{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:44:47Z","timestamp":1781109887487,"version":"3.54.1"},"reference-count":23,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012,1]]},"abstract":"<jats:p>Unlike functional implementations, it is difficult to analyze the impact on security of software enhancements. One of the difficulties is identifying the range of effects on existing software from new security threats, and the other is developing proper countermeasures. The authors propose an analysis method that uses two kinds of security patterns: security requirements patterns for identifying threats and security design patterns for identifying countermeasures at an action class level. With these two patterns and the conventional traceability methodology, developers can estimate and compare the amount of modifications needed for multiple security countermeasures.<\/jats:p>","DOI":"10.4018\/jsse.2012010103","type":"journal-article","created":{"date-parts":[[2012,11,27]],"date-time":"2012-11-27T08:28:24Z","timestamp":1354004904000},"page":"37-61","source":"Crossref","is-referenced-by-count":3,"title":["Analyzing Impacts on Software Enhancement Caused by Security Design Alternatives with Patterns"],"prefix":"10.4018","volume":"3","author":[{"given":"Takao","family":"Okubo","sequence":"first","affiliation":[{"name":"Fujitsu Laboratories Limited, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haruhiko","family":"Kaiya","sequence":"additional","affiliation":[{"name":"National Institute of Informatics, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nobukazu","family":"Yoshioka","sequence":"additional","affiliation":[{"name":"National Institute of Informatics, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jsse.2012010103-0","doi-asserted-by":"crossref","unstructured":"Abadi, A., Nisenson, M., & Simionovici, Y. (2008). A traceability technique for specifications. In Proceedings of the 16th International Conference on Program Comprehension (pp. 103-112).","DOI":"10.1109\/ICPC.2008.30"},{"key":"jsse.2012010103-1","doi-asserted-by":"crossref","unstructured":"Anquetil, N., Royer, J. C., Andr\u00e9, P., Ardourel, G., Hnetynka, P., & Poch, T. (2009). Javacompext: Extracting architectural elements from java source code. In Proceedings of the 16th International Working Conference on Reverse Engineering (pp. 317-318).","DOI":"10.1109\/WCRE.2009.53"},{"key":"jsse.2012010103-2","doi-asserted-by":"crossref","unstructured":"Buckner, J., Buchta, J., Petrenko, M., & Rajlich, V. (2005). Jripples: A tool for program comprehension during incremental change. In Proceedings of the 13th International Workshop on Program Comprehension (pp. 149-152).","DOI":"10.1109\/WPC.2005.22"},{"key":"jsse.2012010103-3","doi-asserted-by":"crossref","unstructured":"Eaddy, M., Aho, A. V., Antoniol, G., & Gu\u00e9h\u00e9neuc, Y. G. (2008). Cerberus: Tracing requirements to source code using information retrieval, dynamic analysis, and program analysis. In Proceedings of the 16th International Conference on Program Comprehension (pp. 53-62).","DOI":"10.1109\/ICPC.2008.39"},{"key":"jsse.2012010103-4","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2003.1178051"},{"key":"jsse.2012010103-5","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2010.159"},{"key":"jsse.2012010103-6","doi-asserted-by":"crossref","unstructured":"Grechanik, M., McKinley, K. S., & Perry, D. E. (2007). Recovering and using use-case-diagram-to-source-code traceability links. In Proceedings of the 6th Joint Meeting of the European Software Engineering Conference and the ACM SIGSOFT Symposium on The Foundations of Software Engineering (pp. 95-104).","DOI":"10.1145\/1287624.1287640"},{"key":"jsse.2012010103-7","doi-asserted-by":"crossref","unstructured":"Heyman, T., Yskout, K., Scandariato, R., & Joosen, W. (2007). An analysis of the security patterns landscape. In Proceedings of the Third International Workshop on Software Engineering for Secure Systems (p. 3).","DOI":"10.1109\/SESS.2007.4"},{"key":"jsse.2012010103-8","author":"M.Howard","year":"2006","journal-title":"The security development lifecycle"},{"key":"jsse.2012010103-9","doi-asserted-by":"crossref","unstructured":"Kusumoto, S., Matsukawa, F., Inoue, K., Hanabusa, S., & Maegawa, Y. (2004). Estimating effort by use case points: Method, tool and case study. In Proceedings of the 10th International Symposium on Software Metrics (pp. 292-299).","DOI":"10.1109\/METRIC.2004.1357913"},{"key":"jsse.2012010103-10","doi-asserted-by":"crossref","unstructured":"Okubo, T., Kaiya, H., & Yoshioka, N. (2011). Effective security impact analysis with patterns for software enhancement. In Proceedings of the International Conference on Availability, Reliability and Security (pp. 527-534).","DOI":"10.1109\/ARES.2011.79"},{"key":"jsse.2012010103-11","doi-asserted-by":"crossref","unstructured":"Okubo, T., Taguchi, K., & Yoshioka, N. (2009). Misuse cases + assets + security goals. In Proceedings of the International Conference on Computational Science and Engineering (p. 424).","DOI":"10.1109\/CSE.2009.18"},{"key":"jsse.2012010103-12","unstructured":"Petrenko, M. (2010). JRipples. Retrieved from http:\/\/jripples.sourceforge.net\/"},{"key":"jsse.2012010103-13","author":"M.Schumacher","year":"2006","journal-title":"Security patterns: Integrating security and systems engineering"},{"key":"jsse.2012010103-14","doi-asserted-by":"crossref","unstructured":"Sindre, G. (2007). Mal-activity diagrams for capturing attacks on business processes. In P. Sawyer, B. Paech, & P. Heymans (Eds.), Proceedings of the 13th International Working Conference on Requirements Engineering: Foundation for Software Quality (LNCS 4542, pp. 355-366).","DOI":"10.1007\/978-3-540-73031-6_27"},{"key":"jsse.2012010103-15","doi-asserted-by":"publisher","DOI":"10.1007\/s00766-004-0194-4"},{"key":"jsse.2012010103-16","doi-asserted-by":"publisher","DOI":"10.1145\/1082983.1083207"},{"key":"jsse.2012010103-17","doi-asserted-by":"crossref","unstructured":"Vinita, Jain, A., & Tayal, D. K. (2008). On reverse engineering an object-oriented code into uml class diagrams incorporating extensible mechanisms. ACM SIGSOFT Software Engineering Notes, 33(5).","DOI":"10.1145\/1402521.1402527"},{"key":"jsse.2012010103-18","unstructured":"W, P. (2001). Cross-site request forgeries. Retrieved from http:\/\/www.tux.org\/~peterw\/csrf.txt"},{"key":"jsse.2012010103-19","unstructured":"Williams, L., Meneely, A., Smith, S., Hayward, L., & Smith, B. (2004). iTrust: Role-based healthcare. Retrieved from http:\/\/agile.csc.ncsu.edu\/iTrust\/wiki\/doku.php"},{"key":"jsse.2012010103-20","doi-asserted-by":"publisher","DOI":"10.1007\/s10270-009-0145-0"},{"key":"jsse.2012010103-21","unstructured":"Yoshikawa, T., Hayashi, S., & Saeki, M. (2009). Recovering traceability links between a simple natural language sentence and source code using domain ontologies. In Proceedings of the International Conference on Software Maintenance (pp. 551-554)."},{"key":"jsse.2012010103-22","doi-asserted-by":"crossref","unstructured":"Yu, Y., J\u00fcrjens, J., & Schreck, J. (2008). Tools for traceability in secure software development. In Proceedings of the International Conference on Automated Software Engineering (pp. 503-504).","DOI":"10.1109\/ASE.2008.92"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=64194","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,2,19]],"date-time":"2019-02-19T11:34:23Z","timestamp":1550576063000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jsse.2012010103"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2012,1]]},"references-count":23,"aliases":["10.4018\/ijsse.2012010103"],"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.4018\/jsse.2012010103","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,1]]}}}