[{"publication_status":"published","date_updated":"2026-03-31T13:53:55Z","author":[{"id":"49934","full_name":"Trentinaglia, Roman","first_name":"Roman","orcid":"0000-0001-9728-4991","last_name":"Trentinaglia"},{"id":"13616","first_name":"Thorsten","last_name":"Koch","full_name":"Koch, Thorsten"},{"id":"59256","full_name":"Bodden, Eric","first_name":"Eric","last_name":"Bodden","orcid":"0000-0003-3470-3647"}],"title":"Using Attack and Failure Propagation Analysis for Context-Aware Security Control Suggestions","status":"public","year":"2026","user_id":"49934","doi":"10.5220/0014278000004058","_id":"65261","publisher":"SCITEPRESS - Science and Technology Publications","language":[{"iso":"eng"}],"citation":{"chicago":"Trentinaglia, Roman, Thorsten Koch, and Eric Bodden. “Using Attack and Failure Propagation Analysis for Context-Aware Security Control Suggestions.” In <i>Proceedings of the 14th International Conference on Model-Based Software and Systems Engineering</i>. SCITEPRESS - Science and Technology Publications, 2026. <a href=\"https://doi.org/10.5220/0014278000004058\">https://doi.org/10.5220/0014278000004058</a>.","short":"R. Trentinaglia, T. Koch, E. Bodden, in: Proceedings of the 14th International Conference on Model-Based Software and Systems Engineering, SCITEPRESS - Science and Technology Publications, 2026.","ama":"Trentinaglia R, Koch T, Bodden E. Using Attack and Failure Propagation Analysis for Context-Aware Security Control Suggestions. In: <i>Proceedings of the 14th International Conference on Model-Based Software and Systems Engineering</i>. SCITEPRESS - Science and Technology Publications; 2026. doi:<a href=\"https://doi.org/10.5220/0014278000004058\">10.5220/0014278000004058</a>","bibtex":"@inproceedings{Trentinaglia_Koch_Bodden_2026, title={Using Attack and Failure Propagation Analysis for Context-Aware Security Control Suggestions}, DOI={<a href=\"https://doi.org/10.5220/0014278000004058\">10.5220/0014278000004058</a>}, booktitle={Proceedings of the 14th International Conference on Model-Based Software and Systems Engineering}, publisher={SCITEPRESS - Science and Technology Publications}, author={Trentinaglia, Roman and Koch, Thorsten and Bodden, Eric}, year={2026} }","apa":"Trentinaglia, R., Koch, T., &#38; Bodden, E. (2026). Using Attack and Failure Propagation Analysis for Context-Aware Security Control Suggestions. <i>Proceedings of the 14th International Conference on Model-Based Software and Systems Engineering</i>. <a href=\"https://doi.org/10.5220/0014278000004058\">https://doi.org/10.5220/0014278000004058</a>","mla":"Trentinaglia, Roman, et al. “Using Attack and Failure Propagation Analysis for Context-Aware Security Control Suggestions.” <i>Proceedings of the 14th International Conference on Model-Based Software and Systems Engineering</i>, SCITEPRESS - Science and Technology Publications, 2026, doi:<a href=\"https://doi.org/10.5220/0014278000004058\">10.5220/0014278000004058</a>.","ieee":"R. Trentinaglia, T. Koch, and E. Bodden, “Using Attack and Failure Propagation Analysis for Context-Aware Security Control Suggestions,” 2026, doi: <a href=\"https://doi.org/10.5220/0014278000004058\">10.5220/0014278000004058</a>."},"publication":"Proceedings of the 14th International Conference on Model-Based Software and Systems Engineering","department":[{"_id":"241"},{"_id":"662"}],"type":"conference","date_created":"2026-03-31T13:52:36Z"},{"status":"public","publisher":"Association for Computing Machinery (ACM)","_id":"61546","page":"527-549","volume":2,"user_id":"15249","citation":{"ama":"Miao M, Kummita S, Bodden E, Wei S. Program Feature-Based Benchmarking for Fuzz Testing. <i>Proceedings of the ACM on Software Engineering</i>. 2025;2(ISSTA):527-549. doi:<a href=\"https://doi.org/10.1145/3728899\">10.1145/3728899</a>","bibtex":"@article{Miao_Kummita_Bodden_Wei_2025, title={Program Feature-Based Benchmarking for Fuzz Testing}, volume={2}, DOI={<a href=\"https://doi.org/10.1145/3728899\">10.1145/3728899</a>}, number={ISSTA}, journal={Proceedings of the ACM on Software Engineering}, publisher={Association for Computing Machinery (ACM)}, author={Miao, Miao and Kummita, Sriteja and Bodden, Eric and Wei, Shiyi}, year={2025}, pages={527–549} }","mla":"Miao, Miao, et al. “Program Feature-Based Benchmarking for Fuzz Testing.” <i>Proceedings of the ACM on Software Engineering</i>, vol. 2, no. ISSTA, Association for Computing Machinery (ACM), 2025, pp. 527–49, doi:<a href=\"https://doi.org/10.1145/3728899\">10.1145/3728899</a>.","short":"M. Miao, S. Kummita, E. Bodden, S. Wei, Proceedings of the ACM on Software Engineering 2 (2025) 527–549.","chicago":"Miao, Miao, Sriteja Kummita, Eric Bodden, and Shiyi Wei. “Program Feature-Based Benchmarking for Fuzz Testing.” <i>Proceedings of the ACM on Software Engineering</i> 2, no. ISSTA (2025): 527–49. <a href=\"https://doi.org/10.1145/3728899\">https://doi.org/10.1145/3728899</a>.","apa":"Miao, M., Kummita, S., Bodden, E., &#38; Wei, S. (2025). Program Feature-Based Benchmarking for Fuzz Testing. <i>Proceedings of the ACM on Software Engineering</i>, <i>2</i>(ISSTA), 527–549. <a href=\"https://doi.org/10.1145/3728899\">https://doi.org/10.1145/3728899</a>","ieee":"M. Miao, S. Kummita, E. Bodden, and S. Wei, “Program Feature-Based Benchmarking for Fuzz Testing,” <i>Proceedings of the ACM on Software Engineering</i>, vol. 2, no. ISSTA, pp. 527–549, 2025, doi: <a href=\"https://doi.org/10.1145/3728899\">10.1145/3728899</a>."},"publication_identifier":{"issn":["2994-970X"]},"author":[{"full_name":"Miao, Miao","first_name":"Miao","last_name":"Miao"},{"last_name":"Kummita","first_name":"Sriteja","full_name":"Kummita, Sriteja","id":"72582"},{"last_name":"Bodden","first_name":"Eric","orcid":"0000-0003-3470-3647","full_name":"Bodden, Eric","id":"59256"},{"first_name":"Shiyi","last_name":"Wei","full_name":"Wei, Shiyi"}],"title":"Program Feature-Based Benchmarking for Fuzz Testing","year":"2025","intvolume":"         2","date_updated":"2025-10-08T08:32:57Z","publication_status":"published","language":[{"iso":"eng"}],"doi":"10.1145/3728899","issue":"ISSTA","publication":"Proceedings of the ACM on Software Engineering","abstract":[{"text":"<jats:p>Fuzzing is a powerful software testing technique renowned for its effectiveness in identifying software vulnerabilities. Traditional fuzzing evaluations typically focus on overall fuzzer performance across a set of target programs, yet few benchmarks consider how fine-grained program features influence fuzzing effectiveness. To bridge this gap, we introduce FeatureBench, a novel benchmark designed to generate programs with configurable, fine-grained program features to enhance fuzzing evaluations. We reviewed 25 recent grey-box fuzzing studies, extracting 7 program features related to control-flow and data-flow that can impact fuzzer performance. Using these features, we generated a benchmark consisting of 153 programs controlled by 10 fine-grained configurable parameters. We evaluated 11 fuzzers using this benchmark, with each fuzzer representing either distinct claimed improvements or serving as a widely used baseline in fuzzing evaluations. The results indicate that fuzzer performance varies significantly based on the program features and their strengths, highlighting the importance of incorporating program characteristics into fuzzing evaluations.</jats:p>","lang":"eng"}],"date_created":"2025-10-08T08:29:39Z","department":[{"_id":"76"},{"_id":"662"}],"type":"journal_article"},{"abstract":[{"lang":"eng","text":"<jats:p>Assessing and communicating software security has become a crucial concern in the era of digital transformation. As software systems grow more complex and interconnected, it becomes increasingly challenging to effectively evaluate and communicate a product's security status to both technical and non-technical stakeholders. The Software Product Health Assistant (SPHA) is designed to automatically collect and aggregate data from existing expert tools and derive, among other scores, a transparent Security Score. SPHA is designed to present and explain this Security Score to decision-makers to support their responsibilities. In this paper, we demonstrate how to integrate data from SMARAGD (System Modeler for Architectural Risk Assessment and Guidance on Defenses), a safety-informed threat modeling tool, into SPHA to enhance the existing definition of its Security Score. To achieve this, we combine information about known vulnerabilities with architectural and threat data to calculate a realistic risk score for the product in question.</jats:p>"}],"citation":{"chicago":"Strüwer, Jan-niclas, Roman Trentinaglia, Benedict Wohlers, Eric Bodden, and Roman Dumitrescu. “Assessing and Communicating Software Security: Enhancing Software Product Health with Architectural Threat Analysis.” In <i>AHFE International</i>, Vol. 168. AHFE International, 2025. <a href=\"https://doi.org/10.54941/ahfe1006145\">https://doi.org/10.54941/ahfe1006145</a>.","short":"J. Strüwer, R. Trentinaglia, B. Wohlers, E. Bodden, R. Dumitrescu, in: AHFE International, AHFE International, 2025.","ieee":"J. Strüwer, R. Trentinaglia, B. Wohlers, E. Bodden, and R. Dumitrescu, “Assessing and Communicating Software Security: Enhancing Software Product Health with Architectural Threat Analysis,” in <i>AHFE International</i>, 2025, vol. 168, doi: <a href=\"https://doi.org/10.54941/ahfe1006145\">10.54941/ahfe1006145</a>.","apa":"Strüwer, J., Trentinaglia, R., Wohlers, B., Bodden, E., &#38; Dumitrescu, R. (2025). Assessing and Communicating Software Security: Enhancing Software Product Health with Architectural Threat Analysis. <i>AHFE International</i>, <i>168</i>. <a href=\"https://doi.org/10.54941/ahfe1006145\">https://doi.org/10.54941/ahfe1006145</a>","bibtex":"@inproceedings{Strüwer_Trentinaglia_Wohlers_Bodden_Dumitrescu_2025, title={Assessing and Communicating Software Security: Enhancing Software Product Health with Architectural Threat Analysis}, volume={168}, DOI={<a href=\"https://doi.org/10.54941/ahfe1006145\">10.54941/ahfe1006145</a>}, booktitle={AHFE International}, publisher={AHFE International}, author={Strüwer, Jan-niclas and Trentinaglia, Roman and Wohlers, Benedict and Bodden, Eric and Dumitrescu, Roman}, year={2025} }","ama":"Strüwer J, Trentinaglia R, Wohlers B, Bodden E, Dumitrescu R. Assessing and Communicating Software Security: Enhancing Software Product Health with Architectural Threat Analysis. In: <i>AHFE International</i>. Vol 168. AHFE International; 2025. doi:<a href=\"https://doi.org/10.54941/ahfe1006145\">10.54941/ahfe1006145</a>","mla":"Strüwer, Jan-niclas, et al. “Assessing and Communicating Software Security: Enhancing Software Product Health with Architectural Threat Analysis.” <i>AHFE International</i>, vol. 168, AHFE International, 2025, doi:<a href=\"https://doi.org/10.54941/ahfe1006145\">10.54941/ahfe1006145</a>."},"publication":"AHFE International","department":[{"_id":"241"},{"_id":"662"}],"type":"conference","date_created":"2025-07-10T06:37:42Z","intvolume":"       168","date_updated":"2025-07-10T06:39:03Z","publication_status":"published","author":[{"full_name":"Strüwer, Jan-niclas","last_name":"Strüwer","first_name":"Jan-niclas"},{"id":"49934","last_name":"Trentinaglia","orcid":"0000-0001-9728-4991","first_name":"Roman","full_name":"Trentinaglia, Roman"},{"id":"53786","full_name":"Wohlers, Benedict","first_name":"Benedict","last_name":"Wohlers"},{"id":"59256","full_name":"Bodden, Eric","last_name":"Bodden","first_name":"Eric","orcid":"0000-0003-3470-3647"},{"id":"16190","last_name":"Dumitrescu","first_name":"Roman","full_name":"Dumitrescu, Roman"}],"publication_identifier":{"issn":["2771-0718"]},"title":"Assessing and Communicating Software Security: Enhancing Software Product Health with Architectural Threat Analysis","status":"public","year":"2025","volume":168,"doi":"10.54941/ahfe1006145","user_id":"49934","_id":"60583","publisher":"AHFE International","language":[{"iso":"eng"}]},{"publisher":"Springer Nature Switzerland","_id":"63854","language":[{"iso":"eng"}],"doi":"10.1007/978-3-031-82362-6_25","user_id":"29279","title":"Enabling Android Application Monitoring by Characterizing Security-Critical Code Fragments","status":"public","year":"2025","publication_identifier":{"issn":["0302-9743","1611-3349"],"isbn":["9783031823619","9783031823626"]},"author":[{"first_name":"Hendrik","last_name":"Eikerling","full_name":"Eikerling, Hendrik"},{"first_name":"Anemone","last_name":"Kampkötter","full_name":"Kampkötter, Anemone"}],"date_updated":"2026-03-16T09:03:52Z","publication_status":"published","place":"Cham","date_created":"2026-02-03T23:17:33Z","type":"conference","department":[{"_id":"241"},{"_id":"662"}],"publication":"Lecture Notes in Computer Science","citation":{"mla":"Eikerling, Hendrik, and Anemone Kampkötter. “Enabling Android Application Monitoring by Characterizing Security-Critical Code Fragments.” <i>Lecture Notes in Computer Science</i>, Springer Nature Switzerland, 2025, doi:<a href=\"https://doi.org/10.1007/978-3-031-82362-6_25\">10.1007/978-3-031-82362-6_25</a>.","bibtex":"@inproceedings{Eikerling_Kampkötter_2025, place={Cham}, title={Enabling Android Application Monitoring by Characterizing Security-Critical Code Fragments}, DOI={<a href=\"https://doi.org/10.1007/978-3-031-82362-6_25\">10.1007/978-3-031-82362-6_25</a>}, booktitle={Lecture Notes in Computer Science}, publisher={Springer Nature Switzerland}, author={Eikerling, Hendrik and Kampkötter, Anemone}, year={2025} }","ama":"Eikerling H, Kampkötter A. Enabling Android Application Monitoring by Characterizing Security-Critical Code Fragments. In: <i>Lecture Notes in Computer Science</i>. Springer Nature Switzerland; 2025. doi:<a href=\"https://doi.org/10.1007/978-3-031-82362-6_25\">10.1007/978-3-031-82362-6_25</a>","ieee":"H. Eikerling and A. Kampkötter, “Enabling Android Application Monitoring by Characterizing Security-Critical Code Fragments,” 2025, doi: <a href=\"https://doi.org/10.1007/978-3-031-82362-6_25\">10.1007/978-3-031-82362-6_25</a>.","apa":"Eikerling, H., &#38; Kampkötter, A. (2025). Enabling Android Application Monitoring by Characterizing Security-Critical Code Fragments. <i>Lecture Notes in Computer Science</i>. <a href=\"https://doi.org/10.1007/978-3-031-82362-6_25\">https://doi.org/10.1007/978-3-031-82362-6_25</a>","chicago":"Eikerling, Hendrik, and Anemone Kampkötter. “Enabling Android Application Monitoring by Characterizing Security-Critical Code Fragments.” In <i>Lecture Notes in Computer Science</i>. Cham: Springer Nature Switzerland, 2025. <a href=\"https://doi.org/10.1007/978-3-031-82362-6_25\">https://doi.org/10.1007/978-3-031-82362-6_25</a>.","short":"H. Eikerling, A. Kampkötter, in: Lecture Notes in Computer Science, Springer Nature Switzerland, Cham, 2025."}},{"date_updated":"2024-05-06T11:47:14Z","status":"public","title":"Detecting Security-Relevant Methods using Multi-label Machine Learning","year":"2024","author":[{"full_name":"Johnson, Oshando","first_name":"Oshando","last_name":"Johnson","id":"66583"},{"id":"41936","full_name":"Piskachev, Goran","orcid":"0000-0003-4424-5838","first_name":"Goran","last_name":"Piskachev"},{"id":"78060","orcid":"0000-0002-0906-5463","last_name":"Krishnamurthy","first_name":"Ranjith","full_name":"Krishnamurthy, Ranjith"},{"orcid":"0000-0003-3470-3647","first_name":"Eric","last_name":"Bodden","full_name":"Bodden, Eric","id":"59256"}],"user_id":"15249","doi":"10.48550/ARXIV.2403.07501","language":[{"iso":"eng"}],"_id":"53958","abstract":[{"lang":"eng","text":"To detect security vulnerabilities, static analysis tools need to be configured with security-relevant methods. Current approaches can automatically identify such methods using binary relevance machine learning approaches. However, they ignore dependencies among security-relevant methods, over-generalize and perform poorly in practice. Additionally, users have to nevertheless manually configure static analysis tools using the detected methods. Based on feedback from users and our observations, the excessive manual steps can often be tedious, error-prone and counter-intuitive.\r\n In this paper, we present Dev-Assist, an IntelliJ IDEA plugin that detects security-relevant methods using a multi-label machine learning approach that considers dependencies among labels. The plugin can automatically generate configurations for static analysis tools, run the static analysis, and show the results in IntelliJ IDEA. Our experiments reveal that Dev-Assist's machine learning approach has a higher F1-Measure than related approaches. Moreover, the plugin reduces and simplifies the manual effort required when configuring and using static analysis tools."}],"publication":"Proceedings of the 46th International Conference on Software Engineering, IDE Workshop","citation":{"ieee":"O. Johnson, G. Piskachev, R. Krishnamurthy, and E. Bodden, “Detecting Security-Relevant Methods using Multi-label Machine Learning,” 2024, doi: <a href=\"https://doi.org/10.48550/ARXIV.2403.07501\">10.48550/ARXIV.2403.07501</a>.","apa":"Johnson, O., Piskachev, G., Krishnamurthy, R., &#38; Bodden, E. (2024). Detecting Security-Relevant Methods using Multi-label Machine Learning. <i>Proceedings of the 46th International Conference on Software Engineering, IDE Workshop</i>. <a href=\"https://doi.org/10.48550/ARXIV.2403.07501\">https://doi.org/10.48550/ARXIV.2403.07501</a>","short":"O. Johnson, G. Piskachev, R. Krishnamurthy, E. Bodden, in: Proceedings of the 46th International Conference on Software Engineering, IDE Workshop, 2024.","chicago":"Johnson, Oshando, Goran Piskachev, Ranjith Krishnamurthy, and Eric Bodden. “Detecting Security-Relevant Methods Using Multi-Label Machine Learning.” In <i>Proceedings of the 46th International Conference on Software Engineering, IDE Workshop</i>, 2024. <a href=\"https://doi.org/10.48550/ARXIV.2403.07501\">https://doi.org/10.48550/ARXIV.2403.07501</a>.","mla":"Johnson, Oshando, et al. “Detecting Security-Relevant Methods Using Multi-Label Machine Learning.” <i>Proceedings of the 46th International Conference on Software Engineering, IDE Workshop</i>, 2024, doi:<a href=\"https://doi.org/10.48550/ARXIV.2403.07501\">10.48550/ARXIV.2403.07501</a>.","bibtex":"@inproceedings{Johnson_Piskachev_Krishnamurthy_Bodden_2024, title={Detecting Security-Relevant Methods using Multi-label Machine Learning}, DOI={<a href=\"https://doi.org/10.48550/ARXIV.2403.07501\">10.48550/ARXIV.2403.07501</a>}, booktitle={Proceedings of the 46th International Conference on Software Engineering, IDE Workshop}, author={Johnson, Oshando and Piskachev, Goran and Krishnamurthy, Ranjith and Bodden, Eric}, year={2024} }","ama":"Johnson O, Piskachev G, Krishnamurthy R, Bodden E. Detecting Security-Relevant Methods using Multi-label Machine Learning. In: <i>Proceedings of the 46th International Conference on Software Engineering, IDE Workshop</i>. ; 2024. doi:<a href=\"https://doi.org/10.48550/ARXIV.2403.07501\">10.48550/ARXIV.2403.07501</a>"},"type":"conference","department":[{"_id":"76"},{"_id":"662"}],"date_created":"2024-05-06T11:43:19Z"},{"user_id":"49934","main_file_link":[{"url":"https://www.iem.fraunhofer.de/content/dam/iem/dokumente/termine/whitepaper_safety-and-security_06_240527_e-v11.pdf"}],"page":"5","language":[{"iso":"eng"}],"_id":"59601","publisher":"dSPACE GmbH","publication_status":"published","date_updated":"2025-04-16T09:30:29Z","year":"2024","status":"public","title":"Whitepaper: From HARA and TARA to Risk-Based Safety and Security Dependency Testing","author":[{"first_name":"Roman","orcid":"0000-0001-9728-4991","last_name":"Trentinaglia","full_name":"Trentinaglia, Roman","id":"49934"},{"first_name":"Markus","orcid":"0000-0002-1269-0702","last_name":"Fockel","full_name":"Fockel, Markus","id":"8472"},{"first_name":"Matthias","last_name":"Pukrop","full_name":"Pukrop, Matthias"},{"first_name":"Tobias","last_name":"Schaeffer","full_name":"Schaeffer, Tobias"}],"type":"misc","department":[{"_id":"241"},{"_id":"662"}],"date_created":"2025-04-16T09:30:13Z","abstract":[{"text":"Modern vehicles are becoming more connected and autonomous, and more software-defined in general. Such connectivity leads to security risks due to the increased attack surface for external intrusions. In addition, attacks can also lead to safety hazards as cars contain multiple safety-critical components. Therefore both safety and security must be considered in combination. In this whitepaper, we describe a tool-supported analysis method aligned with automotive standards to identify safety and security dependencies and automatically derive corresponding test cases. These test cases can be imported into the existing dSPACE tool chain to improve efficiency by reducing time-consuming manual work and susceptibility to errors. Thereby, our method brings together system design and testing phases to pave the way for an integrated safety and security-by-design life cycle in the automotive domain.","lang":"eng"}],"related_material":{"link":[{"relation":"other","url":"https://www.iem.fraunhofer.de/de/newsroom/presse-und-news/fraunhofer-iem-dspace-veroeffentlichen-whitepaper.html"}]},"citation":{"mla":"Trentinaglia, Roman, et al. <i>Whitepaper: From HARA and TARA to Risk-Based Safety and Security Dependency Testing</i>. dSPACE GmbH, 2024.","ama":"Trentinaglia R, Fockel M, Pukrop M, Schaeffer T. <i>Whitepaper: From HARA and TARA to Risk-Based Safety and Security Dependency Testing</i>. dSPACE GmbH; 2024.","bibtex":"@book{Trentinaglia_Fockel_Pukrop_Schaeffer_2024, title={Whitepaper: From HARA and TARA to Risk-Based Safety and Security Dependency Testing}, publisher={dSPACE GmbH}, author={Trentinaglia, Roman and Fockel, Markus and Pukrop, Matthias and Schaeffer, Tobias}, year={2024} }","apa":"Trentinaglia, R., Fockel, M., Pukrop, M., &#38; Schaeffer, T. (2024). <i>Whitepaper: From HARA and TARA to Risk-Based Safety and Security Dependency Testing</i>. dSPACE GmbH.","ieee":"R. Trentinaglia, M. Fockel, M. Pukrop, and T. Schaeffer, <i>Whitepaper: From HARA and TARA to Risk-Based Safety and Security Dependency Testing</i>. dSPACE GmbH, 2024.","short":"R. Trentinaglia, M. Fockel, M. Pukrop, T. Schaeffer, Whitepaper: From HARA and TARA to Risk-Based Safety and Security Dependency Testing, dSPACE GmbH, 2024.","chicago":"Trentinaglia, Roman, Markus Fockel, Matthias Pukrop, and Tobias Schaeffer. <i>Whitepaper: From HARA and TARA to Risk-Based Safety and Security Dependency Testing</i>. dSPACE GmbH, 2024."}},{"date_created":"2024-12-04T14:55:47Z","type":"conference","department":[{"_id":"241"},{"_id":"662"}],"publication":"22th escar Europe : The World’s Leading Automotive Cyber Security Conference : Embedded Security in Cars (Dortmund, 19. - 20.11.2024)","citation":{"bibtex":"@inproceedings{Trentinaglia_Fockel_Pukrop_Schaeffer_2024, title={Automatically deriving test cases from safety-security dependencies}, DOI={<a href=\"https://doi.org/10.13154/294-12716\">10.13154/294-12716</a>}, booktitle={22th escar Europe : The World’s Leading Automotive Cyber Security Conference : Embedded Security in Cars (Dortmund, 19. - 20.11.2024)}, author={Trentinaglia, Roman and Fockel, Markus and Pukrop, Matthias and Schaeffer, Tobias}, year={2024} }","ama":"Trentinaglia R, Fockel M, Pukrop M, Schaeffer T. Automatically deriving test cases from safety-security dependencies. In: <i>22th Escar Europe : The World’s Leading Automotive Cyber Security Conference : Embedded Security in Cars (Dortmund, 19. - 20.11.2024)</i>. ; 2024. doi:<a href=\"https://doi.org/10.13154/294-12716\">10.13154/294-12716</a>","mla":"Trentinaglia, Roman, et al. “Automatically Deriving Test Cases from Safety-Security Dependencies.” <i>22th Escar Europe : The World’s Leading Automotive Cyber Security Conference : Embedded Security in Cars (Dortmund, 19. - 20.11.2024)</i>, 2024, doi:<a href=\"https://doi.org/10.13154/294-12716\">10.13154/294-12716</a>.","chicago":"Trentinaglia, Roman, Markus Fockel, Matthias Pukrop, and Tobias Schaeffer. “Automatically Deriving Test Cases from Safety-Security Dependencies.” In <i>22th Escar Europe : The World’s Leading Automotive Cyber Security Conference : Embedded Security in Cars (Dortmund, 19. - 20.11.2024)</i>, 2024. <a href=\"https://doi.org/10.13154/294-12716\">https://doi.org/10.13154/294-12716</a>.","short":"R. Trentinaglia, M. Fockel, M. Pukrop, T. Schaeffer, in: 22th Escar Europe : The World’s Leading Automotive Cyber Security Conference : Embedded Security in Cars (Dortmund, 19. - 20.11.2024), 2024.","ieee":"R. Trentinaglia, M. Fockel, M. Pukrop, and T. Schaeffer, “Automatically deriving test cases from safety-security dependencies,” 2024, doi: <a href=\"https://doi.org/10.13154/294-12716\">10.13154/294-12716</a>.","apa":"Trentinaglia, R., Fockel, M., Pukrop, M., &#38; Schaeffer, T. (2024). Automatically deriving test cases from safety-security dependencies. <i>22th Escar Europe : The World’s Leading Automotive Cyber Security Conference : Embedded Security in Cars (Dortmund, 19. - 20.11.2024)</i>. <a href=\"https://doi.org/10.13154/294-12716\">https://doi.org/10.13154/294-12716</a>"},"_id":"57578","language":[{"iso":"eng"}],"doi":"10.13154/294-12716","user_id":"49934","title":"Automatically deriving test cases from safety-security dependencies","year":"2024","status":"public","author":[{"id":"49934","orcid":"0000-0001-9728-4991","first_name":"Roman","last_name":"Trentinaglia","full_name":"Trentinaglia, Roman"},{"id":"8472","orcid":"0000-0002-1269-0702","last_name":"Fockel","first_name":"Markus","full_name":"Fockel, Markus"},{"last_name":"Pukrop","first_name":"Matthias","full_name":"Pukrop, Matthias"},{"full_name":"Schaeffer, Tobias","first_name":"Tobias","last_name":"Schaeffer"}],"date_updated":"2025-05-19T09:31:29Z"},{"citation":{"chicago":"Schiebel, Fabian Benedikt, Florian Sattler, Philipp Dominik Schubert, Sven Apel, and Eric Bodden. “Scaling Interprocedural Static Data-Flow Analysis to Large C/C++ Applications: An Experience Report.” In <i>38th European Conference on Object-Oriented Programming (ECOOP 2024)</i>, edited by Jonathan Aldrich and Guido Salvaneschi, 313:36:1–36:28. Leibniz International Proceedings in Informatics (LIPIcs). Dagstuhl, Germany: Schloss Dagstuhl – Leibniz-Zentrum für Informatik, 2024. <a href=\"https://doi.org/10.4230/LIPIcs.ECOOP.2024.36\">https://doi.org/10.4230/LIPIcs.ECOOP.2024.36</a>.","short":"F.B. Schiebel, F. Sattler, P.D. Schubert, S. Apel, E. Bodden, in: J. Aldrich, G. Salvaneschi (Eds.), 38th European Conference on Object-Oriented Programming (ECOOP 2024), Schloss Dagstuhl – Leibniz-Zentrum für Informatik, Dagstuhl, Germany, 2024, p. 36:1–36:28.","ieee":"F. B. Schiebel, F. Sattler, P. D. Schubert, S. Apel, and E. Bodden, “Scaling Interprocedural Static Data-Flow Analysis to Large C/C++ Applications: An Experience Report,” in <i>38th European Conference on Object-Oriented Programming (ECOOP 2024)</i>, 2024, vol. 313, p. 36:1–36:28, doi: <a href=\"https://doi.org/10.4230/LIPIcs.ECOOP.2024.36\">10.4230/LIPIcs.ECOOP.2024.36</a>.","apa":"Schiebel, F. B., Sattler, F., Schubert, P. D., Apel, S., &#38; Bodden, E. (2024). Scaling Interprocedural Static Data-Flow Analysis to Large C/C++ Applications: An Experience Report. In J. Aldrich &#38; G. Salvaneschi (Eds.), <i>38th European Conference on Object-Oriented Programming (ECOOP 2024)</i> (Vol. 313, p. 36:1–36:28). Schloss Dagstuhl – Leibniz-Zentrum für Informatik. <a href=\"https://doi.org/10.4230/LIPIcs.ECOOP.2024.36\">https://doi.org/10.4230/LIPIcs.ECOOP.2024.36</a>","bibtex":"@inproceedings{Schiebel_Sattler_Schubert_Apel_Bodden_2024, place={Dagstuhl, Germany}, series={Leibniz International Proceedings in Informatics (LIPIcs)}, title={Scaling Interprocedural Static Data-Flow Analysis to Large C/C++ Applications: An Experience Report}, volume={313}, DOI={<a href=\"https://doi.org/10.4230/LIPIcs.ECOOP.2024.36\">10.4230/LIPIcs.ECOOP.2024.36</a>}, booktitle={38th European Conference on Object-Oriented Programming (ECOOP 2024)}, publisher={Schloss Dagstuhl – Leibniz-Zentrum für Informatik}, author={Schiebel, Fabian Benedikt and Sattler, Florian and Schubert, Philipp Dominik and Apel, Sven and Bodden, Eric}, editor={Aldrich, Jonathan and Salvaneschi, Guido}, year={2024}, pages={36:1–36:28}, collection={Leibniz International Proceedings in Informatics (LIPIcs)} }","ama":"Schiebel FB, Sattler F, Schubert PD, Apel S, Bodden E. Scaling Interprocedural Static Data-Flow Analysis to Large C/C++ Applications: An Experience Report. In: Aldrich J, Salvaneschi G, eds. <i>38th European Conference on Object-Oriented Programming (ECOOP 2024)</i>. Vol 313. Leibniz International Proceedings in Informatics (LIPIcs). Schloss Dagstuhl – Leibniz-Zentrum für Informatik; 2024:36:1–36:28. doi:<a href=\"https://doi.org/10.4230/LIPIcs.ECOOP.2024.36\">10.4230/LIPIcs.ECOOP.2024.36</a>","mla":"Schiebel, Fabian Benedikt, et al. “Scaling Interprocedural Static Data-Flow Analysis to Large C/C++ Applications: An Experience Report.” <i>38th European Conference on Object-Oriented Programming (ECOOP 2024)</i>, edited by Jonathan Aldrich and Guido Salvaneschi, vol. 313, Schloss Dagstuhl – Leibniz-Zentrum für Informatik, 2024, p. 36:1–36:28, doi:<a href=\"https://doi.org/10.4230/LIPIcs.ECOOP.2024.36\">10.4230/LIPIcs.ECOOP.2024.36</a>."},"place":"Dagstuhl, Germany","status":"public","user_id":"15249","volume":313,"editor":[{"full_name":"Aldrich, Jonathan","first_name":"Jonathan","last_name":"Aldrich"},{"full_name":"Salvaneschi, Guido","last_name":"Salvaneschi","first_name":"Guido"}],"page":"36:1–36:28","_id":"56863","publisher":"Schloss Dagstuhl – Leibniz-Zentrum für Informatik","publication":"38th European Conference on Object-Oriented Programming (ECOOP 2024)","type":"conference","department":[{"_id":"76"},{"_id":"662"}],"date_created":"2024-11-04T13:37:23Z","date_updated":"2025-12-04T10:41:59Z","intvolume":"       313","year":"2024","title":"Scaling Interprocedural Static Data-Flow Analysis to Large C/C++ Applications: An Experience Report","publication_identifier":{"issn":["1868-8969"],"isbn":["978-3-95977-341-6"]},"author":[{"last_name":"Schiebel","first_name":"Fabian Benedikt","orcid":"0009-0008-6867-9802","full_name":"Schiebel, Fabian Benedikt","id":"55745"},{"full_name":"Sattler, Florian","first_name":"Florian","last_name":"Sattler"},{"last_name":"Schubert","first_name":"Philipp Dominik","full_name":"Schubert, Philipp Dominik"},{"full_name":"Apel, Sven","first_name":"Sven","last_name":"Apel"},{"full_name":"Bodden, Eric","orcid":"0000-0003-3470-3647","first_name":"Eric","last_name":"Bodden","id":"59256"}],"doi":"10.4230/LIPIcs.ECOOP.2024.36","language":[{"iso":"eng"}],"series_title":"Leibniz International Proceedings in Informatics (LIPIcs)"},{"citation":{"mla":"Bodden, Eric, et al. “Evaluating Security Through Isolation and Defense in Depth.” <i>IEEE Security &#38; Privacy</i>, vol. 22, no. 1, Institute of Electrical and Electronics Engineers (IEEE), 2024, pp. 69–72, doi:<a href=\"https://doi.org/10.1109/msec.2023.3336028\">10.1109/msec.2023.3336028</a>.","ama":"Bodden E, Pottebaum J, Fockel M, Gräßler I. Evaluating Security Through Isolation and Defense in Depth. <i>IEEE Security &#38; Privacy</i>. 2024;22(1):69-72. doi:<a href=\"https://doi.org/10.1109/msec.2023.3336028\">10.1109/msec.2023.3336028</a>","bibtex":"@article{Bodden_Pottebaum_Fockel_Gräßler_2024, title={Evaluating Security Through Isolation and Defense in Depth}, volume={22}, DOI={<a href=\"https://doi.org/10.1109/msec.2023.3336028\">10.1109/msec.2023.3336028</a>}, number={1}, journal={IEEE Security &#38; Privacy}, publisher={Institute of Electrical and Electronics Engineers (IEEE)}, author={Bodden, Eric and Pottebaum, Jens and Fockel, Markus and Gräßler, Iris}, year={2024}, pages={69–72} }","apa":"Bodden, E., Pottebaum, J., Fockel, M., &#38; Gräßler, I. (2024). Evaluating Security Through Isolation and Defense in Depth. <i>IEEE Security &#38; Privacy</i>, <i>22</i>(1), 69–72. <a href=\"https://doi.org/10.1109/msec.2023.3336028\">https://doi.org/10.1109/msec.2023.3336028</a>","ieee":"E. Bodden, J. Pottebaum, M. Fockel, and I. Gräßler, “Evaluating Security Through Isolation and Defense in Depth,” <i>IEEE Security &#38; Privacy</i>, vol. 22, no. 1, pp. 69–72, 2024, doi: <a href=\"https://doi.org/10.1109/msec.2023.3336028\">10.1109/msec.2023.3336028</a>.","short":"E. Bodden, J. Pottebaum, M. Fockel, I. Gräßler, IEEE Security &#38; Privacy 22 (2024) 69–72.","chicago":"Bodden, Eric, Jens Pottebaum, Markus Fockel, and Iris Gräßler. “Evaluating Security Through Isolation and Defense in Depth.” <i>IEEE Security &#38; Privacy</i> 22, no. 1 (2024): 69–72. <a href=\"https://doi.org/10.1109/msec.2023.3336028\">https://doi.org/10.1109/msec.2023.3336028</a>."},"quality_controlled":"1","status":"public","_id":"52587","publisher":"Institute of Electrical and Electronics Engineers (IEEE)","page":"69-72","volume":22,"user_id":"405","issue":"1","publication":"IEEE Security & Privacy","date_created":"2024-03-15T20:16:18Z","department":[{"_id":"152"},{"_id":"76"},{"_id":"662"}],"keyword":["Law","Electrical and Electronic Engineering","Computer Networks and Communications"],"type":"journal_article","author":[{"id":"59256","full_name":"Bodden, Eric","last_name":"Bodden","first_name":"Eric","orcid":"0000-0003-3470-3647"},{"orcid":"http://orcid.org/0000-0001-8778-2989","first_name":"Jens","last_name":"Pottebaum","full_name":"Pottebaum, Jens","id":"405"},{"id":"8472","last_name":"Fockel","first_name":"Markus","orcid":"0000-0002-1269-0702","full_name":"Fockel, Markus"},{"id":"47565","full_name":"Gräßler, Iris","first_name":"Iris","orcid":"0000-0001-5765-971X","last_name":"Gräßler"}],"publication_identifier":{"issn":["1540-7993","1558-4046"]},"year":"2024","title":"Evaluating Security Through Isolation and Defense in Depth","intvolume":"        22","publication_status":"published","date_updated":"2026-03-31T02:19:49Z","language":[{"iso":"eng"}],"main_file_link":[{"url":"https://ieeexplore.ieee.org/document/10411721"}],"doi":"10.1109/msec.2023.3336028"},{"_id":"53811","ddc":["000"],"user_id":"55800","status":"public","conference":{"end_date":"2024-08-17","start_date":"2024-08-15","name":" 30th Americas Conference on Information Systems","location":"Salt Lake City"},"has_accepted_license":"1","file_date_updated":"2024-05-02T08:54:21Z","citation":{"bibtex":"@inproceedings{Taaibi_Dziwok_Hermerschmidt_Koch_Merschjohann_Vollmary, title={Security Belts: A Maturity Model for DevOps Teams to Increase the Software Security of their Product - An Experience Report}, booktitle={AMCIS 2024 Proceedings. 13.}, author={Taaibi, Samira and Dziwok, Stefan and Hermerschmidt, Lars and Koch, Thorsten and Merschjohann, Sven and Vollmary, Mark} }","ama":"Taaibi S, Dziwok S, Hermerschmidt L, Koch T, Merschjohann S, Vollmary M. Security Belts: A Maturity Model for DevOps Teams to Increase the Software Security of their Product - An Experience Report. In: <i>AMCIS 2024 Proceedings. 13.</i>","mla":"Taaibi, Samira, et al. “Security Belts: A Maturity Model for DevOps Teams to Increase the Software Security of Their Product - An Experience Report.” <i>AMCIS 2024 Proceedings. 13.</i>","chicago":"Taaibi, Samira, Stefan Dziwok, Lars Hermerschmidt, Thorsten Koch, Sven Merschjohann, and Mark Vollmary. “Security Belts: A Maturity Model for DevOps Teams to Increase the Software Security of Their Product - An Experience Report.” In <i>AMCIS 2024 Proceedings. 13.</i>, n.d.","short":"S. Taaibi, S. Dziwok, L. Hermerschmidt, T. Koch, S. Merschjohann, M. Vollmary, in: AMCIS 2024 Proceedings. 13., n.d.","ieee":"S. Taaibi, S. Dziwok, L. Hermerschmidt, T. Koch, S. Merschjohann, and M. Vollmary, “Security Belts: A Maturity Model for DevOps Teams to Increase the Software Security of their Product - An Experience Report,” presented at the  30th Americas Conference on Information Systems, Salt Lake City.","apa":"Taaibi, S., Dziwok, S., Hermerschmidt, L., Koch, T., Merschjohann, S., &#38; Vollmary, M. (n.d.). Security Belts: A Maturity Model for DevOps Teams to Increase the Software Security of their Product - An Experience Report. <i>AMCIS 2024 Proceedings. 13.</i>  30th Americas Conference on Information Systems, Salt Lake City."},"language":[{"iso":"eng"}],"title":"Security Belts: A Maturity Model for DevOps Teams to Increase the Software Security of their Product - An Experience Report","year":"2024","author":[{"id":"55800","full_name":"Taaibi, Samira","last_name":"Taaibi","first_name":"Samira"},{"id":"3901","last_name":"Dziwok","orcid":"http://orcid.org/0000-0002-8679-6673","first_name":"Stefan","full_name":"Dziwok, Stefan"},{"full_name":"Hermerschmidt, Lars","last_name":"Hermerschmidt","first_name":"Lars"},{"id":"13616","full_name":"Koch, Thorsten","last_name":"Koch","first_name":"Thorsten"},{"id":"11394","full_name":"Merschjohann, Sven","first_name":"Sven","last_name":"Merschjohann"},{"full_name":"Vollmary, Mark","last_name":"Vollmary","first_name":"Mark"}],"date_updated":"2026-05-08T03:26:03Z","publication_status":"accepted","file":[{"date_created":"2024-05-02T08:54:21Z","creator":"staaibi","success":1,"content_type":"application/pdf","file_id":"53812","file_size":540990,"access_level":"closed","file_name":"AMCIS2024_final_submission_maturity model security belt paper.pdf","date_updated":"2024-05-02T08:54:21Z","relation":"main_file"}],"date_created":"2024-05-02T08:57:52Z","type":"conference","keyword":["Software security","maturity model"],"department":[{"_id":"662"}],"publication":"AMCIS 2024 Proceedings. 13.","abstract":[{"lang":"eng","text":"Persistent security challenges plague DevOps teams due to a deficiency in expertise regarding security tools and methods, as evidenced by frequent security incidents. Existing maturity models fail to adequately address the specific needs of DevOps teams. In response, this paper proposes \"Security Belts,\" a novel maturity model inspired by martial arts ranking systems. This model aims to assist DevOps teams in enhancing their security capabilities by providing a structured approach, starting with fundamental activities and progressing to more advanced techniques. Drawing from the experiences of monitoring 21 teams, the paper presents lessons learned and offers actionable advice for refining maturity models tailored to software quality improvement."}]},{"doi":"10.1007/s10664-023-10354-3","article_number":"118","language":[{"iso":"eng"}],"publication_status":"published","date_updated":"2023-12-04T11:29:49Z","intvolume":"        28","year":"2023","title":"Can the configuration of static analyses make resolving security vulnerabilities more effective? - A user study","author":[{"full_name":"Piskachev, Goran","orcid":"0000-0003-4424-5838","first_name":"Goran","last_name":"Piskachev","id":"41936"},{"orcid":"https://orcid.org/0000-0003-2465-9347","first_name":"Matthias","last_name":"Becker","full_name":"Becker, Matthias","id":"4870"},{"orcid":"0000-0003-3470-3647","first_name":"Eric","last_name":"Bodden","full_name":"Bodden, Eric","id":"59256"}],"publication_identifier":{"issn":["1382-3256","1573-7616"]},"keyword":["Software"],"type":"journal_article","department":[{"_id":"76"},{"_id":"662"}],"date_created":"2023-12-04T11:14:34Z","abstract":[{"text":"<jats:title>Abstract</jats:title><jats:p>The use of static analysis security testing (SAST) tools has been increasing in recent years. However, previous studies have shown that, when shipped to end users such as development or security teams, the findings of these tools are often unsatisfying. Users report high numbers of false positives or long analysis times, making the tools unusable in the daily workflow. To address this, SAST tool creators provide a wide range of configuration options, such as customization of rules through domain-specific languages or specification of the application-specific analysis scope. In this paper, we study the configuration space of selected existing SAST tools when used within the integrated development environment (IDE). We focus on the configuration options that impact three dimensions, for which a trade-off is unavoidable, i.e., precision, recall, and analysis runtime. We perform a between-subjects user study with 40 users from multiple development and security teams - to our knowledge, the largest population for this kind of user study in the software engineering community. The results show that users who configure SAST tools are more effective in resolving security vulnerabilities detected by the tools than those using the default configuration. Based on post-study interviews, we identify common strategies that users have while configuring the SAST tools to provide further insights for tool creators. Finally, an evaluation of the configuration options of two commercial SAST tools, <jats:sc>Fortify</jats:sc> and <jats:sc>CheckMarx</jats:sc>, reveals that a quarter of the users do not understand the configuration options provided. The configuration options that are found most useful relate to the analysis scope.</jats:p>","lang":"eng"}],"issue":"5","publication":"Empirical Software Engineering","user_id":"15249","volume":28,"publisher":"Springer Science and Business Media LLC","_id":"49439","status":"public","citation":{"mla":"Piskachev, Goran, et al. “Can the Configuration of Static Analyses Make Resolving Security Vulnerabilities More Effective? - A User Study.” <i>Empirical Software Engineering</i>, vol. 28, no. 5, 118, Springer Science and Business Media LLC, 2023, doi:<a href=\"https://doi.org/10.1007/s10664-023-10354-3\">10.1007/s10664-023-10354-3</a>.","bibtex":"@article{Piskachev_Becker_Bodden_2023, title={Can the configuration of static analyses make resolving security vulnerabilities more effective? - A user study}, volume={28}, DOI={<a href=\"https://doi.org/10.1007/s10664-023-10354-3\">10.1007/s10664-023-10354-3</a>}, number={5118}, journal={Empirical Software Engineering}, publisher={Springer Science and Business Media LLC}, author={Piskachev, Goran and Becker, Matthias and Bodden, Eric}, year={2023} }","ama":"Piskachev G, Becker M, Bodden E. Can the configuration of static analyses make resolving security vulnerabilities more effective? - A user study. <i>Empirical Software Engineering</i>. 2023;28(5). doi:<a href=\"https://doi.org/10.1007/s10664-023-10354-3\">10.1007/s10664-023-10354-3</a>","ieee":"G. Piskachev, M. Becker, and E. Bodden, “Can the configuration of static analyses make resolving security vulnerabilities more effective? - A user study,” <i>Empirical Software Engineering</i>, vol. 28, no. 5, Art. no. 118, 2023, doi: <a href=\"https://doi.org/10.1007/s10664-023-10354-3\">10.1007/s10664-023-10354-3</a>.","apa":"Piskachev, G., Becker, M., &#38; Bodden, E. (2023). Can the configuration of static analyses make resolving security vulnerabilities more effective? - A user study. <i>Empirical Software Engineering</i>, <i>28</i>(5), Article 118. <a href=\"https://doi.org/10.1007/s10664-023-10354-3\">https://doi.org/10.1007/s10664-023-10354-3</a>","short":"G. Piskachev, M. Becker, E. Bodden, Empirical Software Engineering 28 (2023).","chicago":"Piskachev, Goran, Matthias Becker, and Eric Bodden. “Can the Configuration of Static Analyses Make Resolving Security Vulnerabilities More Effective? - A User Study.” <i>Empirical Software Engineering</i> 28, no. 5 (2023). <a href=\"https://doi.org/10.1007/s10664-023-10354-3\">https://doi.org/10.1007/s10664-023-10354-3</a>."}},{"date_updated":"2024-06-10T13:17:08Z","publication_status":"published","title":"Trustful Model-Based Information Exchange in Collaborative Engineering","year":"2023","status":"public","publication_identifier":{"issn":["1865-0929","1865-0937"],"isbn":["9783031423062","9783031423079"]},"author":[{"first_name":"David","last_name":"Schmelter","full_name":"Schmelter, David"},{"full_name":"Steghöfer, Jan-Philipp","last_name":"Steghöfer","first_name":"Jan-Philipp"},{"full_name":"Albers, Karsten","last_name":"Albers","first_name":"Karsten"},{"full_name":"Ekman, Mats","last_name":"Ekman","first_name":"Mats"},{"full_name":"Tessmer, Jörg","last_name":"Tessmer","first_name":"Jörg"},{"first_name":"Raphael","last_name":"Weber","full_name":"Weber, Raphael"}],"doi":"10.1007/978-3-031-42307-9_12","user_id":"40982","_id":"54672","publisher":"Springer Nature Switzerland","publication":"Communications in Computer and Information Science","citation":{"ama":"Schmelter D, Steghöfer J-P, Albers K, Ekman M, Tessmer J, Weber R. Trustful Model-Based Information Exchange in Collaborative Engineering. In: <i>Communications in Computer and Information Science</i>. Springer Nature Switzerland; 2023. doi:<a href=\"https://doi.org/10.1007/978-3-031-42307-9_12\">10.1007/978-3-031-42307-9_12</a>","bibtex":"@inbook{Schmelter_Steghöfer_Albers_Ekman_Tessmer_Weber_2023, place={Cham}, title={Trustful Model-Based Information Exchange in Collaborative Engineering}, DOI={<a href=\"https://doi.org/10.1007/978-3-031-42307-9_12\">10.1007/978-3-031-42307-9_12</a>}, booktitle={Communications in Computer and Information Science}, publisher={Springer Nature Switzerland}, author={Schmelter, David and Steghöfer, Jan-Philipp and Albers, Karsten and Ekman, Mats and Tessmer, Jörg and Weber, Raphael}, year={2023} }","mla":"Schmelter, David, et al. “Trustful Model-Based Information Exchange in Collaborative Engineering.” <i>Communications in Computer and Information Science</i>, Springer Nature Switzerland, 2023, doi:<a href=\"https://doi.org/10.1007/978-3-031-42307-9_12\">10.1007/978-3-031-42307-9_12</a>.","short":"D. Schmelter, J.-P. Steghöfer, K. Albers, M. Ekman, J. Tessmer, R. Weber, in: Communications in Computer and Information Science, Springer Nature Switzerland, Cham, 2023.","chicago":"Schmelter, David, Jan-Philipp Steghöfer, Karsten Albers, Mats Ekman, Jörg Tessmer, and Raphael Weber. “Trustful Model-Based Information Exchange in Collaborative Engineering.” In <i>Communications in Computer and Information Science</i>. Cham: Springer Nature Switzerland, 2023. <a href=\"https://doi.org/10.1007/978-3-031-42307-9_12\">https://doi.org/10.1007/978-3-031-42307-9_12</a>.","apa":"Schmelter, D., Steghöfer, J.-P., Albers, K., Ekman, M., Tessmer, J., &#38; Weber, R. (2023). Trustful Model-Based Information Exchange in Collaborative Engineering. In <i>Communications in Computer and Information Science</i>. Springer Nature Switzerland. <a href=\"https://doi.org/10.1007/978-3-031-42307-9_12\">https://doi.org/10.1007/978-3-031-42307-9_12</a>","ieee":"D. Schmelter, J.-P. Steghöfer, K. Albers, M. Ekman, J. Tessmer, and R. Weber, “Trustful Model-Based Information Exchange in Collaborative Engineering,” in <i>Communications in Computer and Information Science</i>, Cham: Springer Nature Switzerland, 2023."},"type":"book_chapter","department":[{"_id":"241"},{"_id":"662"}],"place":"Cham","date_created":"2024-06-10T13:10:39Z"},{"citation":{"short":"R. Trentinaglia, S. Merschjohann, M. Fockel, H. Eikerling, in: REFSQ 2023: Requirements Engineering: Foundation for Software Quality, Springer Nature Switzerland, Cham, 2023.","chicago":"Trentinaglia, Roman, Sven Merschjohann, Markus Fockel, and Hendrik Eikerling. “Eliciting Security Requirements – An Experience Report.” In <i>REFSQ 2023: Requirements Engineering: Foundation for Software Quality</i>. Cham: Springer Nature Switzerland, 2023. <a href=\"https://doi.org/10.1007/978-3-031-29786-1_25\">https://doi.org/10.1007/978-3-031-29786-1_25</a>.","apa":"Trentinaglia, R., Merschjohann, S., Fockel, M., &#38; Eikerling, H. (2023). Eliciting Security Requirements – An Experience Report. <i>REFSQ 2023: Requirements Engineering: Foundation for Software Quality</i>. <a href=\"https://doi.org/10.1007/978-3-031-29786-1_25\">https://doi.org/10.1007/978-3-031-29786-1_25</a>","ieee":"R. Trentinaglia, S. Merschjohann, M. Fockel, and H. Eikerling, “Eliciting Security Requirements – An Experience Report,” 2023, doi: <a href=\"https://doi.org/10.1007/978-3-031-29786-1_25\">10.1007/978-3-031-29786-1_25</a>.","ama":"Trentinaglia R, Merschjohann S, Fockel M, Eikerling H. Eliciting Security Requirements – An Experience Report. In: <i>REFSQ 2023: Requirements Engineering: Foundation for Software Quality</i>. Springer Nature Switzerland; 2023. doi:<a href=\"https://doi.org/10.1007/978-3-031-29786-1_25\">10.1007/978-3-031-29786-1_25</a>","bibtex":"@inproceedings{Trentinaglia_Merschjohann_Fockel_Eikerling_2023, place={Cham}, title={Eliciting Security Requirements – An Experience Report}, DOI={<a href=\"https://doi.org/10.1007/978-3-031-29786-1_25\">10.1007/978-3-031-29786-1_25</a>}, booktitle={REFSQ 2023: Requirements Engineering: Foundation for Software Quality}, publisher={Springer Nature Switzerland}, author={Trentinaglia, Roman and Merschjohann, Sven and Fockel, Markus and Eikerling, Hendrik}, year={2023} }","mla":"Trentinaglia, Roman, et al. “Eliciting Security Requirements – An Experience Report.” <i>REFSQ 2023: Requirements Engineering: Foundation for Software Quality</i>, Springer Nature Switzerland, 2023, doi:<a href=\"https://doi.org/10.1007/978-3-031-29786-1_25\">10.1007/978-3-031-29786-1_25</a>."},"publication":"REFSQ 2023: Requirements Engineering: Foundation for Software Quality","department":[{"_id":"241"},{"_id":"662"}],"type":"conference","date_created":"2023-04-04T12:47:31Z","place":"Cham","publication_status":"published","date_updated":"2023-04-04T12:51:41Z","publication_identifier":{"isbn":["9783031297854","9783031297861"],"issn":["0302-9743","1611-3349"]},"author":[{"id":"49934","first_name":"Roman","orcid":"0000-0001-9728-4991","last_name":"Trentinaglia","full_name":"Trentinaglia, Roman"},{"first_name":"Sven","last_name":"Merschjohann","full_name":"Merschjohann, Sven","id":"11394"},{"id":"8472","first_name":"Markus","orcid":"0000-0002-1269-0702","last_name":"Fockel","full_name":"Fockel, Markus"},{"full_name":"Eikerling, Hendrik","first_name":"Hendrik","last_name":"Eikerling","id":"29279"}],"year":"2023","status":"public","title":"Eliciting Security Requirements – An Experience Report","user_id":"8472","doi":"10.1007/978-3-031-29786-1_25","language":[{"iso":"eng"}],"_id":"43395","publisher":"Springer Nature Switzerland"},{"publication":"IEEE International Conference on Software Testing, Verification and Validation (ICST)","citation":{"ieee":"L. Luo, G. Piskachev, R. Krishnamurthy, J. Dolby, M. Schäf, and E. Bodden, “Model Generation For Java Frameworks,” 2023.","apa":"Luo, L., Piskachev, G., Krishnamurthy, R., Dolby, J., Schäf, M., &#38; Bodden, E. (2023). Model Generation For Java Frameworks. <i>IEEE International Conference on Software Testing, Verification and Validation (ICST)</i>.","short":"L. Luo, G. Piskachev, R. Krishnamurthy, J. Dolby, M. Schäf, E. Bodden, in: IEEE International Conference on Software Testing, Verification and Validation (ICST), 2023.","chicago":"Luo, Linghui, Goran Piskachev, Ranjith Krishnamurthy, Julian Dolby, Martin Schäf, and Eric Bodden. “Model Generation For Java Frameworks.” In <i>IEEE International Conference on Software Testing, Verification and Validation (ICST)</i>, 2023.","mla":"Luo, Linghui, et al. “Model Generation For Java Frameworks.” <i>IEEE International Conference on Software Testing, Verification and Validation (ICST)</i>, 2023.","bibtex":"@inproceedings{Luo_Piskachev_Krishnamurthy_Dolby_Schäf_Bodden_2023, title={Model Generation For Java Frameworks}, booktitle={IEEE International Conference on Software Testing, Verification and Validation (ICST)}, author={Luo, Linghui and Piskachev, Goran and Krishnamurthy, Ranjith and Dolby, Julian and Schäf, Martin and Bodden, Eric}, year={2023} }","ama":"Luo L, Piskachev G, Krishnamurthy R, Dolby J, Schäf M, Bodden E. Model Generation For Java Frameworks. In: <i>IEEE International Conference on Software Testing, Verification and Validation (ICST)</i>. ; 2023."},"type":"conference","department":[{"_id":"76"},{"_id":"662"}],"date_created":"2023-02-06T10:37:23Z","date_updated":"2025-04-07T10:15:08Z","status":"public","year":"2023","title":"Model Generation For Java Frameworks","author":[{"full_name":"Luo, Linghui","last_name":"Luo","first_name":"Linghui"},{"id":"41936","first_name":"Goran","orcid":"0000-0003-4424-5838","last_name":"Piskachev","full_name":"Piskachev, Goran"},{"id":"78060","full_name":"Krishnamurthy, Ranjith","first_name":"Ranjith","orcid":"0000-0002-0906-5463","last_name":"Krishnamurthy"},{"first_name":"Julian","last_name":"Dolby","full_name":"Dolby, Julian"},{"last_name":"Schäf","first_name":"Martin","full_name":"Schäf, Martin"},{"id":"59256","full_name":"Bodden, Eric","orcid":"0000-0003-3470-3647","first_name":"Eric","last_name":"Bodden"}],"user_id":"15249","_id":"41812","language":[{"iso":"eng"}]},{"author":[{"first_name":"Markus","last_name":"Fockel","orcid":"0000-0002-1269-0702","full_name":"Fockel, Markus","id":"8472"},{"full_name":"Schubert, David","last_name":"Schubert","first_name":"David","id":"9106"},{"id":"49934","full_name":"Trentinaglia, Roman","last_name":"Trentinaglia","first_name":"Roman","orcid":"0000-0001-9728-4991"},{"full_name":"Schulz, Hannes","last_name":"Schulz","first_name":"Hannes"},{"last_name":"Kirmair","first_name":"Wolfgang","full_name":"Kirmair, Wolfgang"}],"title":"Semi-automatic Integrated Safety and Security Analysis for Automotive Systems","status":"public","year":"2022","publication_status":"published","date_updated":"2022-02-15T08:14:07Z","_id":"29847","publisher":"SCITEPRESS - Science and Technology Publications","language":[{"iso":"eng"}],"user_id":"49934","doi":"10.5220/0010778500003119","citation":{"ama":"Fockel M, Schubert D, Trentinaglia R, Schulz H, Kirmair W. Semi-automatic Integrated Safety and Security Analysis for Automotive Systems. In: <i>Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development</i>. SCITEPRESS - Science and Technology Publications; 2022. doi:<a href=\"https://doi.org/10.5220/0010778500003119\">10.5220/0010778500003119</a>","bibtex":"@inproceedings{Fockel_Schubert_Trentinaglia_Schulz_Kirmair_2022, title={Semi-automatic Integrated Safety and Security Analysis for Automotive Systems}, DOI={<a href=\"https://doi.org/10.5220/0010778500003119\">10.5220/0010778500003119</a>}, booktitle={Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development}, publisher={SCITEPRESS - Science and Technology Publications}, author={Fockel, Markus and Schubert, David and Trentinaglia, Roman and Schulz, Hannes and Kirmair, Wolfgang}, year={2022} }","mla":"Fockel, Markus, et al. “Semi-Automatic Integrated Safety and Security Analysis for Automotive Systems.” <i>Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development</i>, SCITEPRESS - Science and Technology Publications, 2022, doi:<a href=\"https://doi.org/10.5220/0010778500003119\">10.5220/0010778500003119</a>.","short":"M. Fockel, D. Schubert, R. Trentinaglia, H. Schulz, W. Kirmair, in: Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development, SCITEPRESS - Science and Technology Publications, 2022.","chicago":"Fockel, Markus, David Schubert, Roman Trentinaglia, Hannes Schulz, and Wolfgang Kirmair. “Semi-Automatic Integrated Safety and Security Analysis for Automotive Systems.” In <i>Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development</i>. SCITEPRESS - Science and Technology Publications, 2022. <a href=\"https://doi.org/10.5220/0010778500003119\">https://doi.org/10.5220/0010778500003119</a>.","apa":"Fockel, M., Schubert, D., Trentinaglia, R., Schulz, H., &#38; Kirmair, W. (2022). Semi-automatic Integrated Safety and Security Analysis for Automotive Systems. <i>Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development</i>. <a href=\"https://doi.org/10.5220/0010778500003119\">https://doi.org/10.5220/0010778500003119</a>","ieee":"M. Fockel, D. Schubert, R. Trentinaglia, H. Schulz, and W. Kirmair, “Semi-automatic Integrated Safety and Security Analysis for Automotive Systems,” 2022, doi: <a href=\"https://doi.org/10.5220/0010778500003119\">10.5220/0010778500003119</a>."},"publication":"Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development","date_created":"2022-02-15T08:07:15Z","department":[{"_id":"241"},{"_id":"662"}],"type":"conference"},{"publisher":"SCITEPRESS - Science and Technology Publications","_id":"29844","language":[{"iso":"eng"}],"user_id":"13616","doi":"10.5220/0010783300003119","status":"public","year":"2022","title":"Integrating Security Protocols in Scenario-based Requirements Specifications","author":[{"id":"13616","first_name":"Thorsten","last_name":"Koch","full_name":"Koch, Thorsten"},{"first_name":"Sascha","last_name":"Trippel","full_name":"Trippel, Sascha"},{"full_name":"Dziwok, Stefan","orcid":"http://orcid.org/0000-0002-8679-6673","last_name":"Dziwok","first_name":"Stefan","id":"3901"},{"id":"59256","orcid":"0000-0003-3470-3647","last_name":"Bodden","first_name":"Eric","full_name":"Bodden, Eric"}],"publication_status":"published","date_updated":"2022-02-15T07:48:53Z","date_created":"2022-02-15T07:47:51Z","type":"conference","department":[{"_id":"241"},{"_id":"662"}],"publication":"Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development","citation":{"bibtex":"@inproceedings{Koch_Trippel_Dziwok_Bodden_2022, title={Integrating Security Protocols in Scenario-based Requirements Specifications}, DOI={<a href=\"https://doi.org/10.5220/0010783300003119\">10.5220/0010783300003119</a>}, booktitle={Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development}, publisher={SCITEPRESS - Science and Technology Publications}, author={Koch, Thorsten and Trippel, Sascha and Dziwok, Stefan and Bodden, Eric}, year={2022} }","ama":"Koch T, Trippel S, Dziwok S, Bodden E. Integrating Security Protocols in Scenario-based Requirements Specifications. In: <i>Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development</i>. SCITEPRESS - Science and Technology Publications; 2022. doi:<a href=\"https://doi.org/10.5220/0010783300003119\">10.5220/0010783300003119</a>","mla":"Koch, Thorsten, et al. “Integrating Security Protocols in Scenario-Based Requirements Specifications.” <i>Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development</i>, SCITEPRESS - Science and Technology Publications, 2022, doi:<a href=\"https://doi.org/10.5220/0010783300003119\">10.5220/0010783300003119</a>.","chicago":"Koch, Thorsten, Sascha Trippel, Stefan Dziwok, and Eric Bodden. “Integrating Security Protocols in Scenario-Based Requirements Specifications.” In <i>Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development</i>. SCITEPRESS - Science and Technology Publications, 2022. <a href=\"https://doi.org/10.5220/0010783300003119\">https://doi.org/10.5220/0010783300003119</a>.","short":"T. Koch, S. Trippel, S. Dziwok, E. Bodden, in: Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development, SCITEPRESS - Science and Technology Publications, 2022.","ieee":"T. Koch, S. Trippel, S. Dziwok, and E. Bodden, “Integrating Security Protocols in Scenario-based Requirements Specifications,” 2022, doi: <a href=\"https://doi.org/10.5220/0010783300003119\">10.5220/0010783300003119</a>.","apa":"Koch, T., Trippel, S., Dziwok, S., &#38; Bodden, E. (2022). Integrating Security Protocols in Scenario-based Requirements Specifications. <i>Proceedings of the 10th International Conference on Model-Driven Engineering and Software Development</i>. <a href=\"https://doi.org/10.5220/0010783300003119\">https://doi.org/10.5220/0010783300003119</a>"}},{"abstract":[{"lang":"eng","text":"Distributed, software-intensive systems (e.g., in the automotive sector) must fulfill communication requirements under hard real-time constraints.  The requirements have to be documented and validated carefully using a systematic requirements engineering (RE) approach, for example, by applying scenario-based requirements notations. The resources of the execution platforms and their properties (e.g., CPU frequency or bus throughput) induce effects on the timing behavior, which may lead to violations of the real-time requirements. Nowadays, the platform properties and their induced timing effects are verified against the real-time requirements by means of timing analysis techniques mostly implemented in commercial-off-the-shelf tools. However, such timing analyses are conducted in late development phases since they rely on artifacts produced during these phases (e.g., the platform-specific code). In order to enable early timing analyses already during RE, we extend a scenario-based requirements notation with allocation means to platform models and define operational semantics for the purpose of simulation-based, platform-aware timing analyses. We illustrate and evaluate the approach with an automotive software-intensive system."}],"citation":{"mla":"Holtmann, Jörg, et al. “Early Timing Analysis Based on Scenario Requirements and Platform Models.” <i>Software and Systems Modeling</i>, Springer Science and Business Media LLC, 2022, doi:<a href=\"https://doi.org/10.1007/s10270-022-01002-3\">10.1007/s10270-022-01002-3</a>.","ama":"Holtmann J, Deantoni J, Fockel M. Early timing analysis based on scenario requirements and platform models. <i>Software and Systems Modeling</i>. Published online 2022. doi:<a href=\"https://doi.org/10.1007/s10270-022-01002-3\">10.1007/s10270-022-01002-3</a>","bibtex":"@article{Holtmann_Deantoni_Fockel_2022, title={Early timing analysis based on scenario requirements and platform models}, DOI={<a href=\"https://doi.org/10.1007/s10270-022-01002-3\">10.1007/s10270-022-01002-3</a>}, journal={Software and Systems Modeling}, publisher={Springer Science and Business Media LLC}, author={Holtmann, Jörg and Deantoni, Julien and Fockel, Markus}, year={2022} }","apa":"Holtmann, J., Deantoni, J., &#38; Fockel, M. (2022). Early timing analysis based on scenario requirements and platform models. <i>Software and Systems Modeling</i>. <a href=\"https://doi.org/10.1007/s10270-022-01002-3\">https://doi.org/10.1007/s10270-022-01002-3</a>","ieee":"J. Holtmann, J. Deantoni, and M. Fockel, “Early timing analysis based on scenario requirements and platform models,” <i>Software and Systems Modeling</i>, 2022, doi: <a href=\"https://doi.org/10.1007/s10270-022-01002-3\">10.1007/s10270-022-01002-3</a>.","short":"J. Holtmann, J. Deantoni, M. Fockel, Software and Systems Modeling (2022).","chicago":"Holtmann, Jörg, Julien Deantoni, and Markus Fockel. “Early Timing Analysis Based on Scenario Requirements and Platform Models.” <i>Software and Systems Modeling</i>, 2022. <a href=\"https://doi.org/10.1007/s10270-022-01002-3\">https://doi.org/10.1007/s10270-022-01002-3</a>."},"publication":"Software and Systems Modeling","department":[{"_id":"241"},{"_id":"662"}],"keyword":["Modeling and Simulation","Software"],"type":"journal_article","date_created":"2022-05-05T14:05:32Z","date_updated":"2022-05-05T14:09:41Z","publication_status":"published","author":[{"id":"3875","full_name":"Holtmann, Jörg","last_name":"Holtmann","first_name":"Jörg","orcid":"0000-0001-6141-4571"},{"full_name":"Deantoni, Julien","first_name":"Julien","last_name":"Deantoni"},{"id":"8472","orcid":"0000-0002-1269-0702","last_name":"Fockel","first_name":"Markus","full_name":"Fockel, Markus"}],"publication_identifier":{"issn":["1619-1366","1619-1374"]},"year":"2022","title":"Early timing analysis based on scenario requirements and platform models","status":"public","doi":"10.1007/s10270-022-01002-3","user_id":"8472","language":[{"iso":"eng"}],"_id":"31071","publisher":"Springer Science and Business Media LLC"},{"date_updated":"2022-10-20T12:36:23Z","intvolume":"        27","year":"2022","title":"Fluently specifying taint-flow queries with fluentTQL","status":"public","author":[{"id":"41936","full_name":"Piskachev, Goran","orcid":"0000-0003-4424-5838","last_name":"Piskachev","first_name":"Goran"},{"full_name":"Späth, Johannes","last_name":"Späth","first_name":"Johannes"},{"full_name":"Budde, Ingo","orcid":"https://orcid.org/0000-0003-0124-6291","last_name":"Budde","first_name":"Ingo","id":"13693"},{"id":"59256","full_name":"Bodden, Eric","first_name":"Eric","last_name":"Bodden","orcid":"0000-0003-3470-3647"}],"user_id":"15249","volume":27,"page":"1–33","_id":"33836","language":[{"iso":"eng"}],"publisher":"Springer","publication":"Empirical Software Engineering","issue":"5","citation":{"ama":"Piskachev G, Späth J, Budde I, Bodden E. Fluently specifying taint-flow queries with fluentTQL. <i>Empirical Software Engineering</i>. 2022;27(5):1–33.","bibtex":"@article{Piskachev_Späth_Budde_Bodden_2022, title={Fluently specifying taint-flow queries with fluentTQL}, volume={27}, number={5}, journal={Empirical Software Engineering}, publisher={Springer}, author={Piskachev, Goran and Späth, Johannes and Budde, Ingo and Bodden, Eric}, year={2022}, pages={1–33} }","mla":"Piskachev, Goran, et al. “Fluently Specifying Taint-Flow Queries with FluentTQL.” <i>Empirical Software Engineering</i>, vol. 27, no. 5, Springer, 2022, pp. 1–33.","chicago":"Piskachev, Goran, Johannes Späth, Ingo Budde, and Eric Bodden. “Fluently Specifying Taint-Flow Queries with FluentTQL.” <i>Empirical Software Engineering</i> 27, no. 5 (2022): 1–33.","short":"G. Piskachev, J. Späth, I. Budde, E. Bodden, Empirical Software Engineering 27 (2022) 1–33.","apa":"Piskachev, G., Späth, J., Budde, I., &#38; Bodden, E. (2022). Fluently specifying taint-flow queries with fluentTQL. <i>Empirical Software Engineering</i>, <i>27</i>(5), 1–33.","ieee":"G. Piskachev, J. Späth, I. Budde, and E. Bodden, “Fluently specifying taint-flow queries with fluentTQL,” <i>Empirical Software Engineering</i>, vol. 27, no. 5, pp. 1–33, 2022."},"type":"journal_article","department":[{"_id":"76"},{"_id":"662"}],"date_created":"2022-10-20T12:34:04Z"},{"date_updated":"2022-10-20T12:38:32Z","status":"public","title":"To what extent can we analyze Kotlin programs using existing Java taint analysis tools?","year":"2022","author":[{"id":"78060","full_name":"Krishnamurthy, Ranjith","first_name":"Ranjith","last_name":"Krishnamurthy","orcid":"0000-0002-0906-5463"},{"id":"41936","full_name":"Piskachev, Goran","last_name":"Piskachev","first_name":"Goran","orcid":"0000-0003-4424-5838"},{"first_name":"Eric","orcid":"0000-0003-3470-3647","last_name":"Bodden","full_name":"Bodden, Eric","id":"59256"}],"user_id":"15249","language":[{"iso":"eng"}],"_id":"33838","series_title":"IEEE International Working Conference on Source Code Analysis and Manipulation (SCAM)","citation":{"mla":"Krishnamurthy, Ranjith, et al. <i>To What Extent Can We Analyze Kotlin Programs Using Existing Java Taint Analysis Tools?</i> 2022.","bibtex":"@article{Krishnamurthy_Piskachev_Bodden_2022, series={IEEE International Working Conference on Source Code Analysis and Manipulation (SCAM)}, title={To what extent can we analyze Kotlin programs using existing Java taint analysis tools?}, author={Krishnamurthy, Ranjith and Piskachev, Goran and Bodden, Eric}, year={2022}, collection={IEEE International Working Conference on Source Code Analysis and Manipulation (SCAM)} }","ama":"Krishnamurthy R, Piskachev G, Bodden E. To what extent can we analyze Kotlin programs using existing Java taint analysis tools? Published online 2022.","ieee":"R. Krishnamurthy, G. Piskachev, and E. Bodden, “To what extent can we analyze Kotlin programs using existing Java taint analysis tools?” 2022.","apa":"Krishnamurthy, R., Piskachev, G., &#38; Bodden, E. (2022). <i>To what extent can we analyze Kotlin programs using existing Java taint analysis tools?</i>","chicago":"Krishnamurthy, Ranjith, Goran Piskachev, and Eric Bodden. “To What Extent Can We Analyze Kotlin Programs Using Existing Java Taint Analysis Tools?” IEEE International Working Conference on Source Code Analysis and Manipulation (SCAM), 2022.","short":"R. Krishnamurthy, G. Piskachev, E. Bodden, (2022)."},"type":"conference","department":[{"_id":"76"},{"_id":"662"}],"date_created":"2022-10-20T12:38:09Z"},{"author":[{"orcid":"0000-0003-4424-5838","last_name":"Piskachev","first_name":"Goran","full_name":"Piskachev, Goran","id":"41936"},{"id":"3901","last_name":"Dziwok","orcid":"http://orcid.org/0000-0002-8679-6673","first_name":"Stefan","full_name":"Dziwok, Stefan"},{"id":"13616","full_name":"Koch, Thorsten","last_name":"Koch","first_name":"Thorsten"},{"id":"11394","full_name":"Merschjohann, Sven","last_name":"Merschjohann","first_name":"Sven"},{"id":"59256","full_name":"Bodden, Eric","last_name":"Bodden","first_name":"Eric","orcid":"0000-0003-3470-3647"}],"status":"public","year":"2022","title":"How far are German companies in improving security through static program analysis tools?","date_updated":"2022-10-20T12:37:44Z","_id":"33837","series_title":"IEEE Secure Development Conference (SecDev)","language":[{"iso":"eng"}],"user_id":"15249","citation":{"ama":"Piskachev G, Dziwok S, Koch T, Merschjohann S, Bodden E. How far are German companies in improving security through static program analysis tools? Published online 2022.","bibtex":"@article{Piskachev_Dziwok_Koch_Merschjohann_Bodden_2022, series={IEEE Secure Development Conference (SecDev)}, title={How far are German companies in improving security through static program analysis tools?}, author={Piskachev, Goran and Dziwok, Stefan and Koch, Thorsten and Merschjohann, Sven and Bodden, Eric}, year={2022}, collection={IEEE Secure Development Conference (SecDev)} }","mla":"Piskachev, Goran, et al. <i>How Far Are German Companies in Improving Security through Static Program Analysis Tools?</i> 2022.","short":"G. Piskachev, S. Dziwok, T. Koch, S. Merschjohann, E. Bodden, (2022).","chicago":"Piskachev, Goran, Stefan Dziwok, Thorsten Koch, Sven Merschjohann, and Eric Bodden. “How Far Are German Companies in Improving Security through Static Program Analysis Tools?” IEEE Secure Development Conference (SecDev), 2022.","apa":"Piskachev, G., Dziwok, S., Koch, T., Merschjohann, S., &#38; Bodden, E. (2022). <i>How far are German companies in improving security through static program analysis tools?</i>","ieee":"G. Piskachev, S. Dziwok, T. Koch, S. Merschjohann, and E. Bodden, “How far are German companies in improving security through static program analysis tools?” 2022."},"date_created":"2022-10-20T12:37:14Z","department":[{"_id":"76"},{"_id":"662"}],"type":"conference"}]
