{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T16:35:30Z","timestamp":1781109330232,"version":"3.54.1"},"reference-count":55,"publisher":"IGI Global Scientific Publishing","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012,4]]},"abstract":"<jats:p>Understanding the social engineering threat is important in requirements engineering for security-critical information systems. Mal-activity diagrams have been proposed as being better than misuse cases for this purpose, but without any empirical testing. The research question in this study is whether mal-activity diagrams would be more efficient than misuse cases for understanding social engineering attacks and finding prevention measures. After a conceptual comparison of the modelling techniques, a controlled experiment is presented, comparing the efficiency of using the two techniques together with textual descriptions of social engineering attacks. The results were fairly equal, the only significant difference being a slight advantage for mal-activity diagrams concerning perceived ease of use. The study gives new insights into the relative merits of the two techniques, and suggests that the advantage of mal-activity diagrams is smaller than previously assumed. However, more empirical investigations are needed to make detailed conclusions.<\/jats:p>","DOI":"10.4018\/jsse.2012040103","type":"journal-article","created":{"date-parts":[[2012,5,16]],"date-time":"2012-05-16T09:58:38Z","timestamp":1337162318000},"page":"54-73","source":"Crossref","is-referenced-by-count":7,"title":["Comparing Misuse Case and Mal-Activity Diagrams for Modelling Social Engineering Attacks"],"prefix":"10.4018","volume":"3","author":[{"given":"Peter","family":"Karpati","sequence":"first","affiliation":[{"name":"Norwegian University of Science and Technology, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guttorm","family":"Sindre","sequence":"additional","affiliation":[{"name":"Norwegian University of Science and Technology, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Raimundas","family":"Matulevicius","sequence":"additional","affiliation":[{"name":"Institute of Computer Science, University of Tartu, Estonia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jsse.2012040103-0","doi-asserted-by":"publisher","DOI":"10.1016\/j.techsoc.2010.07.001"},{"key":"jsse.2012040103-1","doi-asserted-by":"crossref","DOI":"10.21236\/ADA634140","author":"C. J.Alberts","year":"2001","journal-title":"OCTAVE method implementation guide version 2.0"},{"key":"jsse.2012040103-2","doi-asserted-by":"crossref","unstructured":"Alexander, I. F. (2002). Initial industrial experience of misuse cases in trade-off analysis. In In Proceedings of the IEEE Joint International Requirements Engineering Conference, Essen, Germany (pp. 61-68).","DOI":"10.1109\/ICRE.2002.1048506"},{"key":"jsse.2012040103-3","doi-asserted-by":"publisher","DOI":"10.1016\/j.compind.2009.10.013"},{"key":"jsse.2012040103-4","doi-asserted-by":"publisher","DOI":"10.1142\/9781860946066_0003"},{"key":"jsse.2012040103-5","doi-asserted-by":"publisher","DOI":"10.1007\/s10550-007-0013-9"},{"key":"jsse.2012040103-6","unstructured":"Broadleaf Capital International. (2004). The Australia and New Zealand standard on risk management (Tech. Rep. No. AS\/NZS 4360). Retrieved from http:\/\/www.ucop.edu\/riskmgt\/erm\/documents\/asnzs4360_2004_tut_notes.pdf"},{"key":"jsse.2012040103-7","volume":"Vol. 3","author":"M.Bunge","year":"1977","journal-title":"Ontology I: The furniture of the world"},{"key":"jsse.2012040103-8","volume":"Vol. 4","author":"M.Bunge","year":"1979","journal-title":"Ontology II: A world of systems"},{"key":"jsse.2012040103-9","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-009-9109-9"},{"key":"jsse.2012040103-10","unstructured":"Chowdhury, M. J. M. (2011). Modelling security risks at the system design stage: Alignment of mal activity diagrams and SecureUML to the ISSRM domain model (Unpublished master\u2019s thesis). University of Tartu, Tartu, Estonia."},{"key":"jsse.2012040103-11","unstructured":"CLUSIF. (2007). Risk Management - Concepts and mechanisms. Retrieved from http:\/\/www.clusif.asso.fr\/fr\/production\/ouvrages\/pdf\/CLUSIF-risk-management.pdf"},{"key":"jsse.2012040103-12","author":"J.Cohen","year":"1988","journal-title":"Statistical power analysis for the behavioural sciences"},{"key":"jsse.2012040103-13","unstructured":"Common Criteria. (2005). Common criteria for information technology security evaluation, version 2.3 (CCMB-2005-08-002). Retrieved from http:\/\/www.tse.org.tr\/turkish\/belgelendirme\/ortakkriter\/ccpart2v2.3.pdf"},{"key":"jsse.2012040103-14","doi-asserted-by":"publisher","DOI":"10.2307\/249008"},{"key":"jsse.2012040103-15","unstructured":"DCSSI. (2004). EBIOS - Expression of needs and identification of security objectives. Retrieved from http:\/\/www.ssi.gouv.fr\/archive\/en\/confidence\/ebiospresentation.html"},{"key":"jsse.2012040103-16","unstructured":"Diallo, M., Mariona-Romero, J., Sim, S. E., & Richardson, D. J. (2006). A comparative evaluation of three approaches to specifying security requirements. In Proceedings of the Twelfth Working Conference Requirements Engineering: Foundation for Software Quality."},{"key":"jsse.2012040103-17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-12544-7_16"},{"key":"jsse.2012040103-18","unstructured":"Firesmith, D. G. (2007). Engineering safety and security related requirements for software intensive systems. In Proceedings of the Companion to the Proceedings of the 29th International Conference on Software Engineering (p. 169)."},{"key":"jsse.2012040103-19","unstructured":"Gallagher, K. P., & Gallagher, V. C. (2010). The state of IT security: Policies, procedures and practices. Paper presented at 1st Security Conference \u2013 Europe, \u00d6rebro, Sweden."},{"key":"jsse.2012040103-20","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2007.70754"},{"key":"jsse.2012040103-21","unstructured":"Haley, C. B., Moffett, J. D., Laney, R., & Nuseibeh, B. (2005). Arguing security: Validating security requirements using structured argumentation. In Proceedings of the 3rd Symposium on Requirements Engineering for Information Security, Paris, France."},{"key":"jsse.2012040103-22","author":"W. G.Hopkins","year":"2001","journal-title":"A new view of statistics"},{"key":"jsse.2012040103-23","doi-asserted-by":"publisher","DOI":"10.1023\/A:1026586415054"},{"key":"jsse.2012040103-24","year":"2003","journal-title":"CRAMM (CCTA Risk Analysis and Management Method) user guide version 5.0. Walton-on-Thames"},{"key":"jsse.2012040103-25","year":"2002","journal-title":"ISO\/IEC guide 73: Risk management - Vocabulary - Guidelines for use in standards"},{"key":"jsse.2012040103-26","year":"2005","journal-title":"ISO\/IEC 27001: Information technology - Security techniques - Information security management systems - Requirements"},{"key":"jsse.2012040103-27","doi-asserted-by":"crossref","unstructured":"Jensen, J., T\u00f8ndel, I., & Meland, P. H. (2010). Experimental threat model reuse with misuse case diagrams. In M. Soriano, S. Qing, & J. L\u00f3pez (Eds.), Proceedings of the 12th International Conference on Information and Communications Security (LNCS 6476, pp. 355-366).","DOI":"10.1007\/978-3-642-17650-0_25"},{"key":"jsse.2012040103-28","author":"J.J\u00fcrjens","year":"2004","journal-title":"Secure systems development with UML"},{"key":"jsse.2012040103-29","doi-asserted-by":"crossref","unstructured":"Karpati, P., Opdahl, A. L., & Sindre, G. (2010). Illustrating cyber attacks with misuse case maps. In Proceedings of the 16th International Working Conference on Requirements Engineering: Foundation for Software Quality (pp. 262-275).","DOI":"10.1007\/978-3-642-14192-8_24"},{"key":"jsse.2012040103-30","unstructured":"Karpati, P., Sindre, G., & Opdahl, A. L. (2010). Towards a hacker attack representation method. In Proceedings of the 5th International Conference on Software and Data Technologies (pp. 92-101)."},{"key":"jsse.2012040103-31","unstructured":"Lamsweerde, A., Brohez, S., Landtsheer, R., & Janssens, D. (2003). From system goals to intruder anti-goals: Attack generation and resolution for security requirements engineering. In Proceedings of the 2nd International Workshop on Requirements Engineering for High Assurance Systems (pp. 49-56)."},{"key":"jsse.2012040103-32","doi-asserted-by":"crossref","unstructured":"Liu, L., Yu, E., & Mylopoulos, J. (2003). Security and privacy requirements analysis within a social setting. In Proceedings of the 11th International Requirements Engineering Conference (pp. 151-161).","DOI":"10.1109\/ICRE.2003.1232746"},{"key":"jsse.2012040103-33","doi-asserted-by":"crossref","unstructured":"Lodderstedt, T., Basin, D., & Doser, J. (2002). SecureUML: A UML-based modelling language for model-driven security. In Proceedings of the 5th International Conference on Unified Modelling Language (pp. 426-441).","DOI":"10.1007\/3-540-45800-X_33"},{"key":"jsse.2012040103-34","doi-asserted-by":"crossref","unstructured":"Matulevi\u010dius, R., Mayer, N., & Heymans, P. (2008). Alignment of misuse cases with security risk management. In Proceedings of the 3rd International Conference on Availability, Reliability and Security.","DOI":"10.1109\/ARES.2008.88"},{"key":"jsse.2012040103-35","unstructured":"Matulevi\u010dius, R., Mayer, N., Mouratidis, H., Dubois, E., Heymans, P., & Genon, N. (2008). Adapting secure tropos for security risk management during early phases of the information systems development. In Proceedings of the International Conference on Advanced Information Systems Engineerin, (pp. 541-555)."},{"key":"jsse.2012040103-36","unstructured":"Mayer, N. (2009). Model-based management of information system security risk (Unpublished doctoral dissertation). University of Namur, Namur, Belgium."},{"key":"jsse.2012040103-37","doi-asserted-by":"crossref","unstructured":"McDermott, J., & Fox, C. (1999). Using abuse case models for security requirements analysis. In Proceedings of the 15th Annual Computer Security Applications Conference.","DOI":"10.1109\/CSAC.1999.816013"},{"key":"jsse.2012040103-38","author":"K. D.Mitnick","year":"2002","journal-title":"The art of deception: Controlling the human element of security"},{"key":"jsse.2012040103-39","doi-asserted-by":"publisher","DOI":"10.1142\/S0218194007003240"},{"key":"jsse.2012040103-40","unstructured":"Northcutt, S. (2011). Sec Lab: Predictions and trends for information, computer and network security. Retrieved January 28, 2011, from http:\/\/www.sans.edu\/research\/security-laboratory\/article\/northcuttpredict2012"},{"key":"jsse.2012040103-41","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2008.05.013"},{"key":"jsse.2012040103-42","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(06)70433-X"},{"key":"jsse.2012040103-43","unstructured":"Runeson, P. (2003). Using students as experiment subjects \u2013 An analysis on graduate and freshmen student data. In Proceedings of the 7th International Conference on Empirical Assessment & Evaluation in Software Engineering, Staffordshire, UK (pp. 95-102)."},{"key":"jsse.2012040103-44","doi-asserted-by":"crossref","unstructured":"Sindre, G. (2007). Mal-activity diagrams for capturing attacks on business processes. In Proceedings of the International Working Conference on Requirements Engineering: Foundations for Software Quality (pp. 252-266).","DOI":"10.1007\/978-3-540-73031-6_27"},{"key":"jsse.2012040103-45","unstructured":"Sindre, G., Firesmith, D., & Opdahl, A. L. (2003). A reuse-based approach to determining security requirements. In Proceedings of the 9th International Workshop Requirements Engineering: Foundation for Software Quality."},{"key":"jsse.2012040103-46","unstructured":"Sindre, G., & Opdahl, A. L. (2001). Template for misuse case description. In Proceedings of the International Workshop Requirements Engineering: Foundation for Software Quality, Essen, Germany (pp. 125-136)."},{"key":"jsse.2012040103-47","doi-asserted-by":"publisher","DOI":"10.1007\/s00766-004-0194-4"},{"key":"jsse.2012040103-48","author":"G.Stoneburner","year":"2002","journal-title":"Risk management guide for information technology systems (NIST Special Publication No. 800-30)"},{"key":"jsse.2012040103-49","doi-asserted-by":"crossref","unstructured":"Sundaram, D., & Rohde, M. E. (2010). Mal-processes: Explicitly modelling the deviant. In J. Proceedings of the 6th International Workshop on Enterprise and Organizational Modelling and Simulation (pp. 164-178).","DOI":"10.1007\/978-3-642-15723-3_11"},{"key":"jsse.2012040103-50","doi-asserted-by":"crossref","unstructured":"Svahnberg, M., Aurum, A., & Wohlin, C. (2008). Using students as subjects - an empirical evaluation. In Proceedings of the Second ACM-IEEE international symposium on Empirical software engineering and measurement (pp. 288-29).","DOI":"10.1145\/1414004.1414055"},{"key":"jsse.2012040103-51","unstructured":"Taylor, C., & Garrett, N. (2007). Social engineering: Where's the research. In Proceedings of the Twenty-Third Annual Computer Security Applications Conference."},{"key":"jsse.2012040103-52","doi-asserted-by":"publisher","DOI":"10.1016\/S1754-4548(10)70068-1"},{"key":"jsse.2012040103-53","doi-asserted-by":"publisher","DOI":"10.1111\/j.1365-2575.1993.tb00127.x"},{"key":"jsse.2012040103-54","doi-asserted-by":"publisher","DOI":"10.1111\/j.1365-2575.1995.tb00108.x"}],"container-title":["International Journal of Secure Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=66408","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,6,28]],"date-time":"2019-06-28T16:12:52Z","timestamp":1561738372000},"score":1,"resource":{"primary":{"URL":"http:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jsse.2012040103"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2012,4]]},"references-count":55,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.4018\/jsse.2012040103","relation":{},"ISSN":["1947-3036","1947-3044"],"issn-type":[{"value":"1947-3036","type":"print"},{"value":"1947-3044","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,4]]}}}