A qualitative and quantitative risk assessment method in software security | IEEE Conference Publication | IEEE Xplore