{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T14:49:22Z","timestamp":1781102962668,"version":"3.54.1"},"reference-count":0,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,1]]},"abstract":"<jats:p>When deciding and evaluating system security strategies, there is a trade-off relationship between security assuring effect and constraint condition, which has been revealed by many qualitative security assurance methods. However, the existing methods cannot be used to make quantitative analysis on security assurance and constraint conditions to support project managers and system engineers to decide system development strategies. Therefore, a quantitative method which can consider both security strategies and constraints is necessary. This paper proposes a semi-automatic, quantitative system security assurance approach for developing security requirement and security assurance cases by extending the traditional GSN (goal structuring notation). Next, two greedy algorithms for quantitative system security assurance are implemented and evaluated. In addition, a case study and an experiment are carried out to verify the effectiveness and efficiency of the proposed approach and the proposed algorithms.<\/jats:p>","DOI":"10.4018\/ijsssp.2021010103","type":"journal-article","created":{"date-parts":[[2021,2,1]],"date-time":"2021-02-01T15:52:09Z","timestamp":1612194729000},"page":"46-62","source":"Crossref","is-referenced-by-count":1,"title":["A Goal-Oriented Approach to Requirements Development and Quantitative Security Assurance"],"prefix":"10.4018","volume":"12","author":[{"given":"Zhengshu","family":"Zhou","sequence":"first","affiliation":[{"name":"Nagoya University, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7057-9888","authenticated-orcid":true,"given":"Qiang","family":"Zhi","sequence":"additional","affiliation":[{"name":"Nagoya University, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zilong","family":"Liang","sequence":"additional","affiliation":[{"name":"University of Tsukuba, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shuji","family":"Morisaki","sequence":"additional","affiliation":[{"name":"Nagoya University, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","container-title":["International Journal of Systems and Software Security and Protection"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=272090","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,6]],"date-time":"2022-05-06T06:59:45Z","timestamp":1651820385000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/IJSSSP.2021010103"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2021,1]]},"references-count":0,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.4018\/ijsssp.2021010103","relation":{},"ISSN":["2640-4265","2640-4273"],"issn-type":[{"value":"2640-4265","type":"print"},{"value":"2640-4273","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,1]]}}}