


default search action
Adam Shostack
Person information
- affiliation: Shostack + Associates, USA
- affiliation: University of Washington, Seattle, WA, USA
Refine list

refinements active!
zoomed in on ?? of ?? records
view refined list in
export refined list as
2020 – today
- 2025
 [i7]Adam Shostack: [i7]Adam Shostack:
 Who Are "We"? Power Centers in Threat Modeling. CoRR abs/2501.10427 (2025)
 [i6]Adam Shostack, L. Jean Camp, Yi Ting Chua, Josiah Dykstra, Brian LaMacchia, Daniel Lopresti: [i6]Adam Shostack, L. Jean Camp, Yi Ting Chua, Josiah Dykstra, Brian LaMacchia, Daniel Lopresti:
 Lessons for Cybersecurity from the American Public Health System. CoRR abs/2506.12257 (2025)
- 2024
 [c14]Josiah Dykstra [c14]Josiah Dykstra , Adam Shostack , Adam Shostack : :
 Handling Pandemic-Scale Cyber Threats: Lessons from COVID-19. NSPW 2024: 1-10
 [i5]Adam Shostack: [i5]Adam Shostack:
 The Boy Who Survived: Removing Harry Potter from an LLM is harder than reported. CoRR abs/2403.12082 (2024)
 [i4]Adam Shostack, Josiah Dykstra: [i4]Adam Shostack, Josiah Dykstra:
 Handling Pandemic-Scale Cyber Threats: Lessons from COVID-19. CoRR abs/2408.08417 (2024)
- 2023
 [j5]Adam Shostack: [j5]Adam Shostack:
 Nothing Is Good Enough: Fast and Cheap Are Undervalued as Influencers of Security Tool Adoption. IEEE Secur. Priv. 21(1): 78-83 (2023)
 [i3]Adam Shostack: [i3]Adam Shostack:
 Fast, Cheap and Good: Lightweight Methods Are Undervalued. CoRR abs/2301.03593 (2023)
- 2022
 [j4]Adam Shostack, Fabio Massacci, Eric Bodden, Antonino Sabetta: [j4]Adam Shostack, Fabio Massacci, Eric Bodden, Antonino Sabetta:
 25 Years in Application Security: Looking Back, Looking Forward. IEEE Secur. Priv. 20(1): 109-112 (2022)
 [j3]Tadayoshi Kohno, Camille Cobb, Ada Lerner, Michelle Lin, Adam Shostack: [j3]Tadayoshi Kohno, Camille Cobb, Ada Lerner, Michelle Lin, Adam Shostack:
 The Buffet Overflow Café. IEEE Secur. Priv. 20(4): 4-7 (2022)
- 2020
 [j2]Adam Shostack, Mary Ellen Zurko: [j2]Adam Shostack, Mary Ellen Zurko:
 Secure development tools and techniques need more research that will increase their impact and effectiveness in practice. Commun. ACM 63(5): 39-41 (2020)
 [c13]Shamal Faily [c13]Shamal Faily , Riccardo Scandariato, Adam Shostack, Laurens Sion , Riccardo Scandariato, Adam Shostack, Laurens Sion , Duncan Ki-Aries , Duncan Ki-Aries : :
 Contextualisation of Data Flow Diagrams for Security Analysis. GraMSec@CSF 2020: 186-197
 [i2]Shamal Faily, Riccardo Scandariato, Adam Shostack, Laurens Sion, Duncan Ki-Aries: [i2]Shamal Faily, Riccardo Scandariato, Adam Shostack, Laurens Sion, Duncan Ki-Aries:
 Contextualisation of Data Flow Diagrams for security analysis. CoRR abs/2006.04098 (2020)
2010 – 2019
- 2019
 [i1]Adam Shostack, Matthew Smith [i1]Adam Shostack, Matthew Smith , Sam Weber, Mary Ellen Zurko: , Sam Weber, Mary Ellen Zurko:
 Empirical Evaluation of Secure Development Processes (Dagstuhl Seminar 19231). Dagstuhl Reports 9(6): 1-25 (2019)
- 2017
 [c12]Sam Weber, Adam Shostack, Jon A. Solworth, Mary Ellen Zurko: [c12]Sam Weber, Adam Shostack, Jon A. Solworth, Mary Ellen Zurko:
 Panel: Empirically-based Secure OS Design. NSPW 2017: 90-93
- 2014
 [j1]Dinei Florêncio, Cormac Herley, Adam Shostack: [j1]Dinei Florêncio, Cormac Herley, Adam Shostack:
 FUD: a plea for intolerance. Commun. ACM 57(6): 31-33 (2014)
 [c11]Tamara Denning, Adam Shostack, Tadayoshi Kohno: [c11]Tamara Denning, Adam Shostack, Tadayoshi Kohno:
 Practical Lessons from Creating the Control-Alt-Hack Card Game and Research Challenges for Games In Education and Research. 3GSE 2014
 [c10]Adam Shostack: [c10]Adam Shostack:
 Elevation of Privilege: Drawing Developers into Threat Modeling. 3GSE 2014
- 2013
 [c9]Tamara Denning, Adam Lerner, Adam Shostack, Tadayoshi Kohno: [c9]Tamara Denning, Adam Lerner, Adam Shostack, Tadayoshi Kohno:
 Control-Alt-Hack: the design and evaluation of a card game for computer security awareness and education. CCS 2013: 915-928
 [c8]Tamara Denning, Tadayoshi Kohno, Adam Shostack: [c8]Tamara Denning, Tadayoshi Kohno, Adam Shostack:
 Control-Alt-Hack™: a card game for computer security outreach and education (abstract only). SIGCSE 2013: 729
2000 – 2009
- 2008
 [c7]Adam Shostack: [c7]Adam Shostack:
 Experiences Threat Modeling at Microsoft. MODSEC@MoDELS 2008
- 2005
 [c6]Adam Shostack: [c6]Adam Shostack:
 Avoiding Liability: An Alternative Route to More Secure Products. WEIS 2005
- 2004
 [p1]Adam Shostack, Paul Syverson: [p1]Adam Shostack, Paul Syverson:
 What Price Privacy? - and why identity theft is about neither identity nor theft. Economics of Information Security 2004: 129-142
- 2002
 [c5]Steve Beattie, Seth Arnold, Crispin Cowan, Perry Wagle, Chris Wright, Adam Shostack: [c5]Steve Beattie, Seth Arnold, Crispin Cowan, Perry Wagle, Chris Wright, Adam Shostack:
 Timing the Application of Security Patches for Optimal Uptime. LISA 2002: 233-242
- 2001
 [c4]Joan Feigenbaum, Michael J. Freedman, Tomas Sander, Adam Shostack: [c4]Joan Feigenbaum, Michael J. Freedman, Tomas Sander, Adam Shostack:
 Privacy Engineering for Digital Rights Management Systems. Digital Rights Management Workshop 2001: 76-105
- 2000
 [c3]Adam Shostack, Ian Goldberg: [c3]Adam Shostack, Ian Goldberg:
 How not to design a privacy system: reflections on the process behind the Freedom product. CFP 2000: 85-87
1990 – 1999
- 1999
 [c2]Adam Shostack: [c2]Adam Shostack:
 Breaking Up Is Hard To Do: Modeling Security Threats for Smart Cards. Smartcard 1999
- 1996
 [c1]Adam Shostack: [c1]Adam Shostack:
 Observed weaknesses in security dynamics' client/server protocol. Network Threats 1996: 41-54
Coauthor Index

manage site settings
To protect your privacy, all features that rely on external API calls from your browser are turned off by default. You need to opt-in for them to become active. All settings here will be stored as cookies with your web browser. For more information see our F.A.Q.
Unpaywalled article links
Add open access links from  to the list of external document links (if available).
 to the list of external document links (if available).
Privacy notice: By enabling the option above, your browser will contact the API of unpaywall.org to load hyperlinks to open access articles. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the Unpaywall privacy policy.
Archived links via Wayback Machine
For web page which are no longer available, try to retrieve content from the  of the Internet Archive (if available).
 of the Internet Archive (if available).
Privacy notice: By enabling the option above, your browser will contact the API of archive.org to check for archived content of web pages that are no longer available. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the Internet Archive privacy policy.
Reference lists
Add a list of references from  ,
,  , and
, and  to record detail pages.
 to record detail pages.
load references from crossref.org and opencitations.net
Privacy notice: By enabling the option above, your browser will contact the APIs of crossref.org, opencitations.net, and semanticscholar.org to load article reference information. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the Crossref privacy policy and the OpenCitations privacy policy, as well as the AI2 Privacy Policy covering Semantic Scholar.
Citation data
Add a list of citing articles from  and
 and  to record detail pages.
 to record detail pages.
load citations from opencitations.net
Privacy notice: By enabling the option above, your browser will contact the API of opencitations.net and semanticscholar.org to load citation information. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the OpenCitations privacy policy as well as the AI2 Privacy Policy covering Semantic Scholar.
OpenAlex data
Load additional information about publications from  .
.
Privacy notice: By enabling the option above, your browser will contact the API of openalex.org to load additional information. Although we do not have any reason to believe that your call will be tracked, we do not have any control over how the remote server uses your data. So please proceed with care and consider checking the information given by OpenAlex.
last updated on 2025-07-28 21:07 CEST by the dblp team
 all metadata released as open data under CC0 1.0 license
 all metadata released as open data under CC0 1.0 license
see also: Terms of Use | Privacy Policy | Imprint


 Google
Google Google Scholar
Google Scholar Semantic Scholar
Semantic Scholar Internet Archive Scholar
Internet Archive Scholar CiteSeerX
CiteSeerX ORCID
ORCID







