<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Enhancement of Confidence in Software in the Context of International Security</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Alexey S. Markov</string-name>
          <email>a.markov@bmstu.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Igor A. Sheremet</string-name>
          <email>sheremet@rfbr.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Information Security Department Bauman Moscow State Technical University Moscow</institution>
          ,
          <country country="RU">Russia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Russian Foundation for Basic Research Moscow</institution>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2019</year>
      </pub-date>
      <fpage>88</fpage>
      <lpage>92</lpage>
      <abstract>
        <p>The objective of the survey is to assess an opportunity to raise international security level in the cyber space through enhancement of confidence in security of software systems activity. The basic investigation method comprises analysis of information security statistics from certified laboratories. The paper shows importance of software systems security within the international security system in the cyber space. We reached the conclusion that reduction of software systems vulnerability dramatically reduces a possibility to attempt cyberattacks, cause damage to infrastructural resources and, consequently, develop a cyber conflict. It is stressed that exclusive bans on the use of foreign software have limits due to design development of international integration and security in the cyber space. We offered two approaches to raise the level of software security: to raise maturity level of international development companies and to enhance efficiency of international technical regulation of software security. We demonstrated that introduction of the international management system in development of secure software may appreciably raise the level of software security due to a lower number of vulnerabilities and higher operability in correction thereof. We approached the conclusion that confidence in software is possible if access to the source code is provided. We offered recommendations as to enhancement of confidence in the international technical regulation process.</p>
      </abstract>
      <kwd-group>
        <kwd>- strategic stability</kwd>
        <kwd>cyber conflict</kwd>
        <kwd>international security</kwd>
        <kwd>information security</kwd>
        <kwd>information and communication technologies</kwd>
        <kwd>cyber space</kwd>
        <kwd>technical regulation</kwd>
        <kwd>management system</kwd>
        <kwd>company maturity</kwd>
        <kwd>supply chains</kwd>
        <kwd>software</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>I. IMPORTANCE OF THE POINT</title>
      <p>As known, in connection of bias of national assets and
communications to the cyber space1, a number of countries
adopted the cyber space concept as the fifth theatre of military
1 The authors use clear definitions accepted by international standardization
societies which Russia joined such as ISO, IEC, ITU (including ISO/IEC
27032).</p>
      <p>It is to be stressed that in general a cyber conflict has a few
phases including:</p>
      <p>- Identification of vulnerabilities and assessment of an
opportunity to exploit them in order to undertake cyberattacks
for various purposes;</p>
      <p>- Detection of and response to incidents relating, as usual, to
cyberattacks to be undertaken;
- Response to successful cyberattacks.</p>
      <p>
        The last two phases mostly pertain to situation and crisis
management, on which attention has been mostly focused in
recent international talks and moves concerning international
security of the cyber space [
        <xref ref-type="bibr" rid="ref5 ref6 ref7">5-7</xref>
        ]. At the same time the initial
phase of a cyber conflict directly associated with software
security is not sufficiently studied in the international law and is
largely the subject of technical regulation which is of national
character in various countries. In addition, the international
technical regulation has a number of inconsistencies,
particularly, associated with a lack of confidence in security of
software developed and tested by companies in other countries.
      </p>
      <p>The paper contains an overview of international aspects of
software security enhancement within the framework of the
problem relating the international cyber space security.</p>
    </sec>
    <sec id="sec-2">
      <title>II. SECURITY SOFTWARE PROBLEMS</title>
      <p>
        In discussions of security software people usually mean that
such software has been developed with measures taken to reduce
the number of vulnerabilities and promptly remove them should
they occur [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
      <p>
        We would like to stress two international security factors
pertaining to software security [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]:
      </p>
      <p>
        1. Critical structural sophistication of software gives rise to
the man-induced risk (e.g. [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]);
      </p>
      <p>2. Application of information and communication
technologies has widened the range of intentional threats, in
particular, to the extent of remote (including hidden and
nonprovable) attacks and threats to very-large-scale data
compromise.</p>
      <p>Now we would like to draw special attention to the critical
structural sophistication of software when the length of the
original text using a high-level language, for instance the
operating system with applications, may reach 5-20 GB. Hence,
the number of logical operators (application software graph
nodes) may amount to some ten millions, which goes far beyond
human programmer’s cognitive abilities or a tester. This being
the case, there are a lot of examples when an error in coding or
design (i.e. vulnerability is not identified as intentional) caused
disasters and critical damage2.</p>
      <p>As to the second factor, it is enough to emphasize that the
overwhelming majority of present-day attacks are based on the
use of vulnerabilities, in which case an attacker needs to find
only one vulnerability in software to realize the threat that
corresponds to such vulnerability.</p>
      <p>Stressing the origin of factors in the information security
theory (defect, vulnerability, threat, risk) we may assert that
detection and repair of vulnerabilities prevent the corresponding
incident (damage, attack) (Fig. 1).</p>
      <p>
        Methods for enhancement of system security oriented to
software vulnerabilities and defects are a priori by nature and,
hence, have a number of advantages over the reactive methods
[
        <xref ref-type="bibr" rid="ref12 ref13">12, 13</xref>
        ] oriented to the security event (incident) that has already
occurred (Fig. 2).
      </p>
      <p>As known, present-day formal methods for software analysis
and testing, except the expert methods, fall into the “curse of
dimensionality” zone. Hence, though programmers take active
actions, the number of vulnerability does not drop (Fig. 3) and it
is easy to prove that the number of computer attacks, including
purpose-oriented (using zero-day vulnerabilities) attacks, so
does the total damage caused by them. By the way, to date the
volume of the open international vulnerability base Mitre CVE
exceeds 100,000 vulnerabilities while the volume of the Russian
base (Vulnerability Database of the Federal Service for
Technical and Export Control) oriented to the domestic market
is above 20,000 vulnerabilities.</p>
      <p>
        In view of growth in attacks based on vulnerabilities, we may
stress two phenomena: on the one hand, the black market of
zero-day vulnerabilities is flourishing [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], on the other hand,
developing companies resort to crowdsourcing and hold open
competitions aimed at detection of vulnerabilities in their
software (bug bounty).
      </p>
      <p>In view of the above, instead of closing the ranks to raise
confidence in software security the world community tends to
abandon the problem and imposes various bans. This can be
illustrated by the following:
– Europe is facing a contradiction between requirements for
collaborative certification (based on cPP) and requirements set
by the European Union or individual countries;</p>
      <p>– The USA introduced restriction on the use of the software
certified in China and Russia while China and Russia take
asymmetric measures;</p>
      <p>– A number of countries clearly pursue the import
substitution policy, maintain blacklists of vendors of foreign
products or impose restrictions on the use of foreign products
etc.</p>
      <p>
        Unfortunately, this policy is not constructive in terms of
enhancement of international integration and security. For
instance, it is in conflict with consolidation of countries to
counteract illegitimate activity of third parties, first of all,
criminal hacker community (e.g. [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]).
      </p>
      <p>As a result, we evidence the compromise of the international
technical and legal regulation system of information and cyber
security.</p>
      <p>III. SOFTWARE SECURITY ENHANCEMENT APPROACHES
As mentioned above, one of the ways to raise the international
security level and ensure strategic stability is to enhance
confidence in security of software systems, in particular, by
closing the ranks of the international community to reduce
degree of software vulnerability.</p>
      <p>Nowadays, the approaches to enhancement of confidence in
security of software systems seem to be as follows:
1. To increase maturity of international software developing
companies;</p>
      <p>2. To raise the level of the international technical regulation
and evaluation of compliance in the form of mandatory software
certification providing access to the source code (at the test
stage).</p>
    </sec>
    <sec id="sec-3">
      <title>IV. ENHANCEMENT OF MATURITY OF DEVELOPING</title>
      <p>
        COMPANIES
It is recognized that the main cause of software vulnerability is
low-level maturity of developing companies which neglect
security practices relating to software design, engineering,
manufacture, introduction, supply, and maintenance. For
instance, we acquired statistics proving that the management (or
maturity3) level in a company produces an appreciable effect on
the security level of developed, manufactured and supplied
software, in particular, the degree of absence of vulnerabilities
and opportunity to promptly repair them if they are discovered.
For example, studies undertaken by the NPO Echelon
Moscow-based test laboratory proved strict inverse
proportionality of the total amount of vulnerabilities to maturity
levels in the software developing company (Fig. 4) [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
      </p>
      <p>
        Besides the point, according to Microsoft, the amount of
software vulnerabilities dropped by more than 80% due to the
3 According to COBIT. URL: https://cobitonline.isaca.org/
introduction of the respective management sub-system
(Microsoft Secure Software Development Life Cycle) [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ].
      </p>
      <p>
        Though today a number of international and national
organizations are concerned over the problem to raise efficiency
of security development management, studies are fragmentary
in nature or are reduced to good practices of the software
developing companies. For instance, bibliographical sources
describe in detail the supply chain threats [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ]; at the same time
selected points pertaining to unintentional threats and the threats
from other sub-stages of software lifecycles are often described
in brief. This issue has been addressed in the Russian technical
regulation system in the form of GOST R 56939-2016
“Information protection. Development of security software.
General requirements” prepared by national technical
committee TC-362. The place it takes in the system of
international standards are shown in Fig. 5.
      </p>
      <p>It is noteworthy that one of the first international companies
of which information security management sub-system has been
certified according to GOST R 56939 is Kaspersky Lab
international company which in an unreciprocated manner
offered its source code to the USA secret services4.</p>
    </sec>
    <sec id="sec-4">
      <title>V. SOFTWARE CERTIFICATION</title>
      <p>At present, the certification procedure in accordance with
information security requirements implies the use of various
testing methods and techniques, because errors and
vulnerabilities are of different nature and have characteristic
symptoms.</p>
      <p>
        At the same time, we may assert that conceptual and
methodical framework for software testing in accordance with
information security requirements is developed and is at the
respective level of iterative development [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. It is worth being
added that modern approaches to detection of vulnerabilities are
based on the conceptual approach laid down in ISO/IEC TR
20004; at the same time there exists a number of guides to code
analysis, penetration test etc.
      </p>
      <p>
        Though software is tested using a great many methods and
techniques, we think that it is impossible to attain an acceptable
level of confidence in software if the access to source code is not
provided. It may be clearly illustrated using floating errors and
software bugs which are initiated by rather rare combinations of
input data, i.e. they may not be found by means of a “black box”
test method, for instance fuzz testing. In other words, only access
to source code provides a probability to detect any vulnerability
using expert knowledge. Fig. 6 gives statistics of efficiency of
basic software security analysis methods [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
companies is the threat of intellectual property theft. At the same
time the experience of the test laboratory has shown that a
solution which ensures stringent compliance with code security
requirements is well known, namely creation of an independent
protected stand in a protected premises or a «clean room».
      </p>
      <p>Such clean room in the client’s premises (under control of
the client’s security guards) serves for the access (in isolated safe
environment) to the source software code, namely, for the period
of tests. Software set-up and necessary checks are undertaken
within the framework of the said access. Certainly, any
information medium may not be taken away or a communication
session may not be initiated etc. without approval by the client’s
security service. Documented evidence of checks and
conclusions are to be discussed and approved by the client. The
above approach has a number of advantages and warranties (Fig.
7), in particular:</p>
      <p>– Enhances software security due to cooperation between
developers and technicians of the certified test laboratory;
– Allows revealed vulnerabilities to be mandatorily repaired
within the certification framework while the relevant
information will remain unknown to any third party;
– Make inspections transparent with all actions (provision of
access, work monitoring and control, discussion of performance,
compiling the reports etc.) being technically and legally ensured
by the client’s security service;</p>
      <p>– Gives rise to confidence in the software product, since
there is always probability to reveal a potentially dangerous code
(or demonstrate the absence of), what both certification parties
are interested in.</p>
      <p>Unfortunately, at present an access to the source code is the
most disputable aspect. Often, officials or journalists, who are
far from understanding programming, easily speculate on this
topic. In business the major threat recognized by developing
4
https://www.reuters.com/article/us-usa-security-kaspersky-russia/kasperskylab-to-open-software-to-review-says-nothing-to-hide-idUSKBN1CS0Y1</p>
      <p>The above approach was approved in many countries and to
date no one compromise case is known. It should be noted that
aspects pertaining to the provision of access to source codes that
need to undertake tests are understandable by many software
developing companies. It is clearly illustrated by the provision
of access to Microsoft product codes in more than 30 countries5.
5 https://blogs.microsoft.com/eupolicy/transparency-center/</p>
    </sec>
    <sec id="sec-5">
      <title>VI. SUMMARY</title>
      <p>This survey makes it possible to reach the conclusion
concerning importance of software security on the global scale.</p>
      <p>We believe that there are two most promising trends in
enhancement of software security on the global scale, namely:
1. Convergence investigations of the best practices in
technical regulation on the condition that access is given to the
source codes at the test stage;</p>
      <p>2. Investigations in management of information and cyber
security undertaken by software developing companies and
vendors of software systems.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Clarke</surname>
            <given-names>R.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Knake</surname>
            <given-names>R.</given-names>
          </string-name>
          <string-name>
            <surname>Cyber</surname>
          </string-name>
          <article-title>War: The Next Threat to National Security and What to Do About It</article-title>
          . HarperCollins,
          <year>2010</year>
          , 312 p.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Harris</surname>
            <given-names>S. @</given-names>
          </string-name>
          <article-title>War: The Rise of the Military-Internet Complex</article-title>
          . - Eamon Dolan/Houghton Miffl in Harcourt,
          <year>2014</year>
          . 288 p.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Axelrod</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Iliev</surname>
            <given-names>R</given-names>
          </string-name>
          .
          <article-title>Timing of Cyber Conflict</article-title>
          .
          <source>In: Proceedings of the National Academy of Sciences of the United States of America</source>
          ,
          <volume>111</volume>
          (
          <issue>42014</issue>
          ),
          <year>January 28</year>
          ,
          <year>2014</year>
          :
          <fpage>1298</fpage>
          -
          <lpage>1303</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>Information</given-names>
            <surname>Security</surname>
          </string-name>
          <article-title>Threats during Crisis and Conflicts of the XXI Century / A</article-title>
          .V.
          <string-name>
            <surname>Zagorskii</surname>
            ,
            <given-names>N.P.</given-names>
          </string-name>
          <string-name>
            <surname>Romashkina</surname>
          </string-name>
          , eds. - Moscow, IMEMO RAN,
          <year>2016</year>
          . - 133 p.
          <source>DOI: 10.20542/978-5-9535-0461-4.</source>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>XII</given-names>
            <surname>International</surname>
          </string-name>
          <article-title>Forum Partnership of State, Business</article-title>
          and Civil Society at Providing International Information
          <string-name>
            <surname>Security (Garmisch-Partenkirchen</surname>
          </string-name>
          ,
          <source>Germany April 16-19</source>
          ,
          <year>2018</year>
          ).
          <source>International Affairs: A Russian Journal of World Politics, Diplomacy and International Relations</source>
          .
          <year>2018</year>
          . Special Issue.
          <volume>146</volume>
          p. URL: https://interaffairs.ru/virtualread/garmish2018/ publication.pdf (in Rus).
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Markov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sheremet</surname>
            <given-names>I.A. Software</given-names>
          </string-name>
          <article-title>Safety in the Context Of Strategic Stability</article-title>
          .
          <source>Vestnik Akademii voennyh nauk [Herald of Academy of military sciences]</source>
          ,
          <year>2019</year>
          , No
          <volume>2</volume>
          (
          <issue>67</issue>
          ), pp.
          <fpage>82</fpage>
          -
          <lpage>90</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Romashkina</surname>
            <given-names>N. Global</given-names>
          </string-name>
          <string-name>
            <surname>Military</surname>
          </string-name>
          Political Problems in International Informational Security: Trends, Threats and Prospects.
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          ,
          <year>2019</year>
          , No
          <volume>1</volume>
          (
          <issue>29</issue>
          ), pp.
          <fpage>2</fpage>
          -
          <lpage>9</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2019-1
          <issue>-2</issue>
          -9.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <string-name>
            <given-names>Mulvenon J.</given-names>
            <surname>Toward</surname>
          </string-name>
          <article-title>a Cyberconflict Studies Research Agenda</article-title>
          .
          <source>IEEE Security &amp; Privacy</source>
          .
          <year>2005</year>
          , V.3, N 4, pp.
          <fpage>52</fpage>
          -
          <lpage>55</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Barabanov</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V.L. Methodological</given-names>
          </string-name>
          <article-title>Framework for Analysis and Synthesis of a Set of Secure Software Development Controls</article-title>
          ,
          <source>Journal of Theoretical and Applied Information Technology</source>
          ,
          <year>2016</year>
          , vol.
          <volume>88</volume>
          , No 1, pp.
          <fpage>77</fpage>
          -
          <lpage>88</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Futter</surname>
            <given-names>A. Hacking</given-names>
          </string-name>
          <article-title>the Bomb: Cyber Threats</article-title>
          and
          <string-name>
            <given-names>Nuclear</given-names>
            <surname>Weapons</surname>
          </string-name>
          . - Georgetown University Press,
          <year>2018</year>
          , 216 p.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11] Probabilistic Modeling in System Engineering / By ed.
          <source>A. Kostogryzov - London: IntechOpen</source>
          ,
          <year>2018</year>
          . 287 p. DOI:
          <volume>10</volume>
          .5772/intechopen.71396.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Petrenko</surname>
            <given-names>S.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Makoveichuk</surname>
            <given-names>K.A.</given-names>
          </string-name>
          <string-name>
            <surname>Big</surname>
          </string-name>
          <article-title>Data Technologies for Cybersecurity</article-title>
          .
          <source>In: CEUR Workshop Proceedings</source>
          .
          <year>2017</year>
          , vol.
          <year>2081</year>
          , pp.
          <fpage>107</fpage>
          -
          <lpage>111</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Zegzhda</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zegzhda</surname>
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pechenkin</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Poltavtseva</surname>
            <given-names>M</given-names>
          </string-name>
          .
          <article-title>Modeling of information systems to their security evaluation</article-title>
          . In: ACM International Conference Proceeding Series,
          <year>2017</year>
          , pp.
          <fpage>295</fpage>
          -
          <lpage>298</lpage>
          . DOI:
          <volume>10</volume>
          .1145/3136825.3136857
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Bauer</surname>
            <given-names>A.</given-names>
          </string-name>
          <article-title>The Rise of Global Crime in the XXIst Century</article-title>
          . Westphalia press,
          <year>2013</year>
          . 57 p.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Barabanov</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V.L.</given-names>
          </string-name>
          <article-title>Statistics of Software Vulnerability Detection in Certification Testing</article-title>
          .
          <source>Journal of Physics: Conference Series</source>
          .
          <year>2018</year>
          . V. 1015. P. 042033. DOI:
          <volume>10</volume>
          .1088/
          <fpage>1742</fpage>
          - 6596/1015/4/042033.
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Howard</surname>
            <given-names>M. S.</given-names>
          </string-name>
          <string-name>
            <surname>Lipner S. The Security Development Lifecycle: A Process for Developing Demonstrably More Secure</surname>
          </string-name>
          Software - Microsoft Press,
          <year>2006</year>
          . 352 p.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Reed</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Miller</surname>
            <given-names>J.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Popick</surname>
            <given-names>P.</given-names>
          </string-name>
          <string-name>
            <surname>Supply Chain Attack</surname>
          </string-name>
          <article-title>Patterns: Framework and Catalog</article-title>
          .
          <source>OUSD (AT&amp;L)</source>
          ,
          <year>2014</year>
          . 88 p. URL: https://www.acq.osd.mil/se/docs/supply-chain-wp.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Reber</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Malmquist</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shcherbakov</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <year>2014</year>
          .
          <article-title>Mapping the Application Security Terrain</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <source>2014. N 1</source>
          (
          <issue>2</issue>
          ). P.
          <volume>36</volume>
          -
          <fpage>39</fpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          -3456-2014-2-
          <fpage>36</fpage>
          -39.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>