Skip to search boxSkip to navigationSkip to main content

120 Domain-Specific Languages for Security

  • Markus Krausz
    ,
  • ,
  • Thorsten Berger
    ,
  • Francesco Regazzoni
    ,
  • Tim Güneysu
  • Ruhr University Bochum
    ,
  • TÜV Informationstechnik GmbH
    ,
  • ,
  • Chalmers university of Gothenburg
    ,
  • University of Amsterdam
    ,
  • Università della Svizzera italiana
Research Output:
Journal Article or Conference Article in Journal
Journal article
Peer-review

Open access

Publication Information

Output type

Research Output:
Journal Article or Conference Article in Journal
Journal article
Peer-review

Original language

English

Journal (Volume, Issue Number)

ACM Computing Surveys (Volume 58, Issue 11)

Publication milestones

  • Published - 13/04/2026

Publication status

Published - 13/04/2026

ISSN

0360-0300

Publication IDs

  • ORCID: /0000-0002-2604-0487/work/211542330
  • Scopus: 105038621460

Abstract

Security engineering—from creating security requirements to the implementation of security features, such as cryptography or authentification—is often supported by domain-specific languages (DSLs). While many security DSLs have been presented, a lack of overview and empirical data about these DSLs, such as which security aspects are addressed and when, hinders their effective use and further research. This systematic literature review examines 120 security DSLs regarding their security aspects and goals addressed, their language-specific characteristics, their integration into the software development lifecycle, and their evaluation. We observe a focus on individual development phases and a high degree of fragmentation, which leads to opportunities for integration. The research community also needs to improve the usability and evaluation of security DSLs.

Publication metrics

Access to documents