{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:57:15Z","timestamp":1781107035816,"version":"3.54.1"},"reference-count":50,"publisher":"IGI Global Scientific Publishing","issue":"4","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011,10]]},"abstract":"<jats:p>Model Driven Development (MDD) is by many considered a promising approach for software development. This article reports the results of a systematic survey to identify the state-of-the-art within the topic of security in model driven development, with a special focus on finding empirical studies. The authors provide an introduction to the major secure MDD initiatives, but the survey shows that there is a lack of empirical work on the topic. The authors conclude that better standardization initiatives and more empirical research in the field is necessary before it can be considered mature.<\/jats:p>","DOI":"10.4018\/jsse.2011100104","type":"journal-article","created":{"date-parts":[[2011,11,16]],"date-time":"2011-11-16T07:47:28Z","timestamp":1321429648000},"page":"49-61","source":"Crossref","is-referenced-by-count":2,"title":["Not Ready for Prime Time"],"prefix":"10.4018","volume":"2","author":[{"given":"Jostein","family":"Jensen","sequence":"first","affiliation":[{"name":"Norwegian University of Science and Technology, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Martin Gilje","family":"Jaatun","sequence":"additional","affiliation":[{"name":"SINTEF, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jsse.2011100104-0","unstructured":"Alam, M., Breu, R., & Breu, M. (2004). Model driven security for web services (MDS4WS). In Proceedings of the 8th International Multitopic Conference (pp. 498-505)."},{"key":"jsse.2011100104-1","doi-asserted-by":"publisher","DOI":"10.4304\/jsw.2.1.47-59"},{"key":"jsse.2011100104-2","doi-asserted-by":"crossref","unstructured":"Alam, M., Hafner, M., & Breu, R. (2006). Constraint based role based access control (CRBAC) for restricted administrative delegation constraints in the SECTET. In Proceedings of the International Conference on Privacy, Security, and Trust: Bridge the Gap between PST Technologies and Business Services, Markham, ON, Canada.","DOI":"10.1145\/1501434.1501487"},{"key":"jsse.2011100104-3","first-page":"289","article-title":"A framework for modelling restricted delegation of rights in the SECTET.","volume":"22","author":"M.Alam","year":"2007","journal-title":"Computer Systems Science and Engineering"},{"key":"jsse.2011100104-4","doi-asserted-by":"crossref","unstructured":"Alam, M., Seifert, J. P., & Xinwen, Z. (2007). A model-driven framework for trusted computing based systems. In Proceedings of the 11th IEEE International Enterprise Distributed Object Computing Conference (pp. 75-75).","DOI":"10.1109\/EDOC.2007.52"},{"key":"jsse.2011100104-5","doi-asserted-by":"crossref","unstructured":"Basin, D., Clavel, M., & Egea, M. (2011). A decade of model-driven security. In Proceedings of the 16th ACM Symposium on Access Control Models and Technologies.","DOI":"10.1145\/1998441.1998443"},{"key":"jsse.2011100104-6","doi-asserted-by":"crossref","unstructured":"Basin, D., Doser, J., & Lodderstedt, T. (2003, June 2-3). Model driven security for process-oriented systems. In Proceedings of the 8th ACM Symposium on Access Control Models and Technologies, Villa Gallia, Como, Italy.","DOI":"10.1145\/775412.775425"},{"key":"jsse.2011100104-7","doi-asserted-by":"publisher","DOI":"10.1145\/1125808.1125810"},{"key":"jsse.2011100104-8","doi-asserted-by":"crossref","unstructured":"Best, B., Jurjens, J., & Nuseibeh, B. (2007). Model-based security engineering of distributed information systems using UMLsec. In Proceedings of the 29th International Conference on Software Engineering.","DOI":"10.1109\/ICSE.2007.55"},{"key":"jsse.2011100104-9","doi-asserted-by":"crossref","unstructured":"Blanco, C., de Guzman, I. G. R., Fernandez-Medina, E., Trujillo, J., & Piattini, M. (2008). Automatic generation of secure multidimensional code for data warehouses: An MDA approach. In R. Meersman & Z. Tari (Eds.), Proceedings of the International Conference of On the Move to Meaningful Internet Systems (LNCS 5332, pp. 1052-1068).","DOI":"10.1007\/978-3-540-88873-4_9"},{"key":"jsse.2011100104-10","doi-asserted-by":"crossref","unstructured":"Blanco, C., Fernandez-Medina, E., Trujillo, J., & Piattini, M. (2008, March 4-7). Implementing multidimensional security into OLAP tools. In Proceedings of the 3rd International Conference on Availability, Security, and Reliability, Barcelona, Spain.","DOI":"10.1109\/ARES.2008.179"},{"key":"jsse.2011100104-11","doi-asserted-by":"crossref","unstructured":"Blanco, C., P\u00e9rez-Castillo, R., Hern\u00e1ndez, A., Fern\u00e1ndez-Medina, E., & Trujillo, J. (2009). Towards a modernization process for secure data warehouses. In T. B. Pedersen, M. K. Mohania, & A. M. Tjoa (Eds.), Proceedings of the 11th International Conference on Data Warehousing and Knowledge Discovery, Linz, Austria (LNCS 5691, pp. 24-35).","DOI":"10.1007\/978-3-642-03730-6_3"},{"key":"jsse.2011100104-12","first-page":"135","article-title":"Software defect reduction top 10 list.","volume":"34","author":"B.Boehm","year":"2001","journal-title":"IEEE Computer"},{"key":"jsse.2011100104-13","doi-asserted-by":"crossref","unstructured":"Breu, R., Hafner, M., Weber, B., & Novak, A. (2005, March 2-4). Model driven security for inter-organizational workflows in e-government. In M. B\u00f6hlen, J. Gamper, W. Polasek, & M. A. Wimmer (Eds.), Proceedings of the International Conference on E-Government: Towards Electronic Democracy, Bolzano, Italy (LNCS 3416, pp. 122-133).","DOI":"10.1007\/978-3-540-32257-3_12"},{"key":"jsse.2011100104-14","doi-asserted-by":"crossref","unstructured":"Clavel, M., Silva, V., Braga, C., & Egea, M. (2008). Model-driven security in practice: An industrial experience. In Proceedings of the 4th European Conference on Model Driven Architecture: Foundations and Applications (pp. 326-337).","DOI":"10.1007\/978-3-540-69100-6_22"},{"key":"jsse.2011100104-15","unstructured":"CVE. (2011). Common vulnerabilities and exposures (CVE). Retrieved from http:\/\/cve.mitre.org\/"},{"key":"jsse.2011100104-16","doi-asserted-by":"crossref","unstructured":"Dyb\u00e5, T., Dings\u00f8yr, T., & Hanssen, G. K. (2007). Applying systematic reviews to diverse study types: An experience report. In Proceedings of the 1st International Symposium on Empirical Software Engineering and Measurement (pp. 225-234).","DOI":"10.1109\/ESEM.2007.59"},{"key":"jsse.2011100104-17","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2008.05.010"},{"key":"jsse.2011100104-18","doi-asserted-by":"crossref","unstructured":"Hafner, M., Alam, M., & Breu, R. (2006, October 1-6). Towards a MOF\/QVT-based domain architecture for model driven security. In O. Nierstrasz, J. Whittle, D. Harel, & G. Reggio (Eds.), Proceedings of the 9th International Conference on Model Driven Engineering Languages and Systems, Genova, Italy (LNCS 4199, pp. 275-290).","DOI":"10.1007\/11880240_20"},{"key":"jsse.2011100104-19","doi-asserted-by":"crossref","unstructured":"Hafner, M., Breu, M., Breu, R., & Nowak, A. (2005). Modelling inter-organizational workflow security in a peer-to-peer environment. In Proceedings of the IEEE International Conference on Web Services.","DOI":"10.1109\/ICWS.2005.83"},{"key":"jsse.2011100104-20","author":"M.Hafner","year":"2009","journal-title":"Security engineering for service-oriented architectures"},{"key":"jsse.2011100104-21","unstructured":"Haug, T. H. (2007). A systematic review of empirical research on model-driven development with UML. Unpublished master's thesis, University of Oslo, Oslo, Norway."},{"key":"jsse.2011100104-22","author":"M.Howard","year":"2006","journal-title":"The security development lifecycle"},{"key":"jsse.2011100104-23","doi-asserted-by":"crossref","unstructured":"Jensen, J., & Jaatun, M. G. (2011). Security in model driven development: A survey. In Proceedings of the 5th International Workshop on Secure Software Engineering.","DOI":"10.1109\/ARES.2011.110"},{"key":"jsse.2011100104-24","author":"J.J\u00fcrjens","year":"2005","journal-title":"Secure systems development with UML"},{"key":"jsse.2011100104-25","doi-asserted-by":"crossref","unstructured":"J\u00fcrjens, J., Schreck, J., & Bartmann, P. (2008). Model-based security analysis for mobile communications. In Proceedings of the 30th International Conference on Software Engineering.","DOI":"10.1145\/1368088.1368186"},{"key":"jsse.2011100104-26","doi-asserted-by":"crossref","unstructured":"Kasal, K., Heurix, J., & Neubauer, T. (2011, January 4-7). Model-driven development meets security: An evaluation of current approaches. In Proceedings of the 44th Hawaii International Conference on Systems Science.","DOI":"10.1109\/HICSS.2011.310"},{"key":"jsse.2011100104-27","author":"B.Kitchenham","year":"2004","journal-title":"Procedures for performing systematic reviews"},{"key":"jsse.2011100104-28","author":"A. G.Kleppe","year":"2003","journal-title":"MDA explained: The model driven architecture: Practice and promise"},{"key":"jsse.2011100104-29","doi-asserted-by":"crossref","unstructured":"Lloyd, J., & J\u00fcrjens, J. (2009). Security analysis of a biometric authentication system using UMLsec and JML. In Proceedings of the 12th International Conference on Model Driven Engineering Languages and Systems.","DOI":"10.1007\/978-3-642-04425-0_7"},{"key":"jsse.2011100104-30","doi-asserted-by":"crossref","unstructured":"McDermott, J. (2005). Visual security protocol modeling. Paper presented at the New Security Paradigms Workshop.","DOI":"10.21236\/ADA464079"},{"key":"jsse.2011100104-31","author":"G.McGraw","year":"2006","journal-title":"Software security: Building security"},{"key":"jsse.2011100104-32","doi-asserted-by":"crossref","unstructured":"Moebius, N., Stenzel, K., Grandy, H., & Reif, W. (2009a). Model-driven code generation for secure smart card applications. In Proceedings of the Australian Software Engineering Conference.","DOI":"10.1109\/ASWEC.2009.15"},{"key":"jsse.2011100104-33","doi-asserted-by":"crossref","unstructured":"Moebius, N., Stenzel, K., Grandy, H., & Reif, W. (2009b). SecureMDD: A model-driven development method for secure smart card applications. In Proceedings of the International Conference on Availability, Reliability and Security.","DOI":"10.1109\/ARES.2009.22"},{"key":"jsse.2011100104-34","doi-asserted-by":"crossref","unstructured":"Moebius, N., Stenzel, K., & Reif, W. (2009). Generating formal specifications for security-critical applications - A model-driven approach. In Proceedings of the ICSE Workshop on Software Engineering for Secure Systems (pp. 68-74).","DOI":"10.1109\/IWSESS.2009.5068461"},{"key":"jsse.2011100104-35","unstructured":"OMG. (2010). Executive overview - Model driven architecture. Retrieved September, 2011, from http:\/\/www.omg.org\/mda\/executive_overview.htm"},{"key":"jsse.2011100104-36","unstructured":"OWASP. (2011). Category: OWASP top ten project. Retrieved from http:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_Project"},{"key":"jsse.2011100104-37","doi-asserted-by":"crossref","unstructured":"Rodriguez, A., Fernandez-Medina, E., & Piattini, M. (2006). Security requirement with a UML 2.0 profile. In Proceedings of the 1st International Conference on Availability, Reliability and Security.","DOI":"10.1109\/ARES.2006.125"},{"key":"jsse.2011100104-38","unstructured":"Rodriguez, A., Fernandez-Medina, E., & Piattini, M. (2006). Towards a UML 2.0 extension for the modeling of security requirements in business processes. In S. Fischer-H\u00fcbner, S. Furnell, & C. Lambrinoudakis (Eds.), Proceedings of the 3rd International Conference on Trust and Privacy in Digital Business (LNCS 4083, pp. 51-61)."},{"key":"jsse.2011100104-39","doi-asserted-by":"crossref","unstructured":"Rodriguez, A., Fernandez-Medina, E., & Piattini, M. (2007). Towards CIM to PIM transformation: From secure business processes defined in BPMN to use-cases. In G. Alonso, P. Dadam, & M. Rosemann (Eds.), Proceedings of the 5th International Conference on Business Process Management (LNCS 4714, pp. 408-415).","DOI":"10.1007\/978-3-540-75183-0_30"},{"key":"jsse.2011100104-40","doi-asserted-by":"crossref","unstructured":"Rodriguez, A., Fernandez-Medina, E., & Piattini, M. (2008). CIM to PIM transformation: A reality. In Proceedings of the IFIP TC 8 WG 8.9 International Conference on Research and Practical Issues of Enterprise Information Systems II (Vol. 255, pp. 1239-1249).","DOI":"10.1007\/978-0-387-76312-5_50"},{"key":"jsse.2011100104-41","doi-asserted-by":"crossref","unstructured":"Soler, E. TruJillo, J., Fernandez-Medina, E., & Piattini, M. (2007a). Application of QVT for the development of secure data warehouses: A case study. In Proceedings of the 2nd International Conference on Availability, Reliability and Security (pp. 829-836).","DOI":"10.1109\/ARES.2007.39"},{"key":"jsse.2011100104-42","doi-asserted-by":"crossref","unstructured":"Soler, E., Stefanov, V., Mazon, J.-N., Trujillo, J., Fernandez-Madina, E., & Piattini, M. (2008). Towards comprehensive requirement analysis for data warehouses: Considering security requirements. In Proceedings of the 3rd International Conference on Availability, Reliability and Security (pp. 104-111).","DOI":"10.1109\/ARES.2008.86"},{"issue":"8","key":"jsse.2011100104-43","first-page":"1607","article-title":"Designing secure data warehouses by using MDA and QVT.","volume":"15","author":"E.Soler","year":"2009","journal-title":"Journal of Universal Computer Science"},{"key":"jsse.2011100104-44","doi-asserted-by":"crossref","unstructured":"Soler, E., Trujillo, J., Fernandez-Medina, E., & Piattini, M. (2007b). A framework for the development of secure data warehouses based on MDA and QVT. In Proceedings of the 2nd International Conference on Availability, Reliability and Security (pp. 294-300).","DOI":"10.1109\/ARES.2007.4"},{"key":"jsse.2011100104-45","doi-asserted-by":"crossref","unstructured":"Soler, E., Trujillo, J., Fernandez-Medina, E., & Piattini, M. (2007c). A set of QVT relations to transform PIM to PSM in the design of secure data warehouses. In Proceedings of the 2nd International Conference on Availability, Reliability and Security (pp. 644-654).","DOI":"10.1109\/ARES.2007.27"},{"key":"jsse.2011100104-46","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2008.19"},{"key":"jsse.2011100104-47","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2008.12.003"},{"key":"jsse.2011100104-48","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2008.09.040"},{"key":"jsse.2011100104-49","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2005.118"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=61153","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,19]],"date-time":"2019-06-19T12:21:11Z","timestamp":1560946871000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jsse.2011100104"}},"subtitle":["A Survey on Security in Model Driven Development"],"short-title":[],"issued":{"date-parts":[[2011,10]]},"references-count":50,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.4018\/jsse.2011100104","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2011,10]]}}}