{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:23:20Z","timestamp":1781105000583,"version":"3.54.1"},"reference-count":27,"publisher":"IGI Global Scientific Publishing","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014,10]]},"abstract":"<jats:p>Software developers are not necessarily security experts, confirming potential threats and vulnerabilities at an early stage of the development process (e.g., in the requirement- and design-phase) is insufficient. Additionally, even if designed software considers security at an early stage, whether the software really satisfies the security requirements must be confirmed. To realize secure design, this work proposes an application to validate security patterns using model testing. Its method provides extended security patterns, which include requirement- and design-level patterns as well as a new model testing process using these patterns. After a developer specifies threats and vulnerabilities in the target system during an early stage of development, this method can validate whether the security patterns are properly applied and assess if these vulnerabilities are resolved.<\/jats:p>","DOI":"10.4018\/ijsse.2014100101","type":"journal-article","created":{"date-parts":[[2015,1,8]],"date-time":"2015-01-08T12:57:19Z","timestamp":1420721839000},"page":"1-30","source":"Crossref","is-referenced-by-count":5,"title":["Validating Security Design Pattern Applications by Testing Design Models"],"prefix":"10.4018","volume":"5","author":[{"given":"Takanori","family":"Kobashi","sequence":"first","affiliation":[{"name":"Computer Science and Engineering Department, Waseda University, Tokyo, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nobukazu","family":"Yoshioka","sequence":"additional","affiliation":[{"name":"GRACE Center, National Institute of Informatics, Tokyo, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haruhiko","family":"Kaiya","sequence":"additional","affiliation":[{"name":"Department of Information Sciences, Kanagawa University, Kanagawa-ken, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hironori","family":"Washizaki","sequence":"additional","affiliation":[{"name":"Computer Science and Engineering Department, Waseda University, Tokyo, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Takano","family":"Okubo","sequence":"additional","affiliation":[{"name":"Institute of Information Security, Yokohama, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yoshiaki","family":"Fukazawa","sequence":"additional","affiliation":[{"name":"Computer Science and Engineer Department, Waseda University, Tokyo, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"ijsse.2014100101-0","unstructured":"Abramov, J., Shoval, P., & Sturm, A. (2009). Validating and Implementing Security Patterns for Database Applications. SPAQu."},{"key":"ijsse.2014100101-1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2007.114"},{"key":"ijsse.2014100101-2","doi-asserted-by":"publisher","DOI":"10.1109\/TOOLS.2000.891363"},{"key":"ijsse.2014100101-3","doi-asserted-by":"publisher","DOI":"10.1145\/949344.949407"},{"key":"ijsse.2014100101-4","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45800-X_33"},{"key":"ijsse.2014100101-5","unstructured":"Bondareva, K., & Milutinovich, J. (2014). Unified Modeling Language. Retrieved September 10, 2014, from http:\/\/www.omg.org\/gettingstarted\/what_is_uml.htm"},{"key":"ijsse.2014100101-6","author":"F.Bschmann","year":"2006","journal-title":"SECURITY PATTERNS: Integrating Security and Systems Engineering"},{"key":"ijsse.2014100101-7","doi-asserted-by":"publisher","DOI":"10.1016\/j.scico.2007.01.013"},{"key":"ijsse.2014100101-8","doi-asserted-by":"publisher","DOI":"10.1145\/1516241.1516349"},{"key":"ijsse.2014100101-9","doi-asserted-by":"publisher","DOI":"10.1145\/5397.5399"},{"key":"ijsse.2014100101-10","unstructured":"Dam, A., Foley, J. D., Feiner, S., & Hughes, J. (1995). Computer Graphics: Principles and Practice in C (2nd Edition)."},{"key":"ijsse.2014100101-11","first-page":"454","author":"J.Dong","year":"2008","journal-title":"Verifying Behavioral Correctness of Design PatternImplementation"},{"key":"ijsse.2014100101-12","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2009.10.001"},{"key":"ijsse.2014100101-13","doi-asserted-by":"publisher","DOI":"10.1109\/EDOC.2004.1342507"},{"key":"ijsse.2014100101-14","doi-asserted-by":"publisher","DOI":"10.1109\/SESS.2007.4"},{"key":"ijsse.2014100101-15","doi-asserted-by":"publisher","DOI":"10.1109\/ICACTE.2008.31"},{"key":"ijsse.2014100101-16","author":"A.Josang","year":"1995","journal-title":"Security protocol verification using spin"},{"key":"ijsse.2014100101-17","unstructured":"Ju \u0308rjens, J., Popp, G., & Wimmel, G. (2002). Towards using security patterns in model-based system development. PLoP. doi: 10.1.1.18.8894."},{"key":"ijsse.2014100101-18","unstructured":"Jurijens, J. (2005). Secure Systems Development with UML."},{"key":"ijsse.2014100101-19","unstructured":"Kaiya, H. Kobashi.T., Okubo, T. Washizaki, H., & Yochioka, N. (2013). SSR-Project. https:\/\/github.com\/SSR-Project"},{"key":"ijsse.2014100101-20","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2011.79"},{"key":"ijsse.2014100101-21","author":"A.Kleppe","year":"1999","journal-title":"The Object Constraint Language: Precise Modeling with UML"},{"key":"ijsse.2014100101-22","unstructured":"Lai, R., Nagappan, R., & Steel, C. (2005). Core Security Patterns: Best Practices and Strategies for J2EE, Web Services, and Identity Management."},{"key":"ijsse.2014100101-23","unstructured":"Mackman, A., & Maher, P. (2007). Web Application Security Frame. Microsoft Patterns & Practices. http:\/\/msdn.microsoft.com\/en-us\/library\/ms978518"},{"key":"ijsse.2014100101-24","unstructured":"Maruyama, k., Washizaki, H., & Yoshioka, N. (2008). A Survey on Security Patterns (pp. 35-47)."},{"key":"ijsse.2014100101-25","doi-asserted-by":"publisher","DOI":"10.1109\/CSE.2009.18"},{"key":"ijsse.2014100101-26","author":"P.Pilgrim","year":"2013","journal-title":"Java EE 7 Developer Handbook. Paperback"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=121680","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,11,20]],"date-time":"2018-11-20T21:39:52Z","timestamp":1542749992000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/ijsse.2014100101"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2014,10]]},"references-count":27,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.4018\/ijsse.2014100101","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,10]]}}}