{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:46:59Z","timestamp":1750308419052,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,4,18]],"date-time":"2022-04-18T00:00:00Z","timestamp":1650240000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,4,18]]},"DOI":"10.1145\/3476883.3520217","type":"proceedings-article","created":{"date-parts":[[2022,5,5]],"date-time":"2022-05-05T02:11:49Z","timestamp":1651716709000},"page":"91-98","source":"Crossref","is-referenced-by-count":0,"title":["Integrating vulnerability risk into the software process"],"prefix":"10.1145","author":[{"given":"Onyeka","family":"Ezenwoye","sequence":"first","affiliation":[{"name":"Augusta University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yi","family":"Liu","sequence":"additional","affiliation":[{"name":"University of Massachusetts Dartmouth"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,5,4]]},"reference":[{"doi-asserted-by":"crossref","unstructured":"2011. CVE-2011-0774. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2011-0774.  2011. CVE-2011-0774. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2011-0774.","key":"e_1_3_2_1_1_1","DOI":"10.1055\/s-0030-1260508"},{"unstructured":"2012. CVE-2012-0792. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2012-0792.  2012. CVE-2012-0792. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2012-0792.","key":"e_1_3_2_1_2_1"},{"unstructured":"2015. CVE-2015-0943. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2015-0943.  2015. CVE-2015-0943. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2015-0943.","key":"e_1_3_2_1_3_1"},{"key":"e_1_3_2_1_4_1","volume-title":"10th International Conference on the Quality of Information and Communications Technology.","author":"Hassan Adelyar S.","year":"2016","unstructured":"S. Hassan Adelyar and Alex Norta . 2016 . Towards a Secure Agile Software Development Process . In 10th International Conference on the Quality of Information and Communications Technology. S. Hassan Adelyar and Alex Norta. 2016. Towards a Secure Agile Software Development Process. In 10th International Conference on the Quality of Information and Communications Technology."},{"key":"e_1_3_2_1_5_1","volume-title":"The ISDF Framework: Towards Secure Software Development. Journal of Information Processing Systems 6 (Mar","author":"Alkussayer Abdulaziz","year":"2010","unstructured":"Abdulaziz Alkussayer and William Allen . 2010. The ISDF Framework: Towards Secure Software Development. Journal of Information Processing Systems 6 (Mar 2010 ). Abdulaziz Alkussayer and William Allen. 2010. The ISDF Framework: Towards Secure Software Development. Journal of Information Processing Systems 6 (Mar 2010)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_6_1","DOI":"10.1109\/MSEC.2019.2929282"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_7_1","DOI":"10.1145\/3347144"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_8_1","DOI":"10.1145\/12944.12948"},{"key":"e_1_3_2_1_9_1","volume-title":"Dutoit","author":"Bruegge Bernd","year":"2009","unstructured":"Bernd Bruegge and Allen H . Dutoit . 2009 . Object-oriented Software Engineering Using UML, Patterns , and Java (3rd ed.). Prentice Hall Press . Bernd Bruegge and Allen H. Dutoit. 2009. Object-oriented Software Engineering Using UML, Patterns, and Java (3rd ed.). Prentice Hall Press."},{"unstructured":"The MITRE Corporation. 2021. Comprehensive CWE Dictionary. https:\/\/cwe.mitre.org\/data\/definitions\/2000.html  The MITRE Corporation. 2021. Comprehensive CWE Dictionary. https:\/\/cwe.mitre.org\/data\/definitions\/2000.html","key":"e_1_3_2_1_10_1"},{"unstructured":"The MITRE Corporation. 2021. Cryptographic Issues. https:\/\/cwe.mitre.org\/data\/definitions\/310.html  The MITRE Corporation. 2021. Cryptographic Issues. https:\/\/cwe.mitre.org\/data\/definitions\/310.html","key":"e_1_3_2_1_11_1"},{"unstructured":"Cybersecurity and Infrastructure Security Agency. 2021. Comprehensive Lightweight Application Security Process. https:\/\/us-cert.cisa.gov\/bsi\/articles\/best-practices\/requirements-engineering\/introduction-to-the-clasp-process  Cybersecurity and Infrastructure Security Agency. 2021. Comprehensive Lightweight Application Security Process. https:\/\/us-cert.cisa.gov\/bsi\/articles\/best-practices\/requirements-engineering\/introduction-to-the-clasp-process","key":"e_1_3_2_1_12_1"},{"volume-title":"Proceedings of the 2006 Conference on Pattern Languages of Programs. Association for Computing Machinery, 10 pages.","author":"Eduardo","unstructured":"Eduardo B. Fernandez and G\u00fcnther Pernul. 2006. Patterns for Session-based Access Control . In Proceedings of the 2006 Conference on Pattern Languages of Programs. Association for Computing Machinery, 10 pages. Eduardo B. Fernandez and G\u00fcnther Pernul. 2006. Patterns for Session-based Access Control. In Proceedings of the 2006 Conference on Pattern Languages of Programs. Association for Computing Machinery, 10 pages.","key":"e_1_3_2_1_13_1"},{"key":"e_1_3_2_1_14_1","volume-title":"Lethbridge","author":"Forward Andrew","year":"2008","unstructured":"Andrew Forward and Timothy C . Lethbridge . 2008 . A Taxonomy of Software Types to Facilitate Search and Evidence-based Software Engineering. In Proceedings of the 2008 Conference of the Center for Advanced Studies on Collaborative Research : Meeting of Minds. Association for Computing Machinery , 13 pages. Andrew Forward and Timothy C. Lethbridge. 2008. A Taxonomy of Software Types to Facilitate Search and Evidence-based Software Engineering. In Proceedings of the 2008 Conference of the Center for Advanced Studies on Collaborative Research: Meeting of Minds. Association for Computing Machinery, 13 pages."},{"key":"e_1_3_2_1_15_1","volume-title":"Security in the Software Lifecycle: Making Software Development Processes and the Software Produced by Them More Secure. U.S. Department of Homeland Security (Aug","author":"Goertzel Karen","year":"2006","unstructured":"Karen Goertzel , Theodore Winograd , Holly McKinley , and Patrick Holley . 2006. Security in the Software Lifecycle: Making Software Development Processes and the Software Produced by Them More Secure. U.S. Department of Homeland Security (Aug 2006 ). Karen Goertzel, Theodore Winograd, Holly McKinley, and Patrick Holley. 2006. Security in the Software Lifecycle: Making Software Development Processes and the Software Produced by Them More Secure. U.S. Department of Homeland Security (Aug 2006)."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_16_1","DOI":"10.1109\/SESS.2007.7"},{"key":"e_1_3_2_1_17_1","volume-title":"A Lightweight Secure Development Process for Developers. Department of Computer and Information Science, Software and Systems","author":"Hellstr\u00f6m Jesper","year":"2019","unstructured":"Jesper Hellstr\u00f6m and Anton Moberg . 2019. A Lightweight Secure Development Process for Developers. Department of Computer and Information Science, Software and Systems , Link\u00f6ping University (June 2019 ). Jesper Hellstr\u00f6m and Anton Moberg. 2019. A Lightweight Secure Development Process for Developers. Department of Computer and Information Science, Software and Systems, Link\u00f6ping University (June 2019)."},{"key":"e_1_3_2_1_18_1","volume-title":"Seven Years of Software Vulnerabilities: The Ebb and Flow","author":"Homaei Hossein","year":"2017","unstructured":"Hossein Homaei and Hamid Reza Shahriari . 2017. Seven Years of Software Vulnerabilities: The Ebb and Flow . IEEE Security Privacy 15 ( Jan 2017 ). Hossein Homaei and Hamid Reza Shahriari. 2017. Seven Years of Software Vulnerabilities: The Ebb and Flow. IEEE Security Privacy 15 (Jan 2017)."},{"volume-title":"Writing Secure Code","author":"Howard Michael","unstructured":"Michael Howard and David LeBlanc . 2002. Writing Secure Code . Microsoft Press . Michael Howard and David LeBlanc. 2002. Writing Secure Code. Microsoft Press.","key":"e_1_3_2_1_19_1"},{"unstructured":"The Software Engineering Institute. 2002. Team Software Process for Secure Software Development. https:\/\/resources.sei.cmu.edu\/asset_files\/Presentation\/2002_017_001_24393.pdf  The Software Engineering Institute. 2002. Team Software Process for Secure Software Development. https:\/\/resources.sei.cmu.edu\/asset_files\/Presentation\/2002_017_001_24393.pdf","key":"e_1_3_2_1_20_1"},{"volume-title":"Information Security Education Across the Curriculum","author":"J\u00f8sang Audun","unstructured":"Audun J\u00f8sang , Marte \u00d8degaard , and Erlend Oftedal . 2015. Cybersecurity Through Secure Software Development . In Information Security Education Across the Curriculum , Matt Bishop, Natalia Miloslavskaya, and Marianthi Theocharidou (Eds.). Springer International Publishing . Audun J\u00f8sang, Marte \u00d8degaard, and Erlend Oftedal. 2015. Cybersecurity Through Secure Software Development. In Information Security Education Across the Curriculum, Matt Bishop, Natalia Miloslavskaya, and Marianthi Theocharidou (Eds.). Springer International Publishing.","key":"e_1_3_2_1_21_1"},{"volume-title":"Design Space Exploration for Security","author":"Kang Eunsuk","unstructured":"Eunsuk Kang . 2016. Design Space Exploration for Security . In IEEE Cybersecurity Development. IEEE Computer Society . Eunsuk Kang. 2016. Design Space Exploration for Security. In IEEE Cybersecurity Development. IEEE Computer Society.","key":"e_1_3_2_1_22_1"},{"key":"e_1_3_2_1_23_1","volume-title":"Tutorial: A Lightweight Web Application for Software Vulnerability Demonstration. In 2021 IEEE Cybersecurity Development","author":"Lee David","year":"2021","unstructured":"David Lee , Brandon Steed , Yi Liu , and Onyeka Ezenwoye . 2021 . Tutorial: A Lightweight Web Application for Software Vulnerability Demonstration. In 2021 IEEE Cybersecurity Development . IEEE Computer Society . David Lee, Brandon Steed, Yi Liu, and Onyeka Ezenwoye. 2021. Tutorial: A Lightweight Web Application for Software Vulnerability Demonstration. In 2021 IEEE Cybersecurity Development. IEEE Computer Society."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_24_1","DOI":"10.1145\/3376127"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_25_1","DOI":"10.1109\/CSAC.2004.41"},{"key":"e_1_3_2_1_26_1","volume-title":"Software Security: Building Security In","author":"McGraw Gary","year":"2006","unstructured":"Gary McGraw . 2006 . Software Security: Building Security In . Addison-Wesley Professional . Gary McGraw. 2006. Software Security: Building Security In. Addison-Wesley Professional."},{"key":"e_1_3_2_1_27_1","volume-title":"Lotfi Ben Othmane, and Andre Kres","author":"Mohan Vaishnavi","year":"2018","unstructured":"Vaishnavi Mohan , Lotfi Ben Othmane, and Andre Kres . 2018 . BP : Security Concerns and Best Practices for Automation of Software Deployment Processes: An Industrial Case Study. In 2018 IEEE Cybersecurity Development. IEEE Computer Society . Vaishnavi Mohan, Lotfi Ben Othmane, and Andre Kres. 2018. BP: Security Concerns and Best Practices for Automation of Software Deployment Processes: An Industrial Case Study. In 2018 IEEE Cybersecurity Development. IEEE Computer Society."},{"key":"e_1_3_2_1_28_1","volume-title":"Security Pattern for Input Validation. In Fifth Nordic Conference on Pattern Languages of Programs.","author":"Netland Lars-Helge","year":"2007","unstructured":"Lars-Helge Netland , Yngve Espelid , and Khalid Azim Mughal . 2007 . Security Pattern for Input Validation. In Fifth Nordic Conference on Pattern Languages of Programs. Lars-Helge Netland, Yngve Espelid, and Khalid Azim Mughal. 2007. Security Pattern for Input Validation. In Fifth Nordic Conference on Pattern Languages of Programs."},{"unstructured":"National Institute of Standards and Technology. 2021. The Common Weakness Enumeration. https:\/\/nvd.nist.gov\/vuln\/categories  National Institute of Standards and Technology. 2021. The Common Weakness Enumeration. https:\/\/nvd.nist.gov\/vuln\/categories","key":"e_1_3_2_1_29_1"},{"unstructured":"National Institute of Standards and Technology. 2021. National Vulnerability Database. https:\/\/nvd.nist.gov\/  National Institute of Standards and Technology. 2021. National Vulnerability Database. https:\/\/nvd.nist.gov\/","key":"e_1_3_2_1_30_1"},{"unstructured":"National Institute of Standards and Technology. 2021. Vulnerability Visualizations. https:\/\/nvd.nist.gov\/General\/Visualizations\/Vulnerability-Visualizations  National Institute of Standards and Technology. 2021. Vulnerability Visualizations. https:\/\/nvd.nist.gov\/General\/Visualizations\/Vulnerability-Visualizations","key":"e_1_3_2_1_31_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_32_1","DOI":"10.1109\/TDSC.2014.2298011"},{"key":"e_1_3_2_1_33_1","volume-title":"Detection, Assessment and Mitigation of Vulnerabilities in Open Source Dependencies. Empir. Softw. Eng. 25, 5","author":"Ponta Serena Elisa","year":"2020","unstructured":"Serena Elisa Ponta , Henrik Plate , and Antonino Sabetta . 2020. Detection, Assessment and Mitigation of Vulnerabilities in Open Source Dependencies. Empir. Softw. Eng. 25, 5 ( 2020 ). Serena Elisa Ponta, Henrik Plate, and Antonino Sabetta. 2020. Detection, Assessment and Mitigation of Vulnerabilities in Open Source Dependencies. Empir. Softw. Eng. 25, 5 (2020)."},{"unstructured":"The Open Web Application Security Project. 2021. OWASP Top 10 Web Application Security Risks. https:\/\/owasp.org\/www-project-top-ten\/  The Open Web Application Security Project. 2021. OWASP Top 10 Web Application Security Risks. https:\/\/owasp.org\/www-project-top-ten\/","key":"e_1_3_2_1_34_1"},{"key":"e_1_3_2_1_35_1","volume-title":"Proceedings of the Workshop on Modeling Security.","author":"Shostack Adam","year":"2008","unstructured":"Adam Shostack . 2008 . Experiences Threat Modeling at Microsoft . In Proceedings of the Workshop on Modeling Security. Adam Shostack. 2008. Experiences Threat Modeling at Microsoft. In Proceedings of the Workshop on Modeling Security."},{"key":"e_1_3_2_1_36_1","volume-title":"Threat Modeling: Designing for Security","author":"Shostack Adam","year":"2014","unstructured":"Adam Shostack . 2014 . Threat Modeling: Designing for Security . Wiley . Adam Shostack. 2014. Threat Modeling: Designing for Security. Wiley."},{"unstructured":"Ian Sommerville. 2015. Software Engineering. Pearson.  Ian Sommerville. 2015. Software Engineering. Pearson.","key":"e_1_3_2_1_37_1"},{"volume-title":"The Behavioral Foundations of Public Policy","author":"Thaler Richard","unstructured":"Richard Thaler , Cass Sunstein , and John Balz . 2013. Choice Architecture . In The Behavioral Foundations of Public Policy , Eldar Shafir (Ed.). Princeton University Press . Richard Thaler, Cass Sunstein, and John Balz. 2013. Choice Architecture. In The Behavioral Foundations of Public Policy, Eldar Shafir (Ed.). Princeton University Press.","key":"e_1_3_2_1_38_1"},{"key":"e_1_3_2_1_39_1","volume-title":"Sunstein","author":"Thaler Richard H.","year":"2008","unstructured":"Richard H. Thaler and Cass R . Sunstein . 2008 . Nudge. Yale University Press . Richard H. Thaler and Cass R. Sunstein. 2008. Nudge. Yale University Press."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_40_1","DOI":"10.1016\/j.jss.2018.06.073"},{"key":"e_1_3_2_1_41_1","volume-title":"Morana","author":"V\u00e9lez Tony Uceda","year":"2015","unstructured":"Tony Uceda V\u00e9lez and Marco M . Morana . 2015 . Risk Centric Threat Modeling: Process for Attack Simulation and Threat Analysis. Wiley . Tony Uceda V\u00e9lez and Marco M. Morana. 2015. Risk Centric Threat Modeling: Process for Attack Simulation and Threat Analysis. Wiley."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_42_1","DOI":"10.1109\/MS.2018.2883876"},{"doi-asserted-by":"crossref","unstructured":"Jim Whitmore and William Tobin. 2017. Improving Attention to Security in Software Design with Analytics and Cognitive Techniques. In 2017 IEEE Cybersecurity Development.  Jim Whitmore and William Tobin. 2017. Improving Attention to Security in Software Design with Analytics and Cognitive Techniques. In 2017 IEEE Cybersecurity Development.","key":"e_1_3_2_1_43_1","DOI":"10.1109\/SecDev.2017.16"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_44_1","DOI":"10.1109\/MC.2019.2891980"},{"unstructured":"Serkan \u00d6zkan. 2021. CVE Details. https:\/\/www.cvedetails.com\/  Serkan \u00d6zkan. 2021. CVE Details. https:\/\/www.cvedetails.com\/","key":"e_1_3_2_1_45_1"}],"event":{"sponsor":["ACM Association for Computing Machinery"],"acronym":"ACM SE '22","name":"ACM SE '22: 2022 ACM Southeast Conference","location":"Virtual Event"},"container-title":["Proceedings of the ACM Southeast Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3476883.3520217","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3476883.3520217","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T17:49:21Z","timestamp":1750268961000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3476883.3520217"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,4,18]]},"references-count":45,"alternative-id":["10.1145\/3476883.3520217","10.1145\/3476883"],"URL":"https:\/\/doi.org\/10.1145\/3476883.3520217","relation":{},"subject":[],"published":{"date-parts":[[2022,4,18]]}}}