{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T12:17:15Z","timestamp":1780316235903,"version":"3.54.1"},"reference-count":59,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","funder":[{"name":"National Natural Science Foundation of China","award":["62102014"],"award-info":[{"award-number":["62102014"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62177003"],"award-info":[{"award-number":["62177003"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"National Science and Technology Major Project of China","award":["Y2022-V-0001-0027"],"award-info":[{"award-number":["Y2022-V-0001-0027"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2025,6,19]]},"abstract":"<jats:p>In the current software-driven era, ensuring privacy and security is critical. Despite this, the specification of security requirements for software is still largely a manual and labor-intensive process. Engineers are tasked with analyzing potential security threats based on functional requirements (FRs), a procedure prone to omissions and errors due to the expertise gap between cybersecurity experts and software engineers. To bridge this gap, we introduce F2SRD (Function-to-Security Requirements Derivation), an automated approach that proactively derives security requirements (SRs) from functional specifications under the guidance of relevant security verification requirements (VRs) drawn from the well recognized OWASP Application Security Verification Standard (ASVS).  \nF2SRD operates in two main phases: Initially, we develop a VR retriever trained on a custom database of FR-VR pairs, enabling it to adeptly select applicable VRs from ASVS. This targeted retrieval informs the precise and actionable formulation of SRs. Subsequently, these VRs are used to construct structured prompts that direct GPT-4 in generating SRs. Our comparative analysis against two established models demonstrates F2SRD's enhanced performance in producing SRs that excel in inspiration, diversity, and specificity\u2014essential attributes for effective security requirement generation. By leveraging security verification standards, we believe that the generated SRs are not only more focused but also resonate stronger with the needs of engineers.<\/jats:p>","DOI":"10.1145\/3729347","type":"journal-article","created":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T15:15:34Z","timestamp":1750346134000},"page":"1710-1732","source":"Crossref","is-referenced-by-count":5,"title":["Incorporating Verification Standards for Security Requirements Generation from Functional Specifications"],"prefix":"10.1145","volume":"2","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6100-7068","authenticated-orcid":false,"given":"Xiaoli","family":"Lian","sequence":"first","affiliation":[{"name":"Beihang University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-2033-7026","authenticated-orcid":false,"given":"Shuaisong","family":"Wang","sequence":"additional","affiliation":[{"name":"Beihang University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-2943-0433","authenticated-orcid":false,"given":"Hanyu","family":"Zou","sequence":"additional","affiliation":[{"name":"Beihang University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3905-8133","authenticated-orcid":false,"given":"Fang","family":"Liu","sequence":"additional","affiliation":[{"name":"Beihang University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-0640-7386","authenticated-orcid":false,"given":"Jiajun","family":"Wu","sequence":"additional","affiliation":[{"name":"Beihang University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2258-5893","authenticated-orcid":false,"given":"Li","family":"Zhang","sequence":"additional","affiliation":[{"name":"Beihang University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,6,19]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"2018. ISO\/IEC\/IEEE Draft International Standard - Systems and Software Engineering \u2013 Life Cycle Processes \u2013Requirements Engineering. ISO\/IEC\/IEEE P29148_FDIS September 2018 1\u2013104."},{"key":"e_1_2_1_2_1","volume-title":"Diogo Almeida, Janko Altenschmidt, Sam Altman, and Shyamal Anadkat.","author":"Achiam Josh","year":"2023","unstructured":"Josh Achiam, Steven Adler, Sandhini Agarwal, Lama Ahmad, Ilge Akkaya, Florencia Leoni Aleman, Diogo Almeida, Janko Altenschmidt, Sam Altman, and Shyamal Anadkat. 2023. Gpt-4 technical report. arXiv preprint arXiv:2303.08774."},{"key":"e_1_2_1_3_1","volume-title":"2021 International Conference on Computing, Communication, and Intelligent Systems (ICCCIS). 58\u201363","author":"Ahmad Javed","year":"2021","unstructured":"Javed Ahmad, Chaudhary Wali Mohammad, and Mohd Sadiq. 2021. Identification of Security Requirements from the Selected Set of Requirements under Fuzzy Environment. In 2021 International Conference on Computing, Communication, and Intelligent Systems (ICCCIS). 58\u201363. https:\/\/doi.org\/10.1109\/ICCCIS51004.2021.9397153 10.1109\/ICCCIS51004.2021.9397153"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","unstructured":"Md Tarique Ansari and Dhirendra Pandey. 2018. Risks security and privacy for HIV\/AIDS data: Big data perspective. 117\u2013139. isbn:9781522532040 https:\/\/doi.org\/10.4018\/978-1-5225-3203-3.ch005 10.4018\/978-1-5225-3203-3.ch005","DOI":"10.4018\/978-1-5225-3203-3.ch005"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jksuci.2018.12.005"},{"key":"e_1_2_1_6_1","volume-title":"2022 IEEE\/ACM 44th International Conference on Software Engineering: Companion Proceedings (ICSE-Companion). 188\u2013192","author":"Bao Tianshu","year":"2022","unstructured":"Tianshu Bao, Jing Yang, Yilong Yang, and Yongfeng Yin. 2022. RM2Doc: A Tool for Automatic Generation of Requirements Documents from Requirements Models. In 2022 IEEE\/ACM 44th International Conference on Software Engineering: Companion Proceedings (ICSE-Companion). 188\u2013192. https:\/\/doi.org\/10.1145\/3510454.3516850 10.1145\/3510454.3516850"},{"key":"e_1_2_1_7_1","volume-title":"11th IEEE International Conference on Requirements Engineering (RE 2003)","author":"Berenbach Brian","year":"2003","unstructured":"Brian Berenbach. 2003. The Automated Extraction of Requirements from UML Models. In 11th IEEE International Conference on Requirements Engineering (RE 2003), 8-12 September 2003, Monterey Bay, CA, USA. IEEE Computer Society, 287."},{"key":"e_1_2_1_8_1","volume-title":"Inpars: Data augmentation for information retrieval using large language models. arXiv preprint arXiv:2202.05144.","author":"Bonifacio Luiz","year":"2022","unstructured":"Luiz Bonifacio, Hugo Abonizio, Marzieh Fadaee, and Rodrigo Nogueira. 2022. Inpars: Data augmentation for information retrieval using large language models. arXiv preprint arXiv:2202.05144."},{"key":"e_1_2_1_9_1","volume-title":"Risks and Security of Internet and Systems: 11th International Conference, CRiSIS 2016","author":"Bulusu Sravani Teja","year":"2017","unstructured":"Sravani Teja Bulusu, Romain Laborde, Ahmad Samer Wazan, Fran\u00e7ois Barr\u00e8re, and Abdelmalek Benzekri. 2017. Towards the weaving of the characteristics of good security requirements. In Risks and Security of Internet and Systems: 11th International Conference, CRiSIS 2016, Roscoff, France, September 5-7, 2016, Revised Selected Papers 11. 60\u201374."},{"key":"e_1_2_1_10_1","doi-asserted-by":"crossref","first-page":"319","DOI":"10.1016\/j.infsof.2004.09.002","article-title":"Deriving requirements from process models via the problem frames approach","volume":"47","author":"Cox Karl","year":"2005","unstructured":"Karl Cox, Keith Phalp, Steven J. Bleistein, and June M. Verner. 2005. Deriving requirements from process models via the problem frames approach. Inf. Softw. Technol., 47, 5 (2005), 319\u2013337.","journal-title":"Inf. Softw. Technol."},{"key":"e_1_2_1_11_1","volume-title":"PROMPTAGATOR: FEW-SHOT DENSE RETRIEVAL FROM 8 EXAMPLES. arXiv preprint arXiv:2209.11755.","author":"Dai Zhuyun","year":"2022","unstructured":"Zhuyun Dai, Vincent Y Zhao, Ji Ma, Yi Luan, Jianmo Ni, Jing Lu, Anton Bakalov, Kelvin Guu, Keith B Hall, and Ming-Wei Chang. 2022. PROMPTAGATOR: FEW-SHOT DENSE RETRIEVAL FROM 8 EXAMPLES. arXiv preprint arXiv:2209.11755."},{"key":"e_1_2_1_12_1","unstructured":"Abhimanyu Dubey Abhinav Jauhri Abhinav Pandey Abhishek Kadian Ahmad Al-Dahle Aiesha Letman Akhil Mathur Alan Schelten Amy Yang and Angela Fan. 2024. The llama 3 herd of models. arXiv preprint arXiv:2407.21783."},{"key":"e_1_2_1_13_1","volume-title":"2021 IEEE\/ACM 43rd International Conference on Software Engineering: Software Engineering Education and Training (ICSE-SEET). 95\u2013104","author":"Elder Sarah","year":"2021","unstructured":"Sarah Elder, Nusrat Zahan, Valeri Kozarev, Rui Shu, Tim Menzies, and Laurie Williams. 2021. Structuring a Comprehensive Software Security Course Around the OWASP Application Security Verification Standard. In 2021 IEEE\/ACM 43rd International Conference on Software Engineering: Software Engineering Education and Training (ICSE-SEET). 95\u2013104. https:\/\/doi.org\/10.1109\/ICSE-SEET52601.2021.00019 10.1109\/ICSE-SEET52601.2021.00019"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-016-9451-7"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4612-4380-9_6"},{"key":"e_1_2_1_16_1","volume-title":"Software requirements classification using word embeddings and convolutional neural networks. Master\u2019s thesis","author":"Fong Vivian","unstructured":"Vivian Fong. 2018. Software requirements classification using word embeddings and convolutional neural networks. Master\u2019s thesis. California Polytechnic State University."},{"key":"e_1_2_1_17_1","volume-title":"2023 IEEE 31st International Requirements Engineering Conference (RE). 134\u2013145","author":"Gudaparthi Hemanth","year":"2023","unstructured":"Hemanth Gudaparthi, Nan Niu, Boyang Wang, Tanmay Bhowmik, Hui Liu, Jianzhang Zhang, Juha Savolainen, Glen Horton, Sean Crowe, Thomas Scherz, and Lisa Haitz. 2023. Prompting Creative Requirements via Traceable and Adversarial Examples in Deep Learning. In 2023 IEEE 31st International Requirements Engineering Conference (RE). 134\u2013145. https:\/\/doi.org\/10.1109\/RE57278.2023.00022 10.1109\/RE57278.2023.00022"},{"key":"e_1_2_1_18_1","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1007\/s00766-009-0093-9","article-title":"Eliciting security requirements and tracing them to design: an integration of Common Criteria, heuristics, and UMLsec","volume":"15","author":"Houmb Siv Hilde","year":"2010","unstructured":"Siv Hilde Houmb, Shareeful Islam, Eric Knauss, Jan J\u00fcrjens, and Kurt Schneider. 2010. Eliciting security requirements and tracing them to design: an integration of Common Criteria, heuristics, and UMLsec. Requirements Engineering, 15 (2010), 63\u201393.","journal-title":"Requirements Engineering"},{"key":"e_1_2_1_19_1","volume-title":"Ieee: Iso\/iec\/ieee 29148, systems and software engineering, life cycle processes. Requirements engineering, 600","author":"IEC","year":"2011","unstructured":"IEC ISO. 2011. Ieee: Iso\/iec\/ieee 29148, systems and software engineering, life cycle processes. Requirements engineering, 600 (2011)."},{"key":"e_1_2_1_20_1","unstructured":"Vitor Jeronymo Luiz Bonifacio Hugo Abonizio Marzieh Fadaee Roberto Lotufo Jakub Zavrel and Rodrigo Nogueira. 2023. Inpars-v2: Large language models as efficient dataset generators for information retrieval. arXiv preprint arXiv:2301.01820."},{"key":"e_1_2_1_21_1","doi-asserted-by":"crossref","first-page":"337","DOI":"10.1109\/TIT.1976.1055554","article-title":"Huffman codes and self-information","volume":"22","author":"Katona Gyula","year":"1976","unstructured":"Gyula Katona and O Nemetz. 1976. Huffman codes and self-information. IEEE Transactions on Information Theory, 22, 3 (1976), 337\u2013340.","journal-title":"IEEE Transactions on Information Theory"},{"key":"e_1_2_1_22_1","volume-title":"Requirements Engineering: Foundation for Software Quality","author":"Knauss Eric","year":"1985","unstructured":"Eric Knauss, Siv Houmb, Kurt Schneider, Shareeful Islam, and Jan J\u00fcrjens. 2011. Supporting Requirements Engineers in Recognising Security Issues. In Requirements Engineering: Foundation for Software Quality, Daniel Berry and Xavier Franch (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg. 4\u201318. isbn:978-3-642-19858-8"},{"key":"e_1_2_1_23_1","doi-asserted-by":"crossref","first-page":"155","DOI":"10.1016\/j.jcm.2016.02.012","article-title":"A Guideline of Selecting and Reporting Intraclass Correlation Coefficients for Reliability Research","volume":"15","author":"Koo Terry K","year":"2016","unstructured":"Terry K Koo and Mae Y Li. 2016. A Guideline of Selecting and Reporting Intraclass Correlation Coefficients for Reliability Research. Journal of chiropractic medicine, 15 (2016), 155\u2013163.","journal-title":"Journal of chiropractic medicine"},{"key":"e_1_2_1_24_1","volume-title":"2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE). 1609\u20131621","author":"Koscinski Viktoria","year":"2023","unstructured":"Viktoria Koscinski, Sara Hashemi, and Mehdi Mirakhorli. 2023. On-demand security requirements synthesis with relational generative adversarial networks. In 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE). 1609\u20131621."},{"key":"e_1_2_1_25_1","volume-title":"On-Demand Security Requirements Synthesis with Relational Generative Adversarial Networks. In 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE). 1609\u20131621","author":"Koscinski Viktoria","year":"2023","unstructured":"Viktoria Koscinski, Sara Hashemi, and Mehdi Mirakhorli. 2023. On-Demand Security Requirements Synthesis with Relational Generative Adversarial Networks. In 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE). 1609\u20131621. https:\/\/doi.org\/10.1109\/ICSE48619.2023.00139 10.1109\/ICSE48619.2023.00139"},{"key":"e_1_2_1_26_1","volume-title":"The Cost of Poor Software Quality in the US: A 2020 Report. CISQ.","author":"Krasner Kerb","year":"2021","unstructured":"Kerb Krasner. 2021. The Cost of Poor Software Quality in the US: A 2020 Report. CISQ."},{"key":"e_1_2_1_27_1","volume-title":"Requirements engineering: from system goals to UML models to software specifications","author":"van Lamsweerde A","unstructured":"A van Lamsweerde. 2009. Requirements engineering: from system goals to UML models to software specifications. John Wiley & Sons, Ltd."},{"key":"e_1_2_1_28_1","doi-asserted-by":"crossref","first-page":"104","DOI":"10.1007\/s00766-004-0189-1","article-title":"Deriving tabular event-based specifications from goal-oriented requirements models","volume":"9","author":"Landtsheer Renaud De","year":"2004","unstructured":"Renaud De Landtsheer, Emmanuel Letier, and Axel van Lamsweerde. 2004. Deriving tabular event-based specifications from goal-oriented requirements models. Requir. Eng., 9, 2 (2004), 104\u2013120.","journal-title":"Requir. Eng."},{"key":"e_1_2_1_29_1","volume-title":"Software Architecture in Practice","author":"Len Bass Rick Kazman","unstructured":"Rick Kazman Len Bass, Paul Clements. 2021. Software Architecture in Practice, 4th Edition. Addison-Wesley Professional.","edition":"4"},{"key":"e_1_2_1_30_1","volume-title":"Proceedings of the Tenth ACM SIGSOFT Symposium on Foundations of Software Engineering 2002","author":"Letier Emmanuel","year":"2002","unstructured":"Emmanuel Letier and Axel van Lamsweerde. 2002. Deriving operational software specifications from system goals. In Proceedings of the Tenth ACM SIGSOFT Symposium on Foundations of Software Engineering 2002, Charleston, South Carolina, USA, November 18-22, 2002. ACM, 119\u2013128."},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","unstructured":"Hongbo Li Xiaohong Li Jianye Hao Guangquan Xu Zhiyong Feng and Xiaofei Xie. 2017. FESR: A Framework for Eliciting Security Requirements Based on Integration of Common Criteria and Weakness Detection Formal Model. In 2017 IEEE International Conference on Software Quality Reliability and Security (QRS). 352\u2013363. https:\/\/doi.org\/10.1109\/QRS.2017.45 10.1109\/QRS.2017.45","DOI":"10.1109\/QRS.2017.45"},{"key":"e_1_2_1_32_1","doi-asserted-by":"crossref","first-page":"276","DOI":"10.1007\/s00766-005-0010-9","article-title":"Generating requirements from systems models using patterns: a case study","volume":"10","author":"Maiden Neil A. M.","year":"2005","unstructured":"Neil A. M. Maiden, Sharon Manning, Sara Jones, and John Greenwood. 2005. Generating requirements from systems models using patterns: a case study. Requir. Eng., 10, 4 (2005), 276\u2013288.","journal-title":"Requir. Eng."},{"key":"e_1_2_1_33_1","volume-title":"Information Theory. https:\/\/www.britannica.com\/science\/information-theory Encyclopedia Britannica","author":"Markowsky George","unstructured":"George Markowsky. 2024. Information Theory. https:\/\/www.britannica.com\/science\/information-theory Encyclopedia Britannica."},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/1082983.1083214"},{"key":"e_1_2_1_35_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s00766-007-0054-0","article-title":"Generating Natural Language specifications from UML class diagrams","volume":"13","author":"Meziane Farid","year":"2008","unstructured":"Farid Meziane, Nikos Athanasakis, and Sophia Ananiadou. 2008. Generating Natural Language specifications from UML class diagrams. Requir. Eng., 13, 1 (2008), 1\u201318.","journal-title":"Requir. Eng."},{"key":"e_1_2_1_36_1","volume-title":"Secure Code Recommendation Based on Code Review Result Using OWASP Code Review Guide. In 2020 International Workshop on Big Data and Information Security (IWBIS). 153\u2013158","author":"Nanisura Damanik Venia Noella","year":"2020","unstructured":"Venia Noella Nanisura Damanik and Septia Ulfa Sunaringtyas. 2020. Secure Code Recommendation Based on Code Review Result Using OWASP Code Review Guide. In 2020 International Workshop on Big Data and Information Security (IWBIS). 153\u2013158. https:\/\/doi.org\/10.1109\/IWBIS50925.2020.9255559 10.1109\/IWBIS50925.2020.9255559"},{"key":"e_1_2_1_37_1","volume-title":"RelGAN: Relational Generative Adversarial Networks for Text Generation. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=rJedV3R5tm","author":"Nie Weili","year":"2019","unstructured":"Weili Nie, Nina Narodytska, and Ankit Patel. 2019. RelGAN: Relational Generative Adversarial Networks for Text Generation. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=rJedV3R5tm"},{"key":"e_1_2_1_38_1","volume-title":"2014 IEEE 22nd International Requirements Engineering Conference (RE). 183\u2013192","author":"Riaz Maria","year":"2014","unstructured":"Maria Riaz, Jason King, John Slankas, and Laurie Williams. 2014. Hidden in plain sight: Automatically identifying security requirements from natural language artifacts. In 2014 IEEE 22nd International Requirements Engineering Conference (RE). 183\u2013192. https:\/\/doi.org\/10.1109\/RE.2014.6912260 10.1109\/RE.2014.6912260"},{"key":"e_1_2_1_39_1","volume-title":"Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing, Houda Bouamor, Juan Pino, and Kalika Bali (Eds.). Association for Computational Linguistics","author":"Saad-Falcon Jon","year":"2023","unstructured":"Jon Saad-Falcon, Omar Khattab, Keshav Santhanam, Radu Florian, Martin Franz, Salim Roukos, Avirup Sil, Md Sultan, and Christopher Potts. 2023. UDAPDR: Unsupervised Domain Adaptation via LLM Prompting and Distillation of Rerankers. In Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing, Houda Bouamor, Juan Pino, and Kalika Bali (Eds.). Association for Computational Linguistics, Singapore. 11265\u201311279. https:\/\/doi.org\/10.18653\/v1\/2023.emnlp-main.693 10.18653\/v1\/2023.emnlp-main.693"},{"key":"e_1_2_1_40_1","doi-asserted-by":"crossref","unstructured":"Keshav Santhanam Omar Khattab Jon Saad-Falcon Christopher Potts and Matei Zaharia. 2021. Colbertv2: Effective and efficient retrieval via lightweight late interaction. arXiv preprint arXiv:2112.01488.","DOI":"10.18653\/v1\/2022.naacl-main.272"},{"key":"e_1_2_1_41_1","volume-title":"Zaharia","author":"Santhanam Keshav","year":"2021","unstructured":"Keshav Santhanam, O. Khattab, Jon Saad-Falcon, Christopher Potts, and Matei A. Zaharia. 2021. ColBERTv2: Effective and Efficient Retrieval via Lightweight Late Interaction. In North American Chapter of the Association for Computational Linguistics. https:\/\/api.semanticscholar.org\/CorpusID:244799249"},{"key":"e_1_2_1_42_1","unstructured":"Contrast Security. 2020. 2020 Application Security Observability Report. https:\/\/www.contrastsecurity.com\/hubfs\/2020-Contrast-Labs-Application-Security-Observability_Annual_Report_07152020.pdf"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1948.tb01338.x"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00766-017-0279-5"},{"key":"e_1_2_1_45_1","doi-asserted-by":"crossref","first-page":"557","DOI":"10.1007\/s00766-017-0279-5","article-title":"Using the AMAN-DA method to generate security requirements: a case study in the maritime domain","volume":"23","author":"Souag Amina","year":"2018","unstructured":"Amina Souag, Ra\u00fal Mazo, Camille Salinesi, and Isabelle Comyn-Wattiau. 2018. Using the AMAN-DA method to generate security requirements: a case study in the maritime domain. Requirements Engineering, 23 (2018), 557\u2013580.","journal-title":"Requirements Engineering"},{"key":"e_1_2_1_46_1","volume-title":"2022 IEEE 16th International Conference on Semantic Computing (ICSC). 151\u2013158","author":"Steinmann Jessica","year":"2022","unstructured":"Jessica Steinmann and Omar Ochoa. 2022. Supporting Security Requirements Engineering through the Development of The Secure Development Ontology. In 2022 IEEE 16th International Conference on Semantic Computing (ICSC). 151\u2013158. https:\/\/doi.org\/10.1109\/ICSC52841.2022.00031 10.1109\/ICSC52841.2022.00031"},{"key":"e_1_2_1_47_1","volume-title":"Accessed","author":"P\u00ae Foundation The","year":"2008","unstructured":"The OWASP\u00ae Foundation. 2008. OWASP Application Security Verification Standard (ASVS). Accessed August 26, 2024. https:\/\/owasp.org\/www-project-application-security-verification-standard\/"},{"key":"e_1_2_1_48_1","volume-title":"1st Conf. on the Principles of Software Eng.(PRISE\u201904)","author":"T\u00fcretken Oktay","year":"2004","unstructured":"Oktay T\u00fcretken, Onur Su, and Onur Demir\u00f6rs. 2004. Automating software requirements generation from business process models. In 1st Conf. on the Principles of Software Eng.(PRISE\u201904), Buenos Aires, Argentina."},{"key":"e_1_2_1_49_1","unstructured":"Nasser Vali and Nasser Modiri. [n. d.]. ISO\/IEC 15408."},{"key":"e_1_2_1_50_1","volume-title":"Proceedings. 12th IEEE International Requirements Engineering Conference","author":"Lamsweerde Axel Van","year":"2004","unstructured":"Axel Van Lamsweerde. 2004. Goal-oriented requirements enginering: a roundtrip from research to practice [enginering read engineering]. In Proceedings. 12th IEEE International Requirements Engineering Conference, 2004.. 4\u20137."},{"key":"e_1_2_1_51_1","doi-asserted-by":"crossref","first-page":"1089","DOI":"10.1109\/32.738341","article-title":"Inferring Declarative Requirements Specifications from Operational Scenarios","volume":"24","author":"van Lamsweerde Axel","year":"1998","unstructured":"Axel van Lamsweerde and Laurent Willemet. 1998. Inferring Declarative Requirements Specifications from Operational Scenarios. IEEE Trans. Software Eng., 24, 12 (1998), 1089\u20131114.","journal-title":"IEEE Trans. Software Eng."},{"key":"e_1_2_1_52_1","first-page":"1","article-title":"The generalization of Student\u2019s problem when several different population variances are involved","volume":"34","author":"Welch B L","year":"1947","unstructured":"B L Welch. 1947. The generalization of Student\u2019s problem when several different population variances are involved. Biometrika, 34, 1-2 (1947), 28\u201335.","journal-title":"Biometrika"},{"key":"e_1_2_1_53_1","unstructured":"Junjie Ye Xuanting Chen Nuo Xu Can Zu Zekai Shao Shichun Liu Yuhan Cui Zeyang Zhou Chao Gong and Yang Shen. 2023. A comprehensive capability analysis of gpt-3 and gpt-3.5 series models. arXiv preprint arXiv:2303.10420."},{"key":"e_1_2_1_54_1","volume-title":"Agents\u2019 Approach. In Proceedings of the Third International Conference on Cooperative Information Systems (CoopIS-95)","author":"Yu Eric S. K.","year":"1995","unstructured":"Eric S. K. Yu, Philippe Du Bois, Eric Dubois, and John Mylopoulos. 1995. From Organization Models to System Requirements: A \u2019Cooperating Agents\u2019 Approach. In Proceedings of the Third International Conference on Cooperative Information Systems (CoopIS-95), May 9-12. 194\u2013204."},{"key":"e_1_2_1_55_1","unstructured":"Jiuang Zhao Donghao Yang Li Zhang Xiaoli Lian and Zitian Yang. 2024. Enhancing LLM-Based Automated Program Repair with Design Rationales. arxiv:2408.12056. arxiv:2408.12056"},{"key":"e_1_2_1_56_1","unstructured":"Jiuang Zhao Zitian Yang Li Zhang Xiaoli Lian and Donghao Yang. 2024. A Novel Approach for Automated Design Information Mining from Issue Logs. arxiv:2405.19623. arxiv:2405.19623"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.3390\/math11020332"},{"key":"e_1_2_1_58_1","volume-title":"The 41st international ACM SIGIR conference on research & development in information retrieval. 1097\u20131100","author":"Zhu Yaoming","year":"2018","unstructured":"Yaoming Zhu, Sidi Lu, Lei Zheng, Jiaxian Guo, Weinan Zhang, Jun Wang, and Yong Yu. 2018. Texygen: A benchmarking platform for text generation models. In The 41st international ACM SIGIR conference on research & development in information retrieval. 1097\u20131100."},{"key":"e_1_2_1_59_1","volume-title":"2019 Federated Conference on Computer Science and Information Systems (FedCSIS). 875\u2013878","author":"\u0141ukasiewicz Katarzyna","year":"2019","unstructured":"Katarzyna \u0141ukasiewicz and Sara Cyga\u0144ska. 2019. Security-oriented agile approach with AgileSafe and OWASP ASVS. In 2019 Federated Conference on Computer Science and Information Systems (FedCSIS). 875\u2013878. https:\/\/doi.org\/10.15439\/2019F213 10.15439\/2019F213"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3729347","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T15:32:17Z","timestamp":1750347137000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3729347"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,19]]},"references-count":59,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2025,6,19]]}},"alternative-id":["10.1145\/3729347"],"URL":"https:\/\/doi.org\/10.1145\/3729347","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,19]]}}}