Pith. sign in

REVIEW 3 major objections 5 minor 179 references

SoK: The Design Paradigm of Safe and Secure Defaults

T0 review · 3 major / 5 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read This systematization of knowledge argues that the safe-and-secure-defaults paradigm, rooted in Saltzer and Schroeder's 1975 fail-safe defaults principle, has been extensively discussed, applied, and extended across computing domains since…

desk verdict Useful, honest first systematic map of the safe/secure-defaults paradigm; the ACM/IEEE-only sample is a real limitation but not a deal-breaker. read the letter →

arxiv 2412.17329 v2 pith:DX2QM456 submitted 2024-12-23 cs.CR cs.NIcs.SE

classification cs.CRcs.NIcs.SE
keywords safeandsecuredefaultsfail-safesecuritydesignprinciplessystematicmappingstudyscopingreviewInternetofThingsSaltzerSchroederdefaultsettings
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper is a systematization of knowledge that maps 148 peer-reviewed papers discussing safe and secure defaults, the design rule that systems should start in a locked-down, safe state rather than an open one. The review shows that the paradigm, born as the fail-safe-defaults access-control principle in Saltzer and Schroeder's 1975 paper, has been continuously discussed and extended since the late 1990s, with publication volume accelerating from the mid-2010s onward as Internet-of-Things insecurity made the topic urgent. The same survey catalogs how the paradigm has expanded beyond access control into networking, cryptography, operating systems, cyber-physical systems, and even work safety, and how newer principles such as off-by-default, automated default generation, and zero-trust verification have been added to the original eight. A sympathetic reader would care because the review gives researchers, practitioners, and regulators a working map of a doctrine that is now written into recent cyber-security regulation, while also exposing how little rigorous empirical evidence backs the behavioral assumptions attached to defaults.

What carries the argument

The load-bearing apparatus is the review protocol itself: a systematic mapping study and scoping review run against ACM's and IEEE's electronic libraries using the Boolean query $(\text{safe AND default}) \lor (\text{secure AND default})$, filtered by four exclusion criteria (primary studies only; substantive discussion of defaults with definition, example, rationale, or elaboration; peer-reviewed journals and conference proceedings; no finance papers where 'default' means non-payment), yielding a corpus of 148 papers analyzed thematically. The conceptual backbone that organizes the findings is Saltzer and Schroeder's 1975 fail-safe-defaults principle, generalized by replacing 'access' with any resource so that the paradigm covers safety as well as security; the review's tables of contextual domains, motivating themes, design principles, and problems carry the argument that the paradigm has both spread and evolved.

What would settle it

Run the same Boolean query and inclusion criteria in Scopus, Web of Science, or domain-specific venues such as SOUPS, CHI, and safety-engineering journals and compare the corpus. If substantial primary studies on safe and secure defaults appear before the late 1990s, if the mid-2010s acceleration disappears outside ACM/IEEE, or if a well-developed body of empirical work on default-setting behavior shows up, the review's claims about the paradigm's timeline, IoT-driven growth, and the folklore of human factors would be contradicted.

Watch

Extended reading notes

Core claim

On the paper's own terms, the central discovery is that the safe-and-secure-defaults paradigm is not a static historical footnote but a live, expanding design doctrine. Reviewing 148 primary studies gathered from the ACM and IEEE digital libraries with the query $(\text{safe AND default}) \lor (\text{secure AND default})$ and strict inclusion criteria, the author concludes that the paradigm has been extensively discussed, used, and developed further since the late 1990s; that its growth accelerated from roughly the mid-2010s, driven substantially by the perceived insecurity of IoT devices; and that it has been applied across a wide range of computing domains while being extended with principles the originators did not consider, including off-by-default, turning security features on by default, overriding and fallback designs, clean-up and leak-prevention routines, automated generation of secure defaults, and zero-trust assumptions. The review also documents recurring problems, such as emergency access overrides, the argument that today's secure default becomes tomorrow's vulnerability, developer workarounds, and security-performance trade-offs, and it notes that most claims about human behavior attached to defaults are speculative folklore rather than robust empirical findings.

Load-bearing premise

The whole picture depends on the search being run only in ACM's and IEEE's electronic libraries; if much of the research on safe and secure defaults lives in other venues, such as human-computer interaction, social science, or safety engineering, the identified timeline, principles, and gaps would be different.

Editorial extensions

If this is right

  • If the review is right, the EU Cyber Resilience Act's 'secure by default configuration' requirement has a concrete body of engineering knowledge behind it, from off-by-default networking to automated credential generation, that implementers and auditors can draw on.
  • If the review is right, designers in domains far from 1970s access control—IoT, cyber-physical systems, web security, cryptography—can legitimately treat safe and secure defaults as a general engineering doctrine rather than a specialized historical principle.
  • If the review is right, the paradigm's expansion means a full catalog of security design principles, with overlapping terms unified (psychological acceptability as least surprise, isolation as compartmentalization), would be a high-value next step for research and practice.
  • If the review is right, the empirical gap matters: regulations and designs that assume users and developers stay with defaults out of inertia or out of information conveyed by defaults rest on claims the literature has not yet tested rigorously.
  • If the review is right, configuration vulnerabilities in cloud computing and other newer domains are under-covered, and secure defaults are the natural starting point for mitigating that class of failures.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • One extension the paper leaves implicit is that the ACM/IEEE restriction may explain the absence of organizational and social-science perspectives: a reader shopping for literature on default settings would find a large body of work in management, psychology, behavioral economics, and policy journals that this sample simply does not include.
  • Because the review treats defaults as largely static, a natural testable extension is to give defaults a temporal dimension—sunset clauses, dynamic re-defaulting, or periodic re-evaluation—so that 'today's secure default becomes tomorrow's vulnerability' becomes a design requirement rather than a critique.
  • The folklore gap in human-factor claims suggests a concrete research program: instrument real systems to measure what happens when users and developers actually encounter secure defaults, using A/B experiments of the kind one paper in the sample used for product features, to replace speculation with effect estimates.
  • A further extension: since the paradigm is now encoded in regulation, one could audit shipped products for default settings that violate the cataloged principles (deny-by-default, off-by-default, least privilege), turning the SoK's taxonomy into a compliance checklist.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. This paper presents a systematization of knowledge (SoK) on the design paradigm of safe and secure defaults, conducted as a systematic mapping study / scoping review. The search protocol is the Boolean query (safe AND default) OR (secure AND default) run in the ACM and IEEE electronic libraries, with four exclusion criteria (primary studies only; substantive discussion of safe or secure defaults; peer-reviewed journal or conference papers; non-financial topics), yielding n=148 papers. The review maps publication trends (growth from the late 1990s, acceleration from the mid-2010s attributed partly to IoT insecurity), contextual domains (28 categories in Table 2, from access control and operating systems to IoT, cyber-physical systems, and work safety), motivations (dominated by insecure or unsafe defaults and human factors), design principles (including newer off-by-default, overriding/fallback, leak-prevention, and zero-trust principles), and four problem areas (break-glass emergencies, prediction failure, developer workarounds, trade-offs). The discussion closes with six summary points, an explicit limitation section (single-author coding; uncertain generalizability of the ACM/IEEE-only sample), and four future-research directions, including the EU Cyber Resilience Act.

Significance. If the review's claims hold, this is the first systematic map of the fail-safe-defaults paradigm and a useful reference for researchers, educators, and regulators. Strengths worth naming: the search string and exclusion criteria are reported verbatim; sampled and non-sampled literature are cleanly separated throughout; quotations are given with page numbers, making the thematic claims checkable; the author candidly classifies much human-factor reasoning in the sampled literature as folklore rather than evidence; and Section 4.2 states the single-coder and generalizability limitations explicitly. I find no circularity: the self-citations serve background or methodological points only. The main contributions are the catalog of emerging principles (off-by-default, overriding and fallback, leak prevention, zero trust), the documentation of the IoT-driven acceleration, and the identified gaps (organizational security, social science, regulation), which give the paper an agenda-setting function despite its exploratory design.

major comments (3)
  1. [Abstract; §2; §4.1; §4.2] Section 2 restricts the search to the ACM and IEEE electronic libraries, Section 4.2 concedes that the n=148 sample cannot be generalized to an unknown theoretical population, and Section 4.3 admits that social-science and organizational-security work is absent from the sample. Despite these concessions, the abstract states that 'the paradigm has been extensively discussed, used, and developed further since the late 1990s,' and Section 4.1 makes unqualified assertions such as 'the domains in which the paradigm has been discussed and applied have considerably expanded over the years' (point 1) and 'the design paradigm has been discussed and developed with many security design principles' (point 5). These are claims about the paradigm as a whole, whereas the evidence base is a single sample drawn from two publisher libraries; major security venues such as USENIX Security, SOUPS, and NDSS, as well as behavioral, privacy, and safety-engineering outlets, are outside the sample. I regard this as a load-bearing scope mismatch rather than a fatal flaw: the fix is to either run the same protocol in additional databases (e.g., Scopus, Web of Science) and report whether the principles and gaps change, or explicitly qualify all headline claims and conclusions with 'in the reviewed ACM/IEEE-indexed literature,' including a visible caveat in the abstract.
  2. [§2; Fig. 1] Fig. 1 reports raw query counts (ACM 76/35; IEEE 35/503) and qualified counts (20/12/22/94) but does not report how many papers were excluded under each of the four inclusion/exclusion criteria, and the date of the searches is not stated anywhere in Section 2. Without this standard screening accounting, readers cannot assess how the exclusion criteria shaped the sample, which is central to a paper that claims systematization. Please add a per-criterion screening table with counts at each stage, state the search date, and clarify whether the ACM and IEEE queries matched metadata or full text.
  3. [§2; §4.2; Figs. 4–6; Table 2] Section 4.2 openly acknowledges that the review was conducted by a single author and that inter-rater reliability measures cannot be provided; this honesty is to the paper's credit. Nevertheless, Figs. 4–6 and Table 2 are the substantive contribution, and the paper currently offers no way to audit the coding: there is no initial category list, no operationalized merging rule beyond 'collating and merging of overlapping... categories,' and no worked example of how borderline papers were assigned (the 'opt-in' category in Fig. 4 is one such case). I recommend adding a codebook with the category definitions and one or two worked coding examples as an appendix or supplementary material so that the thematic constructs can be judged without a second coder.
minor comments (5)
  1. [Table 2; Fig. 1] Table 2 lists 147 paper references by my count, whereas Fig. 1 reports a sample size of n=148; please verify the bookkeeping and add the missing reference or correct the count.
  2. [§3.4; Fig. 5] Section 3.4 states that 'three papers built upon the emerging zero trust principle' and quotes [98], [102], and [112], but Fig. 5 lists [98], [100], and [102] for zero trust; please align the text and the figure.
  3. [§2; §3.3] Section 2 flags paper [10] as likely containing tortured phrases, yet Section 3.3 cites [10] for the substantive claim that email is 'still unencrypted by default'; please verify that citation or replace it with a source of clear provenance.
  4. [References] Several reference entries contain errors: [44] gives the year 2019 for SACMAT 2007, [101] reports the symposium acronym as 'MOMS' where NOMS is presumably intended, [98] reads 'Scince' and [69] reads 'Proceeding sof,' [154] duplicates 'Workshop on,' [125] has '2the IEEE 15th Intl,' and [91] and [142] contain stray commas; a reference-list cleanup is in order.
  5. [Figs. 1, 4; §1; §2] Figure 1 spells 'detaults' twice, Fig. 4 has 'Acess controls,' Section 2 uses the unusual phrase 'overcasting' where 'overarching' seems intended, and Section 1 reads 'The Saltzer's and Schroeder's paper'; a light copy-editing pass over the figures and prose is needed.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the SoK's claims are descriptive summaries of a transparently defined 148-paper sample, and the author's self-citations are auxiliary rather than load-bearing.

full rationale

This is a systematization of knowledge (a scoping review / systematic mapping study), not a derivation chain, so there is no fitted parameter renamed as a prediction and no theorem imported from the author's prior work to force a conclusion. The central claims—that the safe-and-secure-defaults paradigm has been discussed since the late 1990s, accelerated from the mid-2010s, and spread across domains—are expressly grounded in the n = 148 reviewed papers and presented through transparent search and inclusion criteria (Section 2). The author's self-citations ([5], [15], [16], [18], [178]) support only auxiliary points: a safety-versus-security definitional clarification, qualitative thematic-analysis practice, text pre-processing details, and a regulatory reference for the Cyber Resilience Act; none of these feeds back into the review's six conclusions in a way that makes the conclusions equivalent to their inputs. The acknowledged limitations—single-author review and restriction to ACM and IEEE digital libraries—affect generalizability and representativeness, but the paper explicitly hedges its conclusions as exploratory and even notes that social-science and organizational-security literature is missing. Such sampling concerns are correctness risks, not circularity. No step in the paper reduces, by construction or by self-citation, to its own input, so the appropriate finding is no significant circularity.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

The review's conclusions depend on the sampling and coding assumptions rather than on fitted parameters or new constructs. The main risks are that the ACM/IEEE-only search misses relevant literature and that single-author thematic coding is subjective.

assumptions (3)
  • domain assumption The ACM and IEEE digital libraries contain a representative sample of the literature on safe and secure defaults
    The search is restricted to ACM and IEEE in Section 2; if relevant work is predominantly published elsewhere (e.g., social science, usability venues), the trends and gaps identified would be biased.
  • domain assumption Thematic analysis by a single author yields reliable and reproducible categories
    Section 2 and Section 4.2 acknowledge single-author coding with no inter-rater reliability; the theme boundaries could depend on the coder's judgment.
  • domain assumption The search query and exclusion criteria capture the intended scope
    The boolean query (safe AND default) OR (secure AND default) and the four exclusion criteria define what counts as discussing the paradigm; papers using other phrasings may be missed.

how reviews work

0 comments
Cite this review

Pith. "Pith review of SoK: The Design Paradigm of Safe and Secure Defaults." pith.science (2026). https://pith.science/paper/DX2QM456

@misc{pith2026241217329,
  author       = {Pith},
  title        = {Pith review of: SoK: The Design Paradigm of Safe and Secure Defaults},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/DX2QM456}},
  note         = {Machine review of arXiv:2412.17329}
}
read the original abstract

In security engineering, including software security engineering, there is a well-known design paradigm telling to prefer safe and secure defaults. The paper presents a systematization of knowledge (SoK) of this paradigm by the means of a systematic mapping study and a scoping review of relevant literature. According to the mapping and review, the paradigm has been extensively discussed, used, and developed further since the late 1990s. Partially driven by the insecurity of the Internet of things, the volume of publications has accelerated from the circa mid-2010s onward. The publications reviewed indicate that the paradigm has been adopted in numerous different contexts. It has also been expanded with security design principles not originally considered when the paradigm was initiated in the mid-1970s. Among the newer principles are an "off by default" principle, various overriding and fallback principles, as well as those related to the zero trust model. The review also indicates problems developers and others have faced with the paradigm.

Figures

Figures reproduced from arXiv: 2412.17329 by the authors.

Figure 1
Figure 1. The Sample of Literature Reviewed It can be also noted that the criteria were strictly fol￾lowed in order to minimize subjectivity. Therefore, it is worth further remarking that there is a paper [10] that has likely used so-called tortured phrases [11] or something alike. To deal with such papers as well as the overall feasi￾bility problem, it might be possible to evaluate the quality of papers [12], but the problem… view at source ↗
Figure 2
Figure 2. Publication Years As can be seen, there has been a growing interest in the design paradigm. However, the earliest papers were published in the late 1990s, which marks an over twenty years gap between the classic and the initially following contributions. A further point is that the publication pace has accelerated from about mid-2010s onward. As soon discussed, there is a specific reason for the acceleration. The cl… view at source ↗
Figure 3
Figure 3. Top-30 Bigrams Further basic quantitative information can be provided in the form of the top-ranked bigrams shown in [PITH_FULL_IMAGE:figures/full_fig_p004_3.png] view at source ↗
Figures from the paper (2 more)
Figure 4
Figure 4. Figure 4: Thematic Motivations for the Design Paradigm [PITH_FULL_IMAGE:figures/full_fig_p007_4.png]
Figure 5
Figure 5. Figure 5: Design Principles Emergencies and delegations [80] Problems with predictions [134, 135] Risk of workarounds [36, 128, 129] Trade-offs [94, 116, 120, 122] [PITH_FULL_IMAGE:figures/full_fig_p007_5.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

179 extracted references · 78 canonical work pages

  1. [1]

    The Protection of In- formation in Computer Systems,

    J. M. Saltzer and M. D. Schroeder, “The Protection of In- formation in Computer Systems,” Proceedings of the IEEE , vol. 63, no. 9, pp. 1278–1308, 1975

  2. [2]

    Design Notations for Secure Software: A Systematic Litera- ture Review,

    A. van den Berghe, R. Scandariato, K. Yskout, and W. Joosen, “Design Notations for Secure Software: A Systematic Litera- ture Review,” Software & Systems Modeling , vol. 16, pp. 809– 831, 2017

  3. [3]

    The Bur- geoning Role of Literature Review Articles in Management Re- search: An Introduction and Outlook,

    S. Kraus, R. B. Bouncken, and A. Y. Ar´ anega, “The Bur- geoning Role of Literature Review Articles in Management Re- search: An Introduction and Outlook,” Review of Managerial Science, vol. 18, pp. 299–314, 2024

  4. [4]

    Gamma, R

    E. Gamma, R. Helm, R. Johnson, and J. Vlissides, Design Patterns: Elements of Reusable Object-Oriented Software . Boston: Addison-Wesley, 1995

  5. [5]

    A Review of Product Safety Regulations in the European Union,

    J. Ruohonen, “A Review of Product Safety Regulations in the European Union,” International Cybersecurity Law Review , vol. 3, pp. 345–366, 2022

  6. [6]

    Schumacher, Security Engineering with Patterns: Origins, Theoretical Model, and New Applications

    M. Schumacher, Security Engineering with Patterns: Origins, Theoretical Model, and New Applications . Berlin: Springer, 2003. 2 Regulation (EU) 2024/2847. 3 Paragraph 2(b) in Annex I

  7. [7]

    The Benefits of Systematic Mapping to Evidence-Based En- vironmental Management,

    N. R. Haddaway, C. Bernes, B.-G. Jonsson, and K. Hedlund, “The Benefits of Systematic Mapping to Evidence-Based En- vironmental Management,” Ambio, vol. 45, pp. 613–620, 2016

  8. [8]

    A Scoping Review of Scop- ing Reviews: Advancing the Approach and Enhancing the Consistency,

    M. T. Pham, A. Raji´ c, J. D. Greig, J. M. Sargeant, A. Pa- padopoulosa, and S. A. McEwen, “A Scoping Review of Scop- ing Reviews: Advancing the Approach and Enhancing the Consistency,” Research Synthesis Methods , vol. 5, pp. 371– 385, 2014

Show all 179 references
  1. [9]

    Scop- ing Reviews: Reinforcing and Advancing the Methodology and Application,

    M. D. J. Peters, C. Marnie, H. Colquhoun, C. M. Garritty, S. Hempel, T. Horsley, E. V. Langlois, E. Lillie, K. K. O’Brien, O. Tun¸ calp, M. G. Wilson, W. Zarin, and A. C. Tricco, “Scop- ing Reviews: Reinforcing and Advancing the Methodology and Application,” Systematic Reviews...

  2. [10]

    Enhancing Secu- rity Measures of AI Applications,

    Y. S. Chaudhry, U. Sharma, and A. Rana, “Enhancing Secu- rity Measures of AI Applications,” in Proceedings of the 8th International Conference on Reliability, Infocom Technologies and Optimization (Trends and Future Directions) (ICRITO 2020), (Noida), pp. 713–716, IEEE, 2020

  3. [11]

    Tortured Phrases: A Dubious Writing Style Emerging in Science: Evidence of Critical Issues Affecting Established Journals

    G. Cabanac, C. Labb´ e, and A. Magazinov, “Tortured Phrases: A Dubious Writing Style Emerging in Science: Evidence of Critical Issues Affecting Established Journals.” Archived manuscript, available online in December 2024: https:// arxiv.org/abs/2107.06751, 2021

  4. [12]

    Secondary Studies on Human Aspects in Software Engineering: A Ter- tiary Study,

    E. Zolduoarrati, S. A. Licorish, and N. Stanger, “Secondary Studies on Human Aspects in Software Engineering: A Ter- tiary Study,” The Journal of Systems & Software , vol. 200, p. 111654, 2023

  5. [13]

    Lessons From Applying the Systematic Literature Review Process Within the Software Engineering Domain,

    P. Brereton, B. A. Kitchenham, D. Budgen, M. Turner, and M. Khalil, “Lessons From Applying the Systematic Literature Review Process Within the Software Engineering Domain,” Journal of Systems and Software , vol. 80, no. 4, pp. 571–583, 2007

  6. [14]

    Variability in Software Systems—A Systematic Literature Re- view,

    M. Galster, D. Weyns, D. Tofan, B. Michalik, and P. Avgeriou, “Variability in Software Systems—A Systematic Literature Re- view,” IEEE Transactions on Software Engineering , vol. 40, no. 3, pp. 282–306, 2014

  7. [15]

    Mysterious and Manipulative Black Boxes: A Qualitative Analysis of Perceptions on Recommender Sys- tems,

    J. Ruohonen, “Mysterious and Manipulative Black Boxes: A Qualitative Analysis of Perceptions on Recommender Sys- tems,” First Monday , vol. 29, no. 6, pp. 1–35, 2024

  8. [16]

    An Overview of Cyber Security Funding for Open Source Software

    J. Ruohonen, G. Choudhary, and A. Alami, “An Overview of Cyber Security Funding for Open Source Software.” Archived manuscript, available online: https://arxiv.org/abs/2412. 05887, 2024

  9. [17]

    The Art of Coding and Thematic Exploration in Qualitative Research,

    M. Williams and T. Moser, “The Art of Coding and Thematic Exploration in Qualitative Research,” International Manage- ment Review, vol. 15, no. 1, pp. 45–55, 2019

  10. [18]

    The GDPR Enforcement Fines at Glance,

    J. Ruohonen and K. Hjerppe, “The GDPR Enforcement Fines at Glance,” Information Systems , vol. 106, p. 101876, 2022

  11. [19]

    SoK: Secure Data Dele- tion,

    J. Reardon, D. Basin, and S. Capkun, “SoK: Secure Data Dele- tion,” in Proceedings of the IEEE Symposium on Security and Privacy (S&P 2013) , (Berkeley), pp. 301–315, IEEE, 2013

  12. [20]

    A/B Integrations: 7 Lessons Learned from En- abling A/B Testing as a Product Feature,

    A. Fabijan, P. Dmitriev, B. Arai, A. Drake, S. Kohlmeier, and A. Knowng, “A/B Integrations: 7 Lessons Learned from En- abling A/B Testing as a Product Feature,” in Proceedings of the IEEE/ACM 45th International Conference on Software Engineering: Software Engineering in Practi...

  13. [21]

    P. C. van Oorschot, Computer Security and the Internet: Tools and Jewels from Malware to Bitcoin . Cham: Springer, second ed., 2021

  14. [22]

    Big Data Model of Security Sharing Based on Blockchain,

    L. Yue, H. Junqin, Q. Shengzhi, and W. Ruijin, “Big Data Model of Security Sharing Based on Blockchain,” in Proceed- ings of the 3rd International Conference on Big Data Com- puting and Communications (BIGCOM 2017) , (Chengdu), pp. 117–121, IEEE, 2017

  15. [23]

    Better Safe Than Sorry! Automated Identification of Functionality-Breaking Security-Configuration Rules,

    P. St¨ ockle, M. Sammereier, B. Grobauer, and A. Pretschner, “Better Safe Than Sorry! Automated Identification of Functionality-Breaking Security-Configuration Rules,” in Pro- ceedings of the IEEE/ACM International Conference on Au- tomation of Software Test (AST 2023) , (Melb...

  16. [24]

    Learning of Person- alized Security Settings,

    M. Sharifi, E. Fink, and J. G. Carbonell, “Learning of Person- alized Security Settings,” in Proceedings of the IEEE Interna- tional Conference on Systems, Man and Cybernetics , (Istan- bul), pp. 3428–3432, IEEE, 2010

  17. [25]

    Field Trial for Simultaneous Teleoperation of Mobile Social Robots,

    D. F. Glas, T. Kanda, H. Ishiguro, and N. Hagita, “Field Trial for Simultaneous Teleoperation of Mobile Social Robots,” in Proceedings of the 4th ACM/IEEE International Conference on Human Robot Interaction (HRI 2009) , (La Jolla), pp. 149– 156, ACM, 2009

  18. [26]

    Development of IIoT Monitoring and Control Se- curity Scheme for Cyber Physical Systems,

    A. Wadsworth, M. I. Thanoon, C. McCurry, and S. Z. Sabatto, “Development of IIoT Monitoring and Control Se- curity Scheme for Cyber Physical Systems,” in Proceedings of the SoutheastCon, (Huntsville), pp. 1–5, IEEE, 2019

  19. [27]

    An Agent-Based Controller for Vehicular Automation,

    F. He, F.-Y. Wang, and S. Tang, “An Agent-Based Controller for Vehicular Automation,” in Proceedings of the IEEE Intelli- gent Transportation Systems Conference, (Toronto), pp. 771– 776, IEEE, 2006

  20. [28]

    Evaluation of Run- time Monitoring for UA V Emergency Landing,

    J. Guerin, K. Delmas, , and J. Guiochet, “Evaluation of Run- time Monitoring for UA V Emergency Landing,” inProceedings of the International Conference on Robotics and Automation (ICRA 2022) , (Philadelphia), pp. 9703–9709, IEEE, 2022

  21. [29]

    False Data Injection on EKF-Based Navigation Control,

    W. Chen, Z. Duan, and Y. Dong, “False Data Injection on EKF-Based Navigation Control,” in Proceedings of the Inter- national Conference on Unmanned Aircraft Systems (ICUAS 2017), (Miami), pp. 1608–1617, IEEE, 2017

  22. [30]

    Analysis and Prevention of MCAS-Induced Crashes,

    N. T. Curran, T. W. Kennings, and K. G. Shin, “Analysis and Prevention of MCAS-Induced Crashes,” IEEE Transac- tions on Computer-Aided Design of Integrated Circuits and Systems, vol. 43, no. 11, pp. 3382–3394, 2024

  23. [31]

    SROS2: Usable Cyber Security Tools for ROS 2,

    V. Mayoral-Vilches, R. White, G. Caiazza, and M. Argueda, “SROS2: Usable Cyber Security Tools for ROS 2,” in Proceed- ings of the IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS 2022) , (Kyoto), pp. 11253–11259, IEEE, 2022

  24. [32]

    High-Level Cryptographic Abstractions,

    C. Kane, B. Lin, S. Chand, S. D. Stoller, and Y. A. Liu, “High-Level Cryptographic Abstractions,” in Proceedings of the 14th ACM SIGSAC Workshop on Programming Languages and Analysis for Security (PLAS 2019) , (London), pp. 31–43, ACM, 2019

  25. [33]

    Short: Danger is My Middle Name – Experimenting with SSL Vulnerabilities in An- droid Apps,

    L. Onwuzurike and E. De Cristofaro, “Short: Danger is My Middle Name – Experimenting with SSL Vulnerabilities in An- droid Apps,” in Proceedings of the 8th ACM Conference on Security & Privacy in Wireless and Mobile Networks (WiSec 2015), (New York), pp. 1–6, ACM, 2015

  26. [34]

    “Make Sure DSA Signing Exponentiations Really Are Constant-Time,

    C. P. Garc ´ ıa, B. B. Brumley, and Y. Yarom, ““Make Sure DSA Signing Exponentiations Really Are Constant-Time,” in Proceedings of the 2016 ACM SIGSAC Conference on Com- puter and Communications Security (CCS 2016) , (Vienna), pp. 1639–1650, ACM, 2016

  27. [35]

    Securing SSL Certificate Verification Through Dynamic Linking,

    A. Bates, J. Pletcher, T. Nichols, B. Hollembaek, D. Tian, and K. R. B. Butler, “Securing SSL Certificate Verification Through Dynamic Linking,” in Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Se- curity (CCS 2014) , (Scottsdale), pp. 394–405, ACM, 2014

  28. [36]

    Helping Johnny Encrypt: Toward Semantic Interfaces for Crypto- graphic Frameworks,

    S. Indela, M. Kulkarni, and K. N. T. Dumitra¸ s, “Helping Johnny Encrypt: Toward Semantic Interfaces for Crypto- graphic Frameworks,” in Proceedings of the 2016 ACM In- ternational Symposium on New Ideas, New Paradigms, and Reflections on Programming and Software (Onward! 2016...

  29. [37]

    Comparing the Usability of Cryp- tographic APIs,

    Y. Acar, M. Backes, S. Fahl, S. Garfinkel, D. Kim, M. L. Mazurek, and C. Stransky, “Comparing the Usability of Cryp- tographic APIs,” in Proceedings of the IEEE Symposium on Security and Privacy (S&P) , (San Jose), pp. 154–171, IEEE, 2017

  30. [38]

    From Dragondoom to Dragonstar: Side- Channel Attacks and Formally Verified Implementation of WPA3 Dragonfly Handshake,

    D. D. A. Braga, N. Kulatova, M. Sabt, P.-A. Fouque, and K. Bhargavan, “From Dragondoom to Dragonstar: Side- Channel Attacks and Formally Verified Implementation of WPA3 Dragonfly Handshake,” in Proceedings of the IEEE 8th European Symposium on Security and Privacy (EuroS&P) , ...

  31. [39]

    In Encryption We Don’t Trust: The Effect of End-To-End En- cryption to the Masses on User Perception,

    S. Dechand, A. Naiakshina, A. Danilova, and M. Smith, “In Encryption We Don’t Trust: The Effect of End-To-End En- cryption to the Masses on User Perception,” in Proceedings of the IEEE European Symposium on Security and Privacy (EuroS&P), (Stockholm), pp. 401–415, IEEE, 2019

  32. [40]

    Let’s Create! Automated Cer- tificate Management for End-users,

    T. Mueller and A. Michalek, “Let’s Create! Automated Cer- tificate Management for End-users,” in Proceedings of the In- ternational Conference on Software, Telecommunications and Computer Networks (SoftCOM 2021) , (Split), pp. 1–6, IEEE, 2021

  33. [41]

    A Graphical Definition of Au- thorisation Schema in the DTAC Model,

    J. E. Tidswell and J. M. Potter, “A Graphical Definition of Au- thorisation Schema in the DTAC Model,” inProceedings of the Sixth ACM Symposium on Access Control Models and Tech- nologies (SACMAT 2001) , (Chantilly), pp. 109–120, ACM, 2001

  34. [42]

    Forensic Attribution in NoSQL Databases,

    W. K. Hauger and M. S. Olivier, “Forensic Attribution in NoSQL Databases,” in Proceedings of the Information Secu- rity for South Africa (ISSA 2017) , (Johannesburg), pp. 74–82, IEEE, 2017

  35. [43]

    Harvesting Randomness to Optimize Distributed Systems,

    M. Lecuyer, J. Lockerman, L. Nelson, S. Sen, A. Sharma, and A. Slivkins, “Harvesting Randomness to Optimize Distributed Systems,” in Proceedings of the 16th ACM Workshop on Hot Topics in Networks (HotNets 2017) , (Palo Alto), pp. 178–184, ACM, 2017

  36. [44]

    Mesh: Secure, Lightweight Grid Middleware Using Existing SSH Infrastructure,

    P. Z. Kolano, “Mesh: Secure, Lightweight Grid Middleware Using Existing SSH Infrastructure,” in Proceedings of the 12th ACM symposium on Access Control Models and Technologies (SACMAT 2007), (Sophia Antipolis), pp. 111–120, 2019

  37. [45]

    Using Auto- mated Prompts for Student Reflection on Computer Security Concepts,

    H. Chen, A. Ciborowska, and K. Damevski, “Using Auto- mated Prompts for Student Reflection on Computer Security Concepts,” in Proceedings of the 2019 ACM Conference on Innovation and Technology in Computer Science Education (ITiCSE 2019) , (Aberdeen), pp. 506–512, ACM, 2019

  38. [46]

    Assuring the Safety of Opening Email Attach- ments,

    R. Balzer, “Assuring the Safety of Opening Email Attach- ments,” in Proceedings DARPA Information Survivability Conference and Exposition II (DISCEX 2001) , (Anaheim), pp. 257–262, IEEE, 2001

  39. [47]

    PellucidAt- tachment: Protecting Users From Attacks via E-Mail Attach- ments,

    S. Duman, M. B¨ uchler, M. Egele, and E. Kirda, “PellucidAt- tachment: Protecting Users From Attacks via E-Mail Attach- ments,” IEEE Transactions on Dependable and Secure Com- puting, vol. 21, no. 3, pp. 1342–1354, 2024

  40. [48]

    Who’s In Control? On Security Risks of Disjointed IoT Device Man- agement Channels,

    Y. Jia, B. Yuan, L. Xing, D. Zhao, Y. Zhang, X. Wang, Y. Liu, K. Zheng, P. Crnjak, Y. Zhang, D. Zou, and H. Jin, “Who’s In Control? On Security Risks of Disjointed IoT Device Man- agement Channels,” in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communication...

  41. [49]

    SxC4IoT: A Security-by-Contract Framework for Dynamic Evolving IoT Devices,

    A. Giaretta, N. Dragoni, and F. Massacci, “SxC4IoT: A Security-by-Contract Framework for Dynamic Evolving IoT Devices,” ACM Transactions on Sensor Networks , vol. 18, no. 1, pp. 12:1 – 12:51, 2021

  42. [50]

    Don’t Talk Un- less I Say So! Securing the Internet of Things With Default-Off Networking,

    J. Hong, A. Levy, L. Riliskis, , and P. Levis, “Don’t Talk Un- less I Say So! Securing the Internet of Things With Default-Off Networking,” in Proceedings of the IEEE/ACM Third Inter- national Conference on Internet-of-Things Design and Imple- mentation (IoTDI 2018), (Orlando)...

  43. [51]

    Default Credentials Vulnerability: The Case Study of Exposed IP Cams,

    S. Perone, L. Faramondi, and R. Setola, “Default Credentials Vulnerability: The Case Study of Exposed IP Cams,” in Pro- ceedings of the IEEE International Conference on Cyber Secu- rity and Resilience (CSR 2023) , (Venice), pp. 406–411, IEEE, 2023

  44. [52]

    Secure MQTT Authentication and Message Exchange Methods for IoT Con- strained Device,

    F. A. Shodiq, R. R. Pahlevi, and P. Sukarno, “Secure MQTT Authentication and Message Exchange Methods for IoT Con- strained Device,” in Proceedings of the International Con- ference on Intelligent Cybernetics Technology & Applications (ICICyTA 2021), (Bandung), pp. 70–74, IEEE, 2021

  45. [53]

    A Secure Secret Key-Sharing System for Resource- Constrained IoT Devices Using MQTT,

    T. Noguchi, M. Nakagawa, M. Yoshida, and A. G. Ra- monet, “A Secure Secret Key-Sharing System for Resource- Constrained IoT Devices Using MQTT,” in Proceedings of the 24th International Conference on Advanced Communica- tion Technology (ICACT 2022), (PyeongChang), pp. 147–153,...

  46. [54]

    Internet of Vulnerable Things (IoVT): Detect- ing Vulnerable SOHO Routers,

    P. Poornachandran, S. R., M. R. Krishnan, S. Pal, P. S. A. U., and A. Ashok, “Internet of Vulnerable Things (IoVT): Detect- ing Vulnerable SOHO Routers,” in Proceedings of the Inter- national Conference on Information Technology (ICIT 2015) , (Bhubaneswar), pp. 119–123, IEEE, 2015

  47. [55]

    How Secure Are Networked Office Devices?,

    E. Condon, E. Cummins, Z. Afoulki, and M. Cukier, “How Secure Are Networked Office Devices?,” in Proceedings of the IEEE/IFIP 41st International Conference on Dependable Sys- tems & Networks (DSN 2011) , (Hong Kong), pp. 465–472, IEEE, 2011

  48. [56]

    Security and Performance Analysis of MQTT Protocol with TLS in IoT Networks,

    A. R. Alkhafajee, A. M. A. Al-muqarm, A. H. Alwan, and Z. R. Mohammed, “Security and Performance Analysis of MQTT Protocol with TLS in IoT Networks,” in Proceedings of the International Iraqi Conference on Engineering Technology and Their Applications (IICETA 2021), (Najaf), p...

  49. [57]

    BUL W ARK: A Framework to Store IoT Data in User Accounts,

    J. L. Reed and A. S ¸aman Tosun, “BUL W ARK: A Framework to Store IoT Data in User Accounts,” IEEE Access, vol. 10, pp. 15619–15634, 2022

  50. [58]

    Securing the Internet of Things: Exploring MQTT Vulnerabilities and Threats in Pakistan’s IoT Landscape,

    A. Hassan, J. Aslam, S. Tahir, and I. Rashid, “Securing the Internet of Things: Exploring MQTT Vulnerabilities and Threats in Pakistan’s IoT Landscape,” in Proceedings of the International Conference on Engineering & Computing Tech- nologies (ICECT 2024) , (Pakistan), pp. 1–6,...

  51. [59]

    Automated Authentication Credential Derivation for the Secured Configuration of IoT Devices,

    T. Ulz, T. Pieber, C. Steger, A. H¨ ooller, S. Haas, and R. Ma- tischek, “Automated Authentication Credential Derivation for the Secured Configuration of IoT Devices,” in Proceedings of the IEEE 13th International Symposium on Industrial Embed- ded Systems (SIES 2018) , (Graz)...

  52. [60]

    Message Queuing Telemetry Transport (MQTT) Security: A Cryptographic Smart Card Approach,

    E. B. Sanjuan, I. A. Cardiel, J. A. Cerrada, and C. Cerrada, “Message Queuing Telemetry Transport (MQTT) Security: A Cryptographic Smart Card Approach,” IEEE Access, vol. 8, pp. 115051–115062, 2020

  53. [61]

    Keep Rogue IoT Away: IoT Detector Based on Diversified TLS Negotiation,

    C.-W. Ou, F.-H. Hsu, and C.-M. Lai, “Keep Rogue IoT Away: IoT Detector Based on Diversified TLS Negotiation,” in Proceedings of the IEEE Intl. Conf. on Dependable, Auto- nomic and Secure Computing, Intl. Conf. on Pervasive Intel- ligence and Computing, Intl. Conf. on Cloud and...

  54. [62]

    QTTSA: A Tool for Automatically Assisting the Se- cure Deployments of MQTT Brokers,

    A. Palmieri, P. Prem, S. Ranise, U. Morelli, and T. Ah- mad, “QTTSA: A Tool for Automatically Assisting the Se- cure Deployments of MQTT Brokers,” in Proceedings of the IEEE World Congress on Services (SER VICES 2019) , (Mi- lan), pp. 47–53, IEEE, 2019

  55. [63]

    Eval- uating Security of MQTT Protocol in Internet of Things,

    A. Al-Ani, W. K. S. A. K. Al-Ani, and S. A. Laghari, “Eval- uating Security of MQTT Protocol in Internet of Things,” in Proceedings of the IEEE Canadian Conference on Elec- trical and Computer Engineering (CCECE 2023) , (Regina), pp. 502–509, IEEE, 2023

  56. [64]

    Practical Experi- ence Report: Exploiting Memory Corruption Vulnerabilities in Connman for IoT Devices,

    K. V. English, I. Obaidat, and M. Sridhar, “Practical Experi- ence Report: Exploiting Memory Corruption Vulnerabilities in Connman for IoT Devices,” in Proceedings of the 9th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2019) , pp. 247–255,...

  57. [65]

    Embedded Malware – An Analysis of the Chuck Norris Botnet,

    P. ˆCeleda, R. Krejˆ c ´ ı, J. Vykopal, and M. Draˆ sar, “Embedded Malware – An Analysis of the Chuck Norris Botnet,” in Pro- ceedings of the European Conference on Computer Network Defense, (Berlin), pp. 3–10, IEEE, 2010

  58. [66]

    Security Review On The Internet of Things,

    J. Whitter-Jones, “Security Review On The Internet of Things,” in Proceedings of the Third International Confer- ence on Fog and Mobile Edge Computing (FMEC 2018) , (Barcelona), pp. 163–168, IEEE, 2018

  59. [67]

    Is Your Kettle Smarter Than a Hacker? A Scalable Tool for Assessing Replay Attack Vulnerabilities on Consumer IoT Devices,

    S. Lazzaro, V. D. Angelis, A. M. Mandalari, and F. Buccafurri, “Is Your Kettle Smarter Than a Hacker? A Scalable Tool for Assessing Replay Attack Vulnerabilities on Consumer IoT Devices,” in Proceedings of the IEEE International Confer- ence on Pervasive Computing and Communic...

  60. [68]

    Design and Im- plementation of a Lightweight Authentication Framework for the Internet of Things (IoT),

    M. Alshahrani, I. Traore, and I. Woungang, “Design and Im- plementation of a Lightweight Authentication Framework for the Internet of Things (IoT),” inProceedings of the Sixth Inter- national Conference on Internet of Things: Systems, Manage- ment and Security (IOTSMS 2019) , ...

  61. [69]

    A Digi- tal Forensic Methodology for Encryption Key Recovery from Black-Box IoT Devices,

    M. R. Zunaidi, A. Sayakkara, and M. Scanlon, “A Digi- tal Forensic Methodology for Encryption Key Recovery from Black-Box IoT Devices,” in Proceeding sof the 12th Interna- tional Symposium on Digital Forensics and Security (ISDFS 2024), (San Antonio), pp. 1–7, IEEE, 2024

  62. [70]

    Tracing MI- RAI Malware in Networked System,

    Y. Xu, H. Koide, D. V. Vargas, and K. Sakurai, “Tracing MI- RAI Malware in Networked System,” in Proceedings of the Sixth International Symposium on Computing and Network- ing Workshops (CANDAR W 2018), (Takayama), pp. 534–538, IEEE, 2018

  63. [71]

    Exploration of Smart Grid Device Cybersecurity Vulnerability Using Shodan,

    D. Ackley and H. Yang, “Exploration of Smart Grid Device Cybersecurity Vulnerability Using Shodan,” in Proceedings of the IEEE Power & Energy Society General Meeting (PESGM 2020), (Montreal), pp. 1–5, IEEE, 2020

  64. [72]

    Using Graph Databases to Assess the Security of Thingernets Based on the Thingabilities and Thingertivity of Things,

    M. Lewis, “Using Graph Databases to Assess the Security of Thingernets Based on the Thingabilities and Thingertivity of Things,” in Proceedings of the Living in the Internet of Things: Cybersecurity of the IoT , (London), pp. 1–9, IEEE, 2018

  65. [73]

    Advances in IoT Security: Vulnerabilities, Enabled Criminal Services, Attacks, and Countermeasures,

    Y. R. Siwakoti, M. Bhurtel, D. B. Rawat, A. Oest, and R. C. Johnson, “Advances in IoT Security: Vulnerabilities, Enabled Criminal Services, Attacks, and Countermeasures,” IEEE In- ternet of Things Journal , vol. 10, no. 13, pp. 11224–11239, 2023

  66. [74]

    Testing and Hardening IoT Devices Against the Mirai Bot- net,

    C. Kelly, N. Pitropakis, S. McKeown, and C. Lambrinoudakis, “Testing and Hardening IoT Devices Against the Mirai Bot- net,” in Proceedings of the International Conference on Cyber Security and Protection of Digital Services (Cyber Security 2020), (Dublin), pp. 1–8, IEEE, 2020

  67. [75]

    In-Band Secret-Free Pairing for COTS Wireless Devices,

    N. Ghose, L. Lazos, and M. Li, “In-Band Secret-Free Pairing for COTS Wireless Devices,” IEEE Transactions on Mobile Computing, vol. 21, no. 2, pp. 612–628, 2022

  68. [76]

    Policy Through Software De- faults,

    R. C. Shah and J. P. Kesan, “Policy Through Software De- faults,” in Proceedings of the 2006 International Conference on Digital Government Research (dg.o 2006) , (San Diego), pp. 265–272, ACM, 2006

  69. [77]

    Evaluat- ing the Security of eFPGA-Based Redaction Algorithms,

    A. Rezaei, R. Afsharmazayejani, and J. Maynard, “Evaluat- ing the Security of eFPGA-Based Redaction Algorithms,” in Proceedings of the IEEE/ACM International Conference On Computer Aided Design (ICCAD 2022) , (San Diego), pp. 1–7, IEEE, 2022

  70. [78]

    Security Aspects of Masking on FPGAs,

    B. Giger and K. P. ad Stefan Mangard, “Security Aspects of Masking on FPGAs,” in Proceedings of the IEEE International Symposium on Hardware Oriented Security and Trust (HOST 2024), (Tysons Corner), pp. 199–210, IEEE, 2024

  71. [79]

    AMI: An Adaptable Music Interface to Sup- port the Varying Needs of People with Dementia,

    P. F. Seymour, J. Matejka, G. Foulds, I. Petelycky, and F. Anderson, “AMI: An Adaptable Music Interface to Sup- port the Varying Needs of People with Dementia,” in Proceed- ings of the 19th International ACM SIGACCESS Conference on Computers and Accessibility (ASSETS 2017) , (...

  72. [80]

    Secure and Flexible e- Health Access Control System with Provisions for Emergency Access Overrides and Delegation of Access Privileges,

    M. F. F. Khan and K. Sakamura, “Secure and Flexible e- Health Access Control System with Provisions for Emergency Access Overrides and Delegation of Access Privileges,” in Pro- ceedings of the 18th International Conference on Advanced Communication Technology (ICACT 2016) , (P...

  73. [81]

    Re- view and Analysis of Cowrie Artefacts and Their Potential to be Used Deceptively,

    W. Z. Cabral, C. Valli, L. F. Sikos, and S. G. Wakeling, “Re- view and Analysis of Cowrie Artefacts and Their Potential to be Used Deceptively,” in Proceedings of the International Conference on Computational Science and Computational In- telligence (CSCI 2019), (Las Vegas), p...

  74. [82]

    PicNIC: Predictable Virtualized NIC,

    P. Kumar, N. Dukkipati, N. Lewis, Y. Cui, Y. Wang, C. Li, V. Valancius, J. Adriaens, S. Gribble, N. Foster, and A. Vah- dat, “PicNIC: Predictable Virtualized NIC,” in Proceedings of the ACM Special Interest Group on Data Communication (SIGCOMM 2019) , (Beijing), pp. 351–366, ACM, 2019

  75. [83]

    Towards QUIC Debuggability,

    R. Marx, W. Lamotte, J. Reynders, K. Pittevils, and P. Quax, 14 “Towards QUIC Debuggability,” in Proceedings of the Work- shop on the Evolution, Performance, and Interoperability of QUIC (EPIQ 2018) , pp. 1–7, ACM, 2018

  76. [84]

    Neferion: Time Bound, Fail-Safe and Deter- ministic Propagation of Network Connectivity Policies Across Large Multi-Datacenter Networks,

    G. A. N. Yasa, N. Bisht, A. A. Ansari, I. V. P. Reddy, and S. Tangudu, “Neferion: Time Bound, Fail-Safe and Deter- ministic Propagation of Network Connectivity Policies Across Large Multi-Datacenter Networks,” in Proceedings of the 49th Annual IEEE/IFIP International Conferenc...

  77. [85]

    Demonstrating a Personalized Secure-By-Default Bring Your Own Device Solution Based on Software Defined Networking,

    S. Gebert, T. Zinner, N. Gray, R. Durner, C. Lorenz, and S. Lange, “Demonstrating a Personalized Secure-By-Default Bring Your Own Device Solution Based on Software Defined Networking,” in Proceedings of the International Teletraffic Congress (ITC 2016) , (W¨ urzburg), pp. 197–...

  78. [86]

    Iphicles: Tuning Parameters of Data Center Networks with Differen- tiable Performance Model,

    S. Huang, M. Wang, Y. Liu, Z. Liu, and Y. Cui, “Iphicles: Tuning Parameters of Data Center Networks with Differen- tiable Performance Model,” in Proceedings of the IEEE/ACM 32nd International Symposium on Quality of Service (IWQoS 2024), (Guangzhou), pp. 1–10, IEEE, 2024

  79. [87]

    A Frame- work for Home Wireless Network Security Education,

    E. Sackey, D. Lindskog, R. Ruhl, and P. Zavarsky, “A Frame- work for Home Wireless Network Security Education,” in Pro- ceedings of the IEEE Second International Conference on So- cial Computing , (Minneapolis), pp. 1044–1049, IEEE, 2010

  80. [88]

    Evaluating Wi-Fi Security Through Wardriving: A Test-Case Analysis,

    O. Cherqi, A. Sebbar, K. Chougdali, M. Boulmalf, and H. Ben- brahim, “Evaluating Wi-Fi Security Through Wardriving: A Test-Case Analysis,” in Proceedings of the 10th International Conference on Wireless Networks and Mobile Communica- tions (WINCOM 2023) , (Istanbul), pp. 1–7, ...

  81. [89]

    Improve- ments to Multiple Path Secure Copy,

    B. J. Guilfoos, L. R. Humphrey, and J. Unpingco, “Improve- ments to Multiple Path Secure Copy,” in Proceedings of the DoD HPCMP Users Group Conference , (Seattle), pp. 376– 378, IEEE, 2008

  82. [90]

    Securing Mobile Ad Hoc Networks Using Distributed Firewall with PKI,

    J. Filipek and L. Hudec, “Securing Mobile Ad Hoc Networks Using Distributed Firewall with PKI,” in Proceedings of the IEEE 14th International Symposium on Applied Machine In- telligence and Informatics (SAMI 2016) , (Herlany), pp. 321– 325, IEEE, 2016

  83. [91]

    High- Performance Capabilities for 1-Hop Containment of Network Attacks,

    T. Wolf, S. Natarajan, , and K. T. Vasudevan, “High- Performance Capabilities for 1-Hop Containment of Network Attacks,” IEEE/ACM Transactions on Networking , vol. 21, no. 6, pp. 1931–1946, 2013

  84. [92]

    Comparative Analysis of Cybersecurity Mechanisms in SD-W AN Architectures: A Preliminary Results,

    J. R. Bustamante and E. de Posgrado, “Comparative Analysis of Cybersecurity Mechanisms in SD-W AN Architectures: A Preliminary Results,” in Proceedings of the IEEE Engineering International Research Conference (EIRCON 2021) , (Lima), pp. 1–4, IEEE, 2021

  85. [93]

    V- Digger: An Efficient and Secure Vulnerability Assessment for Large-Scale ISP Network,

    N. Lu, R. Huang, M. Yao, W. Shi, and K.-K. R. Choo, “V- Digger: An Efficient and Secure Vulnerability Assessment for Large-Scale ISP Network,” IEEE Transactions on Dependable and Secure Computing , vol. 21, no. 4, pp. 3227–3246, 2024

  86. [94]

    Char- acterizing Throughput Bottlenecks for Secure GridFTP Trans- fers,

    G. Vardoyan, R. Kettimuthu, M. Link, and S. Tuecke, “Char- acterizing Throughput Bottlenecks for Secure GridFTP Trans- fers,” in Proceedings of the International Conference on Com- puting, Networking and Communications (ICNC 2013) , (San Diego), pp. 861–866, IEEE, 2013

  87. [95]

    On Security in Giga- bit Passive Optical Networks,

    T. Horvath, L. Malina, and P. Munster, “On Security in Giga- bit Passive Optical Networks,” in Proceedings of the Interna- tional Workshop on Fiber Optics in Access Network (FOAN 2015), (Brno), pp. 51–55, IEEE, 2015

  88. [96]

    Secu- rity Automation in Next-Generation Networks and Cloud En- vironments,

    F. Pizzato, D. Bringhenti, R. Sisto, and F. Valenza, “Secu- rity Automation in Next-Generation Networks and Cloud En- vironments,” in Proceedings of the IEEE Network Operations and Management Symposium (NOMS 2024) , (Seoul), pp. 1–4, IEEE, 2024

  89. [97]

    Secure Device Bootstrapping Without Secrets Resistant to Signal Manipulation Attacks,

    N. Ghose, L. Lazos, and M. Li, “Secure Device Bootstrapping Without Secrets Resistant to Signal Manipulation Attacks,” in Proceedings of the IEEE Symposium on Security and Privacy (S&P), (San Francisco), pp. 819–835, IEEE, 2018

  90. [98]

    Secure Edge Server Placement With Non-Cooperative Game for Internet of Vehicles in Web 3.0,

    Z. Liu, X. Xu, F. Han, Q. Zhao, L. Qi, W. Dou, and X. Zho, “Secure Edge Server Placement With Non-Cooperative Game for Internet of Vehicles in Web 3.0,” IEEE Transaction on Network Scince and Engineering, vol. 11, no. 5, pp. 4020–4031, 2024

  91. [99]

    Secure and Scalable Permis- sioned Blockchain Using LDE-P2P Networks,

    S. A. Murad and N. Rahimi, “Secure and Scalable Permis- sioned Blockchain Using LDE-P2P Networks,” in Proceedings of the 10th International Conference on Internet of Things: Systems, Management and Security (IOTSMS 2023) , (San Antonio), pp. 111–116, IEEE, 2023

  92. [100]

    An Artificial Intelligence Approach for Deploying Zero Trust architecture (ZTA),

    E. S. Hosney, I. T. A. Halim, and A. H. Yousef, “An Artificial Intelligence Approach for Deploying Zero Trust architecture (ZTA),” in Proceedings of the 5th International Conference on Computing and Informatics (ICCI 2022) , (Cairo), pp. 343– 350, IEEE, 2022

  93. [101]

    Implementing a Security Policy Management for 5G Customer Edge Nodes,

    H. Kabir, M. H. B. Mohsin, and R. Kantola, “Implementing a Security Policy Management for 5G Customer Edge Nodes,” in Proceedings of the IEEE/IFIP Network Operations and Man- agement Symposium (MOMS 2020) , pp. 1–8, IEEE, 2020

  94. [102]

    NEOS: Non- Intrusive Edge Observability Stack Based on Zero Trust Se- curity Model for Ubiquitous Computing,

    A. Kumar, T. Ahmed, K. Saini, and J. Kumar, “NEOS: Non- Intrusive Edge Observability Stack Based on Zero Trust Se- curity Model for Ubiquitous Computing,” in Proceedings of the IEEE International Conference on Edge Computing and Communications (EDGE 2023) , (Chicago), pp. 79–8...

  95. [103]

    Stealth and Semi-Stealth MITM Attacks, Detection and Defense in IPv4 Networks,

    N. R. Samineni, F. A. Barbhuiya, and S. Nandi, “Stealth and Semi-Stealth MITM Attacks, Detection and Defense in IPv4 Networks,” in Proceedings of the 2nd IEEE International Con- ference on Parallel, Distributed and Grid Computing , (Solan), pp. 364–367, IEEE, 2012

  96. [104]

    Network Se- curity Monitoring (NSM): Can It Be Effective in a World With Encrypted Traffic?,

    M. M. Khurana, P. Malik, and M. ShwetaPuneet, “Network Se- curity Monitoring (NSM): Can It Be Effective in a World With Encrypted Traffic?,” in Proceedings of the International Con- ference on Computation, Automation and Knowledge Man- agement (ICCAKM 2020) , (Dubai), pp. 140–...

  97. [105]

    Combining Discretionary Policy with Mandatory Information Flow in Operating Sys- tems,

    Z. Mao, N. Li, and H. Chen, “Combining Discretionary Policy with Mandatory Information Flow in Operating Sys- tems,” ACM Transactions on Information and System Secu- rity, vol. 14, no. 3, pp. 24:1 – 24:27, 2011

  98. [106]

    Securing User Defined Containers for Scientific Computing,

    J. Higgins, V. Holmes, and C. Venters, “Securing User Defined Containers for Scientific Computing,” in Proceedings of the International Conference on High Performance Computing & Simulation (HPCS 2016) , (Innsbruck), pp. 449–453, IEEE, 2016

  99. [107]

    Interdependency Attack-Aware Secure and Performant Virtual Machine Allocation Policies With Low Attack Efficiency and Coverage,

    B. O. Sane, M. Ba, D. Fall, Y. Taenaka, I. Niang, and Y. Kadobayashi, “Interdependency Attack-Aware Secure and Performant Virtual Machine Allocation Policies With Low Attack Efficiency and Coverage,” IEEE Access , vol. 12, pp. 74944–74960, 2024

  100. [108]

    Cybersecurity Evalu- ation with PowerShell,

    S. Zavala, N. Shashidhar, and C. Varol, “Cybersecurity Evalu- ation with PowerShell,” in Proceedings of the 8th International Symposium on Digital Forensics and Security (ISDFS 2020) , (Beirut), pp. 1–6, IEEE, 2020

  101. [109]

    KGSec- Config: A Knowledge Graph Based Approach for Secured Container Orchestrator Configuration,

    M. U. Haque, M. M. Kholoosi, and M. A. Babar, “KGSec- Config: A Knowledge Graph Based Approach for Secured Container Orchestrator Configuration,” in Proceedings of the IEEE International Conference on Software Analysis, Evolu- tion and Reengineering (SANER 2022) , (Honolulu), ...

  102. [110]

    DeviceVeil: Robust Authentication for Individual USB Devices Using Physical Unclonable Functions,

    K. Suzaki, Y. Hori, K. Kobara, and M. Mannan, “DeviceVeil: Robust Authentication for Individual USB Devices Using Physical Unclonable Functions,” in Proceedings of the 49th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN 2019) , (Portland), pp...

  103. [111]

    Enhancing Windows Firewall Security Using Fuzzy Reasoning,

    N. Naik and P. Jenkins, “Enhancing Windows Firewall Security Using Fuzzy Reasoning,” in Proceedings of the IEEE 14th Intl. Conf. on Dependable, Autonomic and Se- cure Computing, 14th Intl. Conf. on Pervasive Intelligence and Computing, and the 2nd Intl. Conf. on Big Data In- t...

  104. [112]

    Solving the Interdependency Prob- lem: A Secure Virtual Machine Allocation Method Relying on the Attacker’s Efficiency and Coverage,

    B. O. Sane, M. Ba, D. Fall, S. kashihara, Y. Taenaka, I. Ni- 15 ang, and Y. Kadobayashi, “Solving the Interdependency Prob- lem: A Secure Virtual Machine Allocation Method Relying on the Attacker’s Efficiency and Coverage,” in Proceedings of the IEEE/ACM International Symposiu...

  105. [113]

    V-MCS: A Configuration System for Virtual Machines,

    X.-H. Sun, C. Du, H. Zou, Y. Chen, and P. Shukla, “V-MCS: A Configuration System for Virtual Machines,” in Proceedings of the IEEE International Conference on Cluster Computing and Workshops , (New Orleans), pp. 1–7, IEEE, 2009

  106. [114]

    Analysis of Various Vulnerabilities in the Raspbian Operating System and Solutions,

    C. Le, A. M. Grande, A. Carmine, J. Thompson, and T. K. Mohd, “Analysis of Various Vulnerabilities in the Raspbian Operating System and Solutions,” in Proceedings of the IEEE World AI IoT Congress (AIIoT 2022) , (Seattle), pp. 1–6, IEEE, 2022

  107. [115]

    IncludeOS: A Minimal, Resource Efficient Unikernel for Cloud Services,

    A. Bratterud, A.-A. Walla, H. Haugerud, P. E. Engelstad, and K. Begnum, “IncludeOS: A Minimal, Resource Efficient Unikernel for Cloud Services,” in Proceedings of the IEEE 7th International Conference on Cloud Computing Technol- ogy and Science (CloudCom 2015) , (Vancouver), p...

  108. [116]

    Security- Performance Trade-Offs of Kubernetes Container Runtimes,

    William Viktorsson, C. Klein, and J. Tordsson, “Security- Performance Trade-Offs of Kubernetes Container Runtimes,” in Proceedings of the 28th International Symposium on Mod- eling, Analysis, and Simulation of Computer and Telecommu- nication Systems (MASCOTS 2020) , (Nice), p...

  109. [117]

    Run Time Con- tainer Security Hardening Using A Proposed Model Of Secu- rity Control Map,

    D. R. Pothula, K. M. Kumar, and S. Kumar, “Run Time Con- tainer Security Hardening Using A Proposed Model Of Secu- rity Control Map,” in Proceedings of the Global Conference for Advancement in Technology (GCAT 2019) , (Bangalore), pp. 1–6, IEEE, 2019

  110. [118]

    Unveiling DNS Spoofing Vulnerabilities: An Ethical Examination Within Lo- cal Area Networks,

    A. Jony, M. N. Islam, , and I. H. Sarker, “Unveiling DNS Spoofing Vulnerabilities: An Ethical Examination Within Lo- cal Area Networks,” in Proceedings of the 26th International Conference on Computer and Information Technology (ICCIT 2023), (Cox’s Bazar), pp. 1–6, IEEE, 2023

  111. [119]

    On a Pattern-Oriented Model for Intrusion Detection,

    S.-P. Shieh and V. D. Gligor, “On a Pattern-Oriented Model for Intrusion Detection,” IEEE Transactions on Knowledge and Data Engineering , vol. 9, no. 4, pp. 661–667, 1997

  112. [120]

    Security Middleground for Resource Protection in Measurement Infrastructure-as-a-Service,

    R. Akella, S. Debroy, P. Calyam, A. Berryman, K. Zhu, and M. Sridharan, “Security Middleground for Resource Protection in Measurement Infrastructure-as-a-Service,” IEEE Transac- tions on Services Computing, vol. 12, no. 4, pp. 621–638, 2019

  113. [121]

    Shrink- ing the Kernel Attack Surface Through Static and Dynamic Syscall Limitation,

    D. Zhan, Z. Yu, X. Yu, H. Zhang, and L. Ye, “Shrink- ing the Kernel Attack Surface Through Static and Dynamic Syscall Limitation,” IEEE Transactions on Services Comput- ing, vol. 16, no. 2, pp. 1431–1443, 2023

  114. [122]

    Bandwidth- Delay-Product-Based ACK Optimization Strategy for QUIC in Wi-Fi Networks,

    Y. Liu, Z. Yang, Y. Peng, T. Bi, and T. Jiang, “Bandwidth- Delay-Product-Based ACK Optimization Strategy for QUIC in Wi-Fi Networks,” IEEE Internet of Things Journal , vol. 10, no. 20, pp. 17635–17646, 2023

  115. [123]

    Find- ing Secret Treasure? Improving Memorized Secrets Through Gamification,

    K. Hartwig, A. Englisch, J. P. Thomson, and C. Reuter, “Find- ing Secret Treasure? Improving Memorized Secrets Through Gamification,” in Proceedings of the 2021 European Sym- posium on Usable Security (EuroUSEC 2021) , (Karlsruhe), pp. 105–117, ACM, 2021

  116. [124]

    What Do Students Do With Their Assigned Default Passwords?,

    L. Boˆ snjak, , and B. Brumen, “What Do Students Do With Their Assigned Default Passwords?,” in Proceedings of the 39th International Convention on Information and Communi- cation Technology, Electronics and Microelectronics (MIPRO 2016), (Opatija), pp. 1430–1435, IEEE, 2016

  117. [125]

    A Weak Password Cracker of UHF RFID Tags,

    Z. Zhao, S. Li, Y. Kang, J. Li, S. Li, and W. Hong, “A Weak Password Cracker of UHF RFID Tags,” in Proceedings of the IEEE 12th Intl. Conf. on Ubiquitous Intelligence and Comput- ing and the IEEE 12th Intl. Conf. on Autonomic and Trusted Computing and 2the IEEE 15th Intl. Conf...

  118. [126]

    Password Usage Among Users of Smart Devices in Hungary and Serbia,

    D. Mandic, G. Kiss, and Z. Rajnai, “Password Usage Among Users of Smart Devices in Hungary and Serbia,” in proceed- ings of the IEEE 18th International Symposium on Applied Computational Intelligence and Informatics (SACI 2024) , (Timisoara), pp. 309–314, IEEE, 2024

  119. [127]

    Some Were Meant for C: The Endurance of an Unmanageable Language,

    S. Kell, “Some Were Meant for C: The Endurance of an Unmanageable Language,” in Proceedings of the 2017 ACM SIGPLAN International Symposium on New Ideas, New Paradigms, and Reflections on Programming and Software (Onward! 2017) , (Vancouver), pp. 229–245, ACM, 2017

  120. [128]

    Towards a Compiler for Reals,

    E. Darulova and V. Kuncak, “Towards a Compiler for Reals,” ACM Transactions on Programming Languages and Systems , vol. 39, no. 2, pp. 8:1 – 8:28, 2017

  121. [129]

    Secure Coding Practices in Java: Challenges and Vulnera- bilities,

    N. Meng, S. Nagy, D. D. Yao, W. Zhuang, and G. A. Argoty, “Secure Coding Practices in Java: Challenges and Vulnera- bilities,” in Proceedings of the IEEE/ACM 40th International Conference on Software Engineering (ICSE 2018) , (Gothen- burg), pp. 372–383, IEEE, 2018

  122. [130]

    Coding Practices and Recommendations of Spring Security for Enterprise Applications,

    M. Islam, S. Rahaman, N. Meng, B. Hassanshahi, P. Krishnan, and D. D. Yao, “Coding Practices and Recommendations of Spring Security for Enterprise Applications,” in Proceedings of the IEEE Secure Development (SecDev 2020) , (Atlanta), pp. 49–57, IEEE, 2020

  123. [131]

    Adopting Trusted Types in Production Web Frameworks to Prevent DOM-Based Cross-Site Scripting: A Case Study,

    P. Wang, B. A. Guomundsson, and K. Kotowicz, “Adopting Trusted Types in Production Web Frameworks to Prevent DOM-Based Cross-Site Scripting: A Case Study,” in Proceed- ings of the IEEE European Symposium on Security and Pri- vacy Workshops (EuroS&PW) , (Vienna), pp. 60–73, IEEE, 2021

  124. [132]

    The Psychology of Security: Why Do Good Users Make Bad Decisions?,

    R. West, “The Psychology of Security: Why Do Good Users Make Bad Decisions?,” Communications of the ACM , vol. 51, no. 4, pp. 34–40, 2008

  125. [133]

    SLR: From Saltzer and Schroeder to 2021... 47 Years of Research on the Development and Validation of Security API Recommenda- tions,

    N. Patnaik, A. Dwyer, J. Hallett, and A. Rashid, “SLR: From Saltzer and Schroeder to 2021... 47 Years of Research on the Development and Validation of Security API Recommenda- tions,” ACM Transactions on Software Engineering Method- ology, vol. 32, no. 3, pp. 60:1 – 60:31, 2023

  126. [134]

    Developer-Centered Security and the Symmetry of Ignorance,

    O. Pieczul, S. Foley, and M. E. Zurko, “Developer-Centered Security and the Symmetry of Ignorance,” in Proceedings of the 2017 New Security Paradigms Workshop (NSPW 2017) , (Santa Cruz), pp. 46–56, ACM, 2017

  127. [135]

    Is “Deny Access

    F. Massacci, “Is “Deny Access” a Valid “Fail-Safe Default”,” IEEE Security & Privacy , vol. 17, no. 5, pp. 90–93, 2019

  128. [136]

    A User-Centered, Modular Authorization Service Built on an RBAC Founda- tion,

    M. E. Zurko, R. Simon, and T. Sanfilippo, “A User-Centered, Modular Authorization Service Built on an RBAC Founda- tion,” in Proceedings of the 1999 IEEE Symposium on Secu- rity and Privacy (S&P 1999) , (Oakland), pp. 57–71, IEEE, 1999

  129. [137]

    Exploring How to Apply Secure Software Design Principles,

    S. A. Ebad, “Exploring How to Apply Secure Software Design Principles,” IEEE Access, vol. 10, pp. 128983–128993, 2022

  130. [138]

    Did You Ever Have To Make Up Your Mind? What Notes Users Do When Faced With A Security Decision,

    M. E. Zurko, C. Kaufman, K. Spanbauer, and C. Bassett, “Did You Ever Have To Make Up Your Mind? What Notes Users Do When Faced With A Security Decision,” in Proceedings of the 18th Annual Computer Security Applications Conference , (Las Vegas), pp. 371–381, IEEE, 2002

  131. [139]

    Computer Security and the Modern Home,

    T. Denning, T. Kohno, and H. M. Levy, “Computer Security and the Modern Home,” Communications of the ACM, vol. 56, no. 1, pp. 94–103, 2013

  132. [140]

    MUSP: Multi-Service, User Self-Controllable and Privacy- Preserving System for Smart Metering,

    M. A. Mustafa, N. Z. ad Georgios Kalogridis, and Z. Fan, “MUSP: Multi-Service, User Self-Controllable and Privacy- Preserving System for Smart Metering,” in Proceedings of the IEEE International Conference on Communications (ICC 2015), (London), pp. 788–794, IEEE, 2015

  133. [141]

    Opti- mistic Access Control for the Smart Home,

    N. Malkin, A. F. Luo, J. Poveda, and M. L. Mazurek, “Opti- mistic Access Control for the Smart Home,” in Proceedings of the IEEE Symposium on Security and Privacy (S&P) , (San Francisco), pp. 3043–3060, IEEE, 2023

  134. [142]

    Demonstrating ScreenshotMatcher: Taking Smartphone Photos to Capture Screenshots,

    A. Schmid, T. Fischer, , A. Weichart, A. Hartmann, and R. Wimme, “Demonstrating ScreenshotMatcher: Taking Smartphone Photos to Capture Screenshots,” in Proceedings of Mensch und Computer 2021 (MuC 2021) , (Ingolstadt), pp. 586–589, ACM, 2021

  135. [143]

    “I’m Surprised So Much Is Connected

    S. Hammann, M. Crabb, S. Radomirovic, R. Sasse, and 16 D. Basin, ““I’m Surprised So Much Is Connected”: A Study on Users’ Online Accounts,” in Proceedings of the 2022 CHI Conference on Human Factors in Computing Systems (CHI 2022), (New Orleans), pp. 1–13, ACM, 2022

  136. [144]

    An Android Application to Secure Text Messages,

    D. Demirol, R. Das, , and G. Tuna, “An Android Application to Secure Text Messages,” in Proceedings of the International Artificial Intelligence and Data Processing Symposium (IDAP 2017), (Malatya), pp. 1–6, IEEE, 2017

  137. [145]

    What Do Software Developers Need to Know to Build Secure Energy-Efficient Android Applications?,

    J. A. Montenegro, M. Pinto, and L. Fuentes, “What Do Software Developers Need to Know to Build Secure Energy-Efficient Android Applications?,” IEEE Access, vol. 6, pp. 1428–1450, 2018

  138. [146]

    “You Received $100,000 From Johnny

    T. Neteler, S. Fahl, and L. L. Iacono, ““You Received $100,000 From Johnny”: A Mixed-Methods Study on Push Notification Security and Privacy in Android Apps,” IEEE Access, vol. 12, pp. 112499–112516, 2024

  139. [147]

    All Friends are NOT Created Equal: An Interaction Intensity Based Approach to Privacy in Online Social Networks,

    L. Banks and S. F. Wu, “All Friends are NOT Created Equal: An Interaction Intensity Based Approach to Privacy in Online Social Networks,” in Proceedings of the International Confer- ence on Computational Science and Engineering, (Vancouver), pp. 970–974, IEEE, 2009

  140. [148]

    Personal Information Disclosure of User-Profiles on Facebook,

    S. I. Bhat, T. Arif, M. B. Malik, and A. A. Sheikh, “Personal Information Disclosure of User-Profiles on Facebook,” in Pro- ceedings of the 2nd International Conference on Advances in Computing, Communication Control and Networking (ICAC- CCN 2020) , (Greater Noida), pp. 71–77...

  141. [149]

    A Trusted Communication Unit for Secure Tiled Hardware Architectures,

    S. Haas and N. Asmussen, “A Trusted Communication Unit for Secure Tiled Hardware Architectures,” in Proceedings of the 29th IEEE International Conference on Electronics, Circuits and Systems (ICECS 2022) , (Glasgow), pp. 1–4, IEEE, 2022

  142. [150]

    Fine-Grained Data- Centric Content Protection Policy for Web Applications,

    Z. Wang, W. Meng, and M. R. Lyu, “Fine-Grained Data- Centric Content Protection Policy for Web Applications,” in Proceedings of the 2023 ACM SIGSAC Conference on Com- puter and Communications Security (CCS 2023) , (Copen- hagen), pp. 2845–2859, ACM, 2023

  143. [151]

    Fine-Grained Privilege Separation for Web Applications,

    A. Krishnamurthy, A. Mettler, and D. Wagner, “Fine-Grained Privilege Separation for Web Applications,” in Proceedings of the 19th International Conference on World wide Web (WWW 2010) , (Raleigh), pp. 551–560, ACM, 2010

  144. [152]

    Evaluating Grid Portal Security,

    D. Del Vecchio, V. Hazlewood, and M. Humphrey, “Evaluating Grid Portal Security,” in Proceedings of the 2006 ACM/IEEE Conference on Supercomputing (SC 2006), (Tampa), pp. 1–14, ACM, 2006

  145. [153]

    An Empirical Study of the Framework Impact on the Security of JavaScript Web Ap- plications,

    K. Peguero, N. Zhang, and X. Cheng, “An Empirical Study of the Framework Impact on the Security of JavaScript Web Ap- plications,” in Companion Proceedings of the The Web Con- ference (WWW 2018) , (Lyon), pp. 753–758, ACM, 2018

  146. [154]

    Empir- ical Analysis and Privacy Implications in OAuth-Based Single Sign-On Systems,

    S. G. Morkonda, S. Chiasson, and P. C. van Oorschot, “Empir- ical Analysis and Privacy Implications in OAuth-Based Single Sign-On Systems,” in Proceedings of the 20th Workshop on Workshop on Privacy in the Electronic Society (WPES 2021) , (Virtual Event), pp. 195–208, ACM, 2021

  147. [155]

    PEBA Enhancing User Privacy and Coverage of Safe Brows- ing Services,

    Y. Du, H. Duan, L. Xu, H. Cui, C. Wang, and Q. Wang, “PEBA Enhancing User Privacy and Coverage of Safe Brows- ing Services,” IEEE Transactions on Dependable and Secure Computing, vol. 20, no. 5, pp. 4343–4358, 2023

  148. [156]

    Forensics Analysis of Private Web Browsing Using Android Memory Acquisition,

    L. B. Younis, S. Sweda, and A. Alzu’bi, “Forensics Analysis of Private Web Browsing Using Android Memory Acquisition,” in Proceedings of the 12th International Conference on Infor- mation and Communication Systems (ICICS 2021) , (Valen- cia), pp. 273–278, IEEE, 2021

  149. [157]

    Oh, the Places You’ll Go! Finding Our Way Back from the Web Platform’s Ill-Conceived Jaunts,

    A. Janc and M. West, “Oh, the Places You’ll Go! Finding Our Way Back from the Web Platform’s Ill-Conceived Jaunts,” in Proceedings of the IEEE European Symposium on Security and Privacy Workshops (EuroS&PW 2020), (Genoa), pp. 673–680, IEEE, 2020

  150. [158]

    Hardening the Client-Side: A Guide to Enterprise-Level Hardening of Web Browsers,

    A. A. Jillepalli, D. C. de Leon, S. Steiner, F. T. Sheldon, and M. A. Haney, “Hardening the Client-Side: A Guide to Enterprise-Level Hardening of Web Browsers,” in Proceedings of the IEEE 15th Intl Conf on Dependable, Autonomic and Secure Computing, the 15th Intl. Conf. on Per...

  151. [159]

    Automated White-List Learning Technique for Detection of Malicious Attack on Web Application,

    S. M. Murtaza and A. S. Abid †, “Automated White-List Learning Technique for Detection of Malicious Attack on Web Application,” in Proceedings of the 13th International Bhur- ban Conference on Applied Sciences and Technology (IBCAST 2016), (Islamabad), pp. 416–420, IEEE, 2016

  152. [160]

    A Comprehensive Approach to Abusing Locality in Shared Web Hosting Servers,

    S. A. Mirheidari, S. Arshad, S. Khoshkdahan, and R. Jalili, “A Comprehensive Approach to Abusing Locality in Shared Web Hosting Servers,” in Proceedings of the 12th IEEE Interna- tional Conference on Trust, Security and Privacy in Comput- ing and Communications, (Melbourne), p...

  153. [161]

    ES- CUDO: A Fine-Grained Protection Model for Web Browsers,

    K. Jayaraman, W. Du, B. Rajagopalan, and S. J. Chapin, “ES- CUDO: A Fine-Grained Protection Model for Web Browsers,” in Proceedings of the IEEE 30th International Conference on Distributed Computing Systems , (Genoa), pp. 231–240, IEEE, 2010

  154. [162]

    CredEx: User-Centric Credential Management for Grid and Web Services,

    D. D. Vecchio, M. Humphrey, , J. Basney, and N. Nagaratnam, “CredEx: User-Centric Credential Management for Grid and Web Services,” in Proceedings of the IEEE International Con- ference on Web Services (ICWS 2005) , (Orlando), pp. 149– 156, IEEE, 2005

  155. [163]

    Research Report: Mitigating LangSec Prob- lems With Capabilities,

    N. W. Filardo, “Research Report: Mitigating LangSec Prob- lems With Capabilities,” in Proceedings of the IEEE Security and Privacy Workshops (S&PW) , (San Jose), pp. 189–197, IEEE, 2016

  156. [164]

    Moving from Training to Compli- ance: Practical Methodology to Monitor Worker Compliance to Electrical Safe Work Practices,

    R. S. LeRoy and T. McCoy, “Moving from Training to Compli- ance: Practical Methodology to Monitor Worker Compliance to Electrical Safe Work Practices,” in Proceedings of the IEEE IAS Electrical Safety Workshop , (San Diego), pp. 1–7, IEEE, 2014

  157. [165]

    Hazard or Risk Analysis, Overcoming the Hu- man Factor,

    R. S. LeRoy, “Hazard or Risk Analysis, Overcoming the Hu- man Factor,” in Proceedings of the 2015 IEEE IAS Electrical Safety Workshop , (Louisville), pp. 1–6, IEEE, 2015

  158. [166]

    The Internet of Things: How the Next Evolu- tion of the Internet Is Changing Everything

    D. Evans, “The Internet of Things: How the Next Evolu- tion of the Internet Is Changing Everything.” Cisco Inter- net Business Solutions Group (IBSG), available online in De- cember: https://www.cisco.com/c/dam/en_us/about/ac79/ docs/innov/IoT_IBSG_0411FINAL.pdf, 2011

  159. [167]

    A Sur- vey on Anti-Honeypot and Anti-Introspection Methods,

    J. Uitto, S. Rauti, S. Laur´ en, and V. Lepp¨ anen, “A Sur- vey on Anti-Honeypot and Anti-Introspection Methods,” in Proceedings of the World Conference on Information Systems and Technologies (WorldCIST 2017), (Madeira), pp. 125–134, Springer, 2017

  160. [168]

    Extending Access Control Models With Break-Glass,

    A. D. Brucker and H. Petritsch, “Extending Access Control Models With Break-Glass,” in Proceedings of the 14th ACM symposium on Access Control Models and Technologies (SAC- MAT 2009), (Stresa), pp. 197–206, ACM, 2009

  161. [169]

    Unhelpful Assumptions in Software Security Research,

    I. Ryan, U. Roedig, and K. Stol, “Unhelpful Assumptions in Software Security Research,” in Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Secu- rity (CCS 2023) , (Copenhagen), pp. 3460–3474, ACM, 2023

  162. [170]

    Lever- aging Sustainable Systematic Literature Reviews

    V. dos Santos, R. Kazman, and E. Y. Nakagawa, “Lever- aging Sustainable Systematic Literature Reviews.” Archived manuscript, available online in January 2025: https://arxiv. org/abs/2501.01819, 2025

  163. [171]

    Disentangling Patent Quality: Using a Large Language Model for a Systematic Literature Review,

    V. J. Schmitt, “Disentangling Patent Quality: Using a Large Language Model for a Systematic Literature Review,” Scien- tometrics, no. Published online in January, pp. 1–45, 2025

  164. [172]

    Empirical Software En- gineering: From Discipline to Interdiscipline,

    D. M. Fern´ andez and J.-H. Passoth, “Empirical Software En- gineering: From Discipline to Interdiscipline,” Journal of Sys- tems and Software , vol. 148, pp. 170–179, 2019

  165. [173]

    SWEBOK: Guide to the Software Engineering Body of Knowledge

    IEEE et al. , “SWEBOK: Guide to the Software Engineering Body of Knowledge.” A Project of the IEEE Computer Soci- ety Professional Practices Committee, IEEE Computer Soci- ety, available online in December 2024: https://sceweb.sce. uhcl.edu/helm/SWEBOK_IEEE/SWEBOK_Guide_2004.pdf, 2004

  166. [174]

    Usability is Not the Dark Side: Secure Usable Design Seen through Star Wars,

    A.-M. Horcher and W. Dula, “Usability is Not the Dark Side: Secure Usable Design Seen through Star Wars,” in Proceedings 17 of the Symposium on Usable Privacy and Security (SOUPS 2019), (Santa Clara), pp. 1–6, USENIX, 2019

  167. [175]

    Software Security,

    G. McGraw, “Software Security,” IEEE Security & Privacy , vol. 2, no. 2, pp. 80–83, 2004

  168. [176]

    There’s a Hole in that Bucket! A Large-Scale Analysis of Misconfig- ured S3 Buckets,

    A. Continella, M. Polino, M. Pogliani, and S. Zanero, “There’s a Hole in that Bucket! A Large-Scale Analysis of Misconfig- ured S3 Buckets,” in Proceedings of the 34th Annual Computer Security Applications Conference (ACSAC 2018), (San Juan), pp. 702–711, ACM, 2018

  169. [177]

    Secu- rity Misconfigurations in Open Source Kubernetes Manifests: An Empirical Study,

    A. Rahman, S. I. Shamim, D. B. Bose, and R. Pandita, “Secu- rity Misconfigurations in Open Source Kubernetes Manifests: An Empirical Study,” ACM Transactions on Software Engi- neering and Methodology, vol. 32, no. 4, pp. 1–36, 2023

  170. [178]

    Vulnerability Coordination Un- der the Cyber Resilience Act

    J. Ruohonen and P. Timmers, “Vulnerability Coordination Un- der the Cyber Resilience Act.” Archived manuscript, available online: https://arxiv.org/abs/2412.06261, 2024

  171. [179]

    Regulating Online Defaults,

    K. Grill, “Regulating Online Defaults,” in The Philosophy of Online Manipulation (F. Jongepier and M. Klenk, eds.), pp. 373–391, New York: Routledge, 2022. 18

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.