{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T18:25:38Z","timestamp":1771611938038,"version":"3.50.1"},"reference-count":122,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2020,3,20]],"date-time":"2020-03-20T00:00:00Z","timestamp":1584662400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100008530","name":"European Regional Development Fund","doi-asserted-by":"crossref","award":["Centro-01-0145-FEDER-000019"],"award-info":[{"award-number":["Centro-01-0145-FEDER-000019"]}],"id":[{"id":"10.13039\/501100008530","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Funda\u00e7\u00e3o para a Ci\u00eancia e a Tecnologia","award":["SFRH\/BD\/133838\/2017,BIM\/n\u00b0\u00e732\/2018-B00582,UID\/EEA\/50008\/2019, POCI-01-0145-FEDER- 030657"],"award-info":[{"award-number":["SFRH\/BD\/133838\/2017,BIM\/n\u00b0\u00e732\/2018-B00582,UID\/EEA\/50008\/2019, POCI-01-0145-FEDER- 030657"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2021,3,31]]},"abstract":"<jats:p>Over the years, pervasive computing and communication technologies have enabled the emergence of new computing paradigms that have gained importance across a wide spectrum of domains. The three most notable that have witnessed significant advancements and have a solid track record of exponential growth in diverse applications are the Internet of Things (IoT), Cloud, and Mobile Computing. The ubiquity of these paradigms, their expandability, and applicability in different problem spaces have made them invaluable in modern computing solutions. Security becomes a real concern, especially when it comes to the development of applications in these environments, as numerous security issues may arise from potential design flaws. Secure application development across these three technologies can only be achieved when applications and systems are designed and developed with security in mind. This will improve the quality of the solutions and ensure that vulnerabilities are identified. It will also help in defining countermeasures against cyberattacks or mitigate the effects of potential threats to the systems. This article surveys existing approaches, tools, and techniques for attack and system modeling applicable to IoT, Cloud computing, and Mobile Computing. It also evaluates the strengths and limitations of the reviewed approaches and tools, from which it highlights the main existing challenges and open issues in the area.<\/jats:p>","DOI":"10.1145\/3376123","type":"journal-article","created":{"date-parts":[[2020,3,20]],"date-time":"2020-03-20T21:04:17Z","timestamp":1584738257000},"page":"1-32","update-policy":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":54,"title":["Attack and System Modeling Applied to IoT, Cloud, and Mobile Ecosystems"],"prefix":"10.1145","volume":"53","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0001-7206-7771","authenticated-orcid":false,"given":"Jo\u00e3o B. F.","family":"Sequeiros","sequence":"first","affiliation":[{"name":"Universidade da Beira Interior and Instituto de Telecomunica\u00e7\u00f5es, Portugal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Francisco T.","family":"Chimuco","sequence":"additional","affiliation":[{"name":"Universidade da Beira Interior and Instituto de Telecomunica\u00e7\u00f5es, Portugal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Musa G.","family":"Samaila","sequence":"additional","affiliation":[{"name":"Universidade da Beira Interior and Instituto de Telecomunica\u00e7\u00f5es, Portugal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"M\u00e1rio M.","family":"Freire","sequence":"additional","affiliation":[{"name":"Universidade da Beira Interior and Instituto de Telecomunica\u00e7\u00f5es, Portugal"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pedro R. M.","family":"In\u00e1cio","sequence":"additional","affiliation":[{"name":"Universidade da Beira Interior and Instituto de Telecomunica\u00e7\u00f5es, Portugal"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,3,20]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/IBCAST.2014.6778179"},{"key":"e_1_2_1_2_1","unstructured":"U.S. Food 8 Drug Administration. 2017. Firmware Update to Address Cybersecurity Vulnerabilities Identified in Abbott\u2019s (formerly St. Jude Medical\u2019s) Implantable Cardiac Pacemakers: FDA Safety Communication. https:\/\/2.zoppoz.workers.dev:443\/https\/www.fda.gov\/medical-devices\/safety-communications\/firmware-update-address-cybersecurity-vulnerabilities-identified-abbotts-formerly-st-jude-medicals.  U.S. Food 8 Drug Administration. 2017. Firmware Update to Address Cybersecurity Vulnerabilities Identified in Abbott\u2019s (formerly St. Jude Medical\u2019s) Implantable Cardiac Pacemakers: FDA Safety Communication. https:\/\/2.zoppoz.workers.dev:443\/https\/www.fda.gov\/medical-devices\/safety-communications\/firmware-update-address-cybersecurity-vulnerabilities-identified-abbotts-formerly-st-jude-medicals."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3140241.3140252"},{"key":"e_1_2_1_4_1","first-page":"30","article-title":"A survey on smartphones security: Software vulnerabilities, malware, and attacks","volume":"8","author":"Ahvanooey Milad Taleby","year":"2017","unstructured":"Milad Taleby Ahvanooey , Qianmu Li , Mahdi Rabbani , and Ahmed Raza Rajput . 2017 . A survey on smartphones security: Software vulnerabilities, malware, and attacks . Int. J. Adv. Comput. Sci. Appl 8 , 10 (2017), 30 -- 45 . Milad Taleby Ahvanooey, Qianmu Li, Mahdi Rabbani, and Ahmed Raza Rajput. 2017. A survey on smartphones security: Software vulnerabilities, malware, and attacks. Int. J. Adv. Comput. Sci. Appl 8, 10 (2017), 30--45.","journal-title":"Int. J. Adv. Comput. Sci. Appl"},{"key":"e_1_2_1_5_1","volume-title":"Internet of Things: A survey on enabling technologies, protocols, and applications","author":"Al-Fuqaha Ala","year":"2015","unstructured":"Ala Al-Fuqaha , Mohsen Guizani , Mehdi Mohammadi , Mohammed Aledhari , and Moussa Ayyash . 2015. Internet of Things: A survey on enabling technologies, protocols, and applications . IEEE Communications Surveys 8 Tutorials 17, 4 ( 2015 ), 2347--2376. Ala Al-Fuqaha, Mohsen Guizani, Mehdi Mohammadi, Mohammed Aledhari, and Moussa Ayyash. 2015. Internet of Things: A survey on enabling technologies, protocols, and applications. IEEE Communications Surveys 8 Tutorials 17, 4 (2015), 2347--2376."},{"key":"e_1_2_1_6_1","volume-title":"Cyber-Attack Modeling Analysis Techniques: An Overview","author":"Al-Mohannadi Hamad","unstructured":"Hamad Al-Mohannadi , Qublai Mirza , Anitta Namanya , Irfan Awan , Andrea Cullen , and Jules Disso . 2016. Cyber-Attack Modeling Analysis Techniques: An Overview . https:\/\/2.zoppoz.workers.dev:443\/http\/hdl.handle.net\/10454\/10703 Accessed: 2018-07-15. Hamad Al-Mohannadi, Qublai Mirza, Anitta Namanya, Irfan Awan, Andrea Cullen, and Jules Disso. 2016. Cyber-Attack Modeling Analysis Techniques: An Overview. https:\/\/2.zoppoz.workers.dev:443\/http\/hdl.handle.net\/10454\/10703 Accessed: 2018-07-15."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/CyberC.2017.37"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.3923\/jas.2015.953.967"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC.2015.7405513"},{"key":"e_1_2_1_10_1","unstructured":"Manos Antonakakis Tim April Michael Bailey Matt Bernhard Elie Bursztein Jaime Cochran Zakir Durumeric J. Alex Halderman Luca Invernizzi Michalis Kallitsis etal 2017. Understanding the Mirai Botnet. In 26th {USENIX} Security Symposium ({USENIX} Security 17). 1093--1110.  Manos Antonakakis Tim April Michael Bailey Matt Bernhard Elie Bursztein Jaime Cochran Zakir Durumeric J. Alex Halderman Luca Invernizzi Michalis Kallitsis et al. 2017. Understanding the Mirai Botnet. In 26th {USENIX} Security Symposium ({USENIX} Security 17). 1093--1110."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/MISE.2012.6226014"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1721654.1721672"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2014.11.011"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14478-3_42"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2011.2"},{"key":"e_1_2_1_16_1","volume-title":"Article 22 (Feb.","author":"Bergmayr Alexander","year":"2018","unstructured":"Alexander Bergmayr , Uwe Breitenb\u00fccher , Nicolas Ferry , Alessandro Rossini , Arnor Solberg , Manuel Wimmer , Gerti Kappel , and Frank Leymann . 2018. A systematic review of cloud modeling languages. ACM Comput. Surv. 51, 1 , Article 22 (Feb. 2018 ), 38 pages. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3150227 10.1145\/3150227 Alexander Bergmayr, Uwe Breitenb\u00fccher, Nicolas Ferry, Alessandro Rossini, Arnor Solberg, Manuel Wimmer, Gerti Kappel, and Frank Leymann. 2018. A systematic review of cloud modeling languages. ACM Comput. Surv. 51, 1, Article 22 (Feb. 2018), 38 pages. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3150227"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2017.62"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CIC.2017.00022"},{"key":"e_1_2_1_19_1","volume-title":"7th International Workshop on the Web of Things. ACM, 38--41","author":"Breiner Spencer","unstructured":"Spencer Breiner , Eswaran Subrahmanian , and Ram D. Sriram . 2016. Modeling the Internet of Things: A foundational approach . In 7th International Workshop on the Web of Things. ACM, 38--41 . Spencer Breiner, Eswaran Subrahmanian, and Ram D. Sriram. 2016. Modeling the Internet of Things: A foundational approach. In 7th International Workshop on the Web of Things. ACM, 38--41."},{"key":"e_1_2_1_20_1","volume-title":"Security of the Internet of Things: Vulnerabilities, attacks and countermeasures","author":"Butun Ismail","year":"2019","unstructured":"Ismail Butun , Patrik \u00d6sterberg , and Houbing Song . 2019. Security of the Internet of Things: Vulnerabilities, attacks and countermeasures . IEEE Communications Surveys 8 Tutorials ( 2019 ). Ismail Butun, Patrik \u00d6sterberg, and Houbing Song. 2019. Security of the Internet of Things: Vulnerabilities, attacks and countermeasures. IEEE Communications Surveys 8 Tutorials (2019)."},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCE.2019.8661909"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECCOM.2007.4550338"},{"key":"e_1_2_1_23_1","volume-title":"A History of Modern Computing","author":"Ceruzzi Paul E.","unstructured":"Paul E. Ceruzzi . 2003. A History of Modern Computing . MIT press . Paul E. Ceruzzi. 2003. A History of Modern Computing. MIT press."},{"key":"e_1_2_1_24_1","volume-title":"High-level modeling and synthesis of smart sensor networks for Industrial Internet of Things. Computers 8 Electrical Engineering 61","author":"Chen Ching-Han","year":"2017","unstructured":"Ching-Han Chen , Ming-Yi Lin , and Xing-Chen Guo . 2017. High-level modeling and synthesis of smart sensor networks for Industrial Internet of Things. Computers 8 Electrical Engineering 61 ( 2017 ), 48--66. Ching-Han Chen, Ming-Yi Lin, and Xing-Chen Guo. 2017. High-level modeling and synthesis of smart sensor networks for Industrial Internet of Things. Computers 8 Electrical Engineering 61 (2017), 48--66."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2016.2584538"},{"key":"e_1_2_1_26_1","unstructured":"Farida Chowdhury and Md Sadek Ferdous. [n.d.]. MODELLING CYBER ATTACKS. ([n.d.]).  Farida Chowdhury and Md Sadek Ferdous. [n.d.]. MODELLING CYBER ATTACKS. ([n.d.])."},{"key":"e_1_2_1_27_1","volume-title":"Cisco IoT Reference Model","unstructured":"Cisco. 2014. Cisco IoT Reference Model . https:\/\/2.zoppoz.workers.dev:443\/http\/cdn.iotwf.com\/resources\/72\/IoT_Reference_Model_04_June_2014.pdf. Accessed: 2018-06-24. Cisco. 2014. Cisco IoT Reference Model. https:\/\/2.zoppoz.workers.dev:443\/http\/cdn.iotwf.com\/resources\/72\/IoT_Reference_Model_04_June_2014.pdf. Accessed: 2018-06-24."},{"key":"e_1_2_1_28_1","volume-title":"Seguran\u00e7a no Software","author":"Correia Miguel Pupo","unstructured":"Miguel Pupo Correia and Paulo Jorge Sousa . 2017. Seguran\u00e7a no Software ( 2 nd ed.). FCA - Editora da Inform\u00e1tica, Lda . Miguel Pupo Correia and Paulo Jorge Sousa. 2017. Seguran\u00e7a no Software (2nd ed.). FCA - Editora da Inform\u00e1tica, Lda.","edition":"2"},{"key":"e_1_2_1_29_1","unstructured":"Cloud Standards Customer Council. 2015. Cloud Customer Architecture for Mobile. https:\/\/2.zoppoz.workers.dev:443\/https\/www.omg.org\/cloud\/deliverables\/cloud-customer-architecture-for-mobile.htm. Accessed: 2019-02-15.  Cloud Standards Customer Council. 2015. Cloud Customer Architecture for Mobile. https:\/\/2.zoppoz.workers.dev:443\/https\/www.omg.org\/cloud\/deliverables\/cloud-customer-architecture-for-mobile.htm. Accessed: 2019-02-15."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2008.60"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2014.2300753"},{"key":"e_1_2_1_32_1","volume-title":"2011 Proceedings of the 34th International Convention MIPRO. 1468--1473","author":"Delac G.","unstructured":"G. Delac , M. Silic , and J. Krolo . 2011. Emerging security threats for mobile platforms . In 2011 Proceedings of the 34th International Convention MIPRO. 1468--1473 . G. Delac, M. Silic, and J. Krolo. 2011. Emerging security threats for mobile platforms. In 2011 Proceedings of the 34th International Convention MIPRO. 1468--1473."},{"key":"e_1_2_1_33_1","volume-title":"Proceedings of the Conference on the Future of Software Engineering (ICSE\u201900)","author":"Premkumar","unstructured":"Premkumar T. Devanbu and Stuart Stubblebine. 2000. Software engineering for security: A roadmap . In Proceedings of the Conference on the Future of Software Engineering (ICSE\u201900) . ACM, New York, NY, USA, 227--239. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/336512.336559 10.1145\/336512.336559 Premkumar T. Devanbu and Stuart Stubblebine. 2000. Software engineering for security: A roadmap. In Proceedings of the Conference on the Future of Software Engineering (ICSE\u201900). ACM, New York, NY, USA, 227--239. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/336512.336559"},{"key":"e_1_2_1_34_1","unstructured":"Mark Dowd John McDonald and Justin Schuh. 2006. The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities. Pearson Education.  Mark Dowd John McDonald and Justin Schuh. 2006. The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities. Pearson Education."},{"key":"e_1_2_1_35_1","volume-title":"IoT cloud, fog, mobile edge, and edge emerging computing paradigms: Disambiguation and research directions. Journal of Network and Computer Applications","author":"Elazhary Hanan","year":"2018","unstructured":"Hanan Elazhary . 2018. Internet of Things (IoT), mobile cloud, cloudlet, mobile IoT , IoT cloud, fog, mobile edge, and edge emerging computing paradigms: Disambiguation and research directions. Journal of Network and Computer Applications ( 2018 ). Hanan Elazhary. 2018. Internet of Things (IoT), mobile cloud, cloudlet, mobile IoT, IoT cloud, fog, mobile edge, and edge emerging computing paradigms: Disambiguation and research directions. Journal of Network and Computer Applications (2018)."},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/s12193-013-0126-z"},{"key":"e_1_2_1_37_1","unstructured":"F-Secure. 2019. 2019 Attack Landscape Report. https:\/\/2.zoppoz.workers.dev:443\/https\/blog.f-secure.com\/attack-landscape-h1-2019-iot-smb-traffic-abound  F-Secure. 2019. 2019 Attack Landscape Report. https:\/\/2.zoppoz.workers.dev:443\/https\/blog.f-secure.com\/attack-landscape-h1-2019-iot-smb-traffic-abound"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-013-0208-7"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-73742-3_24"},{"key":"e_1_2_1_40_1","volume-title":"Modeling and simulating internet-of-things systems: A hybrid agent-oriented approach. Computing in Science 8 Engineering 19, 5","author":"Fortino Giancarlo","year":"2017","unstructured":"Giancarlo Fortino , Raffaele Gravina , Wilma Russo , and Claudio Savaglio . 2017. Modeling and simulating internet-of-things systems: A hybrid agent-oriented approach. Computing in Science 8 Engineering 19, 5 ( 2017 ), 68--76. Giancarlo Fortino, Raffaele Gravina, Wilma Russo, and Claudio Savaglio. 2017. Modeling and simulating internet-of-things systems: A hybrid agent-oriented approach. Computing in Science 8 Engineering 19, 5 (2017), 68--76."},{"key":"e_1_2_1_41_1","volume-title":"IEEE 21st International Conference on Parallel and Distributed Systems (ICPADS\u201915)","author":"Ge Mengmeng","year":"2015","unstructured":"Mengmeng Ge and Dong Seong Kim . 2015 . A framework for modeling and assessing security of the internet of things . In IEEE 21st International Conference on Parallel and Distributed Systems (ICPADS\u201915) . IEEE, 776--781. Mengmeng Ge and Dong Seong Kim. 2015. A framework for modeling and assessing security of the internet of things. In IEEE 21st International Conference on Parallel and Distributed Systems (ICPADS\u201915). IEEE, 776--781."},{"key":"e_1_2_1_42_1","unstructured":"Google. 2019. PHA Family Highlights: Triada. https:\/\/2.zoppoz.workers.dev:443\/https\/security.googleblog.com\/2019\/06\/pha-family-highlights-triada.html.  Google. 2019. PHA Family Highlights: Triada. https:\/\/2.zoppoz.workers.dev:443\/https\/security.googleblog.com\/2019\/06\/pha-family-highlights-triada.html."},{"key":"e_1_2_1_43_1","doi-asserted-by":"crossref","unstructured":"Brij Gupta Dharma P. Agrawal and Shingo Yamaguchi. 2016. Handbook of Research on Modern Cryptographic Solutions for Computer and Cyber Security. IGI global.  Brij Gupta Dharma P. Agrawal and Shingo Yamaguchi. 2016. Handbook of Research on Modern Cryptographic Solutions for Computer and Cyber Security. IGI global.","DOI":"10.4018\/978-1-5225-0105-3"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-016-2317-5"},{"key":"e_1_2_1_45_1","volume-title":"Algorithm, Applications, and Perspectives","author":"Gupta Brij B.","unstructured":"Brij B. Gupta . 2018. Computer and Cyber Security: Principles , Algorithm, Applications, and Perspectives . CRC Press . Brij B. Gupta. 2018. Computer and Cyber Security: Principles, Algorithm, Applications, and Perspectives. CRC Press."},{"key":"e_1_2_1_46_1","unstructured":"Mohammad Hamdaqa Tassos Livogiannis and Ladan Tahvildari. 2011. A reference model for developing cloud applications. In CLOSER. 98--103.  Mohammad Hamdaqa Tassos Livogiannis and Ladan Tahvildari. 2011. A reference model for developing cloud applications. In CLOSER. 98--103."},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11277-011-0385-5"},{"key":"e_1_2_1_48_1","volume-title":"Proceedings of the 28th Annual ACM Symposium on Applied Computing. ACM, 526--533","author":"Heitk\u00f6tter Henning","year":"2013","unstructured":"Henning Heitk\u00f6tter , Tim A. Majchrzak , and Herbert Kuchen . 2013 . Cross-platform model-driven development of mobile applications with MD 2 . In Proceedings of the 28th Annual ACM Symposium on Applied Computing. ACM, 526--533 . Henning Heitk\u00f6tter, Tim A. Majchrzak, and Herbert Kuchen. 2013. Cross-platform model-driven development of mobile applications with MD 2. In Proceedings of the 28th Annual ACM Symposium on Applied Computing. ACM, 526--533."},{"key":"e_1_2_1_49_1","volume-title":"A software fault tree approach to requirements analysis of an intrusion detection system. Requirements Engineering 7, 4 (1","author":"Helmer Guy","year":"2002","unstructured":"Guy Helmer , Johnny Wong , Mark Slagell , Vasant Honavar , Les Miller , and Robyn Lutz . 2002. A software fault tree approach to requirements analysis of an intrusion detection system. Requirements Engineering 7, 4 (1 Dec 2002 ), 207--220. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1007\/s007660200016 10.1007\/s007660200016 Guy Helmer, Johnny Wong, Mark Slagell, Vasant Honavar, Les Miller, and Robyn Lutz. 2002. A software fault tree approach to requirements analysis of an intrusion detection system. Requirements Engineering 7, 4 (1 Dec 2002), 207--220. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1007\/s007660200016"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2017.03.029"},{"key":"e_1_2_1_51_1","volume-title":"System Shock: How a Cloud Leak Exposed Accenture\u2019s Business. https:\/\/2.zoppoz.workers.dev:443\/https\/www.upguard.com\/breaches\/cloud-leak-accenture.","author":"Upguard Inc.","year":"2019","unstructured":"Upguard Inc. 2019 . System Shock: How a Cloud Leak Exposed Accenture\u2019s Business. https:\/\/2.zoppoz.workers.dev:443\/https\/www.upguard.com\/breaches\/cloud-leak-accenture. Upguard Inc. 2019. System Shock: How a Cloud Leak Exposed Accenture\u2019s Business. https:\/\/2.zoppoz.workers.dev:443\/https\/www.upguard.com\/breaches\/cloud-leak-accenture."},{"key":"e_1_2_1_52_1","volume-title":"Mead","author":"Ingalsbe Jeffrey A.","year":"2011","unstructured":"Jeffrey A. Ingalsbe , Dan Shoemaker , and Nancy R . Mead . 2011 . Threat modeling the cloud computing, mobile device toting, consumerized enterprise-an overview of considerations. In AMCIS. Jeffrey A. Ingalsbe, Dan Shoemaker, and Nancy R. Mead. 2011. Threat modeling the cloud computing, mobile device toting, consumerized enterprise-an overview of considerations. In AMCIS."},{"key":"e_1_2_1_53_1","volume-title":"Introduction to the Architectural Reference Model for the Internet of Things","author":"T-A.","unstructured":"Io T-A. 2013. Introduction to the Architectural Reference Model for the Internet of Things . https:\/\/2.zoppoz.workers.dev:443\/http\/iotforum.org\/wp-content\/uploads\/2014\/09\/120613-IoT-A-ARM-Book-Introduction-v7.pdf. Accessed: 2018-07-03. IoT-A. 2013. Introduction to the Architectural Reference Model for the Internet of Things. https:\/\/2.zoppoz.workers.dev:443\/http\/iotforum.org\/wp-content\/uploads\/2014\/09\/120613-IoT-A-ARM-Book-Introduction-v7.pdf. Accessed: 2018-07-03."},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2015.2437951"},{"key":"e_1_2_1_55_1","unstructured":"Ajit Jha and M. C. Sunil. 2014. Security considerations for Internet of Things. L8T Technology Services (2014).  Ajit Jha and M. C. Sunil. 2014. Security considerations for Internet of Things. L8T Technology Services (2014)."},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSUSC.2018.2793284"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2017.8170867"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/SOSE.2016.55"},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2005.06.046"},{"key":"e_1_2_1_60_1","volume-title":"18th International Conference on Advanced Communication Technology (ICACT\u201916)","author":"Kirichek Ruslan","year":"2016","unstructured":"Ruslan Kirichek , Andrei Vladyko , Maxim Zakharov , and Andrey Koucheryavy . 2016 . Model networks for Internet of Things and SDN . In 18th International Conference on Advanced Communication Technology (ICACT\u201916) . IEEE, 76--79. Ruslan Kirichek, Andrei Vladyko, Maxim Zakharov, and Andrey Koucheryavy. 2016. Model networks for Internet of Things and SDN. In 18th International Conference on Advanced Communication Technology (ICACT\u201916). IEEE, 76--79."},{"key":"e_1_2_1_61_1","volume-title":"MDA Explained: The Model Driven Architecture: Practice and Promise","author":"Kleppe Anneke G.","unstructured":"Anneke G. Kleppe , Jos Warmer , Jos B. Warmer , and Wim Bast . 2003. MDA Explained: The Model Driven Architecture: Practice and Promise . Addison-Wesley Professional . Anneke G. Kleppe, Jos Warmer, Jos B. Warmer, and Wim Bast. 2003. MDA Explained: The Model Driven Architecture: Practice and Promise. Addison-Wesley Professional."},{"key":"e_1_2_1_62_1","volume-title":"Spectre attacks: Exploiting speculative execution. arXiv preprint arXiv:1801.01203","author":"Kocher Paul","year":"2018","unstructured":"Paul Kocher , Daniel Genkin , Daniel Gruss , Werner Haas , Mike Hamburg , Moritz Lipp , Stefan Mangard , Thomas Prescher , Michael Schwarz , and Yuval Yarom . 2018. Spectre attacks: Exploiting speculative execution. arXiv preprint arXiv:1801.01203 ( 2018 ). Paul Kocher, Daniel Genkin, Daniel Gruss, Werner Haas, Mike Hamburg, Moritz Lipp, Stefan Mangard, Thomas Prescher, Michael Schwarz, and Yuval Yarom. 2018. Spectre attacks: Exploiting speculative execution. arXiv preprint arXiv:1801.01203 (2018)."},{"key":"e_1_2_1_63_1","volume-title":"5th International Conference on Cyber Conflict (CyCon\u201913)","author":"Kotenko Igor","year":"2013","unstructured":"Igor Kotenko and Andrey Chechulin . 2013 . A cyber attack modeling and impact assessment framework . In 5th International Conference on Cyber Conflict (CyCon\u201913) . IEEE, 1--24. Igor Kotenko and Andrey Chechulin. 2013. A cyber attack modeling and impact assessment framework. In 5th International Conference on Cyber Conflict (CyCon\u201913). IEEE, 1--24."},{"key":"e_1_2_1_64_1","unstructured":"AO Kaspersky Lab. 2016. Kaspersky Threats - Triada. https:\/\/2.zoppoz.workers.dev:443\/https\/threats.kaspersky.com\/en\/threat\/Trojan.AndroidOS.Triada\/.  AO Kaspersky Lab. 2016. Kaspersky Threats - Triada. https:\/\/2.zoppoz.workers.dev:443\/https\/threats.kaspersky.com\/en\/threat\/Trojan.AndroidOS.Triada\/."},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/JETCAS.2013.2243032"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2016.06.019"},{"key":"e_1_2_1_67_1","article-title":"Threat modeling and countermeasures study for the Internet of Things","volume":"8","author":"Li Zhang","year":"2013","unstructured":"Zhang Li and Tong Xin . 2013 . Threat modeling and countermeasures study for the Internet of Things . Journal of Convergence Information Technology 8 , 5 (2013). Zhang Li and Tong Xin. 2013. Threat modeling and countermeasures study for the Internet of Things. Journal of Convergence Information Technology 8, 5 (2013).","journal-title":"Journal of Convergence Information Technology"},{"key":"e_1_2_1_68_1","volume-title":"arXiv preprint arXiv:1801.01207","author":"Lipp Moritz","year":"2018","unstructured":"Moritz Lipp , Michael Schwarz , Daniel Gruss , Thomas Prescher , Werner Haas , Stefan Mangard , Paul Kocher , Daniel Genkin , Yuval Yarom , and Mike Hamburg . 2018. Meltdown. arXiv preprint arXiv:1801.01207 ( 2018 ). Moritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher, Werner Haas, Stefan Mangard, Paul Kocher, Daniel Genkin, Yuval Yarom, and Mike Hamburg. 2018. Meltdown. arXiv preprint arXiv:1801.01207 (2018)."},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45800-X_33"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/iThings\/CPSCom.2011.32"},{"key":"e_1_2_1_71_1","volume-title":"A domain specific language based method to develop cloud-mobile hybrid applications. Kno. e. sis Center Wright State University","author":"Manjunatha Ashwin","year":"2010","unstructured":"Ashwin Manjunatha , Ajith Ranabahu , Amit Sheth , and Krishnaprasad Thirunarayan . 2010. A domain specific language based method to develop cloud-mobile hybrid applications. Kno. e. sis Center Wright State University ( 2010 ), 50--60. Ashwin Manjunatha, Ajith Ranabahu, Amit Sheth, and Krishnaprasad Thirunarayan. 2010. A domain specific language based method to develop cloud-mobile hybrid applications. Kno. e. sis Center Wright State University (2010), 50--60."},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/IC2E.2018.00056"},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/366173.366183"},{"key":"e_1_2_1_74_1","volume-title":"32nd ACM\/IEEE International Conference on Software Engineering","volume":"2","author":"Medvidovic Nenad","unstructured":"Nenad Medvidovic and Richard N. Taylor . 2010. Software architecture: Foundations, theory, and practice . In 32nd ACM\/IEEE International Conference on Software Engineering , Volume 2 . ACM, 471--472. Nenad Medvidovic and Richard N. Taylor. 2010. Software architecture: Foundations, theory, and practice. In 32nd ACM\/IEEE International Conference on Software Engineering, Volume 2. ACM, 471--472."},{"key":"e_1_2_1_75_1","volume-title":"A systematic review of security requirements engineering. Computer Standards 8 Interfaces 32, 4","author":"Mellado Daniel","year":"2010","unstructured":"Daniel Mellado , Carlos Blanco , Luis E. S\u00e1nchez , and Eduardo Fern\u00e1ndez-Medina . 2010. A systematic review of security requirements engineering. Computer Standards 8 Interfaces 32, 4 ( 2010 ), 153--165. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/j.csi.2010.01.006 10.1016\/j.csi.2010.01.006 Daniel Mellado, Carlos Blanco, Luis E.S\u00e1nchez, and Eduardo Fern\u00e1ndez-Medina. 2010. A systematic review of security requirements engineering. Computer Standards 8 Interfaces 32, 4 (2010), 153--165. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/j.csi.2010.01.006"},{"key":"e_1_2_1_76_1","volume-title":"Microsoft Threat Modeling Tool","year":"2016","unstructured":"Microsoft. 2019. Microsoft Threat Modeling Tool 2016 . https:\/\/2.zoppoz.workers.dev:443\/https\/www.microsoft.com\/en-us\/download\/details.aspx?id=49168. Accessed : 2019-02-04. Microsoft. 2019. Microsoft Threat Modeling Tool 2016. https:\/\/2.zoppoz.workers.dev:443\/https\/www.microsoft.com\/en-us\/download\/details.aspx?id=49168. Accessed: 2019-02-04."},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2016.7860484"},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/MS.2017.11"},{"key":"e_1_2_1_79_1","first-page":"29","article-title":"Enabling model driven engineering of cloud services by using mosaic ontology","volume":"13","author":"Moscato Francesco","year":"2012","unstructured":"Francesco Moscato , Beniamino Di Martino , and Rocco Aversa . 2012 . Enabling model driven engineering of cloud services by using mosaic ontology . Scalable Computing: Practice and Experience 13 , 1 (2012), 29 -- 44 . Francesco Moscato, Beniamino Di Martino, and Rocco Aversa. 2012. Enabling model driven engineering of cloud services by using mosaic ontology. Scalable Computing: Practice and Experience 13, 1 (2012), 29--44.","journal-title":"Scalable Computing: Practice and Experience"},{"key":"e_1_2_1_80_1","volume-title":"Symposium on Requirements Engineering for Information Security (SREIS). Citeseer, 1--8.","author":"Myagmar Suvda","year":"2005","unstructured":"Suvda Myagmar , Adam J. Lee , and William Yurcik . 2005 . Threat modeling as a basis for security requirements . In Symposium on Requirements Engineering for Information Security (SREIS). Citeseer, 1--8. Suvda Myagmar, Adam J. Lee, and William Yurcik. 2005. Threat modeling as a basis for security requirements. In Symposium on Requirements Engineering for Information Security (SREIS). Citeseer, 1--8."},{"key":"e_1_2_1_81_1","volume-title":"Harun Baraki, and Kurt Geihs.","author":"Nguyen Xuan Thang","year":"2015","unstructured":"Xuan Thang Nguyen , Huu Tam Tran , Harun Baraki, and Kurt Geihs. 2015 . FRASAD : A framework for model-driven IoT application development. In IEEE 2nd World Forum on Internet of Things (WF-IoT\u201915). IEEE , 387--392. Xuan Thang Nguyen, Huu Tam Tran, Harun Baraki, and Kurt Geihs. 2015. FRASAD: A framework for model-driven IoT application development. In IEEE 2nd World Forum on Internet of Things (WF-IoT\u201915). IEEE, 387--392."},{"key":"e_1_2_1_82_1","volume-title":"Cyber-entity security in the Internet of Things. Computer","author":"Ning Huansheng","year":"2013","unstructured":"Huansheng Ning , Hong Liu , and Laurence Yang . 2013. Cyber-entity security in the Internet of Things. Computer ( 2013 ), 1. Huansheng Ning, Hong Liu, and Laurence Yang. 2013. Cyber-entity security in the Internet of Things. Computer (2013), 1."},{"key":"e_1_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1109\/SERVICES.2010.37"},{"key":"e_1_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1145\/1734583.1734595"},{"key":"e_1_2_1_85_1","first-page":"237","article-title":"The ETSI M2M Architecture. Wiley-Blackwell","volume":"14","author":"Olivier Hersent","year":"2011","unstructured":"Hersent Olivier , Boswarthick David , and Omar Elloumi . 2011 . The ETSI M2M Architecture. Wiley-Blackwell , Chapter 14 , 237 -- 267 . DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1002\/9781119958352.ch14 arXiv:https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/9781119958352.ch14 10.1002\/9781119958352.ch14 Hersent Olivier, Boswarthick David, and Omar Elloumi. 2011. The ETSI M2M Architecture. Wiley-Blackwell, Chapter 14, 237--267. DOI:https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1002\/9781119958352.ch14 arXiv:https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/pdf\/10.1002\/9781119958352.ch14","journal-title":"Chapter"},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2008.05.013"},{"key":"e_1_2_1_87_1","unstructured":"Open Web Application Security Project OWASP. 2017. Application Threat Modeling. https:\/\/2.zoppoz.workers.dev:443\/https\/www.owasp.org\/index.php\/Application_Threat_Modeling.  Open Web Application Security Project OWASP. 2017. Application Threat Modeling. https:\/\/2.zoppoz.workers.dev:443\/https\/www.owasp.org\/index.php\/Application_Threat_Modeling."},{"key":"e_1_2_1_88_1","volume-title":"Brazilian Symposium on Computing System Engineering (SBESC\u201912)","author":"Abilio","unstructured":"Abilio G. Parada and Lisane B. De Brisolara. 2012. A model driven approach for android applications development . In Brazilian Symposium on Computing System Engineering (SBESC\u201912) . IEEE, 192--197. Abilio G. Parada and Lisane B. De Brisolara. 2012. A model driven approach for android applications development. In Brazilian Symposium on Computing System Engineering (SBESC\u201912). IEEE, 192--197."},{"key":"e_1_2_1_89_1","unstructured":"Phoronix. 2019. The Performance Impact of MDS \/ Zombieload Plus the Overall Cost Now of Spectre\/Meltdown\/L1TF\/MDS. https:\/\/2.zoppoz.workers.dev:443\/https\/www.phoronix.com\/scan.php?page=article8item=mds-zombieload-mit8num=1.  Phoronix. 2019. The Performance Impact of MDS \/ Zombieload Plus the Overall Cost Now of Spectre\/Meltdown\/L1TF\/MDS. https:\/\/2.zoppoz.workers.dev:443\/https\/www.phoronix.com\/scan.php?page=article8item=mds-zombieload-mit8num=1."},{"key":"e_1_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1109\/EDCC.2010.32"},{"key":"e_1_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1145\/2095050.2095064"},{"key":"e_1_2_1_92_1","unstructured":"Check Point Research. 2019. Securing the Cloud Mobile and Internet of Things. https:\/\/2.zoppoz.workers.dev:443\/http\/snt.hr\/news\/pressroom\/pressreleases\/CP2019SecurityReportVolume03.pdf.  Check Point Research. 2019. Securing the Cloud Mobile and Internet of Things. https:\/\/2.zoppoz.workers.dev:443\/http\/snt.hr\/news\/pressroom\/pressreleases\/CP2019SecurityReportVolume03.pdf."},{"key":"e_1_2_1_93_1","doi-asserted-by":"publisher","DOI":"10.1145\/2031759.2031770"},{"key":"e_1_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMEAE.2017.20"},{"key":"e_1_2_1_95_1","volume-title":"Unified Modeling Language Reference Manual","author":"Rumbaugh James","unstructured":"James Rumbaugh , Ivar Jacobson , and Grady Booch . 2010. Unified Modeling Language Reference Manual ( 2 nd ed.). Addison-Wesley Professional . James Rumbaugh, Ivar Jacobson, and Grady Booch. 2010. Unified Modeling Language Reference Manual (2nd ed.). Addison-Wesley Professional.","edition":"2"},{"key":"e_1_2_1_96_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2017.2719623"},{"key":"e_1_2_1_97_1","doi-asserted-by":"publisher","DOI":"10.21236\/ADA306271"},{"key":"e_1_2_1_98_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00766-013-0195-2"},{"key":"e_1_2_1_99_1","volume-title":"Attack trees. Dr. Dobb\u2019s Journal 24, 12","author":"Schneier Bruce","year":"1999","unstructured":"Bruce Schneier . 1999. Attack trees. Dr. Dobb\u2019s Journal 24, 12 ( 1999 ), 21--29. Bruce Schneier. 1999. Attack trees. Dr. Dobb\u2019s Journal 24, 12 (1999), 21--29."},{"key":"e_1_2_1_100_1","unstructured":"Continuum Security. 2019. IriusRisk - threat modeling tool. https:\/\/2.zoppoz.workers.dev:443\/https\/continuumsecurity.net\/threat-modeling-tool\/. Accessed: 2019-01-22.  Continuum Security. 2019. IriusRisk - threat modeling tool. https:\/\/2.zoppoz.workers.dev:443\/https\/continuumsecurity.net\/threat-modeling-tool\/. Accessed: 2019-01-22."},{"key":"e_1_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.2013.6704479"},{"key":"e_1_2_1_102_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2014.11.008"},{"key":"e_1_2_1_103_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00766-004-0194-4"},{"key":"e_1_2_1_104_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.sysarc.2018.08.008"},{"key":"e_1_2_1_105_1","doi-asserted-by":"publisher","DOI":"10.1145\/508791.508843"},{"key":"e_1_2_1_106_1","volume-title":"7th International Conference on Security of Information and Networks. ACM, 479","author":"Stepanova Tatiana","unstructured":"Tatiana Stepanova and D. Zegzhda . 2014. Applying large-scale adaptive graphs to modeling Internet of Things security . In 7th International Conference on Security of Information and Networks. ACM, 479 . Tatiana Stepanova and D. Zegzhda. 2014. Applying large-scale adaptive graphs to modeling Internet of Things security. In 7th International Conference on Security of Information and Networks. ACM, 479."},{"key":"e_1_2_1_107_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2016.11.031"},{"key":"e_1_2_1_108_1","volume-title":"Threat Modeling","author":"Swiderski Frank","unstructured":"Frank Swiderski and Window Snyder . 2004. Threat Modeling . Microsoft Press . Frank Swiderski and Window Snyder. 2004. Threat Modeling. Microsoft Press."},{"key":"e_1_2_1_109_1","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2013.101613.00077"},{"key":"e_1_2_1_110_1","unstructured":"Symantec. 2019. 2019 Internet Security Threat Report. https:\/\/2.zoppoz.workers.dev:443\/https\/www.symantec.com\/en\/uk\/security-center\/threat-report.  Symantec. 2019. 2019 Internet Security Threat Report. https:\/\/2.zoppoz.workers.dev:443\/https\/www.symantec.com\/en\/uk\/security-center\/threat-report."},{"key":"e_1_2_1_111_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.186"},{"key":"e_1_2_1_112_1","volume-title":"2001 IEEE Workshop on Information Assurance and Security","volume":"59","author":"Tidwell T.","unstructured":"T. Tidwell , R. Larson , K. Fitch , and J. Hale . 2001. Modeling internet attacks . In 2001 IEEE Workshop on Information Assurance and Security , Vol. 59 . United States Military Academy West Point, NY. T. Tidwell, R. Larson, K. Fitch, and J. Hale. 2001. Modeling internet attacks. In 2001 IEEE Workshop on Information Assurance and Security, Vol. 59. United States Military Academy West Point, NY."},{"key":"e_1_2_1_113_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11235-017-0352-x"},{"key":"e_1_2_1_114_1","doi-asserted-by":"publisher","DOI":"10.1109\/APSEC.2014.26"},{"key":"e_1_2_1_115_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSESS.2017.8342873"},{"key":"e_1_2_1_116_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.adhoc.2014.12.005"},{"key":"e_1_2_1_117_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-014-9489-2"},{"key":"e_1_2_1_118_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2016.2575863"},{"key":"e_1_2_1_119_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2014.01.014"},{"key":"e_1_2_1_120_1","doi-asserted-by":"publisher","DOI":"10.1109\/GLOCOM.2017.8254021"},{"key":"e_1_2_1_121_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2014.2306328"},{"key":"e_1_2_1_122_1","doi-asserted-by":"publisher","DOI":"10.1109\/WCSN.2014.95"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3376123","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3376123","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:44:34Z","timestamp":1750203874000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3376123"}},"subtitle":["Embedding Security by Design"],"short-title":[],"issued":{"date-parts":[[2020,3,20]]},"references-count":122,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2021,3,31]]}},"alternative-id":["10.1145\/3376123"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3376123","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,3,20]]},"assertion":[{"value":"2019-05-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-03-20","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}