{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,6]],"date-time":"2026-07-06T11:25:07Z","timestamp":1783337107562,"version":"3.54.6"},"reference-count":83,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2016,6,9]],"date-time":"2016-06-09T00:00:00Z","timestamp":1465430400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Science Foundation","award":["DUE-0817267 and DUE-1241738"],"award-info":[{"award-number":["DUE-0817267 and DUE-1241738"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Comput. Educ."],"published-print":{"date-parts":[[2016,10,13]]},"abstract":"<jats:p>Despite the critical societal importance of computer security, security is not well integrated into the undergraduate computing curriculum. Security classes and tracks treat security issues as separable topics as opposed to fundamental issues that pervade all aspects of software development. Recently, there has been an increasing focus on security as a cross-cutting concern across the computer science curriculum. The Security Injections@Towson project provides resources and effective strategies to incorporate secure coding in the early programming classes. We describe the development, assessment, and dissemination of more than 40 lab-based security injection modules designed to be injected into courses with minimal impact on the curriculum. We include assessment results from 1,135 students across five diverse institutions demonstrating that the security injections help students retain, comprehend, and apply secure coding concepts in the introductory programming courses.<\/jats:p>","DOI":"10.1145\/2897441","type":"journal-article","created":{"date-parts":[[2016,6,10]],"date-time":"2016-06-10T13:54:00Z","timestamp":1465566840000},"page":"1-20","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":20,"title":["Security Injections@Towson"],"prefix":"10.1145","volume":"16","author":[{"given":"Blair","family":"Taylor","sequence":"first","affiliation":[{"name":"Towson University, MD"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Siddharth","family":"Kaza","sequence":"additional","affiliation":[{"name":"Towson University, MD"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2016,6,9]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Retrieved","author":"ACM","year":"2013","unstructured":"ACM and IEEE-CS. 2013 . Computer Science Curricula 2013 (CS2013) . Retrieved April 27, 2016, from http:\/\/ai.stanford.edu\/users\/sahami\/CS2013\/. ACM and IEEE-CS. 2013. Computer Science Curricula 2013 (CS2013). Retrieved April 27, 2016, from http:\/\/ai.stanford.edu\/users\/sahami\/CS2013\/."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.2190\/ET.41.2.b"},{"key":"e_1_2_1_3_1","volume-title":"ITSEED. In Proceedings of the 45th ACM Technical Symposium on Computer Science Education (SIGCSE\u201914)","author":"Bai Yan","year":"2014","unstructured":"Yan Bai and Xinli Wang . 2014 . ITSEED. In Proceedings of the 45th ACM Technical Symposium on Computer Science Education (SIGCSE\u201914) . ACM, New York, NY, 739. Yan Bai and Xinli Wang. 2014. ITSEED. In Proceedings of the 45th ACM Technical Symposium on Computer Science Education (SIGCSE\u201914). ACM, New York, NY, 739."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/792548.611913"},{"key":"e_1_2_1_5_1","volume-title":"Introduction to Computer Security","author":"Bishop Matt","unstructured":"Matt Bishop . 2004. Introduction to Computer Security . Addison-Wesley . Matt Bishop. 2004. Introduction to Computer Security. Addison-Wesley."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/579090"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1176998"},{"key":"e_1_2_1_8_1","volume-title":"Retrieved","author":"Bishop Matt","year":"2006","unstructured":"Matt Bishop . 2006 . Teaching Assurance Using Checklists . Retrieved April 27, 2016, from http:\/\/nob.cs. ucdavis.edu\/bishop\/talks\/2006-wecs\/wecs2006\/index.html. Matt Bishop. 2006. Teaching Assurance Using Checklists. Retrieved April 27, 2016, from http:\/\/nob.cs. ucdavis.edu\/bishop\/talks\/2006-wecs\/wecs2006\/index.html."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.133"},{"key":"e_1_2_1_10_1","unstructured":"B. Bloom. 1956. Taxonomy of Educational Objectives: The Classification of Educational Goals. Handbook 1: Cognitive Domain. Longman.  B. Bloom. 1956. Taxonomy of Educational Objectives: The Classification of Educational Goals. Handbook 1: Cognitive Domain. Longman."},{"key":"e_1_2_1_11_1","volume-title":"Retrieved","author":"Burley Diana","year":"2011","unstructured":"Diana Burley and Matt Bishop . 2011 . Summit on Education in Secure Software: Final Report . Retrieved April 27, 2016, from https:\/\/www.gwu.edu\/elp\/SESS&percnt;20Report&percnt;20Final_June2011.pdf. Diana Burley and Matt Bishop. 2011. Summit on Education in Secure Software: Final Report. Retrieved April 27, 2016, from https:\/\/www.gwu.edu\/elp\/SESS&percnt;20Report&percnt;20Final_June2011.pdf."},{"key":"e_1_2_1_12_1","volume-title":"Computer Science Education: Secure Software. Proquest","author":"Cain James Francis","unstructured":"James Francis Cain . 2010. Computer Science Education: Secure Software. Proquest , Umi Dissertation Publishing . James Francis Cain. 2010. Computer Science Education: Secure Software. Proquest, Umi Dissertation Publishing."},{"key":"e_1_2_1_13_1","volume-title":"Retrieved","author":"Mellon Carnegie","year":"2015","unstructured":"Carnegie Mellon . 2015 . Principles of Learning . Retrieved April 27, 2016, from https:\/\/www.cmu.edu\/teaching\/principles\/learning.html. Carnegie Mellon. 2015. Principles of Learning. Retrieved April 27, 2016, from https:\/\/www.cmu.edu\/teaching\/principles\/learning.html."},{"key":"e_1_2_1_14_1","first-page":"4","article-title":"Beware of input buffer misbehavior and make your code behave: A nifty hands-on assignment on secure coding at the CS0 and CS1 levels: Nifty assignment","volume":"30","author":"Chattopadhyay Ankur","year":"2015","unstructured":"Ankur Chattopadhyay . 2015 . Beware of input buffer misbehavior and make your code behave: A nifty hands-on assignment on secure coding at the CS0 and CS1 levels: Nifty assignment . Journal of Computing Sciences in Colleges 30 , 4 , 118. Ankur Chattopadhyay. 2015. Beware of input buffer misbehavior and make your code behave: A nifty hands-on assignment on secure coding at the CS0 and CS1 levels: Nifty assignment. Journal of Computing Sciences in Colleges 30, 4, 118.","journal-title":"Journal of Computing Sciences in Colleges"},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the Americas Conference on Information Systems (AMCIS\u201910)","author":"Chen Li-Chiou","year":"2010","unstructured":"Li-Chiou Chen . 2010 . Secure Web development teaching modules . In Proceedings of the Americas Conference on Information Systems (AMCIS\u201910) . Li-Chiou Chen. 2010. Secure Web development teaching modules. In Proceedings of the Americas Conference on Information Systems (AMCIS\u201910)."},{"key":"e_1_2_1_16_1","volume-title":"Proceedings of the 2014 HUIC Education and STEM Conference.","author":"Chung Sam","year":"2014","unstructured":"Sam Chung , Leo Hansel , Yan Bai , Elizabeth Moore , Carol Taylor , Martha Crosby , Rachelle Heller , Viatcheslav Popovsky , and Barbara Endicott-Popovsky . 2014 . What approaches work best for teaching secure coding practices? In Proceedings of the 2014 HUIC Education and STEM Conference. Sam Chung, Leo Hansel, Yan Bai, Elizabeth Moore, Carol Taylor, Martha Crosby, Rachelle Heller, Viatcheslav Popovsky, and Barbara Endicott-Popovsky. 2014. What approaches work best for teaching secure coding practices? In Proceedings of the 2014 HUIC Education and STEM Conference."},{"key":"e_1_2_1_17_1","volume-title":"Retrieved","author":"CLICS.","year":"2005","unstructured":"CLICS. 2005 . CLICS: A Computational Laboratory for Information and Computer Security . Retrieved July 14, 2015, from http:\/\/www.nsf.gov\/awardsearch\/showAward?AWD_ID&equals;0309818. CLICS. 2005. CLICS: A Computational Laboratory for Information and Computer Security. Retrieved July 14, 2015, from http:\/\/www.nsf.gov\/awardsearch\/showAward?AWD_ID&equals;0309818."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2007.477"},{"key":"e_1_2_1_19_1","first-page":"99","article-title":"Professional development of science teachers: History of reform and contributions of the STS-based Iowa Chautauqua Program","volume":"8","author":"Dass Pradeep","year":"2009","unstructured":"Pradeep Dass and Robert Yager . 2009 . Professional development of science teachers: History of reform and contributions of the STS-based Iowa Chautauqua Program . Science Education Review 8 , 3, 99 -- 111 . Pradeep Dass and Robert Yager. 2009. Professional development of science teachers: History of reform and contributions of the STS-based Iowa Chautauqua Program. Science Education Review 8, 3, 99--111.","journal-title":"Science Education Review"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1193212"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.5555\/2337223.2337313"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1348713.1348716"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/2676723.2678290"},{"key":"e_1_2_1_24_1","volume-title":"The Checklist Manifesto: How to Get Things Right","author":"Gawande A.","unstructured":"A. Gawande . 2009. The Checklist Manifesto: How to Get Things Right . Metropolitan Books . A. Gawande. 2009. The Checklist Manifesto: How to Get Things Right. Metropolitan Books."},{"key":"e_1_2_1_25_1","volume-title":"Proceedings of the 12th IEEE International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises (WET ICE\u201903)","author":"Gilliam D. P.","year":"2003","unstructured":"D. P. Gilliam , T. L. Wolfe , J. S. Sherif , and M. Bishop . 2003. Software security checklist for the software life cycle . In Proceedings of the 12th IEEE International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises (WET ICE\u201903) . IEEE, Los Alamitos, CA, 243--248. DOI:http:\/\/dx.doi.org\/10.1109\/ENABL. 2003 .1231415 10.1109\/ENABL.2003.1231415 D. P. Gilliam, T. L. Wolfe, J. S. Sherif, and M. Bishop. 2003. Software security checklist for the software life cycle. In Proceedings of the 12th IEEE International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises (WET ICE\u201903). IEEE, Los Alamitos, CA, 243--248. DOI:http:\/\/dx.doi.org\/10.1109\/ENABL.2003.1231415"},{"key":"e_1_2_1_26_1","volume-title":"Van Wyk","author":"Graff Mark","year":"2003","unstructured":"Mark Graff and Kenneth R . Van Wyk . 2003 . Secure Coding : Principles and Practices. O\u2019Reilly Media . Mark Graff and Kenneth R. Van Wyk. 2003. Secure Coding: Principles and Practices. O\u2019Reilly Media."},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2591708.2602673"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2006.395"},{"key":"e_1_2_1_29_1","volume-title":"Writing Secure Code","author":"Howard M.","unstructured":"M. Howard and D. LeBlanc . 2003. Writing Secure Code . Microsoft Press . M. Howard and D. LeBlanc. 2003. Writing Secure Code. Microsoft Press."},{"key":"e_1_2_1_30_1","unstructured":"M. Howard D. LeBlanc and J. Viega. 2005. 19 Deadly Sins of Software Security. McGraw-Hill Osborne Media.   M. Howard D. LeBlanc and J. Viega. 2005. 19 Deadly Sins of Software Security. McGraw-Hill Osborne Media."},{"key":"e_1_2_1_31_1","volume-title":"Intel Security Curricula. Retrieved","year":"2015","unstructured":"Intel. 2015. Intel Security Curricula. Retrieved July 7, 2015 from http:\/\/www.intel.com\/content\/www\/us\/en\/education\/university\/security-program\/curricula.html. Intel. 2015. Intel Security Curricula. Retrieved July 7, 2015 from http:\/\/www.intel.com\/content\/www\/us\/en\/education\/university\/security-program\/curricula.html."},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.735847"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1566445.1566536"},{"key":"e_1_2_1_34_1","volume-title":"Proceedings of the 14th Colloquium for Information Systems Security Education (CISSE\u201910)","author":"Kaza Siddharth","unstructured":"Siddharth Kaza , Blair Taylor , Harry Hochheiser , Shiva Azadegan , M. O\u2019Leary , and Claude F. Turner . 2010. Injecting security in the curriculum\u2014experiences in effective dissemination and assessment design . In Proceedings of the 14th Colloquium for Information Systems Security Education (CISSE\u201910) . 8. Siddharth Kaza, Blair Taylor, Harry Hochheiser, Shiva Azadegan, M. O\u2019Leary, and Claude F. Turner. 2010. Injecting security in the curriculum\u2014experiences in effective dissemination and assessment design. In Proceedings of the 14th Colloquium for Information Systems Security Education (CISSE\u201910). 8."},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.2307\/2529310"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/1028174.971439"},{"key":"e_1_2_1_37_1","first-page":"129","article-title":"Teachers\u2019 professional development in a climate of educational reform","volume":"15","author":"Little J. W.","year":"1993","unstructured":"J. W. Little . 1993 . Teachers\u2019 professional development in a climate of educational reform . Educational Evaluation and Policy Analysis 15 , 2, 129 -- 151 . J. W. Little. 1993. Teachers\u2019 professional development in a climate of educational reform. Educational Evaluation and Policy Analysis 15, 2, 129--151.","journal-title":"Educational Evaluation and Policy Analysis"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/FIE.2006.322347"},{"key":"e_1_2_1_39_1","first-page":"162","article-title":"Security trumps efficiency: Putting it into the curriculum","volume":"24","author":"Marks Donald G.","year":"2007","unstructured":"Donald G. Marks and Michael Stinson . 2007 . Security trumps efficiency: Putting it into the curriculum . Journal of Computing Sciences in Colleges 24 , 4, 162 -- 169 . Donald G. Marks and Michael Stinson. 2007. Security trumps efficiency: Putting it into the curriculum. Journal of Computing Sciences in Colleges 24, 4, 162--169.","journal-title":"Journal of Computing Sciences in Colleges"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/237466.237526"},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2004.1281254"},{"key":"e_1_2_1_42_1","volume-title":"Software Security: Building Security In","author":"McGraw Gary","year":"2006","unstructured":"Gary McGraw . 2006 . Software Security: Building Security In . Addison-Wesley Professional . Gary McGraw. 2006. Software Security: Building Security In. Addison-Wesley Professional."},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2008.153"},{"key":"e_1_2_1_44_1","volume-title":"Memo from Bill Gates","unstructured":"Microsoft. 2002. Memo from Bill Gates . Company Memo . Microsoft. 2002. Memo from Bill Gates. Company Memo."},{"key":"e_1_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/563340.563480"},{"key":"e_1_2_1_46_1","first-page":"3","article-title":"Virtual laboratory environments: Methodologies for educating cybersecurity researchers","volume":"4","author":"Nance Kara","year":"2009","unstructured":"Kara Nance , Brian Hay , Ronald Dodge , Alex Seazzu , and Steve Burd . 2009 . Virtual laboratory environments: Methodologies for educating cybersecurity researchers . Methodological Innovations Online 4 , 3, 3 -- 14 . Kara Nance, Brian Hay, Ronald Dodge, Alex Seazzu, and Steve Burd. 2009. Virtual laboratory environments: Methodologies for educating cybersecurity researchers. Methodological Innovations Online 4, 3, 3--14.","journal-title":"Methodological Innovations Online"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/1473195.1473230"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.5555\/1060081.1060104"},{"key":"e_1_2_1_49_1","volume-title":"Retrieved","author":"OWASP.","year":"2015","unstructured":"OWASP. 2015 . The Open Web Application Security Project . Retrieved April 27, 2016, from https:\/\/www.owasp.org\/index.php\/Main_Page. OWASP. 2015. The Open Web Application Security Project. Retrieved April 27, 2016, from https:\/\/www.owasp.org\/index.php\/Main_Page."},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/2078856.2078860"},{"key":"e_1_2_1_51_1","volume-title":"Proceedings of the 2005 American Society for Engineering Education Annual Conference and Exposition.","author":"Perrone Luiz Felipe","year":"2005","unstructured":"Luiz Felipe Perrone , Maurice Aburdene , and Xiannong Meng . 2005 . Approaches to undergraduate instruction in computer security . In Proceedings of the 2005 American Society for Engineering Education Annual Conference and Exposition. Luiz Felipe Perrone, Maurice Aburdene, and Xiannong Meng. 2005. Approaches to undergraduate instruction in computer security. In Proceedings of the 2005 American Society for Engineering Education Annual Conference and Exposition."},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/1107622.1107635"},{"key":"e_1_2_1_53_1","first-page":"8","article-title":"Beyond the security track: Embed security education across undergraduate computing curricula using M-thread approach","volume":"11","author":"Ray L.","year":"2011","unstructured":"L. Ray and J. Yang . 2011 . Beyond the security track: Embed security education across undergraduate computing curricula using M-thread approach . International Journal of Computer Science and Network Security 11 , 8 , 131. L. Ray and J. Yang. 2011. Beyond the security track: Embed security education across undergraduate computing curricula using M-thread approach. International Journal of Computer Science and Network Security 11, 8, 131.","journal-title":"International Journal of Computer Science and Network Security"},{"key":"e_1_2_1_54_1","volume-title":"Common Weakness Enumeration. Retrieved","author":"SANS.","year":"2015","unstructured":"SANS. 2015. Common Weakness Enumeration. Retrieved January 1, 2015 , from https:\/\/www.sans.org\/top25-software-errors\/. SANS. 2015. Common Weakness Enumeration. Retrieved January 1, 2015, from https:\/\/www.sans.org\/top25-software-errors\/."},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.5555\/1516595.1516626"},{"key":"e_1_2_1_56_1","volume-title":"Secure Coding in C and C++","author":"Seacord Robert","unstructured":"Robert Seacord . 2005. Secure Coding in C and C++ ( 2 nd ed.). Addison-Wesley . Robert Seacord. 2005. Secure Coding in C and C++ (2nd ed.). Addison-Wesley.","edition":"2"},{"key":"e_1_2_1_57_1","volume-title":"Retrieved","author":"Seacord Robert C.","year":"2011","unstructured":"Robert C. Seacord . 2011 . The Top 10 Secure Coding Practices . Retrieved April 27, 2016, from https:\/\/www.securecoding.cert.org\/confluence\/display\/seccode\/Top+10+Secure+Coding+Practices. Robert C. Seacord. 2011. The Top 10 Secure Coding Practices. Retrieved April 27, 2016, from https:\/\/www.securecoding.cert.org\/confluence\/display\/seccode\/Top+10+Secure+Coding+Practices."},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2010.256"},{"key":"e_1_2_1_59_1","volume-title":"Proceedings of the 14th Western Canadian Conference on Computing Education (WCCCE\u201909)","author":"Michael","unstructured":"Michael L. Stamat and Jeffrey W. Humphries. 2009. Training \u2260 education . In Proceedings of the 14th Western Canadian Conference on Computing Education (WCCCE\u201909) . ACM, New York, NY, 116. DOI:http:\/\/dx.doi.org\/10.1145\/1536274.1536308 10.1145\/1536274.1536308 Michael L. Stamat and Jeffrey W. Humphries. 2009. Training \u2260 education. In Proceedings of the 14th Western Canadian Conference on Computing Education (WCCCE\u201909). ACM, New York, NY, 116. DOI:http:\/\/dx.doi.org\/10.1145\/1536274.1536308"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/ITNG.2012.60"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/1231047.1231053"},{"key":"e_1_2_1_62_1","volume-title":"Proceedings of Frontiers in Education: Computer Science and Engineering. 1--6.","author":"Taylor Blair","year":"2007","unstructured":"Blair Taylor and Shiva Azadegan . 2007 a. Teaching security through active learning . In Proceedings of Frontiers in Education: Computer Science and Engineering. 1--6. Blair Taylor and Shiva Azadegan. 2007a. Teaching security through active learning. In Proceedings of Frontiers in Education: Computer Science and Engineering. 1--6."},{"key":"e_1_2_1_63_1","volume-title":"Proceedings of the National Colloquium for Information Systems Security Education. 4--9.","author":"Taylor Blair","year":"2007","unstructured":"Blair Taylor and Shiva Azadegan . 2007 b. Using security checklists and scorecards in CS curriculum . In Proceedings of the National Colloquium for Information Systems Security Education. 4--9. Blair Taylor and Shiva Azadegan. 2007b. Using security checklists and scorecards in CS curriculum. In Proceedings of the National Colloquium for Information Systems Security Education. 4--9."},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/1352322.1352246"},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/2157136.2157304"},{"key":"e_1_2_1_66_1","volume-title":"Proceedings of the 41st ACM Technical Symposium on Computer Science Education (SIGCSE\u201910)","author":"Taylor B.","unstructured":"B. Taylor , S. Kaza , B. Chu , M. Doyle , and K. C. Du . 2010. Security in the CS curriculum (BOF) . In Proceedings of the 41st ACM Technical Symposium on Computer Science Education (SIGCSE\u201910) . B. Taylor, S. Kaza, B. Chu, M. Doyle, and K. C. Du. 2010. Security in the CS curriculum (BOF). In Proceedings of the 41st ACM Technical Symposium on Computer Science Education (SIGCSE\u201910)."},{"key":"e_1_2_1_67_1","volume-title":"Proceedings of the 10th Conference on Australasian Computing Education","volume":"78","author":"Thompson E.","unstructured":"E. Thompson , A. Luxton-Reilly , J. L. Whalley , M. Hu , and P. Robbins . 2008. Bloom's taxonomy for CS assessment . In Proceedings of the 10th Conference on Australasian Computing Education , Volume 78 . 155--161. E. Thompson, A. Luxton-Reilly, J. L. Whalley, M. Hu, and P. Robbins. 2008. Bloom's taxonomy for CS assessment. In Proceedings of the 10th Conference on Australasian Computing Education, Volume 78. 155--161."},{"key":"e_1_2_1_68_1"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/330908.331822"},{"key":"e_1_2_1_70_1","volume-title":"Building Secure Software: How to Avoid Security Problems the Right Way","author":"Viega John","unstructured":"John Viega and Gary McGraw . 2001. Building Secure Software: How to Avoid Security Problems the Right Way . Addison-Wesley Professional Computing Series . John Viega and Gary McGraw. 2001. Building Secure Software: How to Avoid Security Problems the Right Way. Addison-Wesley Professional Computing Series."},{"key":"e_1_2_1_71_1","volume-title":"Building Secure Software: How to Avoid Security Problems the Right Way","author":"Viega John","unstructured":"John Viega and Gary McGraw . 2002. Building Secure Software: How to Avoid Security Problems the Right Way . Addison-Wesley . John Viega and Gary McGraw. 2002. Building Secure Software: How to Avoid Security Problems the Right Way. Addison-Wesley."},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/1231047.1231052"},{"key":"e_1_2_1_73_1","first-page":"1","article-title":"Secure programming workshop: How to keep our students from causing buffer overflows","volume":"21","author":"Walden James","year":"2005","unstructured":"James Walden , Charles E. Frank , and Laurie Werner . 2005 . Secure programming workshop: How to keep our students from causing buffer overflows . J. Comput. Sci. Coll. 21 , 1 (October 2005), 134--135. James Walden, Charles E. Frank, and Laurie Werner. 2005. Secure programming workshop: How to keep our students from causing buffer overflows. J. Comput. Sci. Coll. 21, 1 (October 2005), 134--135.","journal-title":"J. Comput. Sci. Coll."},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.5555\/2037151.2037185"},{"key":"e_1_2_1_75_1","volume-title":"Proceedings of the 19th National Information Systems Security Conference.","author":"White Georgory","year":"1996","unstructured":"Georgory White and Georgory Nordstorm . 1996 . Security across the curriculum: Using computer security to teach computer science principles . In Proceedings of the 19th National Information Systems Security Conference. Georgory White and Georgory Nordstorm. 1996. Security across the curriculum: Using computer security to teach computer science principles. In Proceedings of the 19th National Information Systems Security Conference."},{"key":"e_1_2_1_76_1","volume-title":"Retrieved","author":"House White","year":"2009","unstructured":"White House . 2009 . Remarks by the President on Securing Our Nation's Cyber Infrastructure . Retrieved April 27, 2016, from https:\/\/www.whitehouse.gov\/video\/President-Obama-on-Cybersecurity#transcript. White House. 2009. Remarks by the President on Securing Our Nation's Cyber Infrastructure. Retrieved April 27, 2016, from https:\/\/www.whitehouse.gov\/video\/President-Obama-on-Cybersecurity#transcript."},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.5555\/2600623.2600641"},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.5555\/1409823.1409836"},{"key":"e_1_2_1_79_1","volume-title":"Retrieved","author":"Yang Li","year":"2015","unstructured":"Li Yang . 2015 a. Bolstering Security Education Through Integration of Research and Education on Browser Security . Retrieved April 27, 2016, from http:\/\/www.utc.edu\/faculty\/li-yang\/browsersecurity.php. Li Yang. 2015a. Bolstering Security Education Through Integration of Research and Education on Browser Security. Retrieved April 27, 2016, from http:\/\/www.utc.edu\/faculty\/li-yang\/browsersecurity.php."},{"key":"e_1_2_1_80_1","volume-title":"Retrieved","author":"Yang Li","year":"2015","unstructured":"Li Yang . 2015 b. Capacity Building Through Curriculum and Faculty Development on Mobile Security . Retrieved April 27, 2016, from from http:\/\/www.utc.edu\/faculty\/li-yang\/mobilesecurity.php. Li Yang. 2015b. Capacity Building Through Curriculum and Faculty Development on Mobile Security. Retrieved April 27, 2016, from from http:\/\/www.utc.edu\/faculty\/li-yang\/mobilesecurity.php."},{"key":"e_1_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2006.187"},{"key":"e_1_2_1_82_1","volume-title":"Retrieved","author":"Younan Yves","year":"2012","unstructured":"Yves Younan . 2012 . 25 Years of Vulnerabilities: 1988-2012 . Retrieved April 27, 2016, from http:\/\/www.rsaconference.com\/events\/us13\/agenda\/sessions\/132\/25-years-of-vulnerabilities-1988--2012. Yves Younan. 2012. 25 Years of Vulnerabilities: 1988-2012. Retrieved April 27, 2016, from http:\/\/www.rsaconference.com\/events\/us13\/agenda\/sessions\/132\/25-years-of-vulnerabilities-1988--2012."},{"key":"e_1_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1145\/2676723.2691902"}],"container-title":["ACM Transactions on Computing Education"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2897441","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2897441","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:39:02Z","timestamp":1750221542000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2897441"}},"subtitle":["Integrating Secure Coding into Introductory Computer Science Courses"],"short-title":[],"issued":{"date-parts":[[2016,6,9]]},"references-count":83,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2016,10,13]]}},"alternative-id":["10.1145\/2897441"],"URL":"https:\/\/doi.org\/10.1145\/2897441","relation":{},"ISSN":["1946-6226"],"issn-type":[{"value":"1946-6226","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,6,9]]},"assertion":[{"value":"2015-07-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2016-02-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2016-06-09","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}