{"id":"https://openalex.org/W2760310980","doi":"https://doi.org/10.1109/re.2017.21","title":"Safety-Focused Security Requirements Elicitation for Medical Device Software","display_name":"Safety-Focused Security Requirements Elicitation for Medical Device Software","publication_year":2017,"publication_date":"2017-09-01","ids":{"openalex":"https://openalex.org/W2760310980","doi":"https://doi.org/10.1109/re.2017.21","mag":"2760310980"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/re.2017.21","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5070426245","display_name":"Mikael Lindvall","orcid":null},"institutions":[{"id":"https://openalex.org/I4210162509","display_name":"Fraunhofer USA Center Mid-Atlantic CMA","ror":"https://ror.org/05sz9gw20","country_code":"US","type":"facility","lineage":["https://openalex.org/I4210161623","https://openalex.org/I4210162509","https://openalex.org/I4923324"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mikael Lindvall","raw_affiliation_strings":["Fraunhofer CESE, College Park, MD, USA"],"affiliations":[{"raw_affiliation_string":"Fraunhofer CESE, College Park, MD, USA","institution_ids":["https://openalex.org/I4210162509"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5054377358","display_name":"Madeline Diep","orcid":"https://orcid.org/0000-0002-9908-0367"},"institutions":[{"id":"https://openalex.org/I4210162509","display_name":"Fraunhofer USA Center Mid-Atlantic CMA","ror":"https://ror.org/05sz9gw20","country_code":"US","type":"facility","lineage":["https://openalex.org/I4210161623","https://openalex.org/I4210162509","https://openalex.org/I4923324"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Madeline Diep","raw_affiliation_strings":["Fraunhofer CESE, College Park, MD, USA"],"affiliations":[{"raw_affiliation_string":"Fraunhofer CESE, College Park, MD, USA","institution_ids":["https://openalex.org/I4210162509"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5112324494","display_name":"Michele Klein","orcid":null},"institutions":[{"id":"https://openalex.org/I4210162509","display_name":"Fraunhofer USA Center Mid-Atlantic CMA","ror":"https://ror.org/05sz9gw20","country_code":"US","type":"facility","lineage":["https://openalex.org/I4210161623","https://openalex.org/I4210162509","https://openalex.org/I4923324"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Michele Klein","raw_affiliation_strings":["Fraunhofer CESE, College Park, MD, USA"],"affiliations":[{"raw_affiliation_string":"Fraunhofer CESE, College Park, MD, USA","institution_ids":["https://openalex.org/I4210162509"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5080152304","display_name":"Paul Jones","orcid":"https://orcid.org/0000-0003-0417-9143"},"institutions":[{"id":"https://openalex.org/I1320320070","display_name":"United States Food and Drug Administration","ror":"https://ror.org/034xvzb47","country_code":"US","type":"government","lineage":["https://openalex.org/I1299022934","https://openalex.org/I1320320070"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Paul Jones","raw_affiliation_strings":["U.S. Food and Drug Administration Silver Spring, MD, USA"],"affiliations":[{"raw_affiliation_string":"U.S. Food and Drug Administration Silver Spring, MD, USA","institution_ids":["https://openalex.org/I1320320070"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100388178","display_name":"Yi Zhang","orcid":"https://orcid.org/0000-0002-5375-360X"},"institutions":[{"id":"https://openalex.org/I1320320070","display_name":"United States Food and Drug Administration","ror":"https://ror.org/034xvzb47","country_code":"US","type":"government","lineage":["https://openalex.org/I1299022934","https://openalex.org/I1320320070"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yi Zhang","raw_affiliation_strings":["U.S. Food and Drug Administration Silver Spring, MD, USA"],"affiliations":[{"raw_affiliation_string":"U.S. Food and Drug Administration Silver Spring, MD, USA","institution_ids":["https://openalex.org/I1320320070"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5061397405","display_name":"Eugene Y. Vasserman","orcid":"https://orcid.org/0000-0002-2420-4329"},"institutions":[{"id":"https://openalex.org/I189590672","display_name":"Kansas State University","ror":"https://ror.org/05p1j8758","country_code":"US","type":"education","lineage":["https://openalex.org/I189590672"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Eugene Vasserman","raw_affiliation_strings":["Kansas State University, Manhattan, KS, USA"],"affiliations":[{"raw_affiliation_string":"Kansas State University, Manhattan, KS, USA","institution_ids":["https://openalex.org/I189590672"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.36,"has_fulltext":true,"fulltext_origin":"ngrams","cited_by_count":6,"citation_normalized_percentile":{"value":0.654808,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":81,"max":82},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9988,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9988,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T13295","display_name":"Safety Systems Engineering in Autonomy","score":0.9959,"subfield":{"id":"https://openalex.org/subfields/2213","display_name":"Safety, Risk, Reliability and Quality"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9932,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/medical-device","display_name":"Medical device","score":0.44314808}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.638795},{"id":"https://openalex.org/C45384764","wikidata":"https://www.wikidata.org/wiki/Q838667","display_name":"Requirements elicitation","level":4,"score":0.5914032},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.46193066},{"id":"https://openalex.org/C3020535179","wikidata":"https://www.wikidata.org/wiki/Q6554101","display_name":"Medical device","level":2,"score":0.44314808},{"id":"https://openalex.org/C62913178","wikidata":"https://www.wikidata.org/wiki/Q7554361","display_name":"Software security assurance","level":4,"score":0.42616603},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3800945},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.36080968},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.22502822},{"id":"https://openalex.org/C59488412","wikidata":"https://www.wikidata.org/wiki/Q187147","display_name":"Requirements analysis","level":3,"score":0.20407128},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.17278013},{"id":"https://openalex.org/C29983905","wikidata":"https://www.wikidata.org/wiki/Q7445066","display_name":"Security service","level":3,"score":0.11723781},{"id":"https://openalex.org/C136229726","wikidata":"https://www.wikidata.org/wiki/Q327092","display_name":"Biomedical engineering","level":1,"score":0.08502212},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.07928333}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/re.2017.21","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, justice, and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.63}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":18,"referenced_works":["https://openalex.org/W1542964113","https://openalex.org/W1861560507","https://openalex.org/W1964053994","https://openalex.org/W1970874249","https://openalex.org/W2029841165","https://openalex.org/W2033392342","https://openalex.org/W2051986607","https://openalex.org/W2061347532","https://openalex.org/W2065076704","https://openalex.org/W2095881341","https://openalex.org/W2106949331","https://openalex.org/W2138530473","https://openalex.org/W2158535304","https://openalex.org/W2158699648","https://openalex.org/W2225876053","https://openalex.org/W2475320399","https://openalex.org/W2610437899","https://openalex.org/W3161918289"],"related_works":["https://openalex.org/W3023846186","https://openalex.org/W2760310980","https://openalex.org/W2367699234","https://openalex.org/W2356158875","https://openalex.org/W2347547156","https://openalex.org/W2155206946","https://openalex.org/W2120367855","https://openalex.org/W2030496847","https://openalex.org/W2003448928","https://openalex.org/W1703282317"],"abstract_inverted_index":{"Security":[0],"attacks":[1],"on":[2,98,155],"medical":[3,29,53,80,115],"devices":[4],"have":[5,9,22],"been":[6],"shown":[7],"to":[8,34,39,73,122,137],"potential":[10],"safety":[11,183],"concerns.":[12],"Because":[13],"of":[14,52,70,78,85,92,114],"this,":[15],"stakeholders":[16],"(device":[17],"makers,":[18],"regulators,":[19],"users,":[20],"etc.)":[21],"increasing":[23],"interest":[24],"in":[25,28,141,178],"enhancing":[26],"security":[27,42,87,149,174],"devices.":[30],"An":[31],"effective":[32],"means":[33],"approach":[35,65,97,108],"this":[36],"objective":[37],"is":[38,109],"integrate":[40],"systematic":[41,64],"requirements":[43,150,193],"elicitation":[44],"and":[45,50,171,186,194],"analysis":[46],"into":[47],"the":[48,59,68,75,83,106,123,128,139,156,164,173,182,191],"design":[49],"evaluation":[51],"device":[54,81,116,140],"software.":[55],"This":[56],"paper":[57],"extends":[58],"sequence-based":[60],"enumeration":[61],"approach,":[62],"a":[63,79,90,99,142],"for":[66,82,111,125],"defining":[67],"behavior":[69],"embedded":[71],"software,":[72],"analyze":[74],"requirement":[76],"documents":[77],"purpose":[84],"eliciting":[86],"requirements.":[88],"As":[89],"proof":[91],"concept,":[93],"we":[94],"apply":[95],"our":[96],"concrete":[100],"case":[101],"study,":[102],"which":[103],"shows":[104],"that":[105,118],"extended":[107],"useful":[110],"identifying":[112],"sequences":[113,162],"events":[117,129],"might":[119],"be":[120,152],"harmful":[121],"patient,":[124],"example":[126],"because":[127],"are":[130],"initiated":[131],"by":[132],"an":[133],"active":[134],"adversary":[135],"trying":[136],"use":[138],"malicious":[143],"way.":[144],"We":[145],"then":[146],"show":[147],"how":[148,172],"may":[151,176],"formulated":[153],"based":[154],"identified":[157],"threats.":[158],"By":[159],"exploring":[160],"these":[161],"systematically,":[163],"developers":[165],"can":[166,189],"reliably":[167],"assess":[168],"what,":[169],"where,":[170],"threats":[175],"manifest":[177],"their":[179],"system,":[180],"what":[181],"implications":[184],"are,":[185],"finally":[187],"they":[188],"evaluate":[190],"resulting":[192],"mitigations.":[195]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2760310980","counts_by_year":[{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":3},{"year":2019,"cited_by_count":1},{"year":2018,"cited_by_count":1}],"updated_date":"2025-01-06T14:10:06.580621","created_date":"2017-10-06"}