{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T00:14:48Z","timestamp":1774397688132,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":84,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,8,26]],"date-time":"2019-08-26T00:00:00Z","timestamp":1566777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,8,26]]},"DOI":"10.1145\/3339252.3339263","type":"proceedings-article","created":{"date-parts":[[2019,8,9]],"date-time":"2019-08-09T12:21:03Z","timestamp":1565353263000},"page":"1-11","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["Costing Secure Software Development"],"prefix":"10.1145","author":[{"given":"Elaine","family":"Venson","sequence":"first","affiliation":[{"name":"Center for Systems and Software Engineering, University of Southern California"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaomeng","family":"Guo","sequence":"additional","affiliation":[{"name":"Center for Systems and Software Engineering, University of Southern California"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zidi","family":"Yan","sequence":"additional","affiliation":[{"name":"University of Southern California"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Barry","family":"Boehm","sequence":"additional","affiliation":[{"name":"Center for Systems and Software Engineering, University of Southern California"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2019,8,26]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"2010 International Symposium on Information Technology","volume":"3","author":"Abdullah N. A. S."},{"key":"e_1_3_2_1_2_1","volume-title":"Mohd Hasan Selamat, and Azmi Jaafar","author":"Sia Abdullah Nur Atiqah","year":"2011"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2012.04.001"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"J. Arunagiri S. Rakhi and K. P. Jevitha. 2016. A Systematic Review of Security Measures for Web Browser Extension Vulnerabilities. SpringerLink (2016) 99--112.  J. Arunagiri S. Rakhi and K. P. Jevitha. 2016. A Systematic Review of Security Measures for Web Browser Extension Vulnerabilities. SpringerLink (2016) 99--112.","DOI":"10.1007\/978-81-322-2674-1_10"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-41488-6_10"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2015.45"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1987875.1987900"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1375696.1375707"},{"key":"e_1_3_2_1_9_1","first-page":"3","article-title":"Improving software security with static automated code analysis in an industry setting. Software","volume":"43","author":"Baca Dejan","year":"2013","journal-title":"Practice and Experience"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-13792-1_15"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2013.04.023"},{"key":"e_1_3_2_1_12_1","volume-title":"2015 6th Brazilian Workshop on Agile Methods (WBMA). 25--31","author":"Barbosa D. A."},{"key":"e_1_3_2_1_13_1","first-page":"3","article-title":"Analysis of Empirical Software Effort Estimation Models","volume":"7","author":"Basha Saleem","year":"2010","journal-title":"International Journal of Computer Science and Information Security"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/2413038.2413041"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1018991717352"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/2.962984"},{"key":"e_1_3_2_1_17_1","volume-title":"Software Engineering Economics (1 edition ed.)","author":"Boehm Barry W."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635880"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/581339.581370"},{"key":"e_1_3_2_1_20_1","volume-title":"Prioritisation and Selection of Software Security Activities. In 2009 International Conference on Availability, Reliability and Security. 201--207","author":"Byers D."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/EUROMICRO.2005.53"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/ITNG.2009.157"},{"key":"e_1_3_2_1_23_1","volume-title":"ECIS 2016 Proceedings. 18","author":"Chehrazi Golriz","year":"2016"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-27896-4_22"},{"key":"e_1_3_2_1_25_1","volume-title":"Cost Estimation for Secure Software & Systems. In ISPA\/SCEA 2008 Joint International Conference. The Netherlands, 9.","author":"Colbert Ed","year":"2008"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ESEM.2011.36"},{"key":"e_1_3_2_1_27_1","volume-title":"Ricardo Batista Rodrigues, Leandro Marques do Nascimento, and Vinicius Cardoso Garcia.","author":"Revoredo da Silva Carlo Marcelo","year":"2013"},{"key":"e_1_3_2_1_28_1","volume-title":"Faiza Ghozzi Jedidi, and Faiez Gargouri","author":"Dammak Salma","year":"2016"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-30806-7_12"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2016.02.005"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.36"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/2652524.2652585"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-05151-7_4"},{"key":"e_1_3_2_1_34_1","volume-title":"International Journal of Software Engineering and Its Applications","author":"Hedayatpour Saman","year":"2014"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1080\/19393550802623206"},{"key":"e_1_3_2_1_36_1","unstructured":"Chad Heitzenrater Rainer Bohme and Andrew Simpson. 2016. The Days Before Zero Day: Investment Models for Secure Software Engineering. 14.  Chad Heitzenrater Rainer Bohme and Andrew Simpson. 2016. The Days Before Zero Day: Investment Models for Secure Software Engineering. 14."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3011883.3011884"},{"key":"e_1_3_2_1_38_1","volume-title":"Abuse and Reuse: Economic Utility Functions for Characterising Security Requirements. In 2016 11th International Conference on Availability, Reliability and Security (ARES). 572--581","author":"Heitzenrater C."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"crossref","unstructured":"C. Heitzenrater and A. Simpson. 2016. Software Security Investment: The Right Amount of a Good Thing. In 2016 IEEE Cybersecurity Development (SecDev). 53--59.  C. Heitzenrater and A. Simpson. 2016. Software Security Investment: The Right Amount of a Good Thing. In 2016 IEEE Cybersecurity Development (SecDev). 53--59.","DOI":"10.1109\/SecDev.2016.020"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICECCS.2005.30"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2016.05.016"},{"key":"e_1_3_2_1_43_1","first-page":"1","article-title":"Systematic Mapping of Security Patterns Research. In Proceedings of the 22Nd Conference on Pattern Languages of Programs (PLoP '15)","volume":"14","author":"Ito Yurina","year":"2015","journal-title":"The Hillside Group, USA"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.5555\/1248721.1248736"},{"key":"e_1_3_2_1_45_1","volume-title":"Securing Large Applications Against Command Injections. In 2007 41st Annual IEEE International Carnahan Conference on Security Technology. 69--78","author":"Jourdan G.","year":"2007"},{"key":"e_1_3_2_1_46_1","volume-title":"2016 International Conference on Software Security and Assurance (ICSSA). 31--36","author":"Khan N. F."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2013.07.010"},{"key":"e_1_3_2_1_48_1","volume-title":"Evidence-Based Software Engineering and Systematic Reviews (1 edition ed.)","author":"Kitchenham Barbara Ann"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2007.1001"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/1842752.1842787"},{"key":"e_1_3_2_1_51_1","first-page":"6","article-title":"It Doesn't Have to Be Like This","volume":"19","author":"Kuhn R.","year":"2017","journal-title":"Cybersecurity Vulnerability Trends. IT Professional"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-012-9220-1"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2004.1281254"},{"key":"e_1_3_2_1_54_1","volume-title":"Software Security: Building Security In (1 edition ed.)","author":"McGraw Gary","year":"2006"},{"key":"e_1_3_2_1_55_1","volume-title":"2017 8th International Conference on Information Technology (ICIT). 814--818","author":"Mohammad A."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2016.10.001"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3055305.3055312"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315311"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2015.08.006"},{"key":"e_1_3_2_1_60_1","volume-title":"Olama and James Nutaro","author":"Mohammed","year":"2013"},{"key":"e_1_3_2_1_61_1","first-page":"2","article-title":"Time for Addressing Software Security Issues: Prediction Models and Impacting Factors","volume":"2","author":"Othmane Lotfi Ben","year":"2017","journal-title":"Data Science and Engineering"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-23318-5_6"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.03.001"},{"key":"e_1_3_2_1_64_1","volume-title":"Convergence and Hybrid Information Technology","author":"Park Keun-Young"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/1047671.1047688"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.56"},{"key":"e_1_3_2_1_67_1","volume-title":"Common Criteria Security Evaluation: A Time and Cost Effective Approach. In 2006 2nd International Conference on Information Communication Technologies","volume":"2","author":"Razzazi M."},{"key":"e_1_3_2_1_68_1","volume-title":"COTS-Based Software Systems","author":"Reifer Donald J."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/2812428.2812431"},{"key":"e_1_3_2_1_70_1","volume-title":"2016 11th International Conference on Availability, Reliability and Security (ARES). 556--563","author":"Rindell K."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2015.12.015"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.81"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/1988630.1988632"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-011-9190-8"},{"key":"e_1_3_2_1_75_1","volume-title":"Proceedings Eighth IEEE Symposium on Software Metrics. 249--258","author":"Shull F."},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10270-015-0486-9"},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.2298\/CSIS160229007W"},{"key":"e_1_3_2_1_78_1","volume-title":"Advances in Computers, Marvin V","author":"Williams Laurie"},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-00199-4_11"},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.58"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/2601248.2601268"},{"key":"e_1_3_2_1_82_1","volume-title":"VulDigger: A Just-in-Time and Cost-Aware Tool for Digging Vulnerability-Contributing Changes. In GLOBECOM 2017 - 2017 IEEE Global Communications Conference. 1--7.","author":"Yang L."},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2015.03.041"},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2010.12.010"},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/BIFE.2012.149"}],"event":{"name":"ARES '19: 14th International Conference on Availability, Reliability and Security","location":"Canterbury CA United Kingdom","acronym":"ARES '19"},"container-title":["Proceedings of the 14th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3339252.3339263","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3339252.3339263","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:44:17Z","timestamp":1750203857000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3339252.3339263"}},"subtitle":["A Systematic Mapping Study"],"short-title":[],"issued":{"date-parts":[[2019,8,26]]},"references-count":84,"alternative-id":["10.1145\/3339252.3339263","10.1145\/3339252"],"URL":"https:\/\/doi.org\/10.1145\/3339252.3339263","relation":{},"subject":[],"published":{"date-parts":[[2019,8,26]]},"assertion":[{"value":"2019-08-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}