton R. J.","year":"1978","unstructured":"R. J. Lipton and F. G. Sayward , \" The Status of Research on Program Mutation ,\" In Digest for the Workshop on Software Testing and Test Documentation , pp. 355 -- 373 , December 1978 . R. J. Lipton and F. G. Sayward, \"The Status of Research on Program Mutation,\" In Digest for the Workshop on Software Testing and Test Documentation, pp. 355--373, December 1978.","journal-title":"Digest for the Workshop on Software Testing and Test Documentation"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.135775"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1062455.1062558"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1062455.1062514"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315311"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/75308.75324"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/1007512.1007524"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSPEC.2007.376605"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1159733.1159739"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2006.38"}],"event":{"name":"CCS08: 15th ACM Conference on Computer and Communications Security 2008","location":"Alexandria Virginia USA","acronym":"CCS08","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control","ACM Association for Computing Machinery"]},"container-title":["Proceedings of the 4th ACM workshop on Quality of protection"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1456362.1456370","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1456362.1456370","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T13:29:53Z","timestamp":1750253393000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1456362.1456370"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008,10,27]]},"references-count":23,"alternative-id":["10.1145\/1456362.1456370","10.1145\/1456362"],"URL":"https:\/\/doi.org\/10.1145\/1456362.1456370","relation":{},"subject":[],"published":{"date-parts":[[2008,10,27]]},"assertion":[{"value":"2008-10-27","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}