{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T03:51:12Z","timestamp":1784260272644,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":34,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,10,16]],"date-time":"2020-10-16T00:00:00Z","timestamp":1602806400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,10,18]]},"DOI":"10.1145\/3365438.3410954","type":"proceedings-article","created":{"date-parts":[[2021,1,19]],"date-time":"2021-01-19T16:09:22Z","timestamp":1611072562000},"page":"332-342","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":32,"title":["Automating the early detection of security design flaws"],"prefix":"10.1145","author":[{"given":"Katja","family":"Tuma","sequence":"first","affiliation":[{"name":"University of Gothenburg and Chalmers University of Technology, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Laurens","family":"Sion","sequence":"additional","affiliation":[{"name":"KU Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Riccardo","family":"Scandariato","sequence":"additional","affiliation":[{"name":"University of Gothenburg and Chalmers University of Technology, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Koen","family":"Yskout","sequence":"additional","affiliation":[{"name":"KU Leuven, Belgium"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,10,16]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2020. CVE - Common Vulnerabilities and Exposures. Available from MITRE. https:\/\/cve.mitre.org  2020. CVE - Common Vulnerabilities and Exposures. Available from MITRE. https:\/\/cve.mitre.org"},{"key":"e_1_3_2_1_2_1","unstructured":"2020. CWE - Common Weakness Enumeration. Available from MITRE. https:\/\/cwe.mitre.org  2020. CWE - Common Weakness Enumeration. Available from MITRE. https:\/\/cwe.mitre.org"},{"key":"e_1_3_2_1_3_1","unstructured":"2020. Security Design Flaw Detection: Companion Web-Site. Available from Google Sites. https:\/\/sites.google.com\/view\/companion-web-site\/  2020. Security Design Flaw Detection: Companion Web-Site. Available from Google Sites. https:\/\/sites.google.com\/view\/companion-web-site\/"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11219-018-9424-8"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.5555\/2486788.2486875"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-30806-7_4"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/CyberSecPODS.2019.8885144"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.5381\/jot.2009.8.3.c5"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASWEC.2018.00023"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/QSIC.2010.58"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"crossref","unstructured":"Tom DeMarco. 1979. Structured Analysis and System Specification. Yourdon.  Tom DeMarco. 1979. Structured Analysis and System Specification. Yourdon.","DOI":"10.1007\/978-3-642-48354-7_9"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00766-010-0115-7"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1155\/2014\/805856"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSA.2019.00012"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10270-012-0263-y"},{"key":"e_1_3_2_1_17_1","volume-title":"The security development lifecycle","author":"Howard Michael"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.5555\/647246.719625"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30187-5_26"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SocialCom.2013.14"},{"key":"e_1_3_2_1_21_1","volume-title":"Model-Driven Risk Analysis","author":"Lund Mass Soldal"},{"key":"e_1_3_2_1_22_1","volume-title":"Proceedings of the 24th Conference on Pattern Languages of Programs. The Hillside Group, ACM, 23","author":"Nafees Tayyaba","year":"2017"},{"key":"e_1_3_2_1_23_1","unstructured":"OWASP. 2017. OWASP Top Ten Project. https:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_Project  OWASP. 2017. OWASP Top Ten Project. https:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_Project"},{"key":"e_1_3_2_1_24_1","unstructured":"SANS. 2011. SANS Top 25 Software Errors. https:\/\/www.sans.org\/top25-software-errors\/  SANS. 2011. SANS Top 25 Software Errors. https:\/\/www.sans.org\/top25-software-errors\/"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSAW.2017.25"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00766-013-0195-2"},{"key":"e_1_3_2_1_27_1","volume-title":"Data-Driven Software Architecture for Analyzing Confidentiality. In 2019 IEEE International Conference on Software Architecture (ICSA). IEEE, 1--10","author":"Seifermann Stephan","year":"2019"},{"key":"e_1_3_2_1_28_1","volume-title":"Threat Modeling: Designing for Security","author":"Shostack Adam","year":"2014"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASEW.2019.00028"},{"key":"e_1_3_2_1_30_1","volume-title":"Proceedings of SAC 2018: The 6th track on Software Architecture: Theory, Technology, and Applications (SA-TTA). ACM, 1425--1432","author":"Sion Laurens","year":"2018"},{"key":"e_1_3_2_1_31_1","volume-title":"On the definition of microservice bad smells","author":"Taibi Davide","year":"2018"},{"key":"e_1_3_2_1_32_1","volume-title":"Flaws in Flows: Unveiling Design Flaws via Information Flow Analysis","author":"Tuma Katja"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2018.06.073"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3344948.3344995"},{"key":"e_1_3_2_1_35_1","volume-title":"Two Architectural Threat Analysis Techniques Compared. In European Conference on Software Architecture. Springer, 347--363","author":"Tuma Katja","year":"2018"}],"event":{"name":"MODELS '20: ACM\/IEEE 23rd International Conference on Model Driven Engineering Languages and Systems","location":"Virtual Event Canada","acronym":"MODELS '20","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS"]},"container-title":["Proceedings of the 23rd ACM\/IEEE International Conference on Model Driven Engineering Languages and Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3365438.3410954","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3365438.3410954","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T17:49:49Z","timestamp":1750268989000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3365438.3410954"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10,16]]},"references-count":34,"alternative-id":["10.1145\/3365438.3410954","10.1145\/3365438"],"URL":"https:\/\/doi.org\/10.1145\/3365438.3410954","relation":{},"subject":[],"published":{"date-parts":[[2020,10,16]]},"assertion":[{"value":"2020-10-16","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}