@inproceedings{essos2017-caution,
	title = {Caution before exploitation: the use of cybersecurity domain knowledge to educate software engineers against software vulnerabilities},
	author = {Tayyaba Nafees and Natalie Coull and Robert Ian Ferguson and Adam Sampson},
	pages = {133--142},
	editor = {Eric Bodden and Mathias Payer and Elias Athanasopoulos},
	booktitle = {{Engineering Secure Software and Systems: 9th International Symposium, ESSoS 2017, Bonn, Germany, July 3-5, 2017. Proceedings}},
	publisher = {Springer},
	series = {Lecture Notes in Computer Science},
	volume = {10379},
	day = 24,
	month = jun,
	year = 2017,
	isbn = {978-3-319-62105-0},
	url = {http://offog.org/publications/essos2017-caution.pdf},
	abstract = {The transfer of cybersecurity domain knowledge from security experts ("Ethical Hackers") to software engineers is discussed in terms of desirability and feasibility. Possible mechanisms for the transfer are critically examined. Software engineering methodologies do not make use of security domain knowledge in its form of vulnerability databases (e.g. CWE, CVE, Exploit DB), which are therefore not appropriate for this purpose. An approach based upon the improved use of pattern languages that encompasses security domain knowledge is proposed.},
}
