{"id":"https://openalex.org/W4308627381","doi":"https://doi.org/10.1145/3558489.3559074","title":"Identifying security-related requirements in regulatory documents based on cross-project classification","display_name":"Identifying security-related requirements in regulatory documents based on cross-project classification","publication_year":2022,"publication_date":"2022-11-07","ids":{"openalex":"https://openalex.org/W4308627381","doi":"https://doi.org/10.1145/3558489.3559074"},"language":"en","primary_location":{"id":"doi:10.1145/3558489.3559074","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3558489.3559074","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3558489.3559074","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 18th International Conference on Predictive Models and Data Analytics in Software Engineering","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3558489.3559074","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5058314937","display_name":"Mazen Mohamad","orcid":"https://orcid.org/0000-0002-3446-1265"},"institutions":[{"id":"https://openalex.org/I881427289","display_name":"University of Gothenburg","ror":"https://ror.org/01tm6cn81","country_code":"SE","type":"education","lineage":["https://openalex.org/I881427289"]},{"id":"https://openalex.org/I66862912","display_name":"Chalmers University of Technology","ror":"https://ror.org/040wg7k59","country_code":"SE","type":"education","lineage":["https://openalex.org/I66862912"]}],"countries":["SE"],"is_corresponding":true,"raw_author_name":"Mazen Mohamad","raw_affiliation_strings":["Chalmers University of Technology, Sweden / University of Gothenburg, Sweden"],"affiliations":[{"raw_affiliation_string":"Chalmers University of Technology, Sweden / University of Gothenburg, Sweden","institution_ids":["https://openalex.org/I66862912","https://openalex.org/I881427289"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5033422210","display_name":"Jan-Philipp Stegh\u00f6fer","orcid":"https://orcid.org/0000-0003-1694-0972"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jan-Philipp Stegh\u00f6fer","raw_affiliation_strings":["Xitaso, Germany"],"affiliations":[{"raw_affiliation_string":"Xitaso, Germany","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5078689393","display_name":"Alexander \u00c5str\u00f6m","orcid":"https://orcid.org/0009-0006-3879-4573"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Alexander \u00c5str\u00f6m","raw_affiliation_strings":["Comentor, Sweden"],"affiliations":[{"raw_affiliation_string":"Comentor, Sweden","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5012313708","display_name":"Riccardo Scandariato","orcid":"https://orcid.org/0000-0003-3591-7671"},"institutions":[{"id":"https://openalex.org/I159176309","display_name":"Universit\u00e4t Hamburg","ror":"https://ror.org/00g30e956","country_code":"DE","type":"education","lineage":["https://openalex.org/I159176309"]},{"id":"https://openalex.org/I884043246","display_name":"Hamburg University of Technology","ror":"https://ror.org/04bs1pb34","country_code":"DE","type":"education","lineage":["https://openalex.org/I884043246"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Riccardo Scandariato","raw_affiliation_strings":["Hamburg University of Technology, Germany"],"affiliations":[{"raw_affiliation_string":"Hamburg University of Technology, Germany","institution_ids":["https://openalex.org/I159176309","https://openalex.org/I884043246"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5058314937"],"corresponding_institution_ids":["https://openalex.org/I66862912","https://openalex.org/I881427289"],"apc_list":null,"apc_paid":null,"fwci":1.9132,"has_fulltext":true,"cited_by_count":6,"citation_normalized_percentile":{"value":0.89133566,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"82","last_page":"91"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9986000061035156,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9986000061035156,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9908999800682068,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7431536316871643},{"id":"https://openalex.org/keywords/classifier","display_name":"Classifier (UML)","score":0.538726806640625},{"id":"https://openalex.org/keywords/security-domain","display_name":"Security domain","score":0.5111809372901917},{"id":"https://openalex.org/keywords/relevance","display_name":"Relevance (law)","score":0.48346811532974243},{"id":"https://openalex.org/keywords/requirements-engineering","display_name":"Requirements engineering","score":0.4823831617832184},{"id":"https://openalex.org/keywords/requirements-analysis","display_name":"Requirements analysis","score":0.4789769649505615},{"id":"https://openalex.org/keywords/security-testing","display_name":"Security testing","score":0.43921852111816406},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.39583733677864075},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.37767916917800903},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3525846302509308},{"id":"https://openalex.org/keywords/security-information-and-event-management","display_name":"Security information and event management","score":0.25952768325805664},{"id":"https://openalex.org/keywords/cloud-computing-security","display_name":"Cloud computing security","score":0.1926630139350891},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.18479666113853455},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.16493582725524902}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7431536316871643},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.538726806640625},{"id":"https://openalex.org/C2780264999","wikidata":"https://www.wikidata.org/wiki/Q7445032","display_name":"Security domain","level":2,"score":0.5111809372901917},{"id":"https://openalex.org/C158154518","wikidata":"https://www.wikidata.org/wiki/Q7310970","display_name":"Relevance (law)","level":2,"score":0.48346811532974243},{"id":"https://openalex.org/C6604083","wikidata":"https://www.wikidata.org/wiki/Q376937","display_name":"Requirements engineering","level":3,"score":0.4823831617832184},{"id":"https://openalex.org/C59488412","wikidata":"https://www.wikidata.org/wiki/Q187147","display_name":"Requirements analysis","level":3,"score":0.4789769649505615},{"id":"https://openalex.org/C195518309","wikidata":"https://www.wikidata.org/wiki/Q13424265","display_name":"Security testing","level":5,"score":0.43921852111816406},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.39583733677864075},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.37767916917800903},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3525846302509308},{"id":"https://openalex.org/C103377522","wikidata":"https://www.wikidata.org/wiki/Q3493999","display_name":"Security information and event management","level":4,"score":0.25952768325805664},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.1926630139350891},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.18479666113853455},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.16493582725524902},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1145/3558489.3559074","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3558489.3559074","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3558489.3559074","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 18th International Conference on Predictive Models and Data Analytics in Software Engineering","raw_type":"proceedings-article"},{"id":"pmh:oai:research.chalmers.se:533604","is_oa":false,"landing_page_url":"https://research.chalmers.se/en/publication/533604","pdf_url":null,"source":{"id":"https://openalex.org/S4306402469","display_name":"Chalmers Research (Chalmers University of Technology)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I66862912","host_organization_name":"Chalmers University of Technology","host_organization_lineage":["https://openalex.org/I66862912"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":""},{"id":"pmh:oai:tore.tuhh.de:11420/14324","is_oa":false,"landing_page_url":"http://hdl.handle.net/11420/14324","pdf_url":null,"source":{"id":"https://openalex.org/S4306401751","display_name":"tub.dok (Hamburg University of Technology)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I884043246","host_organization_name":"Hamburg University of Technology","host_organization_lineage":["https://openalex.org/I884043246"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Conference Paper"}],"best_oa_location":{"id":"doi:10.1145/3558489.3559074","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3558489.3559074","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3558489.3559074","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 18th International Conference on Predictive Models and Data Analytics in Software Engineering","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4308627381.pdf","grobid_xml":"https://content.openalex.org/works/W4308627381.grobid-xml"},"referenced_works_count":16,"referenced_works":["https://openalex.org/W182894708","https://openalex.org/W220935706","https://openalex.org/W1567427961","https://openalex.org/W1930624869","https://openalex.org/W2009190245","https://openalex.org/W2017268127","https://openalex.org/W2024765739","https://openalex.org/W2053154970","https://openalex.org/W2060736388","https://openalex.org/W2127626360","https://openalex.org/W2148143831","https://openalex.org/W2162152641","https://openalex.org/W2213612645","https://openalex.org/W2757062986","https://openalex.org/W3189209532","https://openalex.org/W4213009331"],"related_works":["https://openalex.org/W1490921502","https://openalex.org/W2472769502","https://openalex.org/W4254568495","https://openalex.org/W2047626779","https://openalex.org/W2238632658","https://openalex.org/W142054160","https://openalex.org/W2062417677","https://openalex.org/W2242308721","https://openalex.org/W2784612557","https://openalex.org/W1998119124"],"abstract_inverted_index":{"Security":[0],"is":[1,26,43],"getting":[2],"substantial":[3],"focus":[4],"in":[5,32,154,170,176],"many":[6],"industries,":[7],"especially":[8],"safety-critical":[9],"ones.":[10,57],"When":[11],"new":[12],"regulations":[13,123,172],"and":[14,52,85,153,173],"standards":[15],"which":[16,35,177],"can":[17],"run":[18,99],"to":[19,28,45,166,183],"hundreds":[20],"of":[21,49,62,91,131,139,162],"pages":[22],"are":[23],"introduced,":[24],"it":[25,42],"necessary":[27,44],"identify":[29,53,167],"the":[30,47,54,60,96,104,115,125,137,160],"requirements":[31,48,68,169],"those":[33],"documents":[34],"have":[36],"an":[37],"impact":[38],"on":[39,70,79,103,117],"security.":[40],"Additionally,":[41,157],"revisit":[46],"existing":[50],"systems":[51],"security":[55,132,168],"related":[56],"We":[58,75,112],"investigate":[59],"feasibility":[61,138],"using":[63],"a":[64,89,100,110,141,144,164,179],"classifier":[65,165],"for":[66],"security-related":[67],"trained":[69],"requirement":[71,81],"specifications":[72,149],"available":[73],"online.":[74],"base":[76],"our":[77],"investigation":[78],"15":[80],"documents,":[82],"randomly":[83],"selected":[84],"partially":[86],"pre-labelled,":[87],"with":[88,128],"total":[90],"3,880":[92],"requirements.":[93],"To":[94],"validate":[95],"model,":[97],"we":[98,158],"cross-project":[101],"prediction":[102],"data":[105,146],"where":[106],"each":[107],"specification":[108],"constitutes":[109],"group.":[111],"also":[113],"test":[114],"model":[116,142],"three":[118],"different":[119,129,155],"United":[120],"Nations":[121],"(UN)":[122],"from":[124,143,150],"automotive":[126],"domain":[127],"magnitudes":[130],"relevance.":[133],"Our":[134],"results":[135],"indicate":[136],"training":[140],"heterogeneous":[145],"set":[147],"including":[148],"multiple":[151],"domains":[152],"styles.":[156],"show":[159],"ability":[161],"such":[163,178],"real-life":[171],"discuss":[174],"scenarios":[175],"classification":[180],"becomes":[181],"useful":[182],"practitioners.":[184]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":2}],"updated_date":"2026-04-05T17:49:38.594831","created_date":"2025-10-10T00:00:00"}
