Eliciting security requirements by misuse cases | IEEE Conference Publication | IEEE Xplore