<?xml version="1.0" encoding="UTF-8"?>
<doi_batch version="4.3.0" xmlns="http://www.crossref.org/doi_resources_schema/4.3.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.crossref.org/doi_resources_schema/4.3.0 http://www.crossref.org/schema/deposit/doi_resources4.3.0.xsd">
<head>
<doi_batch_id>04cfea51-379e-4d84-91b6-c6bc146fb3b2</doi_batch_id>
<depositor>
<name>beie</name>
<email_address>director@blueeyesintelligence.org</email_address>
</depositor>
</head>
<body>
<doi_citations>
<doi>10.35940/ijrte.B7671.0712223</doi>
<citation_list><citation key="ref0"><unstructured_citation>J. G. C. &amp;. L.-P. M. M. ACOSTA, &quot;A LITERATURE REVIEW OF VULNERABILITY MANAGEMENT IN INFORMATION SYSTEMS. COMPUTERS SECURITY,&quot; PP. 47-65, 2016.</unstructured_citation></citation><citation key="ref1"><unstructured_citation>J. &amp;. L. B. Jørgensen, &quot;Software vulnerability remediation with risk‐based prioritization. Journal of Software: Evolution and Process,&quot; 2017.</unstructured_citation></citation><citation key="ref2"><unstructured_citation>A. R. V. a. H. M. M. Vieira, &quot;A survey on software vulnerability detection using machine learning.,&quot; vol. 97, pp. 186-198, 2014.</unstructured_citation></citation><citation key="ref3"><unstructured_citation>G. &amp;. O. A. L. Sindre, &quot;Eliciting security requirements with misuse cases. Requirements Engineering,&quot; vol. 16, pp. 31-56, 2011.</unstructured_citation></citation><citation key="ref4"><unstructured_citation>J. &amp;. H. S. Ruohonen, &quot;The effectiveness of static code analysis: A systematic literature review,&quot; vol. 106, pp. 96-115, 2019.</unstructured_citation></citation><citation key="ref5"><unstructured_citation>G. &amp;. S. Z. Wassermann, &quot;Static analysis for security,&quot; pp. 589-619, 2016.</unstructured_citation></citation><citation key="ref6"><unstructured_citation>S. A. K. A. &amp;. M. M. S. Ali, &quot;A systematic literature review on security testing of web applications,&quot; vol. 45, pp. 124-142, 2015.</unstructured_citation></citation><citation key="ref7"><unstructured_citation>M. P. V. T. R. A. &amp;. S. K. Böhme, &quot;The effectiveness of testing techniques for fault detection: A systematic review and meta-analysis,&quot; vol. 52, pp. 1-40, 2019.</unstructured_citation></citation><citation key="ref8"><unstructured_citation>D. R. a. F. R. W. Kuhn, &quot;Penetration testing: A hands-on introduction to hacking,&quot; 2018.</unstructured_citation></citation><citation key="ref9"><unstructured_citation>M. Bishop, &quot;Computer Security: Art and Science,&quot; vol. 1st edition, 2002.</unstructured_citation></citation><citation key="ref10"><unstructured_citation>W. S. a. K. E. Ehab Al-Shaer, &quot;A survey on vulnerability assessment and penetration testing techniques,&quot; vol. 18, pp. 1033-1046, 2016.</unstructured_citation></citation><citation key="ref11"><doi>10.1145/1134285.1134349</doi><unstructured_citation>N. B. T. a. Z. A. Nagappan, &quot;Mining metrics to predict component failures,&quot; pp. 452-461, 2006.</unstructured_citation></citation><citation key="ref12"><unstructured_citation>13.Y. B. a. A. F. G.-S. A. Acosta, &quot;An empirical comparison of automated and manual penetration testing,&quot; vol. 63, pp. 122-144.</unstructured_citation></citation><citation key="ref13"><unstructured_citation>J. C. a. A. Meneely, &quot;The impact of code review coverage and code review participation on software quality: a case study of the qt, vtk, and itk projects,&quot; vol. 19, pp. 1024-1060, 2014.</unstructured_citation></citation><citation key="ref14"><unstructured_citation>D. Spinellis, &quot;Code reviews and static code analysis: the last line of defense against software vulnerabilities,&quot; vol. 34, pp. 92-97, 2017.</unstructured_citation></citation><citation key="ref15"><unstructured_citation>M. A. F. A. a. M. A. A.-S. A. M. A. Rizvi, &quot;Effectiveness of software security testing techniques: a systematic review,&quot; vol. 123, pp. 155-176, 2017.</unstructured_citation></citation><citation key="ref16"><unstructured_citation>J. R. T. a. J. H. Park, &quot;A comparative study of vulnerability detection methods,&quot; vol. 30, pp. 1395-1411, 2014.</unstructured_citation></citation><citation key="ref17"><unstructured_citation>B. C. a. M. O. Dino Juric, &quot;Combining static and dynamic analysis for software security assessment,&quot; pp. 50-62, 2015.</unstructured_citation></citation><citation key="ref18"><unstructured_citation>E. B. J. M. B. d. l. P. a. M. Á. R. L. Martínez, &quot;Towards a new integrated approach for web application security testing,&quot; vol. 85, pp. 553-566, 2012.</unstructured_citation></citation><citation key="ref19"><unstructured_citation>K. M. K. H. a. Y. R. Tari, &quot;An empirical comparison of software vulnerability discovery techniques,&quot; vol. 64, pp. 835-847, 2015.</unstructured_citation></citation><citation key="ref20"><unstructured_citation>Z. T. A. A. a. A. L. A. Abdul-Rahman, &quot;A comparison of static and dynamic analysis for software vulnerability detection,&quot; pp. 912-917.</unstructured_citation></citation><citation key="ref21"><unstructured_citation>W. L. a. T. J. T. Chen, &quot;Systematic Identification of Vulnerabilities in Open-Source Software,&quot; vol. 17, pp. 674-687, 2020.</unstructured_citation></citation><citation key="ref22"><unstructured_citation>L. W. a. R. Kessler, &quot; Pair Programming vs. Up-front Design for Extreme Programming,&quot; vol. 19, pp. 62-70, 2002.</unstructured_citation></citation><citation key="ref23"><unstructured_citation>A. Ghaznavi-Zadeh, &quot;A Comprehensive Review of Penetration Testing,&quot; vol. 7, 2021.</unstructured_citation></citation><citation key="ref24"><unstructured_citation>H. Saidani, &quot;Comparative Analysis of Software Vulnerability Assessment Techniques, Journal of Computer Networks and Communications,&quot; 2018.</unstructured_citation></citation><citation key="ref25"><unstructured_citation>C. L. a. S. Sabetzadeh, &quot;An Empirical Study of Code Review Processes in Open-Source Software Projects,&quot; vol. 110, pp. 64-80, 2015.</unstructured_citation></citation><citation key="ref26"><unstructured_citation>R. Kazman, &quot;Software Design Review,&quot; vol. 55, pp. 129-137, 2012.</unstructured_citation></citation><citation key="ref27"><unstructured_citation>K. Stergiopoulos, &quot;Penetration Testing: A Methodology for Enhancing Vulnerability Assessments,&quot; vol. 4, pp. 263-271, 2013.</unstructured_citation></citation><citation key="ref28"><unstructured_citation>A. A. a. H. Siddiqi, &quot;Penetration Testing Methodologies: A Review,&quot; vol. 2, pp. 98-110, 2014.</unstructured_citation></citation><citation key="ref29"><unstructured_citation>A. W. L. &amp;. O. J. Meneely, &quot;Software engineering for cybersecurity: A research roadmap,&quot; vol. 144, pp. 1-17, 2018.</unstructured_citation></citation><citation key="ref30"><unstructured_citation>L. W. a. J. O. M. A. Rahman, &quot;Improving code review efficiency: A study of static analysis and reviewer recommendation,&quot; vol. 138, pp. 81-96, 2018.</unstructured_citation></citation><citation key="ref31"><unstructured_citation>A. P. a. B. K. A. Zeller, &quot;Code review in the dark,&quot; vol. 36, pp. 40-47, 2019.</unstructured_citation></citation><citation key="ref32"><unstructured_citation>L. Y. Y. &amp;. L. Y. Wang, &quot;A large-scale empirical study of code review practices in open source projects,&quot; vol. 45, pp. 913-935, 2019.</unstructured_citation></citation><citation key="ref33"><unstructured_citation>M. I. Ahmed, &quot;Automated code review: A systematic literature review,&quot; vol. 144, pp. 163-179, 2018.</unstructured_citation></citation><citation key="ref34"><unstructured_citation>S. B. a. J. R. W. N. A. Ernst, &quot;Duration of software code review meetings: An empirical analysis,&quot; pp. 514-524, 2019.</unstructured_citation></citation><citation key="ref35"><unstructured_citation>P. T. P. a. A. Orso, &quot; Are automated debugging techniques actually helping programmers,&quot; pp. 385-394, 2010.</unstructured_citation></citation><citation key="ref36"><unstructured_citation>D. H. Shihab, &quot;An Analysis of the Code Review Processes of Open-Source Software Projects,&quot; vol. 43, pp. 850-867, 2017.</unstructured_citation></citation><citation key="ref37"><unstructured_citation>S. K. a. H. K. K. S. Y. Shin, &quot;Combining Static and Dynamic Analysis for Web Application Security Assessment,&quot; vol. 12, 2016.</unstructured_citation></citation><citation key="ref38"><unstructured_citation>M. V. Tripunitara, &quot;Testing for Security: An Overview,&quot; vol. 47, pp. 1-37, 2015.</unstructured_citation></citation><citation key="ref39"><unstructured_citation>G. McGraw, &quot;Software Security Testing: Do We Really Know How to Do This Stuff,&quot; vol. 2, pp. 83-86, 2004.</unstructured_citation></citation><citation key="ref40"><unstructured_citation>B. H. E. R. M. F. A. M. D. W. A. Edmundson, &quot;An Empirical Study on the Effectiveness of Security Code Review&quot;.</unstructured_citation></citation><citation key="ref41"><unstructured_citation>C. A. G. Ç. A. B. L. Braz, &quot;Less is More: Supporting Developers in Vulnerability Detection during Code Review,&quot; 2022.</unstructured_citation></citation><citation key="ref42"><unstructured_citation>&quot;Secure Code Review,&quot; Application Security.</unstructured_citation></citation><citation key="ref43"><unstructured_citation>Y. C. H. X. S. W. a. J. L. Xinyu Yang, &quot;Empirical evaluation of the effectiveness of code review for finding security vulnerabilities in web applications,&quot; no. 28, pp. 1058-1071, 2013.</unstructured_citation></citation><citation key="ref44"><unstructured_citation>M. S. H. B. M. &amp;. B. M. Kessentini, &quot;A systematic review of software fault prediction approaches. Journal of Systems and Softwar,&quot; vol. 83, pp. 1378-1396, 2010.</unstructured_citation></citation><citation key="ref45"><unstructured_citation>D. Litchfield, &quot;Google Hacking for Penetration Testers,&quot; 2005.</unstructured_citation></citation><citation key="ref46"><unstructured_citation>K. Arvanitakis, S. Mitropoulos and S. Kontogiannis, &quot; A comparative study of code review and penetration testing in web application security,&quot; vol. 3, pp. 235-243, 2012.</unstructured_citation></citation><citation key="ref47"><unstructured_citation>M. K. M. &amp;. O. M. Ferruh, &quot;A comparative study of penetration testing tools,&quot; pp. 483-488, 2012.</unstructured_citation></citation><citation key="ref48"><unstructured_citation>J. &amp;. M. D. DeMott, &quot;The limits of automated web application security scanners,&quot; pp. 421-430, 2008.</unstructured_citation></citation><citation key="ref49"><unstructured_citation>D. H. M. &amp;. A.-A. M. A. Al-Qudah, &quot;A comparative study of code review and testing for finding software defects,&quot; pp. 785-795, 2014.</unstructured_citation></citation><citation key="ref50"><unstructured_citation>W. H. T. &amp;. G. J. Zou, &quot;An empirical study on the effectiveness of code review for finding security vulnerabilities in Android applications,&quot; pp. 36-51, 2016.</unstructured_citation></citation><citation key="ref51"><unstructured_citation>R. M. R. e. al., &quot;Comparative study of code review and penetration testing for detecting security vulnerabilities in software,&quot; pp. 1-6, 2021.</unstructured_citation></citation><citation key="ref52"><unstructured_citation>M. F. K. e. al., &quot;Comparing code review and penetration testing as vulnerability detection techniques,&quot; pp. 1-6, 2019.</unstructured_citation></citation><citation key="ref53"><unstructured_citation>H. A. K. a. H. M. Abbas, &quot;A comparative study of code review and penetration testing,&quot; pp. 191-196, 2018.</unstructured_citation></citation><citation key="ref54"><unstructured_citation>M. A. A. Q. e. al, &quot;Code review versus penetration testing: A comparative analysis,&quot; pp. 1-5, 2018.</unstructured_citation></citation></citation_list>
</doi_citations>
</body>
</doi_batch>
