REVIEW 3 major objections 5 minor 179 references
SoK: The Design Paradigm of Safe and Secure Defaults
T0 review · 3 major / 5 minor · reviewed 2026-08-11 · deepseek-v4-flash
Pith's one-line read This systematization of knowledge argues that the safe-and-secure-defaults paradigm, rooted in Saltzer and Schroeder's 1975 fail-safe defaults principle, has been extensively discussed, applied, and extended across computing domains since…
desk verdict Useful, honest first systematic map of the safe/secure-defaults paradigm; the ACM/IEEE-only sample is a real limitation but not a deal-breaker. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing apparatus is the review protocol itself: a systematic mapping study and scoping review run against ACM's and IEEE's electronic libraries using the Boolean query $(\text{safe AND default}) \lor (\text{secure AND default})$, filtered by four exclusion criteria (primary studies only; substantive discussion of defaults with definition, example, rationale, or elaboration; peer-reviewed journals and conference proceedings; no finance papers where 'default' means non-payment), yielding a corpus of 148 papers analyzed thematically. The conceptual backbone that organizes the findings is Saltzer and Schroeder's 1975 fail-safe-defaults principle, generalized by replacing 'access' with any resource so that the paradigm covers safety as well as security; the review's tables of contextual domains, motivating themes, design principles, and problems carry the argument that the paradigm has both spread and evolved.
What would settle it
Run the same Boolean query and inclusion criteria in Scopus, Web of Science, or domain-specific venues such as SOUPS, CHI, and safety-engineering journals and compare the corpus. If substantial primary studies on safe and secure defaults appear before the late 1990s, if the mid-2010s acceleration disappears outside ACM/IEEE, or if a well-developed body of empirical work on default-setting behavior shows up, the review's claims about the paradigm's timeline, IoT-driven growth, and the folklore of human factors would be contradicted.
Extended reading notes
Core claim
On the paper's own terms, the central discovery is that the safe-and-secure-defaults paradigm is not a static historical footnote but a live, expanding design doctrine. Reviewing 148 primary studies gathered from the ACM and IEEE digital libraries with the query $(\text{safe AND default}) \lor (\text{secure AND default})$ and strict inclusion criteria, the author concludes that the paradigm has been extensively discussed, used, and developed further since the late 1990s; that its growth accelerated from roughly the mid-2010s, driven substantially by the perceived insecurity of IoT devices; and that it has been applied across a wide range of computing domains while being extended with principles the originators did not consider, including off-by-default, turning security features on by default, overriding and fallback designs, clean-up and leak-prevention routines, automated generation of secure defaults, and zero-trust assumptions. The review also documents recurring problems, such as emergency access overrides, the argument that today's secure default becomes tomorrow's vulnerability, developer workarounds, and security-performance trade-offs, and it notes that most claims about human behavior attached to defaults are speculative folklore rather than robust empirical findings.
Load-bearing premise
The whole picture depends on the search being run only in ACM's and IEEE's electronic libraries; if much of the research on safe and secure defaults lives in other venues, such as human-computer interaction, social science, or safety engineering, the identified timeline, principles, and gaps would be different.
Editorial extensions
If this is right
- If the review is right, the EU Cyber Resilience Act's 'secure by default configuration' requirement has a concrete body of engineering knowledge behind it, from off-by-default networking to automated credential generation, that implementers and auditors can draw on.
- If the review is right, designers in domains far from 1970s access control—IoT, cyber-physical systems, web security, cryptography—can legitimately treat safe and secure defaults as a general engineering doctrine rather than a specialized historical principle.
- If the review is right, the paradigm's expansion means a full catalog of security design principles, with overlapping terms unified (psychological acceptability as least surprise, isolation as compartmentalization), would be a high-value next step for research and practice.
- If the review is right, the empirical gap matters: regulations and designs that assume users and developers stay with defaults out of inertia or out of information conveyed by defaults rest on claims the literature has not yet tested rigorously.
- If the review is right, configuration vulnerabilities in cloud computing and other newer domains are under-covered, and secure defaults are the natural starting point for mitigating that class of failures.
Reading between the lines
- One extension the paper leaves implicit is that the ACM/IEEE restriction may explain the absence of organizational and social-science perspectives: a reader shopping for literature on default settings would find a large body of work in management, psychology, behavioral economics, and policy journals that this sample simply does not include.
- Because the review treats defaults as largely static, a natural testable extension is to give defaults a temporal dimension—sunset clauses, dynamic re-defaulting, or periodic re-evaluation—so that 'today's secure default becomes tomorrow's vulnerability' becomes a design requirement rather than a critique.
- The folklore gap in human-factor claims suggests a concrete research program: instrument real systems to measure what happens when users and developers actually encounter secure defaults, using A/B experiments of the kind one paper in the sample used for product features, to replace speculation with effect estimates.
- A further extension: since the paradigm is now encoded in regulation, one could audit shipped products for default settings that violate the cataloged principles (deny-by-default, off-by-default, least privilege), turning the SoK's taxonomy into a compliance checklist.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper presents a systematization of knowledge (SoK) on the design paradigm of safe and secure defaults, conducted as a systematic mapping study / scoping review. The search protocol is the Boolean query (safe AND default) OR (secure AND default) run in the ACM and IEEE electronic libraries, with four exclusion criteria (primary studies only; substantive discussion of safe or secure defaults; peer-reviewed journal or conference papers; non-financial topics), yielding n=148 papers. The review maps publication trends (growth from the late 1990s, acceleration from the mid-2010s attributed partly to IoT insecurity), contextual domains (28 categories in Table 2, from access control and operating systems to IoT, cyber-physical systems, and work safety), motivations (dominated by insecure or unsafe defaults and human factors), design principles (including newer off-by-default, overriding/fallback, leak-prevention, and zero-trust principles), and four problem areas (break-glass emergencies, prediction failure, developer workarounds, trade-offs). The discussion closes with six summary points, an explicit limitation section (single-author coding; uncertain generalizability of the ACM/IEEE-only sample), and four future-research directions, including the EU Cyber Resilience Act.
Significance. If the review's claims hold, this is the first systematic map of the fail-safe-defaults paradigm and a useful reference for researchers, educators, and regulators. Strengths worth naming: the search string and exclusion criteria are reported verbatim; sampled and non-sampled literature are cleanly separated throughout; quotations are given with page numbers, making the thematic claims checkable; the author candidly classifies much human-factor reasoning in the sampled literature as folklore rather than evidence; and Section 4.2 states the single-coder and generalizability limitations explicitly. I find no circularity: the self-citations serve background or methodological points only. The main contributions are the catalog of emerging principles (off-by-default, overriding and fallback, leak prevention, zero trust), the documentation of the IoT-driven acceleration, and the identified gaps (organizational security, social science, regulation), which give the paper an agenda-setting function despite its exploratory design.
major comments (3)
- [Abstract; §2; §4.1; §4.2] Section 2 restricts the search to the ACM and IEEE electronic libraries, Section 4.2 concedes that the n=148 sample cannot be generalized to an unknown theoretical population, and Section 4.3 admits that social-science and organizational-security work is absent from the sample. Despite these concessions, the abstract states that 'the paradigm has been extensively discussed, used, and developed further since the late 1990s,' and Section 4.1 makes unqualified assertions such as 'the domains in which the paradigm has been discussed and applied have considerably expanded over the years' (point 1) and 'the design paradigm has been discussed and developed with many security design principles' (point 5). These are claims about the paradigm as a whole, whereas the evidence base is a single sample drawn from two publisher libraries; major security venues such as USENIX Security, SOUPS, and NDSS, as well as behavioral, privacy, and safety-engineering outlets, are outside the sample. I regard this as a load-bearing scope mismatch rather than a fatal flaw: the fix is to either run the same protocol in additional databases (e.g., Scopus, Web of Science) and report whether the principles and gaps change, or explicitly qualify all headline claims and conclusions with 'in the reviewed ACM/IEEE-indexed literature,' including a visible caveat in the abstract.
- [§2; Fig. 1] Fig. 1 reports raw query counts (ACM 76/35; IEEE 35/503) and qualified counts (20/12/22/94) but does not report how many papers were excluded under each of the four inclusion/exclusion criteria, and the date of the searches is not stated anywhere in Section 2. Without this standard screening accounting, readers cannot assess how the exclusion criteria shaped the sample, which is central to a paper that claims systematization. Please add a per-criterion screening table with counts at each stage, state the search date, and clarify whether the ACM and IEEE queries matched metadata or full text.
- [§2; §4.2; Figs. 4–6; Table 2] Section 4.2 openly acknowledges that the review was conducted by a single author and that inter-rater reliability measures cannot be provided; this honesty is to the paper's credit. Nevertheless, Figs. 4–6 and Table 2 are the substantive contribution, and the paper currently offers no way to audit the coding: there is no initial category list, no operationalized merging rule beyond 'collating and merging of overlapping... categories,' and no worked example of how borderline papers were assigned (the 'opt-in' category in Fig. 4 is one such case). I recommend adding a codebook with the category definitions and one or two worked coding examples as an appendix or supplementary material so that the thematic constructs can be judged without a second coder.
minor comments (5)
- [Table 2; Fig. 1] Table 2 lists 147 paper references by my count, whereas Fig. 1 reports a sample size of n=148; please verify the bookkeeping and add the missing reference or correct the count.
- [§3.4; Fig. 5] Section 3.4 states that 'three papers built upon the emerging zero trust principle' and quotes [98], [102], and [112], but Fig. 5 lists [98], [100], and [102] for zero trust; please align the text and the figure.
- [§2; §3.3] Section 2 flags paper [10] as likely containing tortured phrases, yet Section 3.3 cites [10] for the substantive claim that email is 'still unencrypted by default'; please verify that citation or replace it with a source of clear provenance.
- [References] Several reference entries contain errors: [44] gives the year 2019 for SACMAT 2007, [101] reports the symposium acronym as 'MOMS' where NOMS is presumably intended, [98] reads 'Scince' and [69] reads 'Proceeding sof,' [154] duplicates 'Workshop on,' [125] has '2the IEEE 15th Intl,' and [91] and [142] contain stray commas; a reference-list cleanup is in order.
- [Figs. 1, 4; §1; §2] Figure 1 spells 'detaults' twice, Fig. 4 has 'Acess controls,' Section 2 uses the unusual phrase 'overcasting' where 'overarching' seems intended, and Section 1 reads 'The Saltzer's and Schroeder's paper'; a light copy-editing pass over the figures and prose is needed.
Circularity Check
No significant circularity: the SoK's claims are descriptive summaries of a transparently defined 148-paper sample, and the author's self-citations are auxiliary rather than load-bearing.
full rationale
This is a systematization of knowledge (a scoping review / systematic mapping study), not a derivation chain, so there is no fitted parameter renamed as a prediction and no theorem imported from the author's prior work to force a conclusion. The central claims—that the safe-and-secure-defaults paradigm has been discussed since the late 1990s, accelerated from the mid-2010s, and spread across domains—are expressly grounded in the n = 148 reviewed papers and presented through transparent search and inclusion criteria (Section 2). The author's self-citations ([5], [15], [16], [18], [178]) support only auxiliary points: a safety-versus-security definitional clarification, qualitative thematic-analysis practice, text pre-processing details, and a regulatory reference for the Cyber Resilience Act; none of these feeds back into the review's six conclusions in a way that makes the conclusions equivalent to their inputs. The acknowledged limitations—single-author review and restriction to ACM and IEEE digital libraries—affect generalizability and representativeness, but the paper explicitly hedges its conclusions as exploratory and even notes that social-science and organizational-security literature is missing. Such sampling concerns are correctness risks, not circularity. No step in the paper reduces, by construction or by self-citation, to its own input, so the appropriate finding is no significant circularity.
Assumptions & free parameters
assumptions (3)
- domain assumption The ACM and IEEE digital libraries contain a representative sample of the literature on safe and secure defaults
- domain assumption Thematic analysis by a single author yields reliable and reproducible categories
- domain assumption The search query and exclusion criteria capture the intended scope
Cite this review
Pith. "Pith review of SoK: The Design Paradigm of Safe and Secure Defaults." pith.science (2026). https://pith.science/paper/DX2QM456
@misc{pith2026241217329,
author = {Pith},
title = {Pith review of: SoK: The Design Paradigm of Safe and Secure Defaults},
year = {2026},
howpublished = {\url{https://pith.science/paper/DX2QM456}},
note = {Machine review of arXiv:2412.17329}
}
read the original abstract
In security engineering, including software security engineering, there is a well-known design paradigm telling to prefer safe and secure defaults. The paper presents a systematization of knowledge (SoK) of this paradigm by the means of a systematic mapping study and a scoping review of relevant literature. According to the mapping and review, the paradigm has been extensively discussed, used, and developed further since the late 1990s. Partially driven by the insecurity of the Internet of things, the volume of publications has accelerated from the circa mid-2010s onward. The publications reviewed indicate that the paradigm has been adopted in numerous different contexts. It has also been expanded with security design principles not originally considered when the paradigm was initiated in the mid-1970s. Among the newer principles are an "off by default" principle, various overriding and fallback principles, as well as those related to the zero trust model. The review also indicates problems developers and others have faced with the paradigm.
Figures
Figures from the paper (2 more)
Reference graph
Works this paper leans on
-
[1]
The Protection of In- formation in Computer Systems,
J. M. Saltzer and M. D. Schroeder, “The Protection of In- formation in Computer Systems,” Proceedings of the IEEE , vol. 63, no. 9, pp. 1278–1308, 1975
1975
-
[2]
Design Notations for Secure Software: A Systematic Litera- ture Review,
A. van den Berghe, R. Scandariato, K. Yskout, and W. Joosen, “Design Notations for Secure Software: A Systematic Litera- ture Review,” Software & Systems Modeling , vol. 16, pp. 809– 831, 2017
2017
-
[3]
The Bur- geoning Role of Literature Review Articles in Management Re- search: An Introduction and Outlook,
S. Kraus, R. B. Bouncken, and A. Y. Ar´ anega, “The Bur- geoning Role of Literature Review Articles in Management Re- search: An Introduction and Outlook,” Review of Managerial Science, vol. 18, pp. 299–314, 2024
2024
-
[4]
Gamma, R
E. Gamma, R. Helm, R. Johnson, and J. Vlissides, Design Patterns: Elements of Reusable Object-Oriented Software . Boston: Addison-Wesley, 1995
1995
-
[5]
A Review of Product Safety Regulations in the European Union,
J. Ruohonen, “A Review of Product Safety Regulations in the European Union,” International Cybersecurity Law Review , vol. 3, pp. 345–366, 2022
2022
-
[6]
Schumacher, Security Engineering with Patterns: Origins, Theoretical Model, and New Applications
M. Schumacher, Security Engineering with Patterns: Origins, Theoretical Model, and New Applications . Berlin: Springer, 2003. 2 Regulation (EU) 2024/2847. 3 Paragraph 2(b) in Annex I
2003
-
[7]
The Benefits of Systematic Mapping to Evidence-Based En- vironmental Management,
N. R. Haddaway, C. Bernes, B.-G. Jonsson, and K. Hedlund, “The Benefits of Systematic Mapping to Evidence-Based En- vironmental Management,” Ambio, vol. 45, pp. 613–620, 2016
2016
-
[8]
A Scoping Review of Scop- ing Reviews: Advancing the Approach and Enhancing the Consistency,
M. T. Pham, A. Raji´ c, J. D. Greig, J. M. Sargeant, A. Pa- padopoulosa, and S. A. McEwen, “A Scoping Review of Scop- ing Reviews: Advancing the Approach and Enhancing the Consistency,” Research Synthesis Methods , vol. 5, pp. 371– 385, 2014
2014
Show all 179 references
-
[9]
Scop- ing Reviews: Reinforcing and Advancing the Methodology and Application,
M. D. J. Peters, C. Marnie, H. Colquhoun, C. M. Garritty, S. Hempel, T. Horsley, E. V. Langlois, E. Lillie, K. K. O’Brien, O. Tun¸ calp, M. G. Wilson, W. Zarin, and A. C. Tricco, “Scop- ing Reviews: Reinforcing and Advancing the Methodology and Application,” Systematic Reviews...
2021
-
[10]
Enhancing Secu- rity Measures of AI Applications,
Y. S. Chaudhry, U. Sharma, and A. Rana, “Enhancing Secu- rity Measures of AI Applications,” in Proceedings of the 8th International Conference on Reliability, Infocom Technologies and Optimization (Trends and Future Directions) (ICRITO 2020), (Noida), pp. 713–716, IEEE, 2020
2020
-
[11]
Tortured Phrases: A Dubious Writing Style Emerging in Science: Evidence of Critical Issues Affecting Established Journals
G. Cabanac, C. Labb´ e, and A. Magazinov, “Tortured Phrases: A Dubious Writing Style Emerging in Science: Evidence of Critical Issues Affecting Established Journals.” Archived manuscript, available online in December 2024: https:// arxiv.org/abs/2107.06751, 2021
2024 arXiv
-
[12]
Secondary Studies on Human Aspects in Software Engineering: A Ter- tiary Study,
E. Zolduoarrati, S. A. Licorish, and N. Stanger, “Secondary Studies on Human Aspects in Software Engineering: A Ter- tiary Study,” The Journal of Systems & Software , vol. 200, p. 111654, 2023
2023
-
[13]
Lessons From Applying the Systematic Literature Review Process Within the Software Engineering Domain,
P. Brereton, B. A. Kitchenham, D. Budgen, M. Turner, and M. Khalil, “Lessons From Applying the Systematic Literature Review Process Within the Software Engineering Domain,” Journal of Systems and Software , vol. 80, no. 4, pp. 571–583, 2007
2007
-
[14]
Variability in Software Systems—A Systematic Literature Re- view,
M. Galster, D. Weyns, D. Tofan, B. Michalik, and P. Avgeriou, “Variability in Software Systems—A Systematic Literature Re- view,” IEEE Transactions on Software Engineering , vol. 40, no. 3, pp. 282–306, 2014
2014
-
[15]
Mysterious and Manipulative Black Boxes: A Qualitative Analysis of Perceptions on Recommender Sys- tems,
J. Ruohonen, “Mysterious and Manipulative Black Boxes: A Qualitative Analysis of Perceptions on Recommender Sys- tems,” First Monday , vol. 29, no. 6, pp. 1–35, 2024
2024
-
[16]
An Overview of Cyber Security Funding for Open Source Software
J. Ruohonen, G. Choudhary, and A. Alami, “An Overview of Cyber Security Funding for Open Source Software.” Archived manuscript, available online: https://arxiv.org/abs/2412. 05887, 2024
2024
-
[17]
The Art of Coding and Thematic Exploration in Qualitative Research,
M. Williams and T. Moser, “The Art of Coding and Thematic Exploration in Qualitative Research,” International Manage- ment Review, vol. 15, no. 1, pp. 45–55, 2019
2019
-
[18]
The GDPR Enforcement Fines at Glance,
J. Ruohonen and K. Hjerppe, “The GDPR Enforcement Fines at Glance,” Information Systems , vol. 106, p. 101876, 2022
2022
-
[19]
SoK: Secure Data Dele- tion,
J. Reardon, D. Basin, and S. Capkun, “SoK: Secure Data Dele- tion,” in Proceedings of the IEEE Symposium on Security and Privacy (S&P 2013) , (Berkeley), pp. 301–315, IEEE, 2013
2013
-
[20]
A/B Integrations: 7 Lessons Learned from En- abling A/B Testing as a Product Feature,
A. Fabijan, P. Dmitriev, B. Arai, A. Drake, S. Kohlmeier, and A. Knowng, “A/B Integrations: 7 Lessons Learned from En- abling A/B Testing as a Product Feature,” in Proceedings of the IEEE/ACM 45th International Conference on Software Engineering: Software Engineering in Practi...
2023
-
[21]
P. C. van Oorschot, Computer Security and the Internet: Tools and Jewels from Malware to Bitcoin . Cham: Springer, second ed., 2021
2021
-
[22]
Big Data Model of Security Sharing Based on Blockchain,
L. Yue, H. Junqin, Q. Shengzhi, and W. Ruijin, “Big Data Model of Security Sharing Based on Blockchain,” in Proceed- ings of the 3rd International Conference on Big Data Com- puting and Communications (BIGCOM 2017) , (Chengdu), pp. 117–121, IEEE, 2017
2017
-
[23]
Better Safe Than Sorry! Automated Identification of Functionality-Breaking Security-Configuration Rules,
P. St¨ ockle, M. Sammereier, B. Grobauer, and A. Pretschner, “Better Safe Than Sorry! Automated Identification of Functionality-Breaking Security-Configuration Rules,” in Pro- ceedings of the IEEE/ACM International Conference on Au- tomation of Software Test (AST 2023) , (Melb...
2023
-
[24]
Learning of Person- alized Security Settings,
M. Sharifi, E. Fink, and J. G. Carbonell, “Learning of Person- alized Security Settings,” in Proceedings of the IEEE Interna- tional Conference on Systems, Man and Cybernetics , (Istan- bul), pp. 3428–3432, IEEE, 2010
2010
-
[25]
Field Trial for Simultaneous Teleoperation of Mobile Social Robots,
D. F. Glas, T. Kanda, H. Ishiguro, and N. Hagita, “Field Trial for Simultaneous Teleoperation of Mobile Social Robots,” in Proceedings of the 4th ACM/IEEE International Conference on Human Robot Interaction (HRI 2009) , (La Jolla), pp. 149– 156, ACM, 2009
2009
-
[26]
Development of IIoT Monitoring and Control Se- curity Scheme for Cyber Physical Systems,
A. Wadsworth, M. I. Thanoon, C. McCurry, and S. Z. Sabatto, “Development of IIoT Monitoring and Control Se- curity Scheme for Cyber Physical Systems,” in Proceedings of the SoutheastCon, (Huntsville), pp. 1–5, IEEE, 2019
2019
-
[27]
An Agent-Based Controller for Vehicular Automation,
F. He, F.-Y. Wang, and S. Tang, “An Agent-Based Controller for Vehicular Automation,” in Proceedings of the IEEE Intelli- gent Transportation Systems Conference, (Toronto), pp. 771– 776, IEEE, 2006
2006
-
[28]
Evaluation of Run- time Monitoring for UA V Emergency Landing,
J. Guerin, K. Delmas, , and J. Guiochet, “Evaluation of Run- time Monitoring for UA V Emergency Landing,” inProceedings of the International Conference on Robotics and Automation (ICRA 2022) , (Philadelphia), pp. 9703–9709, IEEE, 2022
2022
-
[29]
False Data Injection on EKF-Based Navigation Control,
W. Chen, Z. Duan, and Y. Dong, “False Data Injection on EKF-Based Navigation Control,” in Proceedings of the Inter- national Conference on Unmanned Aircraft Systems (ICUAS 2017), (Miami), pp. 1608–1617, IEEE, 2017
2017
-
[30]
Analysis and Prevention of MCAS-Induced Crashes,
N. T. Curran, T. W. Kennings, and K. G. Shin, “Analysis and Prevention of MCAS-Induced Crashes,” IEEE Transac- tions on Computer-Aided Design of Integrated Circuits and Systems, vol. 43, no. 11, pp. 3382–3394, 2024
2024
-
[31]
SROS2: Usable Cyber Security Tools for ROS 2,
V. Mayoral-Vilches, R. White, G. Caiazza, and M. Argueda, “SROS2: Usable Cyber Security Tools for ROS 2,” in Proceed- ings of the IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS 2022) , (Kyoto), pp. 11253–11259, IEEE, 2022
2022
-
[32]
High-Level Cryptographic Abstractions,
C. Kane, B. Lin, S. Chand, S. D. Stoller, and Y. A. Liu, “High-Level Cryptographic Abstractions,” in Proceedings of the 14th ACM SIGSAC Workshop on Programming Languages and Analysis for Security (PLAS 2019) , (London), pp. 31–43, ACM, 2019
2019
-
[33]
Short: Danger is My Middle Name – Experimenting with SSL Vulnerabilities in An- droid Apps,
L. Onwuzurike and E. De Cristofaro, “Short: Danger is My Middle Name – Experimenting with SSL Vulnerabilities in An- droid Apps,” in Proceedings of the 8th ACM Conference on Security & Privacy in Wireless and Mobile Networks (WiSec 2015), (New York), pp. 1–6, ACM, 2015
2015
-
[34]
“Make Sure DSA Signing Exponentiations Really Are Constant-Time,
C. P. Garc ´ ıa, B. B. Brumley, and Y. Yarom, ““Make Sure DSA Signing Exponentiations Really Are Constant-Time,” in Proceedings of the 2016 ACM SIGSAC Conference on Com- puter and Communications Security (CCS 2016) , (Vienna), pp. 1639–1650, ACM, 2016
2016
-
[35]
Securing SSL Certificate Verification Through Dynamic Linking,
A. Bates, J. Pletcher, T. Nichols, B. Hollembaek, D. Tian, and K. R. B. Butler, “Securing SSL Certificate Verification Through Dynamic Linking,” in Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Se- curity (CCS 2014) , (Scottsdale), pp. 394–405, ACM, 2014
2014
-
[36]
Helping Johnny Encrypt: Toward Semantic Interfaces for Crypto- graphic Frameworks,
S. Indela, M. Kulkarni, and K. N. T. Dumitra¸ s, “Helping Johnny Encrypt: Toward Semantic Interfaces for Crypto- graphic Frameworks,” in Proceedings of the 2016 ACM In- ternational Symposium on New Ideas, New Paradigms, and Reflections on Programming and Software (Onward! 2016...
2016
-
[37]
Comparing the Usability of Cryp- tographic APIs,
Y. Acar, M. Backes, S. Fahl, S. Garfinkel, D. Kim, M. L. Mazurek, and C. Stransky, “Comparing the Usability of Cryp- tographic APIs,” in Proceedings of the IEEE Symposium on Security and Privacy (S&P) , (San Jose), pp. 154–171, IEEE, 2017
2017
-
[38]
From Dragondoom to Dragonstar: Side- Channel Attacks and Formally Verified Implementation of WPA3 Dragonfly Handshake,
D. D. A. Braga, N. Kulatova, M. Sabt, P.-A. Fouque, and K. Bhargavan, “From Dragondoom to Dragonstar: Side- Channel Attacks and Formally Verified Implementation of WPA3 Dragonfly Handshake,” in Proceedings of the IEEE 8th European Symposium on Security and Privacy (EuroS&P) , ...
2023
-
[39]
In Encryption We Don’t Trust: The Effect of End-To-End En- cryption to the Masses on User Perception,
S. Dechand, A. Naiakshina, A. Danilova, and M. Smith, “In Encryption We Don’t Trust: The Effect of End-To-End En- cryption to the Masses on User Perception,” in Proceedings of the IEEE European Symposium on Security and Privacy (EuroS&P), (Stockholm), pp. 401–415, IEEE, 2019
2019
-
[40]
Let’s Create! Automated Cer- tificate Management for End-users,
T. Mueller and A. Michalek, “Let’s Create! Automated Cer- tificate Management for End-users,” in Proceedings of the In- ternational Conference on Software, Telecommunications and Computer Networks (SoftCOM 2021) , (Split), pp. 1–6, IEEE, 2021
2021
-
[41]
A Graphical Definition of Au- thorisation Schema in the DTAC Model,
J. E. Tidswell and J. M. Potter, “A Graphical Definition of Au- thorisation Schema in the DTAC Model,” inProceedings of the Sixth ACM Symposium on Access Control Models and Tech- nologies (SACMAT 2001) , (Chantilly), pp. 109–120, ACM, 2001
2001
-
[42]
Forensic Attribution in NoSQL Databases,
W. K. Hauger and M. S. Olivier, “Forensic Attribution in NoSQL Databases,” in Proceedings of the Information Secu- rity for South Africa (ISSA 2017) , (Johannesburg), pp. 74–82, IEEE, 2017
2017
-
[43]
Harvesting Randomness to Optimize Distributed Systems,
M. Lecuyer, J. Lockerman, L. Nelson, S. Sen, A. Sharma, and A. Slivkins, “Harvesting Randomness to Optimize Distributed Systems,” in Proceedings of the 16th ACM Workshop on Hot Topics in Networks (HotNets 2017) , (Palo Alto), pp. 178–184, ACM, 2017
2017
-
[44]
Mesh: Secure, Lightweight Grid Middleware Using Existing SSH Infrastructure,
P. Z. Kolano, “Mesh: Secure, Lightweight Grid Middleware Using Existing SSH Infrastructure,” in Proceedings of the 12th ACM symposium on Access Control Models and Technologies (SACMAT 2007), (Sophia Antipolis), pp. 111–120, 2019
2007
-
[45]
Using Auto- mated Prompts for Student Reflection on Computer Security Concepts,
H. Chen, A. Ciborowska, and K. Damevski, “Using Auto- mated Prompts for Student Reflection on Computer Security Concepts,” in Proceedings of the 2019 ACM Conference on Innovation and Technology in Computer Science Education (ITiCSE 2019) , (Aberdeen), pp. 506–512, ACM, 2019
2019
-
[46]
Assuring the Safety of Opening Email Attach- ments,
R. Balzer, “Assuring the Safety of Opening Email Attach- ments,” in Proceedings DARPA Information Survivability Conference and Exposition II (DISCEX 2001) , (Anaheim), pp. 257–262, IEEE, 2001
2001
-
[47]
PellucidAt- tachment: Protecting Users From Attacks via E-Mail Attach- ments,
S. Duman, M. B¨ uchler, M. Egele, and E. Kirda, “PellucidAt- tachment: Protecting Users From Attacks via E-Mail Attach- ments,” IEEE Transactions on Dependable and Secure Com- puting, vol. 21, no. 3, pp. 1342–1354, 2024
2024
-
[48]
Who’s In Control? On Security Risks of Disjointed IoT Device Man- agement Channels,
Y. Jia, B. Yuan, L. Xing, D. Zhao, Y. Zhang, X. Wang, Y. Liu, K. Zheng, P. Crnjak, Y. Zhang, D. Zou, and H. Jin, “Who’s In Control? On Security Risks of Disjointed IoT Device Man- agement Channels,” in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communication...
2021
-
[49]
SxC4IoT: A Security-by-Contract Framework for Dynamic Evolving IoT Devices,
A. Giaretta, N. Dragoni, and F. Massacci, “SxC4IoT: A Security-by-Contract Framework for Dynamic Evolving IoT Devices,” ACM Transactions on Sensor Networks , vol. 18, no. 1, pp. 12:1 – 12:51, 2021
2021
-
[50]
Don’t Talk Un- less I Say So! Securing the Internet of Things With Default-Off Networking,
J. Hong, A. Levy, L. Riliskis, , and P. Levis, “Don’t Talk Un- less I Say So! Securing the Internet of Things With Default-Off Networking,” in Proceedings of the IEEE/ACM Third Inter- national Conference on Internet-of-Things Design and Imple- mentation (IoTDI 2018), (Orlando)...
2018
-
[51]
Default Credentials Vulnerability: The Case Study of Exposed IP Cams,
S. Perone, L. Faramondi, and R. Setola, “Default Credentials Vulnerability: The Case Study of Exposed IP Cams,” in Pro- ceedings of the IEEE International Conference on Cyber Secu- rity and Resilience (CSR 2023) , (Venice), pp. 406–411, IEEE, 2023
2023
-
[52]
Secure MQTT Authentication and Message Exchange Methods for IoT Con- strained Device,
F. A. Shodiq, R. R. Pahlevi, and P. Sukarno, “Secure MQTT Authentication and Message Exchange Methods for IoT Con- strained Device,” in Proceedings of the International Con- ference on Intelligent Cybernetics Technology & Applications (ICICyTA 2021), (Bandung), pp. 70–74, IEEE, 2021
2021
-
[53]
A Secure Secret Key-Sharing System for Resource- Constrained IoT Devices Using MQTT,
T. Noguchi, M. Nakagawa, M. Yoshida, and A. G. Ra- monet, “A Secure Secret Key-Sharing System for Resource- Constrained IoT Devices Using MQTT,” in Proceedings of the 24th International Conference on Advanced Communica- tion Technology (ICACT 2022), (PyeongChang), pp. 147–153,...
2022
-
[54]
Internet of Vulnerable Things (IoVT): Detect- ing Vulnerable SOHO Routers,
P. Poornachandran, S. R., M. R. Krishnan, S. Pal, P. S. A. U., and A. Ashok, “Internet of Vulnerable Things (IoVT): Detect- ing Vulnerable SOHO Routers,” in Proceedings of the Inter- national Conference on Information Technology (ICIT 2015) , (Bhubaneswar), pp. 119–123, IEEE, 2015
2015
-
[55]
How Secure Are Networked Office Devices?,
E. Condon, E. Cummins, Z. Afoulki, and M. Cukier, “How Secure Are Networked Office Devices?,” in Proceedings of the IEEE/IFIP 41st International Conference on Dependable Sys- tems & Networks (DSN 2011) , (Hong Kong), pp. 465–472, IEEE, 2011
2011
-
[56]
Security and Performance Analysis of MQTT Protocol with TLS in IoT Networks,
A. R. Alkhafajee, A. M. A. Al-muqarm, A. H. Alwan, and Z. R. Mohammed, “Security and Performance Analysis of MQTT Protocol with TLS in IoT Networks,” in Proceedings of the International Iraqi Conference on Engineering Technology and Their Applications (IICETA 2021), (Najaf), p...
2021
-
[57]
BUL W ARK: A Framework to Store IoT Data in User Accounts,
J. L. Reed and A. S ¸aman Tosun, “BUL W ARK: A Framework to Store IoT Data in User Accounts,” IEEE Access, vol. 10, pp. 15619–15634, 2022
2022
-
[58]
Securing the Internet of Things: Exploring MQTT Vulnerabilities and Threats in Pakistan’s IoT Landscape,
A. Hassan, J. Aslam, S. Tahir, and I. Rashid, “Securing the Internet of Things: Exploring MQTT Vulnerabilities and Threats in Pakistan’s IoT Landscape,” in Proceedings of the International Conference on Engineering & Computing Tech- nologies (ICECT 2024) , (Pakistan), pp. 1–6,...
2024
-
[59]
Automated Authentication Credential Derivation for the Secured Configuration of IoT Devices,
T. Ulz, T. Pieber, C. Steger, A. H¨ ooller, S. Haas, and R. Ma- tischek, “Automated Authentication Credential Derivation for the Secured Configuration of IoT Devices,” in Proceedings of the IEEE 13th International Symposium on Industrial Embed- ded Systems (SIES 2018) , (Graz)...
2018
-
[60]
Message Queuing Telemetry Transport (MQTT) Security: A Cryptographic Smart Card Approach,
E. B. Sanjuan, I. A. Cardiel, J. A. Cerrada, and C. Cerrada, “Message Queuing Telemetry Transport (MQTT) Security: A Cryptographic Smart Card Approach,” IEEE Access, vol. 8, pp. 115051–115062, 2020
2020
-
[61]
Keep Rogue IoT Away: IoT Detector Based on Diversified TLS Negotiation,
C.-W. Ou, F.-H. Hsu, and C.-M. Lai, “Keep Rogue IoT Away: IoT Detector Based on Diversified TLS Negotiation,” in Proceedings of the IEEE Intl. Conf. on Dependable, Auto- nomic and Secure Computing, Intl. Conf. on Pervasive Intel- ligence and Computing, Intl. Conf. on Cloud and...
2019
-
[62]
QTTSA: A Tool for Automatically Assisting the Se- cure Deployments of MQTT Brokers,
A. Palmieri, P. Prem, S. Ranise, U. Morelli, and T. Ah- mad, “QTTSA: A Tool for Automatically Assisting the Se- cure Deployments of MQTT Brokers,” in Proceedings of the IEEE World Congress on Services (SER VICES 2019) , (Mi- lan), pp. 47–53, IEEE, 2019
2019
-
[63]
Eval- uating Security of MQTT Protocol in Internet of Things,
A. Al-Ani, W. K. S. A. K. Al-Ani, and S. A. Laghari, “Eval- uating Security of MQTT Protocol in Internet of Things,” in Proceedings of the IEEE Canadian Conference on Elec- trical and Computer Engineering (CCECE 2023) , (Regina), pp. 502–509, IEEE, 2023
2023
-
[64]
Practical Experi- ence Report: Exploiting Memory Corruption Vulnerabilities in Connman for IoT Devices,
K. V. English, I. Obaidat, and M. Sridhar, “Practical Experi- ence Report: Exploiting Memory Corruption Vulnerabilities in Connman for IoT Devices,” in Proceedings of the 9th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2019) , pp. 247–255,...
2019
-
[65]
Embedded Malware – An Analysis of the Chuck Norris Botnet,
P. ˆCeleda, R. Krejˆ c ´ ı, J. Vykopal, and M. Draˆ sar, “Embedded Malware – An Analysis of the Chuck Norris Botnet,” in Pro- ceedings of the European Conference on Computer Network Defense, (Berlin), pp. 3–10, IEEE, 2010
2010
-
[66]
Security Review On The Internet of Things,
J. Whitter-Jones, “Security Review On The Internet of Things,” in Proceedings of the Third International Confer- ence on Fog and Mobile Edge Computing (FMEC 2018) , (Barcelona), pp. 163–168, IEEE, 2018
2018
-
[67]
Is Your Kettle Smarter Than a Hacker? A Scalable Tool for Assessing Replay Attack Vulnerabilities on Consumer IoT Devices,
S. Lazzaro, V. D. Angelis, A. M. Mandalari, and F. Buccafurri, “Is Your Kettle Smarter Than a Hacker? A Scalable Tool for Assessing Replay Attack Vulnerabilities on Consumer IoT Devices,” in Proceedings of the IEEE International Confer- ence on Pervasive Computing and Communic...
2024
-
[68]
Design and Im- plementation of a Lightweight Authentication Framework for the Internet of Things (IoT),
M. Alshahrani, I. Traore, and I. Woungang, “Design and Im- plementation of a Lightweight Authentication Framework for the Internet of Things (IoT),” inProceedings of the Sixth Inter- national Conference on Internet of Things: Systems, Manage- ment and Security (IOTSMS 2019) , ...
2019
-
[69]
A Digi- tal Forensic Methodology for Encryption Key Recovery from Black-Box IoT Devices,
M. R. Zunaidi, A. Sayakkara, and M. Scanlon, “A Digi- tal Forensic Methodology for Encryption Key Recovery from Black-Box IoT Devices,” in Proceeding sof the 12th Interna- tional Symposium on Digital Forensics and Security (ISDFS 2024), (San Antonio), pp. 1–7, IEEE, 2024
2024
-
[70]
Tracing MI- RAI Malware in Networked System,
Y. Xu, H. Koide, D. V. Vargas, and K. Sakurai, “Tracing MI- RAI Malware in Networked System,” in Proceedings of the Sixth International Symposium on Computing and Network- ing Workshops (CANDAR W 2018), (Takayama), pp. 534–538, IEEE, 2018
2018
-
[71]
Exploration of Smart Grid Device Cybersecurity Vulnerability Using Shodan,
D. Ackley and H. Yang, “Exploration of Smart Grid Device Cybersecurity Vulnerability Using Shodan,” in Proceedings of the IEEE Power & Energy Society General Meeting (PESGM 2020), (Montreal), pp. 1–5, IEEE, 2020
2020
-
[72]
Using Graph Databases to Assess the Security of Thingernets Based on the Thingabilities and Thingertivity of Things,
M. Lewis, “Using Graph Databases to Assess the Security of Thingernets Based on the Thingabilities and Thingertivity of Things,” in Proceedings of the Living in the Internet of Things: Cybersecurity of the IoT , (London), pp. 1–9, IEEE, 2018
2018
-
[73]
Advances in IoT Security: Vulnerabilities, Enabled Criminal Services, Attacks, and Countermeasures,
Y. R. Siwakoti, M. Bhurtel, D. B. Rawat, A. Oest, and R. C. Johnson, “Advances in IoT Security: Vulnerabilities, Enabled Criminal Services, Attacks, and Countermeasures,” IEEE In- ternet of Things Journal , vol. 10, no. 13, pp. 11224–11239, 2023
2023
-
[74]
Testing and Hardening IoT Devices Against the Mirai Bot- net,
C. Kelly, N. Pitropakis, S. McKeown, and C. Lambrinoudakis, “Testing and Hardening IoT Devices Against the Mirai Bot- net,” in Proceedings of the International Conference on Cyber Security and Protection of Digital Services (Cyber Security 2020), (Dublin), pp. 1–8, IEEE, 2020
2020
-
[75]
In-Band Secret-Free Pairing for COTS Wireless Devices,
N. Ghose, L. Lazos, and M. Li, “In-Band Secret-Free Pairing for COTS Wireless Devices,” IEEE Transactions on Mobile Computing, vol. 21, no. 2, pp. 612–628, 2022
2022
-
[76]
Policy Through Software De- faults,
R. C. Shah and J. P. Kesan, “Policy Through Software De- faults,” in Proceedings of the 2006 International Conference on Digital Government Research (dg.o 2006) , (San Diego), pp. 265–272, ACM, 2006
2006
-
[77]
Evaluat- ing the Security of eFPGA-Based Redaction Algorithms,
A. Rezaei, R. Afsharmazayejani, and J. Maynard, “Evaluat- ing the Security of eFPGA-Based Redaction Algorithms,” in Proceedings of the IEEE/ACM International Conference On Computer Aided Design (ICCAD 2022) , (San Diego), pp. 1–7, IEEE, 2022
2022
-
[78]
Security Aspects of Masking on FPGAs,
B. Giger and K. P. ad Stefan Mangard, “Security Aspects of Masking on FPGAs,” in Proceedings of the IEEE International Symposium on Hardware Oriented Security and Trust (HOST 2024), (Tysons Corner), pp. 199–210, IEEE, 2024
2024
-
[79]
AMI: An Adaptable Music Interface to Sup- port the Varying Needs of People with Dementia,
P. F. Seymour, J. Matejka, G. Foulds, I. Petelycky, and F. Anderson, “AMI: An Adaptable Music Interface to Sup- port the Varying Needs of People with Dementia,” in Proceed- ings of the 19th International ACM SIGACCESS Conference on Computers and Accessibility (ASSETS 2017) , (...
2017
-
[80]
Secure and Flexible e- Health Access Control System with Provisions for Emergency Access Overrides and Delegation of Access Privileges,
M. F. F. Khan and K. Sakamura, “Secure and Flexible e- Health Access Control System with Provisions for Emergency Access Overrides and Delegation of Access Privileges,” in Pro- ceedings of the 18th International Conference on Advanced Communication Technology (ICACT 2016) , (P...
2016
-
[81]
Re- view and Analysis of Cowrie Artefacts and Their Potential to be Used Deceptively,
W. Z. Cabral, C. Valli, L. F. Sikos, and S. G. Wakeling, “Re- view and Analysis of Cowrie Artefacts and Their Potential to be Used Deceptively,” in Proceedings of the International Conference on Computational Science and Computational In- telligence (CSCI 2019), (Las Vegas), p...
2019
-
[82]
PicNIC: Predictable Virtualized NIC,
P. Kumar, N. Dukkipati, N. Lewis, Y. Cui, Y. Wang, C. Li, V. Valancius, J. Adriaens, S. Gribble, N. Foster, and A. Vah- dat, “PicNIC: Predictable Virtualized NIC,” in Proceedings of the ACM Special Interest Group on Data Communication (SIGCOMM 2019) , (Beijing), pp. 351–366, ACM, 2019
2019
-
[83]
Towards QUIC Debuggability,
R. Marx, W. Lamotte, J. Reynders, K. Pittevils, and P. Quax, 14 “Towards QUIC Debuggability,” in Proceedings of the Work- shop on the Evolution, Performance, and Interoperability of QUIC (EPIQ 2018) , pp. 1–7, ACM, 2018
2018
-
[84]
Neferion: Time Bound, Fail-Safe and Deter- ministic Propagation of Network Connectivity Policies Across Large Multi-Datacenter Networks,
G. A. N. Yasa, N. Bisht, A. A. Ansari, I. V. P. Reddy, and S. Tangudu, “Neferion: Time Bound, Fail-Safe and Deter- ministic Propagation of Network Connectivity Policies Across Large Multi-Datacenter Networks,” in Proceedings of the 49th Annual IEEE/IFIP International Conferenc...
2019
-
[85]
Demonstrating a Personalized Secure-By-Default Bring Your Own Device Solution Based on Software Defined Networking,
S. Gebert, T. Zinner, N. Gray, R. Durner, C. Lorenz, and S. Lange, “Demonstrating a Personalized Secure-By-Default Bring Your Own Device Solution Based on Software Defined Networking,” in Proceedings of the International Teletraffic Congress (ITC 2016) , (W¨ urzburg), pp. 197–...
2016
-
[86]
Iphicles: Tuning Parameters of Data Center Networks with Differen- tiable Performance Model,
S. Huang, M. Wang, Y. Liu, Z. Liu, and Y. Cui, “Iphicles: Tuning Parameters of Data Center Networks with Differen- tiable Performance Model,” in Proceedings of the IEEE/ACM 32nd International Symposium on Quality of Service (IWQoS 2024), (Guangzhou), pp. 1–10, IEEE, 2024
2024
-
[87]
A Frame- work for Home Wireless Network Security Education,
E. Sackey, D. Lindskog, R. Ruhl, and P. Zavarsky, “A Frame- work for Home Wireless Network Security Education,” in Pro- ceedings of the IEEE Second International Conference on So- cial Computing , (Minneapolis), pp. 1044–1049, IEEE, 2010
2010
-
[88]
Evaluating Wi-Fi Security Through Wardriving: A Test-Case Analysis,
O. Cherqi, A. Sebbar, K. Chougdali, M. Boulmalf, and H. Ben- brahim, “Evaluating Wi-Fi Security Through Wardriving: A Test-Case Analysis,” in Proceedings of the 10th International Conference on Wireless Networks and Mobile Communica- tions (WINCOM 2023) , (Istanbul), pp. 1–7, ...
2023
-
[89]
Improve- ments to Multiple Path Secure Copy,
B. J. Guilfoos, L. R. Humphrey, and J. Unpingco, “Improve- ments to Multiple Path Secure Copy,” in Proceedings of the DoD HPCMP Users Group Conference , (Seattle), pp. 376– 378, IEEE, 2008
2008
-
[90]
Securing Mobile Ad Hoc Networks Using Distributed Firewall with PKI,
J. Filipek and L. Hudec, “Securing Mobile Ad Hoc Networks Using Distributed Firewall with PKI,” in Proceedings of the IEEE 14th International Symposium on Applied Machine In- telligence and Informatics (SAMI 2016) , (Herlany), pp. 321– 325, IEEE, 2016
2016
-
[91]
High- Performance Capabilities for 1-Hop Containment of Network Attacks,
T. Wolf, S. Natarajan, , and K. T. Vasudevan, “High- Performance Capabilities for 1-Hop Containment of Network Attacks,” IEEE/ACM Transactions on Networking , vol. 21, no. 6, pp. 1931–1946, 2013
1931
-
[92]
Comparative Analysis of Cybersecurity Mechanisms in SD-W AN Architectures: A Preliminary Results,
J. R. Bustamante and E. de Posgrado, “Comparative Analysis of Cybersecurity Mechanisms in SD-W AN Architectures: A Preliminary Results,” in Proceedings of the IEEE Engineering International Research Conference (EIRCON 2021) , (Lima), pp. 1–4, IEEE, 2021
2021
-
[93]
V- Digger: An Efficient and Secure Vulnerability Assessment for Large-Scale ISP Network,
N. Lu, R. Huang, M. Yao, W. Shi, and K.-K. R. Choo, “V- Digger: An Efficient and Secure Vulnerability Assessment for Large-Scale ISP Network,” IEEE Transactions on Dependable and Secure Computing , vol. 21, no. 4, pp. 3227–3246, 2024
2024
-
[94]
Char- acterizing Throughput Bottlenecks for Secure GridFTP Trans- fers,
G. Vardoyan, R. Kettimuthu, M. Link, and S. Tuecke, “Char- acterizing Throughput Bottlenecks for Secure GridFTP Trans- fers,” in Proceedings of the International Conference on Com- puting, Networking and Communications (ICNC 2013) , (San Diego), pp. 861–866, IEEE, 2013
2013
-
[95]
On Security in Giga- bit Passive Optical Networks,
T. Horvath, L. Malina, and P. Munster, “On Security in Giga- bit Passive Optical Networks,” in Proceedings of the Interna- tional Workshop on Fiber Optics in Access Network (FOAN 2015), (Brno), pp. 51–55, IEEE, 2015
2015
-
[96]
Secu- rity Automation in Next-Generation Networks and Cloud En- vironments,
F. Pizzato, D. Bringhenti, R. Sisto, and F. Valenza, “Secu- rity Automation in Next-Generation Networks and Cloud En- vironments,” in Proceedings of the IEEE Network Operations and Management Symposium (NOMS 2024) , (Seoul), pp. 1–4, IEEE, 2024
2024
-
[97]
Secure Device Bootstrapping Without Secrets Resistant to Signal Manipulation Attacks,
N. Ghose, L. Lazos, and M. Li, “Secure Device Bootstrapping Without Secrets Resistant to Signal Manipulation Attacks,” in Proceedings of the IEEE Symposium on Security and Privacy (S&P), (San Francisco), pp. 819–835, IEEE, 2018
2018
-
[98]
Secure Edge Server Placement With Non-Cooperative Game for Internet of Vehicles in Web 3.0,
Z. Liu, X. Xu, F. Han, Q. Zhao, L. Qi, W. Dou, and X. Zho, “Secure Edge Server Placement With Non-Cooperative Game for Internet of Vehicles in Web 3.0,” IEEE Transaction on Network Scince and Engineering, vol. 11, no. 5, pp. 4020–4031, 2024
2024
-
[99]
Secure and Scalable Permis- sioned Blockchain Using LDE-P2P Networks,
S. A. Murad and N. Rahimi, “Secure and Scalable Permis- sioned Blockchain Using LDE-P2P Networks,” in Proceedings of the 10th International Conference on Internet of Things: Systems, Management and Security (IOTSMS 2023) , (San Antonio), pp. 111–116, IEEE, 2023
2023
-
[100]
An Artificial Intelligence Approach for Deploying Zero Trust architecture (ZTA),
E. S. Hosney, I. T. A. Halim, and A. H. Yousef, “An Artificial Intelligence Approach for Deploying Zero Trust architecture (ZTA),” in Proceedings of the 5th International Conference on Computing and Informatics (ICCI 2022) , (Cairo), pp. 343– 350, IEEE, 2022
2022
-
[101]
Implementing a Security Policy Management for 5G Customer Edge Nodes,
H. Kabir, M. H. B. Mohsin, and R. Kantola, “Implementing a Security Policy Management for 5G Customer Edge Nodes,” in Proceedings of the IEEE/IFIP Network Operations and Man- agement Symposium (MOMS 2020) , pp. 1–8, IEEE, 2020
2020
-
[102]
NEOS: Non- Intrusive Edge Observability Stack Based on Zero Trust Se- curity Model for Ubiquitous Computing,
A. Kumar, T. Ahmed, K. Saini, and J. Kumar, “NEOS: Non- Intrusive Edge Observability Stack Based on Zero Trust Se- curity Model for Ubiquitous Computing,” in Proceedings of the IEEE International Conference on Edge Computing and Communications (EDGE 2023) , (Chicago), pp. 79–8...
2023
-
[103]
Stealth and Semi-Stealth MITM Attacks, Detection and Defense in IPv4 Networks,
N. R. Samineni, F. A. Barbhuiya, and S. Nandi, “Stealth and Semi-Stealth MITM Attacks, Detection and Defense in IPv4 Networks,” in Proceedings of the 2nd IEEE International Con- ference on Parallel, Distributed and Grid Computing , (Solan), pp. 364–367, IEEE, 2012
2012
-
[104]
Network Se- curity Monitoring (NSM): Can It Be Effective in a World With Encrypted Traffic?,
M. M. Khurana, P. Malik, and M. ShwetaPuneet, “Network Se- curity Monitoring (NSM): Can It Be Effective in a World With Encrypted Traffic?,” in Proceedings of the International Con- ference on Computation, Automation and Knowledge Man- agement (ICCAKM 2020) , (Dubai), pp. 140–...
2020
-
[105]
Combining Discretionary Policy with Mandatory Information Flow in Operating Sys- tems,
Z. Mao, N. Li, and H. Chen, “Combining Discretionary Policy with Mandatory Information Flow in Operating Sys- tems,” ACM Transactions on Information and System Secu- rity, vol. 14, no. 3, pp. 24:1 – 24:27, 2011
2011
-
[106]
Securing User Defined Containers for Scientific Computing,
J. Higgins, V. Holmes, and C. Venters, “Securing User Defined Containers for Scientific Computing,” in Proceedings of the International Conference on High Performance Computing & Simulation (HPCS 2016) , (Innsbruck), pp. 449–453, IEEE, 2016
2016
-
[107]
Interdependency Attack-Aware Secure and Performant Virtual Machine Allocation Policies With Low Attack Efficiency and Coverage,
B. O. Sane, M. Ba, D. Fall, Y. Taenaka, I. Niang, and Y. Kadobayashi, “Interdependency Attack-Aware Secure and Performant Virtual Machine Allocation Policies With Low Attack Efficiency and Coverage,” IEEE Access , vol. 12, pp. 74944–74960, 2024
2024
-
[108]
Cybersecurity Evalu- ation with PowerShell,
S. Zavala, N. Shashidhar, and C. Varol, “Cybersecurity Evalu- ation with PowerShell,” in Proceedings of the 8th International Symposium on Digital Forensics and Security (ISDFS 2020) , (Beirut), pp. 1–6, IEEE, 2020
2020
-
[109]
KGSec- Config: A Knowledge Graph Based Approach for Secured Container Orchestrator Configuration,
M. U. Haque, M. M. Kholoosi, and M. A. Babar, “KGSec- Config: A Knowledge Graph Based Approach for Secured Container Orchestrator Configuration,” in Proceedings of the IEEE International Conference on Software Analysis, Evolu- tion and Reengineering (SANER 2022) , (Honolulu), ...
2022
-
[110]
DeviceVeil: Robust Authentication for Individual USB Devices Using Physical Unclonable Functions,
K. Suzaki, Y. Hori, K. Kobara, and M. Mannan, “DeviceVeil: Robust Authentication for Individual USB Devices Using Physical Unclonable Functions,” in Proceedings of the 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2019) , (Portland), pp...
2019
-
[111]
Enhancing Windows Firewall Security Using Fuzzy Reasoning,
N. Naik and P. Jenkins, “Enhancing Windows Firewall Security Using Fuzzy Reasoning,” in Proceedings of the IEEE 14th Intl. Conf. on Dependable, Autonomic and Se- cure Computing, 14th Intl. Conf. on Pervasive Intelligence and Computing, and the 2nd Intl. Conf. on Big Data In- t...
2016
-
[112]
Solving the Interdependency Prob- lem: A Secure Virtual Machine Allocation Method Relying on the Attacker’s Efficiency and Coverage,
B. O. Sane, M. Ba, D. Fall, S. kashihara, Y. Taenaka, I. Ni- 15 ang, and Y. Kadobayashi, “Solving the Interdependency Prob- lem: A Secure Virtual Machine Allocation Method Relying on the Attacker’s Efficiency and Coverage,” in Proceedings of the IEEE/ACM International Symposiu...
2020
-
[113]
V-MCS: A Configuration System for Virtual Machines,
X.-H. Sun, C. Du, H. Zou, Y. Chen, and P. Shukla, “V-MCS: A Configuration System for Virtual Machines,” in Proceedings of the IEEE International Conference on Cluster Computing and Workshops , (New Orleans), pp. 1–7, IEEE, 2009
2009
-
[114]
Analysis of Various Vulnerabilities in the Raspbian Operating System and Solutions,
C. Le, A. M. Grande, A. Carmine, J. Thompson, and T. K. Mohd, “Analysis of Various Vulnerabilities in the Raspbian Operating System and Solutions,” in Proceedings of the IEEE World AI IoT Congress (AIIoT 2022) , (Seattle), pp. 1–6, IEEE, 2022
2022
-
[115]
IncludeOS: A Minimal, Resource Efficient Unikernel for Cloud Services,
A. Bratterud, A.-A. Walla, H. Haugerud, P. E. Engelstad, and K. Begnum, “IncludeOS: A Minimal, Resource Efficient Unikernel for Cloud Services,” in Proceedings of the IEEE 7th International Conference on Cloud Computing Technol- ogy and Science (CloudCom 2015) , (Vancouver), p...
2015
-
[116]
Security- Performance Trade-Offs of Kubernetes Container Runtimes,
William Viktorsson, C. Klein, and J. Tordsson, “Security- Performance Trade-Offs of Kubernetes Container Runtimes,” in Proceedings of the 28th International Symposium on Mod- eling, Analysis, and Simulation of Computer and Telecommu- nication Systems (MASCOTS 2020) , (Nice), p...
2020
-
[117]
Run Time Con- tainer Security Hardening Using A Proposed Model Of Secu- rity Control Map,
D. R. Pothula, K. M. Kumar, and S. Kumar, “Run Time Con- tainer Security Hardening Using A Proposed Model Of Secu- rity Control Map,” in Proceedings of the Global Conference for Advancement in Technology (GCAT 2019) , (Bangalore), pp. 1–6, IEEE, 2019
2019
-
[118]
Unveiling DNS Spoofing Vulnerabilities: An Ethical Examination Within Lo- cal Area Networks,
A. Jony, M. N. Islam, , and I. H. Sarker, “Unveiling DNS Spoofing Vulnerabilities: An Ethical Examination Within Lo- cal Area Networks,” in Proceedings of the 26th International Conference on Computer and Information Technology (ICCIT 2023), (Cox’s Bazar), pp. 1–6, IEEE, 2023
2023
-
[119]
On a Pattern-Oriented Model for Intrusion Detection,
S.-P. Shieh and V. D. Gligor, “On a Pattern-Oriented Model for Intrusion Detection,” IEEE Transactions on Knowledge and Data Engineering , vol. 9, no. 4, pp. 661–667, 1997
1997
-
[120]
Security Middleground for Resource Protection in Measurement Infrastructure-as-a-Service,
R. Akella, S. Debroy, P. Calyam, A. Berryman, K. Zhu, and M. Sridharan, “Security Middleground for Resource Protection in Measurement Infrastructure-as-a-Service,” IEEE Transac- tions on Services Computing, vol. 12, no. 4, pp. 621–638, 2019
2019
-
[121]
Shrink- ing the Kernel Attack Surface Through Static and Dynamic Syscall Limitation,
D. Zhan, Z. Yu, X. Yu, H. Zhang, and L. Ye, “Shrink- ing the Kernel Attack Surface Through Static and Dynamic Syscall Limitation,” IEEE Transactions on Services Comput- ing, vol. 16, no. 2, pp. 1431–1443, 2023
2023
-
[122]
Bandwidth- Delay-Product-Based ACK Optimization Strategy for QUIC in Wi-Fi Networks,
Y. Liu, Z. Yang, Y. Peng, T. Bi, and T. Jiang, “Bandwidth- Delay-Product-Based ACK Optimization Strategy for QUIC in Wi-Fi Networks,” IEEE Internet of Things Journal , vol. 10, no. 20, pp. 17635–17646, 2023
2023
-
[123]
Find- ing Secret Treasure? Improving Memorized Secrets Through Gamification,
K. Hartwig, A. Englisch, J. P. Thomson, and C. Reuter, “Find- ing Secret Treasure? Improving Memorized Secrets Through Gamification,” in Proceedings of the 2021 European Sym- posium on Usable Security (EuroUSEC 2021) , (Karlsruhe), pp. 105–117, ACM, 2021
2021
-
[124]
What Do Students Do With Their Assigned Default Passwords?,
L. Boˆ snjak, , and B. Brumen, “What Do Students Do With Their Assigned Default Passwords?,” in Proceedings of the 39th International Convention on Information and Communi- cation Technology, Electronics and Microelectronics (MIPRO 2016), (Opatija), pp. 1430–1435, IEEE, 2016
2016
-
[125]
A Weak Password Cracker of UHF RFID Tags,
Z. Zhao, S. Li, Y. Kang, J. Li, S. Li, and W. Hong, “A Weak Password Cracker of UHF RFID Tags,” in Proceedings of the IEEE 12th Intl. Conf. on Ubiquitous Intelligence and Comput- ing and the IEEE 12th Intl. Conf. on Autonomic and Trusted Computing and 2the IEEE 15th Intl. Conf...
2015
-
[126]
Password Usage Among Users of Smart Devices in Hungary and Serbia,
D. Mandic, G. Kiss, and Z. Rajnai, “Password Usage Among Users of Smart Devices in Hungary and Serbia,” in proceed- ings of the IEEE 18th International Symposium on Applied Computational Intelligence and Informatics (SACI 2024) , (Timisoara), pp. 309–314, IEEE, 2024
2024
-
[127]
Some Were Meant for C: The Endurance of an Unmanageable Language,
S. Kell, “Some Were Meant for C: The Endurance of an Unmanageable Language,” in Proceedings of the 2017 ACM SIGPLAN International Symposium on New Ideas, New Paradigms, and Reflections on Programming and Software (Onward! 2017) , (Vancouver), pp. 229–245, ACM, 2017
2017
-
[128]
Towards a Compiler for Reals,
E. Darulova and V. Kuncak, “Towards a Compiler for Reals,” ACM Transactions on Programming Languages and Systems , vol. 39, no. 2, pp. 8:1 – 8:28, 2017
2017
-
[129]
Secure Coding Practices in Java: Challenges and Vulnera- bilities,
N. Meng, S. Nagy, D. D. Yao, W. Zhuang, and G. A. Argoty, “Secure Coding Practices in Java: Challenges and Vulnera- bilities,” in Proceedings of the IEEE/ACM 40th International Conference on Software Engineering (ICSE 2018) , (Gothen- burg), pp. 372–383, IEEE, 2018
2018
-
[130]
Coding Practices and Recommendations of Spring Security for Enterprise Applications,
M. Islam, S. Rahaman, N. Meng, B. Hassanshahi, P. Krishnan, and D. D. Yao, “Coding Practices and Recommendations of Spring Security for Enterprise Applications,” in Proceedings of the IEEE Secure Development (SecDev 2020) , (Atlanta), pp. 49–57, IEEE, 2020
2020
-
[131]
Adopting Trusted Types in Production Web Frameworks to Prevent DOM-Based Cross-Site Scripting: A Case Study,
P. Wang, B. A. Guomundsson, and K. Kotowicz, “Adopting Trusted Types in Production Web Frameworks to Prevent DOM-Based Cross-Site Scripting: A Case Study,” in Proceed- ings of the IEEE European Symposium on Security and Pri- vacy Workshops (EuroS&PW) , (Vienna), pp. 60–73, IEEE, 2021
2021
-
[132]
The Psychology of Security: Why Do Good Users Make Bad Decisions?,
R. West, “The Psychology of Security: Why Do Good Users Make Bad Decisions?,” Communications of the ACM , vol. 51, no. 4, pp. 34–40, 2008
2008
-
[133]
SLR: From Saltzer and Schroeder to 2021... 47 Years of Research on the Development and Validation of Security API Recommenda- tions,
N. Patnaik, A. Dwyer, J. Hallett, and A. Rashid, “SLR: From Saltzer and Schroeder to 2021... 47 Years of Research on the Development and Validation of Security API Recommenda- tions,” ACM Transactions on Software Engineering Method- ology, vol. 32, no. 3, pp. 60:1 – 60:31, 2023
2021
-
[134]
Developer-Centered Security and the Symmetry of Ignorance,
O. Pieczul, S. Foley, and M. E. Zurko, “Developer-Centered Security and the Symmetry of Ignorance,” in Proceedings of the 2017 New Security Paradigms Workshop (NSPW 2017) , (Santa Cruz), pp. 46–56, ACM, 2017
2017
-
[135]
Is “Deny Access
F. Massacci, “Is “Deny Access” a Valid “Fail-Safe Default”,” IEEE Security & Privacy , vol. 17, no. 5, pp. 90–93, 2019
2019
-
[136]
A User-Centered, Modular Authorization Service Built on an RBAC Founda- tion,
M. E. Zurko, R. Simon, and T. Sanfilippo, “A User-Centered, Modular Authorization Service Built on an RBAC Founda- tion,” in Proceedings of the 1999 IEEE Symposium on Secu- rity and Privacy (S&P 1999) , (Oakland), pp. 57–71, IEEE, 1999
1999
-
[137]
Exploring How to Apply Secure Software Design Principles,
S. A. Ebad, “Exploring How to Apply Secure Software Design Principles,” IEEE Access, vol. 10, pp. 128983–128993, 2022
2022
-
[138]
Did You Ever Have To Make Up Your Mind? What Notes Users Do When Faced With A Security Decision,
M. E. Zurko, C. Kaufman, K. Spanbauer, and C. Bassett, “Did You Ever Have To Make Up Your Mind? What Notes Users Do When Faced With A Security Decision,” in Proceedings of the 18th Annual Computer Security Applications Conference , (Las Vegas), pp. 371–381, IEEE, 2002
2002
-
[139]
Computer Security and the Modern Home,
T. Denning, T. Kohno, and H. M. Levy, “Computer Security and the Modern Home,” Communications of the ACM, vol. 56, no. 1, pp. 94–103, 2013
2013
-
[140]
MUSP: Multi-Service, User Self-Controllable and Privacy- Preserving System for Smart Metering,
M. A. Mustafa, N. Z. ad Georgios Kalogridis, and Z. Fan, “MUSP: Multi-Service, User Self-Controllable and Privacy- Preserving System for Smart Metering,” in Proceedings of the IEEE International Conference on Communications (ICC 2015), (London), pp. 788–794, IEEE, 2015
2015
-
[141]
Opti- mistic Access Control for the Smart Home,
N. Malkin, A. F. Luo, J. Poveda, and M. L. Mazurek, “Opti- mistic Access Control for the Smart Home,” in Proceedings of the IEEE Symposium on Security and Privacy (S&P) , (San Francisco), pp. 3043–3060, IEEE, 2023
2023
-
[142]
Demonstrating ScreenshotMatcher: Taking Smartphone Photos to Capture Screenshots,
A. Schmid, T. Fischer, , A. Weichart, A. Hartmann, and R. Wimme, “Demonstrating ScreenshotMatcher: Taking Smartphone Photos to Capture Screenshots,” in Proceedings of Mensch und Computer 2021 (MuC 2021) , (Ingolstadt), pp. 586–589, ACM, 2021
2021
-
[143]
“I’m Surprised So Much Is Connected
S. Hammann, M. Crabb, S. Radomirovic, R. Sasse, and 16 D. Basin, ““I’m Surprised So Much Is Connected”: A Study on Users’ Online Accounts,” in Proceedings of the 2022 CHI Conference on Human Factors in Computing Systems (CHI 2022), (New Orleans), pp. 1–13, ACM, 2022
2022
-
[144]
An Android Application to Secure Text Messages,
D. Demirol, R. Das, , and G. Tuna, “An Android Application to Secure Text Messages,” in Proceedings of the International Artificial Intelligence and Data Processing Symposium (IDAP 2017), (Malatya), pp. 1–6, IEEE, 2017
2017
-
[145]
What Do Software Developers Need to Know to Build Secure Energy-Efficient Android Applications?,
J. A. Montenegro, M. Pinto, and L. Fuentes, “What Do Software Developers Need to Know to Build Secure Energy-Efficient Android Applications?,” IEEE Access, vol. 6, pp. 1428–1450, 2018
2018
-
[146]
“You Received $100,000 From Johnny
T. Neteler, S. Fahl, and L. L. Iacono, ““You Received $100,000 From Johnny”: A Mixed-Methods Study on Push Notification Security and Privacy in Android Apps,” IEEE Access, vol. 12, pp. 112499–112516, 2024
2024
-
[147]
All Friends are NOT Created Equal: An Interaction Intensity Based Approach to Privacy in Online Social Networks,
L. Banks and S. F. Wu, “All Friends are NOT Created Equal: An Interaction Intensity Based Approach to Privacy in Online Social Networks,” in Proceedings of the International Confer- ence on Computational Science and Engineering, (Vancouver), pp. 970–974, IEEE, 2009
2009
-
[148]
Personal Information Disclosure of User-Profiles on Facebook,
S. I. Bhat, T. Arif, M. B. Malik, and A. A. Sheikh, “Personal Information Disclosure of User-Profiles on Facebook,” in Pro- ceedings of the 2nd International Conference on Advances in Computing, Communication Control and Networking (ICAC- CCN 2020) , (Greater Noida), pp. 71–77...
2020
-
[149]
A Trusted Communication Unit for Secure Tiled Hardware Architectures,
S. Haas and N. Asmussen, “A Trusted Communication Unit for Secure Tiled Hardware Architectures,” in Proceedings of the 29th IEEE International Conference on Electronics, Circuits and Systems (ICECS 2022) , (Glasgow), pp. 1–4, IEEE, 2022
2022
-
[150]
Fine-Grained Data- Centric Content Protection Policy for Web Applications,
Z. Wang, W. Meng, and M. R. Lyu, “Fine-Grained Data- Centric Content Protection Policy for Web Applications,” in Proceedings of the 2023 ACM SIGSAC Conference on Com- puter and Communications Security (CCS 2023) , (Copen- hagen), pp. 2845–2859, ACM, 2023
2023
-
[151]
Fine-Grained Privilege Separation for Web Applications,
A. Krishnamurthy, A. Mettler, and D. Wagner, “Fine-Grained Privilege Separation for Web Applications,” in Proceedings of the 19th International Conference on World wide Web (WWW 2010) , (Raleigh), pp. 551–560, ACM, 2010
2010
-
[152]
Evaluating Grid Portal Security,
D. Del Vecchio, V. Hazlewood, and M. Humphrey, “Evaluating Grid Portal Security,” in Proceedings of the 2006 ACM/IEEE Conference on Supercomputing (SC 2006), (Tampa), pp. 1–14, ACM, 2006
2006
-
[153]
An Empirical Study of the Framework Impact on the Security of JavaScript Web Ap- plications,
K. Peguero, N. Zhang, and X. Cheng, “An Empirical Study of the Framework Impact on the Security of JavaScript Web Ap- plications,” in Companion Proceedings of the The Web Con- ference (WWW 2018) , (Lyon), pp. 753–758, ACM, 2018
2018
-
[154]
Empir- ical Analysis and Privacy Implications in OAuth-Based Single Sign-On Systems,
S. G. Morkonda, S. Chiasson, and P. C. van Oorschot, “Empir- ical Analysis and Privacy Implications in OAuth-Based Single Sign-On Systems,” in Proceedings of the 20th Workshop on Workshop on Privacy in the Electronic Society (WPES 2021) , (Virtual Event), pp. 195–208, ACM, 2021
2021
-
[155]
PEBA Enhancing User Privacy and Coverage of Safe Brows- ing Services,
Y. Du, H. Duan, L. Xu, H. Cui, C. Wang, and Q. Wang, “PEBA Enhancing User Privacy and Coverage of Safe Brows- ing Services,” IEEE Transactions on Dependable and Secure Computing, vol. 20, no. 5, pp. 4343–4358, 2023
2023
-
[156]
Forensics Analysis of Private Web Browsing Using Android Memory Acquisition,
L. B. Younis, S. Sweda, and A. Alzu’bi, “Forensics Analysis of Private Web Browsing Using Android Memory Acquisition,” in Proceedings of the 12th International Conference on Infor- mation and Communication Systems (ICICS 2021) , (Valen- cia), pp. 273–278, IEEE, 2021
2021
-
[157]
Oh, the Places You’ll Go! Finding Our Way Back from the Web Platform’s Ill-Conceived Jaunts,
A. Janc and M. West, “Oh, the Places You’ll Go! Finding Our Way Back from the Web Platform’s Ill-Conceived Jaunts,” in Proceedings of the IEEE European Symposium on Security and Privacy Workshops (EuroS&PW 2020), (Genoa), pp. 673–680, IEEE, 2020
2020
-
[158]
Hardening the Client-Side: A Guide to Enterprise-Level Hardening of Web Browsers,
A. A. Jillepalli, D. C. de Leon, S. Steiner, F. T. Sheldon, and M. A. Haney, “Hardening the Client-Side: A Guide to Enterprise-Level Hardening of Web Browsers,” in Proceedings of the IEEE 15th Intl Conf on Dependable, Autonomic and Secure Computing, the 15th Intl. Conf. on Per...
2017
-
[159]
Automated White-List Learning Technique for Detection of Malicious Attack on Web Application,
S. M. Murtaza and A. S. Abid †, “Automated White-List Learning Technique for Detection of Malicious Attack on Web Application,” in Proceedings of the 13th International Bhur- ban Conference on Applied Sciences and Technology (IBCAST 2016), (Islamabad), pp. 416–420, IEEE, 2016
2016
-
[160]
A Comprehensive Approach to Abusing Locality in Shared Web Hosting Servers,
S. A. Mirheidari, S. Arshad, S. Khoshkdahan, and R. Jalili, “A Comprehensive Approach to Abusing Locality in Shared Web Hosting Servers,” in Proceedings of the 12th IEEE Interna- tional Conference on Trust, Security and Privacy in Comput- ing and Communications, (Melbourne), p...
2013
-
[161]
ES- CUDO: A Fine-Grained Protection Model for Web Browsers,
K. Jayaraman, W. Du, B. Rajagopalan, and S. J. Chapin, “ES- CUDO: A Fine-Grained Protection Model for Web Browsers,” in Proceedings of the IEEE 30th International Conference on Distributed Computing Systems , (Genoa), pp. 231–240, IEEE, 2010
2010
-
[162]
CredEx: User-Centric Credential Management for Grid and Web Services,
D. D. Vecchio, M. Humphrey, , J. Basney, and N. Nagaratnam, “CredEx: User-Centric Credential Management for Grid and Web Services,” in Proceedings of the IEEE International Con- ference on Web Services (ICWS 2005) , (Orlando), pp. 149– 156, IEEE, 2005
2005
-
[163]
Research Report: Mitigating LangSec Prob- lems With Capabilities,
N. W. Filardo, “Research Report: Mitigating LangSec Prob- lems With Capabilities,” in Proceedings of the IEEE Security and Privacy Workshops (S&PW) , (San Jose), pp. 189–197, IEEE, 2016
2016
-
[164]
Moving from Training to Compli- ance: Practical Methodology to Monitor Worker Compliance to Electrical Safe Work Practices,
R. S. LeRoy and T. McCoy, “Moving from Training to Compli- ance: Practical Methodology to Monitor Worker Compliance to Electrical Safe Work Practices,” in Proceedings of the IEEE IAS Electrical Safety Workshop , (San Diego), pp. 1–7, IEEE, 2014
2014
-
[165]
Hazard or Risk Analysis, Overcoming the Hu- man Factor,
R. S. LeRoy, “Hazard or Risk Analysis, Overcoming the Hu- man Factor,” in Proceedings of the 2015 IEEE IAS Electrical Safety Workshop , (Louisville), pp. 1–6, IEEE, 2015
2015
-
[166]
The Internet of Things: How the Next Evolu- tion of the Internet Is Changing Everything
D. Evans, “The Internet of Things: How the Next Evolu- tion of the Internet Is Changing Everything.” Cisco Inter- net Business Solutions Group (IBSG), available online in De- cember: https://www.cisco.com/c/dam/en_us/about/ac79/ docs/innov/IoT_IBSG_0411FINAL.pdf, 2011
2011
-
[167]
A Sur- vey on Anti-Honeypot and Anti-Introspection Methods,
J. Uitto, S. Rauti, S. Laur´ en, and V. Lepp¨ anen, “A Sur- vey on Anti-Honeypot and Anti-Introspection Methods,” in Proceedings of the World Conference on Information Systems and Technologies (WorldCIST 2017), (Madeira), pp. 125–134, Springer, 2017
2017
-
[168]
Extending Access Control Models With Break-Glass,
A. D. Brucker and H. Petritsch, “Extending Access Control Models With Break-Glass,” in Proceedings of the 14th ACM symposium on Access Control Models and Technologies (SAC- MAT 2009), (Stresa), pp. 197–206, ACM, 2009
2009
-
[169]
Unhelpful Assumptions in Software Security Research,
I. Ryan, U. Roedig, and K. Stol, “Unhelpful Assumptions in Software Security Research,” in Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Secu- rity (CCS 2023) , (Copenhagen), pp. 3460–3474, ACM, 2023
2023
-
[170]
Lever- aging Sustainable Systematic Literature Reviews
V. dos Santos, R. Kazman, and E. Y. Nakagawa, “Lever- aging Sustainable Systematic Literature Reviews.” Archived manuscript, available online in January 2025: https://arxiv. org/abs/2501.01819, 2025
2025 arXiv
-
[171]
Disentangling Patent Quality: Using a Large Language Model for a Systematic Literature Review,
V. J. Schmitt, “Disentangling Patent Quality: Using a Large Language Model for a Systematic Literature Review,” Scien- tometrics, no. Published online in January, pp. 1–45, 2025
2025
-
[172]
Empirical Software En- gineering: From Discipline to Interdiscipline,
D. M. Fern´ andez and J.-H. Passoth, “Empirical Software En- gineering: From Discipline to Interdiscipline,” Journal of Sys- tems and Software , vol. 148, pp. 170–179, 2019
2019
-
[173]
SWEBOK: Guide to the Software Engineering Body of Knowledge
IEEE et al. , “SWEBOK: Guide to the Software Engineering Body of Knowledge.” A Project of the IEEE Computer Soci- ety Professional Practices Committee, IEEE Computer Soci- ety, available online in December 2024: https://sceweb.sce. uhcl.edu/helm/SWEBOK_IEEE/SWEBOK_Guide_2004.pdf, 2004
2024
-
[174]
Usability is Not the Dark Side: Secure Usable Design Seen through Star Wars,
A.-M. Horcher and W. Dula, “Usability is Not the Dark Side: Secure Usable Design Seen through Star Wars,” in Proceedings 17 of the Symposium on Usable Privacy and Security (SOUPS 2019), (Santa Clara), pp. 1–6, USENIX, 2019
2019
-
[175]
Software Security,
G. McGraw, “Software Security,” IEEE Security & Privacy , vol. 2, no. 2, pp. 80–83, 2004
2004
-
[176]
There’s a Hole in that Bucket! A Large-Scale Analysis of Misconfig- ured S3 Buckets,
A. Continella, M. Polino, M. Pogliani, and S. Zanero, “There’s a Hole in that Bucket! A Large-Scale Analysis of Misconfig- ured S3 Buckets,” in Proceedings of the 34th Annual Computer Security Applications Conference (ACSAC 2018), (San Juan), pp. 702–711, ACM, 2018
2018
-
[177]
Secu- rity Misconfigurations in Open Source Kubernetes Manifests: An Empirical Study,
A. Rahman, S. I. Shamim, D. B. Bose, and R. Pandita, “Secu- rity Misconfigurations in Open Source Kubernetes Manifests: An Empirical Study,” ACM Transactions on Software Engi- neering and Methodology, vol. 32, no. 4, pp. 1–36, 2023
2023
-
[178]
Vulnerability Coordination Un- der the Cyber Resilience Act
J. Ruohonen and P. Timmers, “Vulnerability Coordination Un- der the Cyber Resilience Act.” Archived manuscript, available online: https://arxiv.org/abs/2412.06261, 2024
2024
-
[179]
Regulating Online Defaults,
K. Grill, “Regulating Online Defaults,” in The Philosophy of Online Manipulation (F. Jongepier and M. Klenk, eds.), pp. 373–391, New York: Routledge, 2022. 18
2022
Reviewed August 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.