---
_id: '65261'
author:
- first_name: Roman
  full_name: Trentinaglia, Roman
  id: '49934'
  last_name: Trentinaglia
  orcid: 0000-0001-9728-4991
- first_name: Thorsten
  full_name: Koch, Thorsten
  id: '13616'
  last_name: Koch
- first_name: Eric
  full_name: Bodden, Eric
  id: '59256'
  last_name: Bodden
  orcid: 0000-0003-3470-3647
citation:
  ama: 'Trentinaglia R, Koch T, Bodden E. Using Attack and Failure Propagation Analysis
    for Context-Aware Security Control Suggestions. In: <i>Proceedings of the 14th
    International Conference on Model-Based Software and Systems Engineering</i>.
    SCITEPRESS - Science and Technology Publications; 2026. doi:<a href="https://doi.org/10.5220/0014278000004058">10.5220/0014278000004058</a>'
  apa: Trentinaglia, R., Koch, T., &#38; Bodden, E. (2026). Using Attack and Failure
    Propagation Analysis for Context-Aware Security Control Suggestions. <i>Proceedings
    of the 14th International Conference on Model-Based Software and Systems Engineering</i>.
    <a href="https://doi.org/10.5220/0014278000004058">https://doi.org/10.5220/0014278000004058</a>
  bibtex: '@inproceedings{Trentinaglia_Koch_Bodden_2026, title={Using Attack and Failure
    Propagation Analysis for Context-Aware Security Control Suggestions}, DOI={<a
    href="https://doi.org/10.5220/0014278000004058">10.5220/0014278000004058</a>},
    booktitle={Proceedings of the 14th International Conference on Model-Based Software
    and Systems Engineering}, publisher={SCITEPRESS - Science and Technology Publications},
    author={Trentinaglia, Roman and Koch, Thorsten and Bodden, Eric}, year={2026}
    }'
  chicago: Trentinaglia, Roman, Thorsten Koch, and Eric Bodden. “Using Attack and
    Failure Propagation Analysis for Context-Aware Security Control Suggestions.”
    In <i>Proceedings of the 14th International Conference on Model-Based Software
    and Systems Engineering</i>. SCITEPRESS - Science and Technology Publications,
    2026. <a href="https://doi.org/10.5220/0014278000004058">https://doi.org/10.5220/0014278000004058</a>.
  ieee: 'R. Trentinaglia, T. Koch, and E. Bodden, “Using Attack and Failure Propagation
    Analysis for Context-Aware Security Control Suggestions,” 2026, doi: <a href="https://doi.org/10.5220/0014278000004058">10.5220/0014278000004058</a>.'
  mla: Trentinaglia, Roman, et al. “Using Attack and Failure Propagation Analysis
    for Context-Aware Security Control Suggestions.” <i>Proceedings of the 14th International
    Conference on Model-Based Software and Systems Engineering</i>, SCITEPRESS - Science
    and Technology Publications, 2026, doi:<a href="https://doi.org/10.5220/0014278000004058">10.5220/0014278000004058</a>.
  short: 'R. Trentinaglia, T. Koch, E. Bodden, in: Proceedings of the 14th International
    Conference on Model-Based Software and Systems Engineering, SCITEPRESS - Science
    and Technology Publications, 2026.'
date_created: 2026-03-31T13:52:36Z
date_updated: 2026-03-31T13:53:55Z
department:
- _id: '241'
- _id: '662'
doi: 10.5220/0014278000004058
language:
- iso: eng
publication: Proceedings of the 14th International Conference on Model-Based Software
  and Systems Engineering
publication_status: published
publisher: SCITEPRESS - Science and Technology Publications
status: public
title: Using Attack and Failure Propagation Analysis for Context-Aware Security Control
  Suggestions
type: conference
user_id: '49934'
year: '2026'
...
---
_id: '61546'
abstract:
- lang: eng
  text: <jats:p>Fuzzing is a powerful software testing technique renowned for its
    effectiveness in identifying software vulnerabilities. Traditional fuzzing evaluations
    typically focus on overall fuzzer performance across a set of target programs,
    yet few benchmarks consider how fine-grained program features influence fuzzing
    effectiveness. To bridge this gap, we introduce FeatureBench, a novel benchmark
    designed to generate programs with configurable, fine-grained program features
    to enhance fuzzing evaluations. We reviewed 25 recent grey-box fuzzing studies,
    extracting 7 program features related to control-flow and data-flow that can impact
    fuzzer performance. Using these features, we generated a benchmark consisting
    of 153 programs controlled by 10 fine-grained configurable parameters. We evaluated
    11 fuzzers using this benchmark, with each fuzzer representing either distinct
    claimed improvements or serving as a widely used baseline in fuzzing evaluations.
    The results indicate that fuzzer performance varies significantly based on the
    program features and their strengths, highlighting the importance of incorporating
    program characteristics into fuzzing evaluations.</jats:p>
author:
- first_name: Miao
  full_name: Miao, Miao
  last_name: Miao
- first_name: Sriteja
  full_name: Kummita, Sriteja
  id: '72582'
  last_name: Kummita
- first_name: Eric
  full_name: Bodden, Eric
  id: '59256'
  last_name: Bodden
  orcid: 0000-0003-3470-3647
- first_name: Shiyi
  full_name: Wei, Shiyi
  last_name: Wei
citation:
  ama: Miao M, Kummita S, Bodden E, Wei S. Program Feature-Based Benchmarking for
    Fuzz Testing. <i>Proceedings of the ACM on Software Engineering</i>. 2025;2(ISSTA):527-549.
    doi:<a href="https://doi.org/10.1145/3728899">10.1145/3728899</a>
  apa: Miao, M., Kummita, S., Bodden, E., &#38; Wei, S. (2025). Program Feature-Based
    Benchmarking for Fuzz Testing. <i>Proceedings of the ACM on Software Engineering</i>,
    <i>2</i>(ISSTA), 527–549. <a href="https://doi.org/10.1145/3728899">https://doi.org/10.1145/3728899</a>
  bibtex: '@article{Miao_Kummita_Bodden_Wei_2025, title={Program Feature-Based Benchmarking
    for Fuzz Testing}, volume={2}, DOI={<a href="https://doi.org/10.1145/3728899">10.1145/3728899</a>},
    number={ISSTA}, journal={Proceedings of the ACM on Software Engineering}, publisher={Association
    for Computing Machinery (ACM)}, author={Miao, Miao and Kummita, Sriteja and Bodden,
    Eric and Wei, Shiyi}, year={2025}, pages={527–549} }'
  chicago: 'Miao, Miao, Sriteja Kummita, Eric Bodden, and Shiyi Wei. “Program Feature-Based
    Benchmarking for Fuzz Testing.” <i>Proceedings of the ACM on Software Engineering</i>
    2, no. ISSTA (2025): 527–49. <a href="https://doi.org/10.1145/3728899">https://doi.org/10.1145/3728899</a>.'
  ieee: 'M. Miao, S. Kummita, E. Bodden, and S. Wei, “Program Feature-Based Benchmarking
    for Fuzz Testing,” <i>Proceedings of the ACM on Software Engineering</i>, vol.
    2, no. ISSTA, pp. 527–549, 2025, doi: <a href="https://doi.org/10.1145/3728899">10.1145/3728899</a>.'
  mla: Miao, Miao, et al. “Program Feature-Based Benchmarking for Fuzz Testing.” <i>Proceedings
    of the ACM on Software Engineering</i>, vol. 2, no. ISSTA, Association for Computing
    Machinery (ACM), 2025, pp. 527–49, doi:<a href="https://doi.org/10.1145/3728899">10.1145/3728899</a>.
  short: M. Miao, S. Kummita, E. Bodden, S. Wei, Proceedings of the ACM on Software
    Engineering 2 (2025) 527–549.
date_created: 2025-10-08T08:29:39Z
date_updated: 2025-10-08T08:32:57Z
department:
- _id: '76'
- _id: '662'
doi: 10.1145/3728899
intvolume: '         2'
issue: ISSTA
language:
- iso: eng
page: 527-549
publication: Proceedings of the ACM on Software Engineering
publication_identifier:
  issn:
  - 2994-970X
publication_status: published
publisher: Association for Computing Machinery (ACM)
status: public
title: Program Feature-Based Benchmarking for Fuzz Testing
type: journal_article
user_id: '15249'
volume: 2
year: '2025'
...
---
_id: '60583'
abstract:
- lang: eng
  text: <jats:p>Assessing and communicating software security has become a crucial
    concern in the era of digital transformation. As software systems grow more complex
    and interconnected, it becomes increasingly challenging to effectively evaluate
    and communicate a product's security status to both technical and non-technical
    stakeholders. The Software Product Health Assistant (SPHA) is designed to automatically
    collect and aggregate data from existing expert tools and derive, among other
    scores, a transparent Security Score. SPHA is designed to present and explain
    this Security Score to decision-makers to support their responsibilities. In this
    paper, we demonstrate how to integrate data from SMARAGD (System Modeler for Architectural
    Risk Assessment and Guidance on Defenses), a safety-informed threat modeling tool,
    into SPHA to enhance the existing definition of its Security Score. To achieve
    this, we combine information about known vulnerabilities with architectural and
    threat data to calculate a realistic risk score for the product in question.</jats:p>
author:
- first_name: Jan-niclas
  full_name: Strüwer, Jan-niclas
  last_name: Strüwer
- first_name: Roman
  full_name: Trentinaglia, Roman
  id: '49934'
  last_name: Trentinaglia
  orcid: 0000-0001-9728-4991
- first_name: Benedict
  full_name: Wohlers, Benedict
  id: '53786'
  last_name: Wohlers
- first_name: Eric
  full_name: Bodden, Eric
  id: '59256'
  last_name: Bodden
  orcid: 0000-0003-3470-3647
- first_name: Roman
  full_name: Dumitrescu, Roman
  id: '16190'
  last_name: Dumitrescu
citation:
  ama: 'Strüwer J, Trentinaglia R, Wohlers B, Bodden E, Dumitrescu R. Assessing and
    Communicating Software Security: Enhancing Software Product Health with Architectural
    Threat Analysis. In: <i>AHFE International</i>. Vol 168. AHFE International; 2025.
    doi:<a href="https://doi.org/10.54941/ahfe1006145">10.54941/ahfe1006145</a>'
  apa: 'Strüwer, J., Trentinaglia, R., Wohlers, B., Bodden, E., &#38; Dumitrescu,
    R. (2025). Assessing and Communicating Software Security: Enhancing Software Product
    Health with Architectural Threat Analysis. <i>AHFE International</i>, <i>168</i>.
    <a href="https://doi.org/10.54941/ahfe1006145">https://doi.org/10.54941/ahfe1006145</a>'
  bibtex: '@inproceedings{Strüwer_Trentinaglia_Wohlers_Bodden_Dumitrescu_2025, title={Assessing
    and Communicating Software Security: Enhancing Software Product Health with Architectural
    Threat Analysis}, volume={168}, DOI={<a href="https://doi.org/10.54941/ahfe1006145">10.54941/ahfe1006145</a>},
    booktitle={AHFE International}, publisher={AHFE International}, author={Strüwer,
    Jan-niclas and Trentinaglia, Roman and Wohlers, Benedict and Bodden, Eric and
    Dumitrescu, Roman}, year={2025} }'
  chicago: 'Strüwer, Jan-niclas, Roman Trentinaglia, Benedict Wohlers, Eric Bodden,
    and Roman Dumitrescu. “Assessing and Communicating Software Security: Enhancing
    Software Product Health with Architectural Threat Analysis.” In <i>AHFE International</i>,
    Vol. 168. AHFE International, 2025. <a href="https://doi.org/10.54941/ahfe1006145">https://doi.org/10.54941/ahfe1006145</a>.'
  ieee: 'J. Strüwer, R. Trentinaglia, B. Wohlers, E. Bodden, and R. Dumitrescu, “Assessing
    and Communicating Software Security: Enhancing Software Product Health with Architectural
    Threat Analysis,” in <i>AHFE International</i>, 2025, vol. 168, doi: <a href="https://doi.org/10.54941/ahfe1006145">10.54941/ahfe1006145</a>.'
  mla: 'Strüwer, Jan-niclas, et al. “Assessing and Communicating Software Security:
    Enhancing Software Product Health with Architectural Threat Analysis.” <i>AHFE
    International</i>, vol. 168, AHFE International, 2025, doi:<a href="https://doi.org/10.54941/ahfe1006145">10.54941/ahfe1006145</a>.'
  short: 'J. Strüwer, R. Trentinaglia, B. Wohlers, E. Bodden, R. Dumitrescu, in: AHFE
    International, AHFE International, 2025.'
date_created: 2025-07-10T06:37:42Z
date_updated: 2025-07-10T06:39:03Z
department:
- _id: '241'
- _id: '662'
doi: 10.54941/ahfe1006145
intvolume: '       168'
language:
- iso: eng
publication: AHFE International
publication_identifier:
  issn:
  - 2771-0718
publication_status: published
publisher: AHFE International
status: public
title: 'Assessing and Communicating Software Security: Enhancing Software Product
  Health with Architectural Threat Analysis'
type: conference
user_id: '49934'
volume: 168
year: '2025'
...
---
_id: '63854'
author:
- first_name: Hendrik
  full_name: Eikerling, Hendrik
  last_name: Eikerling
- first_name: Anemone
  full_name: Kampkötter, Anemone
  last_name: Kampkötter
citation:
  ama: 'Eikerling H, Kampkötter A. Enabling Android Application Monitoring by Characterizing
    Security-Critical Code Fragments. In: <i>Lecture Notes in Computer Science</i>.
    Springer Nature Switzerland; 2025. doi:<a href="https://doi.org/10.1007/978-3-031-82362-6_25">10.1007/978-3-031-82362-6_25</a>'
  apa: Eikerling, H., &#38; Kampkötter, A. (2025). Enabling Android Application Monitoring
    by Characterizing Security-Critical Code Fragments. <i>Lecture Notes in Computer
    Science</i>. <a href="https://doi.org/10.1007/978-3-031-82362-6_25">https://doi.org/10.1007/978-3-031-82362-6_25</a>
  bibtex: '@inproceedings{Eikerling_Kampkötter_2025, place={Cham}, title={Enabling
    Android Application Monitoring by Characterizing Security-Critical Code Fragments},
    DOI={<a href="https://doi.org/10.1007/978-3-031-82362-6_25">10.1007/978-3-031-82362-6_25</a>},
    booktitle={Lecture Notes in Computer Science}, publisher={Springer Nature Switzerland},
    author={Eikerling, Hendrik and Kampkötter, Anemone}, year={2025} }'
  chicago: 'Eikerling, Hendrik, and Anemone Kampkötter. “Enabling Android Application
    Monitoring by Characterizing Security-Critical Code Fragments.” In <i>Lecture
    Notes in Computer Science</i>. Cham: Springer Nature Switzerland, 2025. <a href="https://doi.org/10.1007/978-3-031-82362-6_25">https://doi.org/10.1007/978-3-031-82362-6_25</a>.'
  ieee: 'H. Eikerling and A. Kampkötter, “Enabling Android Application Monitoring
    by Characterizing Security-Critical Code Fragments,” 2025, doi: <a href="https://doi.org/10.1007/978-3-031-82362-6_25">10.1007/978-3-031-82362-6_25</a>.'
  mla: Eikerling, Hendrik, and Anemone Kampkötter. “Enabling Android Application Monitoring
    by Characterizing Security-Critical Code Fragments.” <i>Lecture Notes in Computer
    Science</i>, Springer Nature Switzerland, 2025, doi:<a href="https://doi.org/10.1007/978-3-031-82362-6_25">10.1007/978-3-031-82362-6_25</a>.
  short: 'H. Eikerling, A. Kampkötter, in: Lecture Notes in Computer Science, Springer
    Nature Switzerland, Cham, 2025.'
date_created: 2026-02-03T23:17:33Z
date_updated: 2026-03-16T09:03:52Z
department:
- _id: '241'
- _id: '662'
doi: 10.1007/978-3-031-82362-6_25
language:
- iso: eng
place: Cham
publication: Lecture Notes in Computer Science
publication_identifier:
  isbn:
  - '9783031823619'
  - '9783031823626'
  issn:
  - 0302-9743
  - 1611-3349
publication_status: published
publisher: Springer Nature Switzerland
status: public
title: Enabling Android Application Monitoring by Characterizing Security-Critical
  Code Fragments
type: conference
user_id: '29279'
year: '2025'
...
---
_id: '53958'
abstract:
- lang: eng
  text: "To detect security vulnerabilities, static analysis tools need to be configured
    with security-relevant methods. Current approaches can automatically identify
    such methods using binary relevance machine learning approaches. However, they
    ignore dependencies among security-relevant methods, over-generalize and perform
    poorly in practice. Additionally, users have to nevertheless manually configure
    static analysis tools using the detected methods. Based on feedback from users
    and our observations, the excessive manual steps can often be tedious, error-prone
    and counter-intuitive.\r\n In this paper, we present Dev-Assist, an IntelliJ IDEA
    plugin that detects security-relevant methods using a multi-label machine learning
    approach that considers dependencies among labels. The plugin can automatically
    generate configurations for static analysis tools, run the static analysis, and
    show the results in IntelliJ IDEA. Our experiments reveal that Dev-Assist's machine
    learning approach has a higher F1-Measure than related approaches. Moreover, the
    plugin reduces and simplifies the manual effort required when configuring and
    using static analysis tools."
author:
- first_name: Oshando
  full_name: Johnson, Oshando
  id: '66583'
  last_name: Johnson
- first_name: Goran
  full_name: Piskachev, Goran
  id: '41936'
  last_name: Piskachev
  orcid: 0000-0003-4424-5838
- first_name: Ranjith
  full_name: Krishnamurthy, Ranjith
  id: '78060'
  last_name: Krishnamurthy
  orcid: 0000-0002-0906-5463
- first_name: Eric
  full_name: Bodden, Eric
  id: '59256'
  last_name: Bodden
  orcid: 0000-0003-3470-3647
citation:
  ama: 'Johnson O, Piskachev G, Krishnamurthy R, Bodden E. Detecting Security-Relevant
    Methods using Multi-label Machine Learning. In: <i>Proceedings of the 46th International
    Conference on Software Engineering, IDE Workshop</i>. ; 2024. doi:<a href="https://doi.org/10.48550/ARXIV.2403.07501">10.48550/ARXIV.2403.07501</a>'
  apa: Johnson, O., Piskachev, G., Krishnamurthy, R., &#38; Bodden, E. (2024). Detecting
    Security-Relevant Methods using Multi-label Machine Learning. <i>Proceedings of
    the 46th International Conference on Software Engineering, IDE Workshop</i>. <a
    href="https://doi.org/10.48550/ARXIV.2403.07501">https://doi.org/10.48550/ARXIV.2403.07501</a>
  bibtex: '@inproceedings{Johnson_Piskachev_Krishnamurthy_Bodden_2024, title={Detecting
    Security-Relevant Methods using Multi-label Machine Learning}, DOI={<a href="https://doi.org/10.48550/ARXIV.2403.07501">10.48550/ARXIV.2403.07501</a>},
    booktitle={Proceedings of the 46th International Conference on Software Engineering,
    IDE Workshop}, author={Johnson, Oshando and Piskachev, Goran and Krishnamurthy,
    Ranjith and Bodden, Eric}, year={2024} }'
  chicago: Johnson, Oshando, Goran Piskachev, Ranjith Krishnamurthy, and Eric Bodden.
    “Detecting Security-Relevant Methods Using Multi-Label Machine Learning.” In <i>Proceedings
    of the 46th International Conference on Software Engineering, IDE Workshop</i>,
    2024. <a href="https://doi.org/10.48550/ARXIV.2403.07501">https://doi.org/10.48550/ARXIV.2403.07501</a>.
  ieee: 'O. Johnson, G. Piskachev, R. Krishnamurthy, and E. Bodden, “Detecting Security-Relevant
    Methods using Multi-label Machine Learning,” 2024, doi: <a href="https://doi.org/10.48550/ARXIV.2403.07501">10.48550/ARXIV.2403.07501</a>.'
  mla: Johnson, Oshando, et al. “Detecting Security-Relevant Methods Using Multi-Label
    Machine Learning.” <i>Proceedings of the 46th International Conference on Software
    Engineering, IDE Workshop</i>, 2024, doi:<a href="https://doi.org/10.48550/ARXIV.2403.07501">10.48550/ARXIV.2403.07501</a>.
  short: 'O. Johnson, G. Piskachev, R. Krishnamurthy, E. Bodden, in: Proceedings of
    the 46th International Conference on Software Engineering, IDE Workshop, 2024.'
date_created: 2024-05-06T11:43:19Z
date_updated: 2024-05-06T11:47:14Z
department:
- _id: '76'
- _id: '662'
doi: 10.48550/ARXIV.2403.07501
language:
- iso: eng
publication: Proceedings of the 46th International Conference on Software Engineering,
  IDE Workshop
status: public
title: Detecting Security-Relevant Methods using Multi-label Machine Learning
type: conference
user_id: '15249'
year: '2024'
...
---
_id: '59601'
abstract:
- lang: eng
  text: Modern vehicles are becoming more connected and autonomous, and more software-defined
    in general. Such connectivity leads to security risks due to the increased attack
    surface for external intrusions. In addition, attacks can also lead to safety
    hazards as cars contain multiple safety-critical components. Therefore both safety
    and security must be considered in combination. In this whitepaper, we describe
    a tool-supported analysis method aligned with automotive standards to identify
    safety and security dependencies and automatically derive corresponding test cases.
    These test cases can be imported into the existing dSPACE tool chain to improve
    efficiency by reducing time-consuming manual work and susceptibility to errors.
    Thereby, our method brings together system design and testing phases to pave the
    way for an integrated safety and security-by-design life cycle in the automotive
    domain.
author:
- first_name: Roman
  full_name: Trentinaglia, Roman
  id: '49934'
  last_name: Trentinaglia
  orcid: 0000-0001-9728-4991
- first_name: Markus
  full_name: Fockel, Markus
  id: '8472'
  last_name: Fockel
  orcid: 0000-0002-1269-0702
- first_name: Matthias
  full_name: Pukrop, Matthias
  last_name: Pukrop
- first_name: Tobias
  full_name: Schaeffer, Tobias
  last_name: Schaeffer
citation:
  ama: 'Trentinaglia R, Fockel M, Pukrop M, Schaeffer T. <i>Whitepaper: From HARA
    and TARA to Risk-Based Safety and Security Dependency Testing</i>. dSPACE GmbH;
    2024.'
  apa: 'Trentinaglia, R., Fockel, M., Pukrop, M., &#38; Schaeffer, T. (2024). <i>Whitepaper:
    From HARA and TARA to Risk-Based Safety and Security Dependency Testing</i>. dSPACE
    GmbH.'
  bibtex: '@book{Trentinaglia_Fockel_Pukrop_Schaeffer_2024, title={Whitepaper: From
    HARA and TARA to Risk-Based Safety and Security Dependency Testing}, publisher={dSPACE
    GmbH}, author={Trentinaglia, Roman and Fockel, Markus and Pukrop, Matthias and
    Schaeffer, Tobias}, year={2024} }'
  chicago: 'Trentinaglia, Roman, Markus Fockel, Matthias Pukrop, and Tobias Schaeffer.
    <i>Whitepaper: From HARA and TARA to Risk-Based Safety and Security Dependency
    Testing</i>. dSPACE GmbH, 2024.'
  ieee: 'R. Trentinaglia, M. Fockel, M. Pukrop, and T. Schaeffer, <i>Whitepaper: From
    HARA and TARA to Risk-Based Safety and Security Dependency Testing</i>. dSPACE
    GmbH, 2024.'
  mla: 'Trentinaglia, Roman, et al. <i>Whitepaper: From HARA and TARA to Risk-Based
    Safety and Security Dependency Testing</i>. dSPACE GmbH, 2024.'
  short: 'R. Trentinaglia, M. Fockel, M. Pukrop, T. Schaeffer, Whitepaper: From HARA
    and TARA to Risk-Based Safety and Security Dependency Testing, dSPACE GmbH, 2024.'
date_created: 2025-04-16T09:30:13Z
date_updated: 2025-04-16T09:30:29Z
department:
- _id: '241'
- _id: '662'
language:
- iso: eng
main_file_link:
- url: https://www.iem.fraunhofer.de/content/dam/iem/dokumente/termine/whitepaper_safety-and-security_06_240527_e-v11.pdf
page: '5'
publication_status: published
publisher: dSPACE GmbH
related_material:
  link:
  - relation: other
    url: https://www.iem.fraunhofer.de/de/newsroom/presse-und-news/fraunhofer-iem-dspace-veroeffentlichen-whitepaper.html
status: public
title: 'Whitepaper: From HARA and TARA to Risk-Based Safety and Security Dependency
  Testing'
type: misc
user_id: '49934'
year: '2024'
...
---
_id: '57578'
author:
- first_name: Roman
  full_name: Trentinaglia, Roman
  id: '49934'
  last_name: Trentinaglia
  orcid: 0000-0001-9728-4991
- first_name: Markus
  full_name: Fockel, Markus
  id: '8472'
  last_name: Fockel
  orcid: 0000-0002-1269-0702
- first_name: Matthias
  full_name: Pukrop, Matthias
  last_name: Pukrop
- first_name: Tobias
  full_name: Schaeffer, Tobias
  last_name: Schaeffer
citation:
  ama: 'Trentinaglia R, Fockel M, Pukrop M, Schaeffer T. Automatically deriving test
    cases from safety-security dependencies. In: <i>22th Escar Europe : The World’s
    Leading Automotive Cyber Security Conference : Embedded Security in Cars (Dortmund,
    19. - 20.11.2024)</i>. ; 2024. doi:<a href="https://doi.org/10.13154/294-12716">10.13154/294-12716</a>'
  apa: 'Trentinaglia, R., Fockel, M., Pukrop, M., &#38; Schaeffer, T. (2024). Automatically
    deriving test cases from safety-security dependencies. <i>22th Escar Europe :
    The World’s Leading Automotive Cyber Security Conference : Embedded Security in
    Cars (Dortmund, 19. - 20.11.2024)</i>. <a href="https://doi.org/10.13154/294-12716">https://doi.org/10.13154/294-12716</a>'
  bibtex: '@inproceedings{Trentinaglia_Fockel_Pukrop_Schaeffer_2024, title={Automatically
    deriving test cases from safety-security dependencies}, DOI={<a href="https://doi.org/10.13154/294-12716">10.13154/294-12716</a>},
    booktitle={22th escar Europe : The World’s Leading Automotive Cyber Security Conference :
    Embedded Security in Cars (Dortmund, 19. - 20.11.2024)}, author={Trentinaglia,
    Roman and Fockel, Markus and Pukrop, Matthias and Schaeffer, Tobias}, year={2024}
    }'
  chicago: 'Trentinaglia, Roman, Markus Fockel, Matthias Pukrop, and Tobias Schaeffer.
    “Automatically Deriving Test Cases from Safety-Security Dependencies.” In <i>22th
    Escar Europe : The World’s Leading Automotive Cyber Security Conference : Embedded
    Security in Cars (Dortmund, 19. - 20.11.2024)</i>, 2024. <a href="https://doi.org/10.13154/294-12716">https://doi.org/10.13154/294-12716</a>.'
  ieee: 'R. Trentinaglia, M. Fockel, M. Pukrop, and T. Schaeffer, “Automatically deriving
    test cases from safety-security dependencies,” 2024, doi: <a href="https://doi.org/10.13154/294-12716">10.13154/294-12716</a>.'
  mla: 'Trentinaglia, Roman, et al. “Automatically Deriving Test Cases from Safety-Security
    Dependencies.” <i>22th Escar Europe : The World’s Leading Automotive Cyber Security
    Conference : Embedded Security in Cars (Dortmund, 19. - 20.11.2024)</i>, 2024,
    doi:<a href="https://doi.org/10.13154/294-12716">10.13154/294-12716</a>.'
  short: 'R. Trentinaglia, M. Fockel, M. Pukrop, T. Schaeffer, in: 22th Escar Europe :
    The World’s Leading Automotive Cyber Security Conference : Embedded Security in
    Cars (Dortmund, 19. - 20.11.2024), 2024.'
date_created: 2024-12-04T14:55:47Z
date_updated: 2025-05-19T09:31:29Z
department:
- _id: '241'
- _id: '662'
doi: 10.13154/294-12716
language:
- iso: eng
publication: '22th escar Europe : The World’s Leading Automotive Cyber Security Conference
  : Embedded Security in Cars (Dortmund, 19. - 20.11.2024)'
status: public
title: Automatically deriving test cases from safety-security dependencies
type: conference
user_id: '49934'
year: '2024'
...
---
_id: '56863'
author:
- first_name: Fabian Benedikt
  full_name: Schiebel, Fabian Benedikt
  id: '55745'
  last_name: Schiebel
  orcid: 0009-0008-6867-9802
- first_name: Florian
  full_name: Sattler, Florian
  last_name: Sattler
- first_name: Philipp Dominik
  full_name: Schubert, Philipp Dominik
  last_name: Schubert
- first_name: Sven
  full_name: Apel, Sven
  last_name: Apel
- first_name: Eric
  full_name: Bodden, Eric
  id: '59256'
  last_name: Bodden
  orcid: 0000-0003-3470-3647
citation:
  ama: 'Schiebel FB, Sattler F, Schubert PD, Apel S, Bodden E. Scaling Interprocedural
    Static Data-Flow Analysis to Large C/C++ Applications: An Experience Report. In:
    Aldrich J, Salvaneschi G, eds. <i>38th European Conference on Object-Oriented
    Programming (ECOOP 2024)</i>. Vol 313. Leibniz International Proceedings in Informatics
    (LIPIcs). Schloss Dagstuhl – Leibniz-Zentrum für Informatik; 2024:36:1–36:28.
    doi:<a href="https://doi.org/10.4230/LIPIcs.ECOOP.2024.36">10.4230/LIPIcs.ECOOP.2024.36</a>'
  apa: 'Schiebel, F. B., Sattler, F., Schubert, P. D., Apel, S., &#38; Bodden, E.
    (2024). Scaling Interprocedural Static Data-Flow Analysis to Large C/C++ Applications:
    An Experience Report. In J. Aldrich &#38; G. Salvaneschi (Eds.), <i>38th European
    Conference on Object-Oriented Programming (ECOOP 2024)</i> (Vol. 313, p. 36:1–36:28).
    Schloss Dagstuhl – Leibniz-Zentrum für Informatik. <a href="https://doi.org/10.4230/LIPIcs.ECOOP.2024.36">https://doi.org/10.4230/LIPIcs.ECOOP.2024.36</a>'
  bibtex: '@inproceedings{Schiebel_Sattler_Schubert_Apel_Bodden_2024, place={Dagstuhl,
    Germany}, series={Leibniz International Proceedings in Informatics (LIPIcs)},
    title={Scaling Interprocedural Static Data-Flow Analysis to Large C/C++ Applications:
    An Experience Report}, volume={313}, DOI={<a href="https://doi.org/10.4230/LIPIcs.ECOOP.2024.36">10.4230/LIPIcs.ECOOP.2024.36</a>},
    booktitle={38th European Conference on Object-Oriented Programming (ECOOP 2024)},
    publisher={Schloss Dagstuhl – Leibniz-Zentrum für Informatik}, author={Schiebel,
    Fabian Benedikt and Sattler, Florian and Schubert, Philipp Dominik and Apel, Sven
    and Bodden, Eric}, editor={Aldrich, Jonathan and Salvaneschi, Guido}, year={2024},
    pages={36:1–36:28}, collection={Leibniz International Proceedings in Informatics
    (LIPIcs)} }'
  chicago: 'Schiebel, Fabian Benedikt, Florian Sattler, Philipp Dominik Schubert,
    Sven Apel, and Eric Bodden. “Scaling Interprocedural Static Data-Flow Analysis
    to Large C/C++ Applications: An Experience Report.” In <i>38th European Conference
    on Object-Oriented Programming (ECOOP 2024)</i>, edited by Jonathan Aldrich and
    Guido Salvaneschi, 313:36:1–36:28. Leibniz International Proceedings in Informatics
    (LIPIcs). Dagstuhl, Germany: Schloss Dagstuhl – Leibniz-Zentrum für Informatik,
    2024. <a href="https://doi.org/10.4230/LIPIcs.ECOOP.2024.36">https://doi.org/10.4230/LIPIcs.ECOOP.2024.36</a>.'
  ieee: 'F. B. Schiebel, F. Sattler, P. D. Schubert, S. Apel, and E. Bodden, “Scaling
    Interprocedural Static Data-Flow Analysis to Large C/C++ Applications: An Experience
    Report,” in <i>38th European Conference on Object-Oriented Programming (ECOOP
    2024)</i>, 2024, vol. 313, p. 36:1–36:28, doi: <a href="https://doi.org/10.4230/LIPIcs.ECOOP.2024.36">10.4230/LIPIcs.ECOOP.2024.36</a>.'
  mla: 'Schiebel, Fabian Benedikt, et al. “Scaling Interprocedural Static Data-Flow
    Analysis to Large C/C++ Applications: An Experience Report.” <i>38th European
    Conference on Object-Oriented Programming (ECOOP 2024)</i>, edited by Jonathan
    Aldrich and Guido Salvaneschi, vol. 313, Schloss Dagstuhl – Leibniz-Zentrum für
    Informatik, 2024, p. 36:1–36:28, doi:<a href="https://doi.org/10.4230/LIPIcs.ECOOP.2024.36">10.4230/LIPIcs.ECOOP.2024.36</a>.'
  short: 'F.B. Schiebel, F. Sattler, P.D. Schubert, S. Apel, E. Bodden, in: J. Aldrich,
    G. Salvaneschi (Eds.), 38th European Conference on Object-Oriented Programming
    (ECOOP 2024), Schloss Dagstuhl – Leibniz-Zentrum für Informatik, Dagstuhl, Germany,
    2024, p. 36:1–36:28.'
date_created: 2024-11-04T13:37:23Z
date_updated: 2025-12-04T10:41:59Z
department:
- _id: '76'
- _id: '662'
doi: 10.4230/LIPIcs.ECOOP.2024.36
editor:
- first_name: Jonathan
  full_name: Aldrich, Jonathan
  last_name: Aldrich
- first_name: Guido
  full_name: Salvaneschi, Guido
  last_name: Salvaneschi
intvolume: '       313'
language:
- iso: eng
page: 36:1–36:28
place: Dagstuhl, Germany
publication: 38th European Conference on Object-Oriented Programming (ECOOP 2024)
publication_identifier:
  isbn:
  - 978-3-95977-341-6
  issn:
  - 1868-8969
publisher: Schloss Dagstuhl – Leibniz-Zentrum für Informatik
series_title: Leibniz International Proceedings in Informatics (LIPIcs)
status: public
title: 'Scaling Interprocedural Static Data-Flow Analysis to Large C/C++ Applications:
  An Experience Report'
type: conference
user_id: '15249'
volume: 313
year: '2024'
...
---
_id: '52587'
author:
- first_name: Eric
  full_name: Bodden, Eric
  id: '59256'
  last_name: Bodden
  orcid: 0000-0003-3470-3647
- first_name: Jens
  full_name: Pottebaum, Jens
  id: '405'
  last_name: Pottebaum
  orcid: http://orcid.org/0000-0001-8778-2989
- first_name: Markus
  full_name: Fockel, Markus
  id: '8472'
  last_name: Fockel
  orcid: 0000-0002-1269-0702
- first_name: Iris
  full_name: Gräßler, Iris
  id: '47565'
  last_name: Gräßler
  orcid: 0000-0001-5765-971X
citation:
  ama: Bodden E, Pottebaum J, Fockel M, Gräßler I. Evaluating Security Through Isolation
    and Defense in Depth. <i>IEEE Security &#38; Privacy</i>. 2024;22(1):69-72. doi:<a
    href="https://doi.org/10.1109/msec.2023.3336028">10.1109/msec.2023.3336028</a>
  apa: Bodden, E., Pottebaum, J., Fockel, M., &#38; Gräßler, I. (2024). Evaluating
    Security Through Isolation and Defense in Depth. <i>IEEE Security &#38; Privacy</i>,
    <i>22</i>(1), 69–72. <a href="https://doi.org/10.1109/msec.2023.3336028">https://doi.org/10.1109/msec.2023.3336028</a>
  bibtex: '@article{Bodden_Pottebaum_Fockel_Gräßler_2024, title={Evaluating Security
    Through Isolation and Defense in Depth}, volume={22}, DOI={<a href="https://doi.org/10.1109/msec.2023.3336028">10.1109/msec.2023.3336028</a>},
    number={1}, journal={IEEE Security &#38; Privacy}, publisher={Institute of Electrical
    and Electronics Engineers (IEEE)}, author={Bodden, Eric and Pottebaum, Jens and
    Fockel, Markus and Gräßler, Iris}, year={2024}, pages={69–72} }'
  chicago: 'Bodden, Eric, Jens Pottebaum, Markus Fockel, and Iris Gräßler. “Evaluating
    Security Through Isolation and Defense in Depth.” <i>IEEE Security &#38; Privacy</i>
    22, no. 1 (2024): 69–72. <a href="https://doi.org/10.1109/msec.2023.3336028">https://doi.org/10.1109/msec.2023.3336028</a>.'
  ieee: 'E. Bodden, J. Pottebaum, M. Fockel, and I. Gräßler, “Evaluating Security
    Through Isolation and Defense in Depth,” <i>IEEE Security &#38; Privacy</i>, vol.
    22, no. 1, pp. 69–72, 2024, doi: <a href="https://doi.org/10.1109/msec.2023.3336028">10.1109/msec.2023.3336028</a>.'
  mla: Bodden, Eric, et al. “Evaluating Security Through Isolation and Defense in
    Depth.” <i>IEEE Security &#38; Privacy</i>, vol. 22, no. 1, Institute of Electrical
    and Electronics Engineers (IEEE), 2024, pp. 69–72, doi:<a href="https://doi.org/10.1109/msec.2023.3336028">10.1109/msec.2023.3336028</a>.
  short: E. Bodden, J. Pottebaum, M. Fockel, I. Gräßler, IEEE Security &#38; Privacy
    22 (2024) 69–72.
date_created: 2024-03-15T20:16:18Z
date_updated: 2026-03-31T02:19:49Z
department:
- _id: '152'
- _id: '76'
- _id: '662'
doi: 10.1109/msec.2023.3336028
intvolume: '        22'
issue: '1'
keyword:
- Law
- Electrical and Electronic Engineering
- Computer Networks and Communications
language:
- iso: eng
main_file_link:
- url: https://ieeexplore.ieee.org/document/10411721
page: 69-72
publication: IEEE Security & Privacy
publication_identifier:
  issn:
  - 1540-7993
  - 1558-4046
publication_status: published
publisher: Institute of Electrical and Electronics Engineers (IEEE)
quality_controlled: '1'
status: public
title: Evaluating Security Through Isolation and Defense in Depth
type: journal_article
user_id: '405'
volume: 22
year: '2024'
...
---
_id: '53811'
abstract:
- lang: eng
  text: Persistent security challenges plague DevOps teams due to a deficiency in
    expertise regarding security tools and methods, as evidenced by frequent security
    incidents. Existing maturity models fail to adequately address the specific needs
    of DevOps teams. In response, this paper proposes "Security Belts," a novel maturity
    model inspired by martial arts ranking systems. This model aims to assist DevOps
    teams in enhancing their security capabilities by providing a structured approach,
    starting with fundamental activities and progressing to more advanced techniques.
    Drawing from the experiences of monitoring 21 teams, the paper presents lessons
    learned and offers actionable advice for refining maturity models tailored to
    software quality improvement.
author:
- first_name: Samira
  full_name: Taaibi, Samira
  id: '55800'
  last_name: Taaibi
- first_name: Stefan
  full_name: Dziwok, Stefan
  id: '3901'
  last_name: Dziwok
  orcid: http://orcid.org/0000-0002-8679-6673
- first_name: Lars
  full_name: Hermerschmidt, Lars
  last_name: Hermerschmidt
- first_name: Thorsten
  full_name: Koch, Thorsten
  id: '13616'
  last_name: Koch
- first_name: Sven
  full_name: Merschjohann, Sven
  id: '11394'
  last_name: Merschjohann
- first_name: Mark
  full_name: Vollmary, Mark
  last_name: Vollmary
citation:
  ama: 'Taaibi S, Dziwok S, Hermerschmidt L, Koch T, Merschjohann S, Vollmary M. Security
    Belts: A Maturity Model for DevOps Teams to Increase the Software Security of
    their Product - An Experience Report. In: <i>AMCIS 2024 Proceedings. 13.</i>'
  apa: 'Taaibi, S., Dziwok, S., Hermerschmidt, L., Koch, T., Merschjohann, S., &#38;
    Vollmary, M. (n.d.). Security Belts: A Maturity Model for DevOps Teams to Increase
    the Software Security of their Product - An Experience Report. <i>AMCIS 2024 Proceedings.
    13.</i>  30th Americas Conference on Information Systems, Salt Lake City.'
  bibtex: '@inproceedings{Taaibi_Dziwok_Hermerschmidt_Koch_Merschjohann_Vollmary,
    title={Security Belts: A Maturity Model for DevOps Teams to Increase the Software
    Security of their Product - An Experience Report}, booktitle={AMCIS 2024 Proceedings.
    13.}, author={Taaibi, Samira and Dziwok, Stefan and Hermerschmidt, Lars and Koch,
    Thorsten and Merschjohann, Sven and Vollmary, Mark} }'
  chicago: 'Taaibi, Samira, Stefan Dziwok, Lars Hermerschmidt, Thorsten Koch, Sven
    Merschjohann, and Mark Vollmary. “Security Belts: A Maturity Model for DevOps
    Teams to Increase the Software Security of Their Product - An Experience Report.”
    In <i>AMCIS 2024 Proceedings. 13.</i>, n.d.'
  ieee: 'S. Taaibi, S. Dziwok, L. Hermerschmidt, T. Koch, S. Merschjohann, and M.
    Vollmary, “Security Belts: A Maturity Model for DevOps Teams to Increase the Software
    Security of their Product - An Experience Report,” presented at the  30th Americas
    Conference on Information Systems, Salt Lake City.'
  mla: 'Taaibi, Samira, et al. “Security Belts: A Maturity Model for DevOps Teams
    to Increase the Software Security of Their Product - An Experience Report.” <i>AMCIS
    2024 Proceedings. 13.</i>'
  short: 'S. Taaibi, S. Dziwok, L. Hermerschmidt, T. Koch, S. Merschjohann, M. Vollmary,
    in: AMCIS 2024 Proceedings. 13., n.d.'
conference:
  end_date: 2024-08-17
  location: Salt Lake City
  name: ' 30th Americas Conference on Information Systems'
  start_date: 2024-08-15
date_created: 2024-05-02T08:57:52Z
date_updated: 2026-05-08T03:26:03Z
ddc:
- '000'
department:
- _id: '662'
file:
- access_level: closed
  content_type: application/pdf
  creator: staaibi
  date_created: 2024-05-02T08:54:21Z
  date_updated: 2024-05-02T08:54:21Z
  file_id: '53812'
  file_name: AMCIS2024_final_submission_maturity model security belt paper.pdf
  file_size: 540990
  relation: main_file
  success: 1
file_date_updated: 2024-05-02T08:54:21Z
has_accepted_license: '1'
keyword:
- Software security
- maturity model
language:
- iso: eng
publication: AMCIS 2024 Proceedings. 13.
publication_status: accepted
status: public
title: 'Security Belts: A Maturity Model for DevOps Teams to Increase the Software
  Security of their Product - An Experience Report'
type: conference
user_id: '55800'
year: '2024'
...
---
_id: '49439'
abstract:
- lang: eng
  text: <jats:title>Abstract</jats:title><jats:p>The use of static analysis security
    testing (SAST) tools has been increasing in recent years. However, previous studies
    have shown that, when shipped to end users such as development or security teams,
    the findings of these tools are often unsatisfying. Users report high numbers
    of false positives or long analysis times, making the tools unusable in the daily
    workflow. To address this, SAST tool creators provide a wide range of configuration
    options, such as customization of rules through domain-specific languages or specification
    of the application-specific analysis scope. In this paper, we study the configuration
    space of selected existing SAST tools when used within the integrated development
    environment (IDE). We focus on the configuration options that impact three dimensions,
    for which a trade-off is unavoidable, i.e., precision, recall, and analysis runtime.
    We perform a between-subjects user study with 40 users from multiple development
    and security teams - to our knowledge, the largest population for this kind of
    user study in the software engineering community. The results show that users
    who configure SAST tools are more effective in resolving security vulnerabilities
    detected by the tools than those using the default configuration. Based on post-study
    interviews, we identify common strategies that users have while configuring the
    SAST tools to provide further insights for tool creators. Finally, an evaluation
    of the configuration options of two commercial SAST tools, <jats:sc>Fortify</jats:sc>
    and <jats:sc>CheckMarx</jats:sc>, reveals that a quarter of the users do not understand
    the configuration options provided. The configuration options that are found most
    useful relate to the analysis scope.</jats:p>
article_number: '118'
author:
- first_name: Goran
  full_name: Piskachev, Goran
  id: '41936'
  last_name: Piskachev
  orcid: 0000-0003-4424-5838
- first_name: Matthias
  full_name: Becker, Matthias
  id: '4870'
  last_name: Becker
  orcid: https://orcid.org/0000-0003-2465-9347
- first_name: Eric
  full_name: Bodden, Eric
  id: '59256'
  last_name: Bodden
  orcid: 0000-0003-3470-3647
citation:
  ama: Piskachev G, Becker M, Bodden E. Can the configuration of static analyses make
    resolving security vulnerabilities more effective? - A user study. <i>Empirical
    Software Engineering</i>. 2023;28(5). doi:<a href="https://doi.org/10.1007/s10664-023-10354-3">10.1007/s10664-023-10354-3</a>
  apa: Piskachev, G., Becker, M., &#38; Bodden, E. (2023). Can the configuration of
    static analyses make resolving security vulnerabilities more effective? - A user
    study. <i>Empirical Software Engineering</i>, <i>28</i>(5), Article 118. <a href="https://doi.org/10.1007/s10664-023-10354-3">https://doi.org/10.1007/s10664-023-10354-3</a>
  bibtex: '@article{Piskachev_Becker_Bodden_2023, title={Can the configuration of
    static analyses make resolving security vulnerabilities more effective? - A user
    study}, volume={28}, DOI={<a href="https://doi.org/10.1007/s10664-023-10354-3">10.1007/s10664-023-10354-3</a>},
    number={5118}, journal={Empirical Software Engineering}, publisher={Springer Science
    and Business Media LLC}, author={Piskachev, Goran and Becker, Matthias and Bodden,
    Eric}, year={2023} }'
  chicago: Piskachev, Goran, Matthias Becker, and Eric Bodden. “Can the Configuration
    of Static Analyses Make Resolving Security Vulnerabilities More Effective? - A
    User Study.” <i>Empirical Software Engineering</i> 28, no. 5 (2023). <a href="https://doi.org/10.1007/s10664-023-10354-3">https://doi.org/10.1007/s10664-023-10354-3</a>.
  ieee: 'G. Piskachev, M. Becker, and E. Bodden, “Can the configuration of static
    analyses make resolving security vulnerabilities more effective? - A user study,”
    <i>Empirical Software Engineering</i>, vol. 28, no. 5, Art. no. 118, 2023, doi:
    <a href="https://doi.org/10.1007/s10664-023-10354-3">10.1007/s10664-023-10354-3</a>.'
  mla: Piskachev, Goran, et al. “Can the Configuration of Static Analyses Make Resolving
    Security Vulnerabilities More Effective? - A User Study.” <i>Empirical Software
    Engineering</i>, vol. 28, no. 5, 118, Springer Science and Business Media LLC,
    2023, doi:<a href="https://doi.org/10.1007/s10664-023-10354-3">10.1007/s10664-023-10354-3</a>.
  short: G. Piskachev, M. Becker, E. Bodden, Empirical Software Engineering 28 (2023).
date_created: 2023-12-04T11:14:34Z
date_updated: 2023-12-04T11:29:49Z
department:
- _id: '76'
- _id: '662'
doi: 10.1007/s10664-023-10354-3
intvolume: '        28'
issue: '5'
keyword:
- Software
language:
- iso: eng
publication: Empirical Software Engineering
publication_identifier:
  issn:
  - 1382-3256
  - 1573-7616
publication_status: published
publisher: Springer Science and Business Media LLC
status: public
title: Can the configuration of static analyses make resolving security vulnerabilities
  more effective? - A user study
type: journal_article
user_id: '15249'
volume: 28
year: '2023'
...
---
_id: '54672'
author:
- first_name: David
  full_name: Schmelter, David
  last_name: Schmelter
- first_name: Jan-Philipp
  full_name: Steghöfer, Jan-Philipp
  last_name: Steghöfer
- first_name: Karsten
  full_name: Albers, Karsten
  last_name: Albers
- first_name: Mats
  full_name: Ekman, Mats
  last_name: Ekman
- first_name: Jörg
  full_name: Tessmer, Jörg
  last_name: Tessmer
- first_name: Raphael
  full_name: Weber, Raphael
  last_name: Weber
citation:
  ama: 'Schmelter D, Steghöfer J-P, Albers K, Ekman M, Tessmer J, Weber R. Trustful
    Model-Based Information Exchange in Collaborative Engineering. In: <i>Communications
    in Computer and Information Science</i>. Springer Nature Switzerland; 2023. doi:<a
    href="https://doi.org/10.1007/978-3-031-42307-9_12">10.1007/978-3-031-42307-9_12</a>'
  apa: Schmelter, D., Steghöfer, J.-P., Albers, K., Ekman, M., Tessmer, J., &#38;
    Weber, R. (2023). Trustful Model-Based Information Exchange in Collaborative Engineering.
    In <i>Communications in Computer and Information Science</i>. Springer Nature
    Switzerland. <a href="https://doi.org/10.1007/978-3-031-42307-9_12">https://doi.org/10.1007/978-3-031-42307-9_12</a>
  bibtex: '@inbook{Schmelter_Steghöfer_Albers_Ekman_Tessmer_Weber_2023, place={Cham},
    title={Trustful Model-Based Information Exchange in Collaborative Engineering},
    DOI={<a href="https://doi.org/10.1007/978-3-031-42307-9_12">10.1007/978-3-031-42307-9_12</a>},
    booktitle={Communications in Computer and Information Science}, publisher={Springer
    Nature Switzerland}, author={Schmelter, David and Steghöfer, Jan-Philipp and Albers,
    Karsten and Ekman, Mats and Tessmer, Jörg and Weber, Raphael}, year={2023} }'
  chicago: 'Schmelter, David, Jan-Philipp Steghöfer, Karsten Albers, Mats Ekman, Jörg
    Tessmer, and Raphael Weber. “Trustful Model-Based Information Exchange in Collaborative
    Engineering.” In <i>Communications in Computer and Information Science</i>. Cham:
    Springer Nature Switzerland, 2023. <a href="https://doi.org/10.1007/978-3-031-42307-9_12">https://doi.org/10.1007/978-3-031-42307-9_12</a>.'
  ieee: 'D. Schmelter, J.-P. Steghöfer, K. Albers, M. Ekman, J. Tessmer, and R. Weber,
    “Trustful Model-Based Information Exchange in Collaborative Engineering,” in <i>Communications
    in Computer and Information Science</i>, Cham: Springer Nature Switzerland, 2023.'
  mla: Schmelter, David, et al. “Trustful Model-Based Information Exchange in Collaborative
    Engineering.” <i>Communications in Computer and Information Science</i>, Springer
    Nature Switzerland, 2023, doi:<a href="https://doi.org/10.1007/978-3-031-42307-9_12">10.1007/978-3-031-42307-9_12</a>.
  short: 'D. Schmelter, J.-P. Steghöfer, K. Albers, M. Ekman, J. Tessmer, R. Weber,
    in: Communications in Computer and Information Science, Springer Nature Switzerland,
    Cham, 2023.'
date_created: 2024-06-10T13:10:39Z
date_updated: 2024-06-10T13:17:08Z
department:
- _id: '241'
- _id: '662'
doi: 10.1007/978-3-031-42307-9_12
place: Cham
publication: Communications in Computer and Information Science
publication_identifier:
  isbn:
  - '9783031423062'
  - '9783031423079'
  issn:
  - 1865-0929
  - 1865-0937
publication_status: published
publisher: Springer Nature Switzerland
status: public
title: Trustful Model-Based Information Exchange in Collaborative Engineering
type: book_chapter
user_id: '40982'
year: '2023'
...
---
_id: '43395'
author:
- first_name: Roman
  full_name: Trentinaglia, Roman
  id: '49934'
  last_name: Trentinaglia
  orcid: 0000-0001-9728-4991
- first_name: Sven
  full_name: Merschjohann, Sven
  id: '11394'
  last_name: Merschjohann
- first_name: Markus
  full_name: Fockel, Markus
  id: '8472'
  last_name: Fockel
  orcid: 0000-0002-1269-0702
- first_name: Hendrik
  full_name: Eikerling, Hendrik
  id: '29279'
  last_name: Eikerling
citation:
  ama: 'Trentinaglia R, Merschjohann S, Fockel M, Eikerling H. Eliciting Security
    Requirements – An Experience Report. In: <i>REFSQ 2023: Requirements Engineering:
    Foundation for Software Quality</i>. Springer Nature Switzerland; 2023. doi:<a
    href="https://doi.org/10.1007/978-3-031-29786-1_25">10.1007/978-3-031-29786-1_25</a>'
  apa: 'Trentinaglia, R., Merschjohann, S., Fockel, M., &#38; Eikerling, H. (2023).
    Eliciting Security Requirements – An Experience Report. <i>REFSQ 2023: Requirements
    Engineering: Foundation for Software Quality</i>. <a href="https://doi.org/10.1007/978-3-031-29786-1_25">https://doi.org/10.1007/978-3-031-29786-1_25</a>'
  bibtex: '@inproceedings{Trentinaglia_Merschjohann_Fockel_Eikerling_2023, place={Cham},
    title={Eliciting Security Requirements – An Experience Report}, DOI={<a href="https://doi.org/10.1007/978-3-031-29786-1_25">10.1007/978-3-031-29786-1_25</a>},
    booktitle={REFSQ 2023: Requirements Engineering: Foundation for Software Quality},
    publisher={Springer Nature Switzerland}, author={Trentinaglia, Roman and Merschjohann,
    Sven and Fockel, Markus and Eikerling, Hendrik}, year={2023} }'
  chicago: 'Trentinaglia, Roman, Sven Merschjohann, Markus Fockel, and Hendrik Eikerling.
    “Eliciting Security Requirements – An Experience Report.” In <i>REFSQ 2023: Requirements
    Engineering: Foundation for Software Quality</i>. Cham: Springer Nature Switzerland,
    2023. <a href="https://doi.org/10.1007/978-3-031-29786-1_25">https://doi.org/10.1007/978-3-031-29786-1_25</a>.'
  ieee: 'R. Trentinaglia, S. Merschjohann, M. Fockel, and H. Eikerling, “Eliciting
    Security Requirements – An Experience Report,” 2023, doi: <a href="https://doi.org/10.1007/978-3-031-29786-1_25">10.1007/978-3-031-29786-1_25</a>.'
  mla: 'Trentinaglia, Roman, et al. “Eliciting Security Requirements – An Experience
    Report.” <i>REFSQ 2023: Requirements Engineering: Foundation for Software Quality</i>,
    Springer Nature Switzerland, 2023, doi:<a href="https://doi.org/10.1007/978-3-031-29786-1_25">10.1007/978-3-031-29786-1_25</a>.'
  short: 'R. Trentinaglia, S. Merschjohann, M. Fockel, H. Eikerling, in: REFSQ 2023:
    Requirements Engineering: Foundation for Software Quality, Springer Nature Switzerland,
    Cham, 2023.'
date_created: 2023-04-04T12:47:31Z
date_updated: 2023-04-04T12:51:41Z
department:
- _id: '241'
- _id: '662'
doi: 10.1007/978-3-031-29786-1_25
language:
- iso: eng
place: Cham
publication: 'REFSQ 2023: Requirements Engineering: Foundation for Software Quality'
publication_identifier:
  isbn:
  - '9783031297854'
  - '9783031297861'
  issn:
  - 0302-9743
  - 1611-3349
publication_status: published
publisher: Springer Nature Switzerland
status: public
title: Eliciting Security Requirements – An Experience Report
type: conference
user_id: '8472'
year: '2023'
...
---
_id: '41812'
author:
- first_name: Linghui
  full_name: Luo, Linghui
  last_name: Luo
- first_name: Goran
  full_name: Piskachev, Goran
  id: '41936'
  last_name: Piskachev
  orcid: 0000-0003-4424-5838
- first_name: Ranjith
  full_name: Krishnamurthy, Ranjith
  id: '78060'
  last_name: Krishnamurthy
  orcid: 0000-0002-0906-5463
- first_name: Julian
  full_name: Dolby, Julian
  last_name: Dolby
- first_name: Martin
  full_name: Schäf, Martin
  last_name: Schäf
- first_name: Eric
  full_name: Bodden, Eric
  id: '59256'
  last_name: Bodden
  orcid: 0000-0003-3470-3647
citation:
  ama: 'Luo L, Piskachev G, Krishnamurthy R, Dolby J, Schäf M, Bodden E. Model Generation
    For Java Frameworks. In: <i>IEEE International Conference on Software Testing,
    Verification and Validation (ICST)</i>. ; 2023.'
  apa: Luo, L., Piskachev, G., Krishnamurthy, R., Dolby, J., Schäf, M., &#38; Bodden,
    E. (2023). Model Generation For Java Frameworks. <i>IEEE International Conference
    on Software Testing, Verification and Validation (ICST)</i>.
  bibtex: '@inproceedings{Luo_Piskachev_Krishnamurthy_Dolby_Schäf_Bodden_2023, title={Model
    Generation For Java Frameworks}, booktitle={IEEE International Conference on Software
    Testing, Verification and Validation (ICST)}, author={Luo, Linghui and Piskachev,
    Goran and Krishnamurthy, Ranjith and Dolby, Julian and Schäf, Martin and Bodden,
    Eric}, year={2023} }'
  chicago: Luo, Linghui, Goran Piskachev, Ranjith Krishnamurthy, Julian Dolby, Martin
    Schäf, and Eric Bodden. “Model Generation For Java Frameworks.” In <i>IEEE International
    Conference on Software Testing, Verification and Validation (ICST)</i>, 2023.
  ieee: L. Luo, G. Piskachev, R. Krishnamurthy, J. Dolby, M. Schäf, and E. Bodden,
    “Model Generation For Java Frameworks,” 2023.
  mla: Luo, Linghui, et al. “Model Generation For Java Frameworks.” <i>IEEE International
    Conference on Software Testing, Verification and Validation (ICST)</i>, 2023.
  short: 'L. Luo, G. Piskachev, R. Krishnamurthy, J. Dolby, M. Schäf, E. Bodden, in:
    IEEE International Conference on Software Testing, Verification and Validation
    (ICST), 2023.'
date_created: 2023-02-06T10:37:23Z
date_updated: 2025-04-07T10:15:08Z
department:
- _id: '76'
- _id: '662'
language:
- iso: eng
publication: IEEE International Conference on Software Testing, Verification and Validation
  (ICST)
status: public
title: Model Generation For Java Frameworks
type: conference
user_id: '15249'
year: '2023'
...
---
_id: '29847'
author:
- first_name: Markus
  full_name: Fockel, Markus
  id: '8472'
  last_name: Fockel
  orcid: 0000-0002-1269-0702
- first_name: David
  full_name: Schubert, David
  id: '9106'
  last_name: Schubert
- first_name: Roman
  full_name: Trentinaglia, Roman
  id: '49934'
  last_name: Trentinaglia
  orcid: 0000-0001-9728-4991
- first_name: Hannes
  full_name: Schulz, Hannes
  last_name: Schulz
- first_name: Wolfgang
  full_name: Kirmair, Wolfgang
  last_name: Kirmair
citation:
  ama: 'Fockel M, Schubert D, Trentinaglia R, Schulz H, Kirmair W. Semi-automatic
    Integrated Safety and Security Analysis for Automotive Systems. In: <i>Proceedings
    of the 10th International Conference on Model-Driven Engineering and Software
    Development</i>. SCITEPRESS - Science and Technology Publications; 2022. doi:<a
    href="https://doi.org/10.5220/0010778500003119">10.5220/0010778500003119</a>'
  apa: Fockel, M., Schubert, D., Trentinaglia, R., Schulz, H., &#38; Kirmair, W. (2022).
    Semi-automatic Integrated Safety and Security Analysis for Automotive Systems.
    <i>Proceedings of the 10th International Conference on Model-Driven Engineering
    and Software Development</i>. <a href="https://doi.org/10.5220/0010778500003119">https://doi.org/10.5220/0010778500003119</a>
  bibtex: '@inproceedings{Fockel_Schubert_Trentinaglia_Schulz_Kirmair_2022, title={Semi-automatic
    Integrated Safety and Security Analysis for Automotive Systems}, DOI={<a href="https://doi.org/10.5220/0010778500003119">10.5220/0010778500003119</a>},
    booktitle={Proceedings of the 10th International Conference on Model-Driven Engineering
    and Software Development}, publisher={SCITEPRESS - Science and Technology Publications},
    author={Fockel, Markus and Schubert, David and Trentinaglia, Roman and Schulz,
    Hannes and Kirmair, Wolfgang}, year={2022} }'
  chicago: Fockel, Markus, David Schubert, Roman Trentinaglia, Hannes Schulz, and
    Wolfgang Kirmair. “Semi-Automatic Integrated Safety and Security Analysis for
    Automotive Systems.” In <i>Proceedings of the 10th International Conference on
    Model-Driven Engineering and Software Development</i>. SCITEPRESS - Science and
    Technology Publications, 2022. <a href="https://doi.org/10.5220/0010778500003119">https://doi.org/10.5220/0010778500003119</a>.
  ieee: 'M. Fockel, D. Schubert, R. Trentinaglia, H. Schulz, and W. Kirmair, “Semi-automatic
    Integrated Safety and Security Analysis for Automotive Systems,” 2022, doi: <a
    href="https://doi.org/10.5220/0010778500003119">10.5220/0010778500003119</a>.'
  mla: Fockel, Markus, et al. “Semi-Automatic Integrated Safety and Security Analysis
    for Automotive Systems.” <i>Proceedings of the 10th International Conference on
    Model-Driven Engineering and Software Development</i>, SCITEPRESS - Science and
    Technology Publications, 2022, doi:<a href="https://doi.org/10.5220/0010778500003119">10.5220/0010778500003119</a>.
  short: 'M. Fockel, D. Schubert, R. Trentinaglia, H. Schulz, W. Kirmair, in: Proceedings
    of the 10th International Conference on Model-Driven Engineering and Software
    Development, SCITEPRESS - Science and Technology Publications, 2022.'
date_created: 2022-02-15T08:07:15Z
date_updated: 2022-02-15T08:14:07Z
department:
- _id: '241'
- _id: '662'
doi: 10.5220/0010778500003119
language:
- iso: eng
publication: Proceedings of the 10th International Conference on Model-Driven Engineering
  and Software Development
publication_status: published
publisher: SCITEPRESS - Science and Technology Publications
status: public
title: Semi-automatic Integrated Safety and Security Analysis for Automotive Systems
type: conference
user_id: '49934'
year: '2022'
...
---
_id: '29844'
author:
- first_name: Thorsten
  full_name: Koch, Thorsten
  id: '13616'
  last_name: Koch
- first_name: Sascha
  full_name: Trippel, Sascha
  last_name: Trippel
- first_name: Stefan
  full_name: Dziwok, Stefan
  id: '3901'
  last_name: Dziwok
  orcid: http://orcid.org/0000-0002-8679-6673
- first_name: Eric
  full_name: Bodden, Eric
  id: '59256'
  last_name: Bodden
  orcid: 0000-0003-3470-3647
citation:
  ama: 'Koch T, Trippel S, Dziwok S, Bodden E. Integrating Security Protocols in Scenario-based
    Requirements Specifications. In: <i>Proceedings of the 10th International Conference
    on Model-Driven Engineering and Software Development</i>. SCITEPRESS - Science
    and Technology Publications; 2022. doi:<a href="https://doi.org/10.5220/0010783300003119">10.5220/0010783300003119</a>'
  apa: Koch, T., Trippel, S., Dziwok, S., &#38; Bodden, E. (2022). Integrating Security
    Protocols in Scenario-based Requirements Specifications. <i>Proceedings of the
    10th International Conference on Model-Driven Engineering and Software Development</i>.
    <a href="https://doi.org/10.5220/0010783300003119">https://doi.org/10.5220/0010783300003119</a>
  bibtex: '@inproceedings{Koch_Trippel_Dziwok_Bodden_2022, title={Integrating Security
    Protocols in Scenario-based Requirements Specifications}, DOI={<a href="https://doi.org/10.5220/0010783300003119">10.5220/0010783300003119</a>},
    booktitle={Proceedings of the 10th International Conference on Model-Driven Engineering
    and Software Development}, publisher={SCITEPRESS - Science and Technology Publications},
    author={Koch, Thorsten and Trippel, Sascha and Dziwok, Stefan and Bodden, Eric},
    year={2022} }'
  chicago: Koch, Thorsten, Sascha Trippel, Stefan Dziwok, and Eric Bodden. “Integrating
    Security Protocols in Scenario-Based Requirements Specifications.” In <i>Proceedings
    of the 10th International Conference on Model-Driven Engineering and Software
    Development</i>. SCITEPRESS - Science and Technology Publications, 2022. <a href="https://doi.org/10.5220/0010783300003119">https://doi.org/10.5220/0010783300003119</a>.
  ieee: 'T. Koch, S. Trippel, S. Dziwok, and E. Bodden, “Integrating Security Protocols
    in Scenario-based Requirements Specifications,” 2022, doi: <a href="https://doi.org/10.5220/0010783300003119">10.5220/0010783300003119</a>.'
  mla: Koch, Thorsten, et al. “Integrating Security Protocols in Scenario-Based Requirements
    Specifications.” <i>Proceedings of the 10th International Conference on Model-Driven
    Engineering and Software Development</i>, SCITEPRESS - Science and Technology
    Publications, 2022, doi:<a href="https://doi.org/10.5220/0010783300003119">10.5220/0010783300003119</a>.
  short: 'T. Koch, S. Trippel, S. Dziwok, E. Bodden, in: Proceedings of the 10th International
    Conference on Model-Driven Engineering and Software Development, SCITEPRESS -
    Science and Technology Publications, 2022.'
date_created: 2022-02-15T07:47:51Z
date_updated: 2022-02-15T07:48:53Z
department:
- _id: '241'
- _id: '662'
doi: 10.5220/0010783300003119
language:
- iso: eng
publication: Proceedings of the 10th International Conference on Model-Driven Engineering
  and Software Development
publication_status: published
publisher: SCITEPRESS - Science and Technology Publications
status: public
title: Integrating Security Protocols in Scenario-based Requirements Specifications
type: conference
user_id: '13616'
year: '2022'
...
---
_id: '31071'
abstract:
- lang: eng
  text: Distributed, software-intensive systems (e.g., in the automotive sector) must
    fulfill communication requirements under hard real-time constraints.  The requirements
    have to be documented and validated carefully using a systematic requirements
    engineering (RE) approach, for example, by applying scenario-based requirements
    notations. The resources of the execution platforms and their properties (e.g.,
    CPU frequency or bus throughput) induce effects on the timing behavior, which
    may lead to violations of the real-time requirements. Nowadays, the platform properties
    and their induced timing effects are verified against the real-time requirements
    by means of timing analysis techniques mostly implemented in commercial-off-the-shelf
    tools. However, such timing analyses are conducted in late development phases
    since they rely on artifacts produced during these phases (e.g., the platform-specific
    code). In order to enable early timing analyses already during RE, we extend a
    scenario-based requirements notation with allocation means to platform models
    and define operational semantics for the purpose of simulation-based, platform-aware
    timing analyses. We illustrate and evaluate the approach with an automotive software-intensive
    system.
author:
- first_name: Jörg
  full_name: Holtmann, Jörg
  id: '3875'
  last_name: Holtmann
  orcid: 0000-0001-6141-4571
- first_name: Julien
  full_name: Deantoni, Julien
  last_name: Deantoni
- first_name: Markus
  full_name: Fockel, Markus
  id: '8472'
  last_name: Fockel
  orcid: 0000-0002-1269-0702
citation:
  ama: Holtmann J, Deantoni J, Fockel M. Early timing analysis based on scenario requirements
    and platform models. <i>Software and Systems Modeling</i>. Published online 2022.
    doi:<a href="https://doi.org/10.1007/s10270-022-01002-3">10.1007/s10270-022-01002-3</a>
  apa: Holtmann, J., Deantoni, J., &#38; Fockel, M. (2022). Early timing analysis
    based on scenario requirements and platform models. <i>Software and Systems Modeling</i>.
    <a href="https://doi.org/10.1007/s10270-022-01002-3">https://doi.org/10.1007/s10270-022-01002-3</a>
  bibtex: '@article{Holtmann_Deantoni_Fockel_2022, title={Early timing analysis based
    on scenario requirements and platform models}, DOI={<a href="https://doi.org/10.1007/s10270-022-01002-3">10.1007/s10270-022-01002-3</a>},
    journal={Software and Systems Modeling}, publisher={Springer Science and Business
    Media LLC}, author={Holtmann, Jörg and Deantoni, Julien and Fockel, Markus}, year={2022}
    }'
  chicago: Holtmann, Jörg, Julien Deantoni, and Markus Fockel. “Early Timing Analysis
    Based on Scenario Requirements and Platform Models.” <i>Software and Systems Modeling</i>,
    2022. <a href="https://doi.org/10.1007/s10270-022-01002-3">https://doi.org/10.1007/s10270-022-01002-3</a>.
  ieee: 'J. Holtmann, J. Deantoni, and M. Fockel, “Early timing analysis based on
    scenario requirements and platform models,” <i>Software and Systems Modeling</i>,
    2022, doi: <a href="https://doi.org/10.1007/s10270-022-01002-3">10.1007/s10270-022-01002-3</a>.'
  mla: Holtmann, Jörg, et al. “Early Timing Analysis Based on Scenario Requirements
    and Platform Models.” <i>Software and Systems Modeling</i>, Springer Science and
    Business Media LLC, 2022, doi:<a href="https://doi.org/10.1007/s10270-022-01002-3">10.1007/s10270-022-01002-3</a>.
  short: J. Holtmann, J. Deantoni, M. Fockel, Software and Systems Modeling (2022).
date_created: 2022-05-05T14:05:32Z
date_updated: 2022-05-05T14:09:41Z
department:
- _id: '241'
- _id: '662'
doi: 10.1007/s10270-022-01002-3
keyword:
- Modeling and Simulation
- Software
language:
- iso: eng
publication: Software and Systems Modeling
publication_identifier:
  issn:
  - 1619-1366
  - 1619-1374
publication_status: published
publisher: Springer Science and Business Media LLC
status: public
title: Early timing analysis based on scenario requirements and platform models
type: journal_article
user_id: '8472'
year: '2022'
...
---
_id: '33836'
author:
- first_name: Goran
  full_name: Piskachev, Goran
  id: '41936'
  last_name: Piskachev
  orcid: 0000-0003-4424-5838
- first_name: Johannes
  full_name: Späth, Johannes
  last_name: Späth
- first_name: Ingo
  full_name: Budde, Ingo
  id: '13693'
  last_name: Budde
  orcid: https://orcid.org/0000-0003-0124-6291
- first_name: Eric
  full_name: Bodden, Eric
  id: '59256'
  last_name: Bodden
  orcid: 0000-0003-3470-3647
citation:
  ama: Piskachev G, Späth J, Budde I, Bodden E. Fluently specifying taint-flow queries
    with fluentTQL. <i>Empirical Software Engineering</i>. 2022;27(5):1–33.
  apa: Piskachev, G., Späth, J., Budde, I., &#38; Bodden, E. (2022). Fluently specifying
    taint-flow queries with fluentTQL. <i>Empirical Software Engineering</i>, <i>27</i>(5),
    1–33.
  bibtex: '@article{Piskachev_Späth_Budde_Bodden_2022, title={Fluently specifying
    taint-flow queries with fluentTQL}, volume={27}, number={5}, journal={Empirical
    Software Engineering}, publisher={Springer}, author={Piskachev, Goran and Späth,
    Johannes and Budde, Ingo and Bodden, Eric}, year={2022}, pages={1–33} }'
  chicago: 'Piskachev, Goran, Johannes Späth, Ingo Budde, and Eric Bodden. “Fluently
    Specifying Taint-Flow Queries with FluentTQL.” <i>Empirical Software Engineering</i>
    27, no. 5 (2022): 1–33.'
  ieee: G. Piskachev, J. Späth, I. Budde, and E. Bodden, “Fluently specifying taint-flow
    queries with fluentTQL,” <i>Empirical Software Engineering</i>, vol. 27, no. 5,
    pp. 1–33, 2022.
  mla: Piskachev, Goran, et al. “Fluently Specifying Taint-Flow Queries with FluentTQL.”
    <i>Empirical Software Engineering</i>, vol. 27, no. 5, Springer, 2022, pp. 1–33.
  short: G. Piskachev, J. Späth, I. Budde, E. Bodden, Empirical Software Engineering
    27 (2022) 1–33.
date_created: 2022-10-20T12:34:04Z
date_updated: 2022-10-20T12:36:23Z
department:
- _id: '76'
- _id: '662'
intvolume: '        27'
issue: '5'
language:
- iso: eng
page: 1–33
publication: Empirical Software Engineering
publisher: Springer
status: public
title: Fluently specifying taint-flow queries with fluentTQL
type: journal_article
user_id: '15249'
volume: 27
year: '2022'
...
---
_id: '33838'
author:
- first_name: Ranjith
  full_name: Krishnamurthy, Ranjith
  id: '78060'
  last_name: Krishnamurthy
  orcid: 0000-0002-0906-5463
- first_name: Goran
  full_name: Piskachev, Goran
  id: '41936'
  last_name: Piskachev
  orcid: 0000-0003-4424-5838
- first_name: Eric
  full_name: Bodden, Eric
  id: '59256'
  last_name: Bodden
  orcid: 0000-0003-3470-3647
citation:
  ama: Krishnamurthy R, Piskachev G, Bodden E. To what extent can we analyze Kotlin
    programs using existing Java taint analysis tools? Published online 2022.
  apa: Krishnamurthy, R., Piskachev, G., &#38; Bodden, E. (2022). <i>To what extent
    can we analyze Kotlin programs using existing Java taint analysis tools?</i>
  bibtex: '@article{Krishnamurthy_Piskachev_Bodden_2022, series={IEEE International
    Working Conference on Source Code Analysis and Manipulation (SCAM)}, title={To
    what extent can we analyze Kotlin programs using existing Java taint analysis
    tools?}, author={Krishnamurthy, Ranjith and Piskachev, Goran and Bodden, Eric},
    year={2022}, collection={IEEE International Working Conference on Source Code
    Analysis and Manipulation (SCAM)} }'
  chicago: Krishnamurthy, Ranjith, Goran Piskachev, and Eric Bodden. “To What Extent
    Can We Analyze Kotlin Programs Using Existing Java Taint Analysis Tools?” IEEE
    International Working Conference on Source Code Analysis and Manipulation (SCAM),
    2022.
  ieee: R. Krishnamurthy, G. Piskachev, and E. Bodden, “To what extent can we analyze
    Kotlin programs using existing Java taint analysis tools?” 2022.
  mla: Krishnamurthy, Ranjith, et al. <i>To What Extent Can We Analyze Kotlin Programs
    Using Existing Java Taint Analysis Tools?</i> 2022.
  short: R. Krishnamurthy, G. Piskachev, E. Bodden, (2022).
date_created: 2022-10-20T12:38:09Z
date_updated: 2022-10-20T12:38:32Z
department:
- _id: '76'
- _id: '662'
language:
- iso: eng
series_title: IEEE International Working Conference on Source Code Analysis and Manipulation
  (SCAM)
status: public
title: To what extent can we analyze Kotlin programs using existing Java taint analysis
  tools?
type: conference
user_id: '15249'
year: '2022'
...
---
_id: '33837'
author:
- first_name: Goran
  full_name: Piskachev, Goran
  id: '41936'
  last_name: Piskachev
  orcid: 0000-0003-4424-5838
- first_name: Stefan
  full_name: Dziwok, Stefan
  id: '3901'
  last_name: Dziwok
  orcid: http://orcid.org/0000-0002-8679-6673
- first_name: Thorsten
  full_name: Koch, Thorsten
  id: '13616'
  last_name: Koch
- first_name: Sven
  full_name: Merschjohann, Sven
  id: '11394'
  last_name: Merschjohann
- first_name: Eric
  full_name: Bodden, Eric
  id: '59256'
  last_name: Bodden
  orcid: 0000-0003-3470-3647
citation:
  ama: Piskachev G, Dziwok S, Koch T, Merschjohann S, Bodden E. How far are German
    companies in improving security through static program analysis tools? Published
    online 2022.
  apa: Piskachev, G., Dziwok, S., Koch, T., Merschjohann, S., &#38; Bodden, E. (2022).
    <i>How far are German companies in improving security through static program analysis
    tools?</i>
  bibtex: '@article{Piskachev_Dziwok_Koch_Merschjohann_Bodden_2022, series={IEEE Secure
    Development Conference (SecDev)}, title={How far are German companies in improving
    security through static program analysis tools?}, author={Piskachev, Goran and
    Dziwok, Stefan and Koch, Thorsten and Merschjohann, Sven and Bodden, Eric}, year={2022},
    collection={IEEE Secure Development Conference (SecDev)} }'
  chicago: Piskachev, Goran, Stefan Dziwok, Thorsten Koch, Sven Merschjohann, and
    Eric Bodden. “How Far Are German Companies in Improving Security through Static
    Program Analysis Tools?” IEEE Secure Development Conference (SecDev), 2022.
  ieee: G. Piskachev, S. Dziwok, T. Koch, S. Merschjohann, and E. Bodden, “How far
    are German companies in improving security through static program analysis tools?”
    2022.
  mla: Piskachev, Goran, et al. <i>How Far Are German Companies in Improving Security
    through Static Program Analysis Tools?</i> 2022.
  short: G. Piskachev, S. Dziwok, T. Koch, S. Merschjohann, E. Bodden, (2022).
date_created: 2022-10-20T12:37:14Z
date_updated: 2022-10-20T12:37:44Z
department:
- _id: '76'
- _id: '662'
language:
- iso: eng
series_title: IEEE Secure Development Conference (SecDev)
status: public
title: How far are German companies in improving security through static program analysis
  tools?
type: conference
user_id: '15249'
year: '2022'
...
