{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T23:19:46Z","timestamp":1784243986915,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":51,"publisher":"ACM","license":[{"start":{"date-parts":[[2014,11,3]],"date-time":"2014-11-03T00:00:00Z","timestamp":1414972800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000181","name":"Air Force Office of Scientific Research","doi-asserted-by":"publisher","award":["FA9550-12- 1-0400"],"award-info":[{"award-number":["FA9550-12- 1-0400"]}],"id":[{"id":"10.13039\/100000181","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000185","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["N66001-11-C-4020"],"award-info":[{"award-number":["N66001-11-C-4020"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006503","name":"SPAWAR Systems Center Pacific, Space and Naval Warfare Systems Command","doi-asserted-by":"publisher","award":["N66001-11-C-4020"],"award-info":[{"award-number":["N66001-11-C-4020"]}],"id":[{"id":"10.13039\/100006503","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2014,11,3]]},"DOI":"10.1145\/2660267.2660320","type":"proceedings-article","created":{"date-parts":[[2014,11,11]],"date-time":"2014-11-11T13:40:05Z","timestamp":1415713205000},"page":"1256-1266","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":15,"title":["Moving Targets"],"prefix":"10.1145","author":[{"given":"Sandy","family":"Clark","sequence":"first","affiliation":[{"name":"University of Pennsylvania, Philadelphia, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Collis","sequence":"additional","affiliation":[{"name":"University of Pennsylvania, Philadelphia, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Matt","family":"Blaze","sequence":"additional","affiliation":[{"name":"University of Pennsylvania, Philadelphia, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jonathan M.","family":"Smith","sequence":"additional","affiliation":[{"name":"University of Pennsylvania, Philadelphia, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2014,11,3]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2008.916872"},{"key":"e_1_3_2_1_2_1","volume-title":"May","author":"Almossawi Ali","year":"2013","unstructured":"Ali Almossawi . How maintainable is the Firefox codebase? , May 2013 . http:\/\/almossawi.com\/firefox\/prose\/. Ali Almossawi. How maintainable is the Firefox codebase?, May 2013. http:\/\/almossawi.com\/firefox\/prose\/."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.889093"},{"key":"e_1_3_2_1_4_1","unstructured":"Baker Mitchell. Mozilla Blog. http:\/\/blog.lizardwrangler.com\/2011\/08\/25\/rapid-release-process\/.  Baker Mitchell. Mozilla Blog. http:\/\/blog.lizardwrangler.com\/2011\/08\/25\/rapid-release-process\/."},{"key":"e_1_3_2_1_5_1","volume-title":"Manifesto for Agile Software Development","author":"Beck Kent","year":"2001","unstructured":"Kent Beck , Mike Beedle , Arie van Bennekum , Alistair Cockburn , Ward Cunningham , Martin Fowler , James Grenning , Jim Highsmith , Andrew Hunt , Ron Jeffries , Jon Kern , Brian Marick , Robert C. Martin , Steve Mellor , Ken Schwaber , Jeff Sutherland , and Dave Thomas . Manifesto for Agile Software Development , 2001 . http:\/\/www.agilemanifesto.org\/. Kent Beck, Mike Beedle, Arie van Bennekum, Alistair Cockburn, Ward Cunningham, Martin Fowler, James Grenning, Jim Highsmith, Andrew Hunt, Ron Jeffries, Jon Kern, Brian Marick, Robert C. Martin, Steve Mellor, Ken Schwaber, Jeff Sutherland, and Dave Thomas. Manifesto for Agile Software Development, 2001. http:\/\/www.agilemanifesto.org\/."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1646353.1646374"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1065907.1066034"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.59"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF02249046"},{"key":"e_1_3_2_1_10_1","unstructured":"Brink DerekA. Security and the Software Development Lifecycle: Secure at the Source. download.microsoft.com\/download\/9\/D\/4\/9D403333-C4F6--4770-A330--89661BE545CF\/Aberdeen_ SecureSource.pdf.  Brink DerekA. Security and the Software Development Lifecycle: Secure at the Source. download.microsoft.com\/download\/9\/D\/4\/9D403333-C4F6--4770-A330--89661BE545CF\/Aberdeen_ SecureSource.pdf."},{"key":"e_1_3_2_1_11_1","volume-title":"The Mythical Man-Month: Essays on Software Engineering, 20th Anniversary Edition","author":"Brooks Frederick P.","year":"1995","unstructured":"Frederick P. Brooks . The Mythical Man-Month: Essays on Software Engineering, 20th Anniversary Edition . Addison-Wesley Professional , August 1995 . Frederick P. Brooks. The Mythical Man-Month: Essays on Software Engineering, 20th Anniversary Edition. Addison-Wesley Professional, August 1995."},{"key":"e_1_3_2_1_12_1","volume-title":"The Mythical Man-Month: Essays on Software Engineering, 20th Anniversary Edition","author":"Brooks Frederick P.","year":"1995","unstructured":"Frederick P. Brooks . The Mythical Man-Month: Essays on Software Engineering, 20th Anniversary Edition . Addison-Wesley Professional , August 1995 . http:\/\/www.amazon.ca\/exec\/obidos\/redirect?tag=citeulike09--20&path=ASIN\/0201835959. Frederick P. Brooks. The Mythical Man-Month: Essays on Software Engineering, 20th Anniversary Edition. Addison-Wesley Professional, August 1995. http:\/\/www.amazon.ca\/exec\/obidos\/redirect?tag=citeulike09--20&path=ASIN\/0201835959."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920299"},{"key":"e_1_3_2_1_14_1","first-page":"182","volume-title":"Java Modeling in Color with UML","author":"Coad Peter","year":"1999","unstructured":"Peter Coad , Eric LeFebrve , and Jeff De Luca . Feature-driven development . Java Modeling in Color with UML , pages 182 -- 203 , 1999 . Peter Coad, Eric LeFebrve, and Jeff De Luca. Feature-driven development. Java Modeling in Color with UML, pages 182--203, 1999."},{"key":"e_1_3_2_1_15_1","volume-title":"September","author":"Coates Michael","year":"2011","unstructured":"Michael Coates . Security Evolution - Bug Bounty Programs for Web Applications , September 2011 . http:\/\/www.slideshare.net\/michael_coates\/bug-bounty-programs-for-the-web. Michael Coates. Security Evolution - Bug Bounty Programs for Web Applications, September 2011. http:\/\/www.slideshare.net\/michael_coates\/bug-bounty-programs-for-the-web."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029997.1030005"},{"key":"e_1_3_2_1_17_1","volume-title":"State of Application Security: Immature Practices Fuel Inefficiencies, but Positive ROI Is Attainable - A Forrester Consulting Thought Leadership Paper Commissioned by Microsoft","author":"Consulting Forrester","year":"2011","unstructured":"Forrester Consulting . State of Application Security: Immature Practices Fuel Inefficiencies, but Positive ROI Is Attainable - A Forrester Consulting Thought Leadership Paper Commissioned by Microsoft . 2011 . http:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=2629. Forrester Consulting. State of Application Security: Immature Practices Fuel Inefficiencies, but Positive ROI Is Attainable - A Forrester Consulting Thought Leadership Paper Commissioned by Microsoft. 2011. http:\/\/www.microsoft.com\/en-us\/download\/details.aspx?id=2629."},{"key":"e_1_3_2_1_18_1","volume-title":"Microsoft Security Development Lifecycle for Agile","author":"Microsoft Corporation","year":"2009","unstructured":"Microsoft Corporation . Microsoft Security Development Lifecycle for Agile . 2009 . http:\/\/www.microsoft.com\/security\/sdl\/discover\/sdlagile-onetime.aspx. Microsoft Corporation. Microsoft Security Development Lifecycle for Agile. 2009. http:\/\/www.microsoft.com\/security\/sdl\/discover\/sdlagile-onetime.aspx."},{"key":"e_1_3_2_1_19_1","volume-title":"http:\/\/www.microsoft.com\/en-us\/news\/speeches\/2013\/06--26build2013.aspx","author":"Microsoft Corporation","year":"2013","unstructured":"Microsoft Corporation . http:\/\/www.microsoft.com\/en-us\/news\/speeches\/2013\/06--26build2013.aspx , 2013 . Microsoft Corporation. http:\/\/www.microsoft.com\/en-us\/news\/speeches\/2013\/06--26build2013.aspx, 2013."},{"key":"e_1_3_2_1_20_1","volume-title":"September","author":"Criteria Common","year":"2012","unstructured":"Common Criteria . Common Criteria for Information Technology Security Evaluation. Technical report , September 2012 . Common Criteria. Common Criteria for Information Technology Security Evaluation. Technical report, September 2012."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/255656.255698"},{"key":"e_1_3_2_1_22_1","volume-title":"http:\/\/cve.mitre.org","author":"CVE.","year":"2008","unstructured":"CVE. Common vulnerabilities and exposures. http:\/\/cve.mitre.org , 2008 . CVE. Common vulnerabilities and exposures. http:\/\/cve.mitre.org, 2008."},{"key":"e_1_3_2_1_23_1","volume-title":"An Empirical Study of Vulnerability Reward Programs. In 22nd USENIX Security Symposium","author":"Finifter M.","year":"2013","unstructured":"M. Finifter , D. Akhawe , and D. Wagner . An Empirical Study of Vulnerability Reward Programs. In 22nd USENIX Security Symposium , 2013 . M. Finifter, D. Akhawe, and D. Wagner. An Empirical Study of Vulnerability Reward Programs. In 22nd USENIX Security Symposium, 2013."},{"key":"e_1_3_2_1_24_1","volume-title":"Mozilla firefox esr overview","author":"Foundation Mozilla","year":"2014","unstructured":"Mozilla Foundation . Mozilla firefox esr overview , 2014 . https:\/\/www.mozilla.org\/en-US\/firefox\/ organizations\/faq\/. Mozilla Foundation. Mozilla firefox esr overview, 2014. https:\/\/www.mozilla.org\/en-US\/firefox\/ organizations\/faq\/."},{"key":"e_1_3_2_1_26_1","volume-title":"Oracle Software Security Assurance. Technical report","author":"Harris Duncan","year":"2014","unstructured":"Duncan Harris . Oracle Software Security Assurance. Technical report , 2014 . http:\/\/www.oracle.com\/us\/ support\/assurance\/overview\/index.html. Duncan Harris. Oracle Software Security Assurance. Technical report, 2014. http:\/\/www.oracle.com\/us\/ support\/assurance\/overview\/index.html."},{"key":"e_1_3_2_1_27_1","volume-title":"Adaptive software development: a collaborative approach to managing complex systems","author":"Highsmith Jim","year":"2013","unstructured":"Jim Highsmith . Adaptive software development: a collaborative approach to managing complex systems . Addison-Wesley , 2013 . Jim Highsmith. Adaptive software development: a collaborative approach to managing complex systems. Addison-Wesley, 2013."},{"key":"e_1_3_2_1_28_1","volume-title":"The Security Development Lifecycle","author":"Howard Michael","year":"2006","unstructured":"Michael Howard and Steve Lipner . The Security Development Lifecycle . Microsoft Press , May 2006 . Michael Howard and Steve Lipner. The Security Development Lifecycle. Microsoft Press, May 2006."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/13487689.13487690"},{"key":"e_1_3_2_1_30_1","volume-title":"NIST and CSSPAB Workshop","author":"Jelen George","year":"2000","unstructured":"George Jelen . Sse-cmm security metrics . In NIST and CSSPAB Workshop , 2000 . George Jelen. Sse-cmm security metrics. In NIST and CSSPAB Workshop, 2000."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.588541"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/AICCSA.2008.4493611"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.5555\/2664446.2664475"},{"key":"e_1_3_2_1_34_1","unstructured":"Anthony Laforge. Release Early Release Often July 2010. http:\/\/blog.chromium.org\/2010\/07\/ release-early-release-often.html.  Anthony Laforge. Release Early Release Often July 2010. http:\/\/blog.chromium.org\/2010\/07\/ release-early-release-often.html."},{"key":"e_1_3_2_1_35_1","volume-title":"Software Security Touchpoint: Architectural Risk Analysis. Technical report","author":"McGraw Gary","year":"2010","unstructured":"Gary McGraw . Software Security Touchpoint: Architectural Risk Analysis. Technical report , 2010 . http:\/\/www.cigital.com\/presentations\/ARA10.pdf. Gary McGraw. Software Security Touchpoint: Architectural Risk Analysis. Technical report, 2010. http:\/\/www.cigital.com\/presentations\/ARA10.pdf."},{"key":"e_1_3_2_1_36_1","volume-title":"Proceedings of the 18th USENIX Security Symposium (USENIX Security '09)","author":"McGraw Gary","year":"2009","unstructured":"Gary McGraw and Brian Chess . The building security in maturity model(bsimm) . In Proceedings of the 18th USENIX Security Symposium (USENIX Security '09) , Montreal, Canada , August 2009 . Gary McGraw and Brian Chess. The building security in maturity model(bsimm). In Proceedings of the 18th USENIX Security Symposium (USENIX Security '09), Montreal, Canada, August 2009."},{"key":"e_1_3_2_1_37_1","volume-title":"October","author":"Meier J.D.","year":"2005","unstructured":"J.D. Meier , Alex Mackman , Blaine Wastell , Prashant Bansode , Andy Wigley , and Kishore Gopalan . Security Guidelines for .NET Framework Version 2.0. Technical report , October 2005 . http:\/\/msdn. microsoft.com\/en-us\/library\/aa480477.aspx. J.D. Meier, Alex Mackman, Blaine Wastell, Prashant Bansode, Andy Wigley, and Kishore Gopalan. Security Guidelines for .NET Framework Version 2.0. Technical report, October 2005. http:\/\/msdn. microsoft.com\/en-us\/library\/aa480477.aspx."},{"key":"e_1_3_2_1_38_1","volume-title":"September","year":"2013","unstructured":"Mozilla. Bugzilla@Mozilla. https:\/\/bugzilla.mozilla.org\/ , September 2013 . Mozilla. Bugzilla@Mozilla. https:\/\/bugzilla.mozilla.org\/, September 2013."},{"key":"e_1_3_2_1_39_1","volume-title":"September","year":"2013","unstructured":"Mozilla. Mozilla Foundation Security Advisories. https:\/\/www.mozilla.org\/security\/announce\/ , September 2013 . Mozilla. Mozilla Foundation Security Advisories. https:\/\/www.mozilla.org\/security\/announce\/, September 2013."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1975.6312856"},{"key":"e_1_3_2_1_41_1","volume-title":"Prediction, Application","author":"Musa John D.","year":"1987","unstructured":"John D. Musa , Anthony Iannino , and Kasuhira Okumoto . Software Reliability: Measurement , Prediction, Application . McGraw-Hill , 1987 . John D. Musa, Anthony Iannino, and Kasuhira Okumoto. Software Reliability: Measurement, Prediction, Application. McGraw-Hill, 1987."},{"key":"e_1_3_2_1_42_1","volume-title":"Mozilla blog post future releases","author":"Nightingale Johnathan","year":"2011","unstructured":"Johnathan Nightingale . Mozilla blog post future releases , 2011 . https:\/\/blog.mozilla.org\/ futurereleases\/2011\/07\/19\/every-six-weeks\/. Johnathan Nightingale. Mozilla blog post future releases, 2011. https:\/\/blog.mozilla.org\/ futurereleases\/2011\/07\/19\/every-six-weeks\/."},{"key":"e_1_3_2_1_43_1","volume-title":"http:\/\/nvd.nist.gov","author":"NIST. National Vulnerability Database.","year":"2008","unstructured":"NIST. National Vulnerability Database. http:\/\/nvd.nist.gov , 2008 . NIST. National Vulnerability Database. http:\/\/nvd.nist.gov, 2008."},{"key":"e_1_3_2_1_44_1","volume-title":"SECURITY IN THE SOFTWARE LIFECYCLE: Making Software Development Processes{ and Software Produced by Them{ More Secure","author":"Department of Homeland Security.","year":"2006","unstructured":"Department of Homeland Security. SECURITY IN THE SOFTWARE LIFECYCLE: Making Software Development Processes{ and Software Produced by Them{ More Secure . 2006 . http:\/\/resources.sei.cmu.edu\/asset_files\/ WhitePaper\/ 2006_019_001_52113.pdf. Department of Homeland Security. SECURITY IN THE SOFTWARE LIFECYCLE: Making Software Development Processes{ and Software Produced by Them{ More Secure. 2006. http:\/\/resources.sei.cmu.edu\/asset_files\/ WhitePaper\/2006_019_001_52113.pdf."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314257.1314261"},{"key":"e_1_3_2_1_46_1","volume-title":"USENIX-SS'06: Proceedings of the 15th USENIX Security Symposium","author":"Ozment Andy","year":"2006","unstructured":"Andy Ozment and Stuart E. Schechter . Milk or wine: does software security improve with age? In USENIX-SS'06: Proceedings of the 15th USENIX Security Symposium , Berkeley, CA, USA , 2006 . USENIX Association. Andy Ozment and Stuart E. Schechter. Milk or wine: does software security improve with age? In USENIX-SS'06: Proceedings of the 15th USENIX Security Symposium, Berkeley, CA, USA, 2006. USENIX Association."},{"key":"e_1_3_2_1_47_1","volume-title":"Secure Coding in C and C++","author":"Seacord Robert C.","year":"2008","unstructured":"Robert C. Seacord . Secure Coding in C and C++ . Addison-Wesley Professional , June 2008 . Robert C. Seacord. Secure Coding in C and C++. Addison-Wesley Professional, June 2008."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2005.329"},{"key":"e_1_3_2_1_49_1","volume-title":"The economic impacts of inadequate infrastructure for software testing","author":"Tassey Gregory","year":"2002","unstructured":"Gregory Tassey . The economic impacts of inadequate infrastructure for software testing . 2002 . Gregory Tassey. The economic impacts of inadequate infrastructure for software testing. 2002."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/1083200.1083207"},{"key":"e_1_3_2_1_51_1","first-page":"117","volume-title":"Security engineering and extreme programming: An impossible marriage? In Extreme programming and agile methods-XP\/Agile Universe","author":"W\u00e4yrynen Jaana","year":"2004","unstructured":"Jaana W\u00e4yrynen , Marine Boden , and Gustav Bostrom . Security engineering and extreme programming: An impossible marriage? In Extreme programming and agile methods-XP\/Agile Universe 2004 , pages 117 -- 128 . Springer , 2004. Jaana W\u00e4yrynen, Marine Boden, and Gustav Bostrom. Security engineering and extreme programming: An impossible marriage? In Extreme programming and agile methods-XP\/Agile Universe 2004, pages 117--128. Springer, 2004."},{"key":"e_1_3_2_1_52_1","volume-title":"Agile security review of current research and pilot usages","author":"Woody Carol","year":"2013","unstructured":"Carol Woody . Agile security review of current research and pilot usages . SEI Library White Paper , 2013 . http:\/\/resources.sei.cmu.edu\/library\/asset-view.cfm?assetid=70232. Carol Woody. Agile security review of current research and pilot usages. SEI Library White Paper, 2013. http:\/\/resources.sei.cmu.edu\/library\/asset-view.cfm?assetid=70232."}],"event":{"name":"CCS'14: 2014 ACM SIGSAC Conference on Computer and Communications Security","location":"Scottsdale Arizona USA","acronym":"CCS'14","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2660267.2660320","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2660267.2660320","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:56:10Z","timestamp":1750229770000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2660267.2660320"}},"subtitle":["Security and Rapid-Release in Firefox"],"short-title":[],"issued":{"date-parts":[[2014,11,3]]},"references-count":51,"alternative-id":["10.1145\/2660267.2660320","10.1145\/2660267"],"URL":"https:\/\/doi.org\/10.1145\/2660267.2660320","relation":{},"subject":[],"published":{"date-parts":[[2014,11,3]]},"assertion":[{"value":"2014-11-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}