{"id":"https://openalex.org/W1628063087","doi":"https://doi.org/10.1007/978-3-642-36563-8_14","title":"An Empirical Study on the Effectiveness of Security Code Review","display_name":"An Empirical Study on the Effectiveness of Security Code Review","publication_year":2013,"publication_date":"2013-01-01","ids":{"openalex":"https://openalex.org/W1628063087","doi":"https://doi.org/10.1007/978-3-642-36563-8_14","mag":"1628063087"},"language":"en","primary_location":{"id":"doi:10.1007/978-3-642-36563-8_14","is_oa":false,"landing_page_url":"https://doi.org/10.1007/978-3-642-36563-8_14","pdf_url":null,"source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"type":"book-chapter","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5041402866","display_name":"Anne Edmundson","orcid":null},"institutions":[{"id":"https://openalex.org/I205783295","display_name":"Cornell University","ror":"https://ror.org/05bnh6r87","country_code":"US","type":"education","lineage":["https://openalex.org/I205783295"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Anne Edmundson","raw_affiliation_strings":["Cornell University, Ithaca, NY, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Cornell University, Ithaca, NY, USA","institution_ids":["https://openalex.org/I205783295"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5017423274","display_name":"Brian Holtkamp","orcid":null},"institutions":[{"id":"https://openalex.org/I16277215","display_name":"University of Houston - Downtown","ror":"https://ror.org/05mj6fy81","country_code":"US","type":"education","lineage":["https://openalex.org/I16277215"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Brian Holtkamp","raw_affiliation_strings":["University of Houston\u2013Downtown, Houston, TX, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Houston\u2013Downtown, Houston, TX, USA","institution_ids":["https://openalex.org/I16277215"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5021034045","display_name":"Emanuel Rivera","orcid":null},"institutions":[{"id":"https://openalex.org/I121595252","display_name":"Polytechnic University of Puerto Rico","ror":"https://ror.org/01b8jmq89","country_code":"PR","type":"education","lineage":["https://openalex.org/I121595252"]}],"countries":["PR"],"is_corresponding":false,"raw_author_name":"Emanuel Rivera","raw_affiliation_strings":["Polytechnic University of Puerto Rico, San Juan, Puerto Rico, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Polytechnic University of Puerto Rico, San Juan, Puerto Rico, USA","institution_ids":["https://openalex.org/I121595252"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5074003373","display_name":"Matthew Finifter","orcid":null},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Matthew Finifter","raw_affiliation_strings":["University of California, Berkeley, CA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of California, Berkeley, CA, USA","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5017559907","display_name":"Adrian Mettler","orcid":null},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Adrian Mettler","raw_affiliation_strings":["University of California, Berkeley, CA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of California, Berkeley, CA, USA","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5062174672","display_name":"David Wagner","orcid":"https://orcid.org/0000-0001-7728-4273"},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"David Wagner","raw_affiliation_strings":["University of California, Berkeley, CA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of California, Berkeley, CA, USA","institution_ids":["https://openalex.org/I95457486"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":{"value":5000,"currency":"EUR","value_usd":5392},"apc_paid":null,"fwci":8.5145,"has_fulltext":false,"cited_by_count":75,"citation_normalized_percentile":{"value":0.98225957,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"197","last_page":"212"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9886999726295471,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9854000210762024,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8256679773330688},{"id":"https://openalex.org/keywords/secure-coding","display_name":"Secure coding","score":0.8182061910629272},{"id":"https://openalex.org/keywords/sql-injection","display_name":"SQL injection","score":0.7567002773284912},{"id":"https://openalex.org/keywords/cross-site-scripting","display_name":"Cross-site scripting","score":0.7487617135047913},{"id":"https://openalex.org/keywords/web-application-security","display_name":"Web application security","score":0.7334975004196167},{"id":"https://openalex.org/keywords/web-application","display_name":"Web application","score":0.6201075315475464},{"id":"https://openalex.org/keywords/scripting-language","display_name":"Scripting language","score":0.6151199340820312},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.5498981475830078},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5431238412857056},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.4895683228969574},{"id":"https://openalex.org/keywords/security-bug","display_name":"Security bug","score":0.4638962745666504},{"id":"https://openalex.org/keywords/code-review","display_name":"Code review","score":0.45056360960006714},{"id":"https://openalex.org/keywords/application-security","display_name":"Application security","score":0.42446091771125793},{"id":"https://openalex.org/keywords/software-security-assurance","display_name":"Software security assurance","score":0.42120838165283203},{"id":"https://openalex.org/keywords/web-application-development","display_name":"Web application development","score":0.4170762300491333},{"id":"https://openalex.org/keywords/web-development","display_name":"Web development","score":0.3941155672073364},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.37300020456314087},{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.2608134150505066},{"id":"https://openalex.org/keywords/static-program-analysis","display_name":"Static program analysis","score":0.2435683012008667},{"id":"https://openalex.org/keywords/web-service","display_name":"Web service","score":0.23433154821395874},{"id":"https://openalex.org/keywords/software-development","display_name":"Software development","score":0.17982980608940125},{"id":"https://openalex.org/keywords/security-service","display_name":"Security service","score":0.11750096082687378},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.08309751749038696}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8256679773330688},{"id":"https://openalex.org/C22680326","wikidata":"https://www.wikidata.org/wiki/Q7444867","display_name":"Secure coding","level":5,"score":0.8182061910629272},{"id":"https://openalex.org/C150451098","wikidata":"https://www.wikidata.org/wiki/Q506059","display_name":"SQL injection","level":5,"score":0.7567002773284912},{"id":"https://openalex.org/C39569185","wikidata":"https://www.wikidata.org/wiki/Q371199","display_name":"Cross-site scripting","level":5,"score":0.7487617135047913},{"id":"https://openalex.org/C59241245","wikidata":"https://www.wikidata.org/wiki/Q4781497","display_name":"Web application security","level":4,"score":0.7334975004196167},{"id":"https://openalex.org/C118643609","wikidata":"https://www.wikidata.org/wiki/Q189210","display_name":"Web application","level":2,"score":0.6201075315475464},{"id":"https://openalex.org/C61423126","wikidata":"https://www.wikidata.org/wiki/Q187432","display_name":"Scripting language","level":2,"score":0.6151199340820312},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.5498981475830078},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5431238412857056},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.4895683228969574},{"id":"https://openalex.org/C131275738","wikidata":"https://www.wikidata.org/wiki/Q7445023","display_name":"Security bug","level":5,"score":0.4638962745666504},{"id":"https://openalex.org/C150292731","wikidata":"https://www.wikidata.org/wiki/Q1342704","display_name":"Code review","level":5,"score":0.45056360960006714},{"id":"https://openalex.org/C77109596","wikidata":"https://www.wikidata.org/wiki/Q4781497","display_name":"Application security","level":5,"score":0.42446091771125793},{"id":"https://openalex.org/C62913178","wikidata":"https://www.wikidata.org/wiki/Q7554361","display_name":"Software security assurance","level":4,"score":0.42120838165283203},{"id":"https://openalex.org/C120927855","wikidata":"https://www.wikidata.org/wiki/Q189210","display_name":"Web application development","level":4,"score":0.4170762300491333},{"id":"https://openalex.org/C79373723","wikidata":"https://www.wikidata.org/wiki/Q386275","display_name":"Web development","level":3,"score":0.3941155672073364},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.37300020456314087},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.2608134150505066},{"id":"https://openalex.org/C137287247","wikidata":"https://www.wikidata.org/wiki/Q1329550","display_name":"Static program analysis","level":4,"score":0.2435683012008667},{"id":"https://openalex.org/C35578498","wikidata":"https://www.wikidata.org/wiki/Q193424","display_name":"Web service","level":2,"score":0.23433154821395874},{"id":"https://openalex.org/C529173508","wikidata":"https://www.wikidata.org/wiki/Q638608","display_name":"Software development","level":3,"score":0.17982980608940125},{"id":"https://openalex.org/C29983905","wikidata":"https://www.wikidata.org/wiki/Q7445066","display_name":"Security service","level":3,"score":0.11750096082687378},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.08309751749038696},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0},{"id":"https://openalex.org/C164120249","wikidata":"https://www.wikidata.org/wiki/Q995982","display_name":"Web search query","level":3,"score":0.0},{"id":"https://openalex.org/C194222762","wikidata":"https://www.wikidata.org/wiki/Q114486","display_name":"Query by Example","level":4,"score":0.0},{"id":"https://openalex.org/C97854310","wikidata":"https://www.wikidata.org/wiki/Q19541","display_name":"Search engine","level":2,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1007/978-3-642-36563-8_14","is_oa":false,"landing_page_url":"https://doi.org/10.1007/978-3-642-36563-8_14","pdf_url":null,"source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.269.5776","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.269.5776","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www.cs.berkeley.edu/%7Efinifter/papers/coderev-essos13.pdf","raw_type":"text"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.7599999904632568,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":20,"referenced_works":["https://openalex.org/W125279808","https://openalex.org/W188134738","https://openalex.org/W1825390599","https://openalex.org/W1970153834","https://openalex.org/W1970565328","https://openalex.org/W1979109530","https://openalex.org/W1979931683","https://openalex.org/W1983142587","https://openalex.org/W2008158744","https://openalex.org/W2056740472","https://openalex.org/W2084076735","https://openalex.org/W2085925880","https://openalex.org/W2106371080","https://openalex.org/W2122303417","https://openalex.org/W2132791332","https://openalex.org/W2161407365","https://openalex.org/W2166381878","https://openalex.org/W2170923331","https://openalex.org/W2177797324","https://openalex.org/W2912410914"],"related_works":["https://openalex.org/W2070218579","https://openalex.org/W4235617552","https://openalex.org/W3013564133","https://openalex.org/W4242738188","https://openalex.org/W3141626627","https://openalex.org/W4240401768","https://openalex.org/W2067195038","https://openalex.org/W2553301301","https://openalex.org/W3033957407","https://openalex.org/W2521071348"],"abstract_inverted_index":null,"counts_by_year":[{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":8},{"year":2022,"cited_by_count":3},{"year":2021,"cited_by_count":12},{"year":2020,"cited_by_count":9},{"year":2019,"cited_by_count":4},{"year":2018,"cited_by_count":7},{"year":2017,"cited_by_count":8},{"year":2016,"cited_by_count":6},{"year":2015,"cited_by_count":4},{"year":2014,"cited_by_count":2},{"year":2013,"cited_by_count":3}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
