{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,18]],"date-time":"2026-03-18T18:31:26Z","timestamp":1773858686655,"version":"3.50.1"},"publisher-location":"Boston, MA","reference-count":18,"publisher":"Springer US","isbn-type":[{"value":"9780387290164","type":"print"},{"value":"9780387365848","type":"electronic"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"DOI":"10.1007\/978-0-387-36584-8_6","type":"book-chapter","created":{"date-parts":[[2008,5,5]],"date-time":"2008-05-05T22:11:39Z","timestamp":1210025499000},"page":"65-77","source":"Crossref","is-referenced-by-count":16,"title":["Assessing the risk of using vulnerable components"],"prefix":"10.1007","author":[{"given":"Davide","family":"Balzarotti","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mattia","family":"Monga","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sabrina","family":"Sicari","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"6_CR1","doi-asserted-by":"crossref","unstructured":"Christopher Alberts, Audree Dorofee, James Stevens, and Carol Woody. Introduction to the Octave approach, http:\/\/www.cert.org\/octave\/ , 2003.","DOI":"10.21236\/ADA634134"},{"issue":"4","key":"6_CR2","doi-asserted-by":"publisher","first-page":"375","DOI":"10.1145\/162124.162127","volume":"25","author":"R. Baskerville","year":"1993","unstructured":"Richard Baskerville. Information system security design methods: Implications for information systems development. ACM Computing Survey, 25(4):375\u2013412, 1993.","journal-title":"ACM Computing Survey"},{"key":"6_CR3","doi-asserted-by":"crossref","unstructured":"Gautam Biswas, Kenneth A. Debelak, and Kazuhiko Kawamura. Application of qualitative modelling to knoweledge-based risk assessment studies. IEA\/AIE \u201889: Second International Conference on Industrial & Engineering Applications of Artificial Intelligence & Expert Systems-ACM, pages 92\u2013101, 1989.","DOI":"10.1145\/66617.66630"},{"key":"6_CR4","unstructured":"B. Jenkins. Risk analysis helps establish a good security posture; risk management keeps it that way. whitepaper, pages 1\u201316, 1998."},{"key":"6_CR5","unstructured":"Harvey M. Deitel, Paul J. Deitel, B. DuWaldt, and L. K. Trees. Web Services: A Technical Introduction. Prentice Hall, 2002."},{"key":"6_CR6","doi-asserted-by":"crossref","unstructured":"Zaid Dwaikat and Francesco Parisi-Presicce. Risky trust: Risk-based analysis of software system. Proceedings of the first workshop on Software Engineering for Secure Systems (SESS05).","DOI":"10.1145\/1083200.1083206"},{"key":"6_CR7","doi-asserted-by":"crossref","unstructured":"S. Evans, D. Heinbuch, E Kyle, J. Piorkowski,and J. Wallener. Risk-based system security engineering: Stopping attacks with intention. IEEE Security & Privacy, pages 59\u201362, 2004.","DOI":"10.1109\/MSP.2004.109"},{"key":"6_CR8","unstructured":"Network Working Group. Internet security glossary, http:\/\/rfc.net\/rfc2828.html , May 2000. Request for Comments: 2828."},{"key":"6_CR9","unstructured":"Michael Howard and David Leblanc. Writing secure Code. Microsoft Press, 2003."},{"key":"6_CR10","unstructured":"Khaled Khan, Jun Han, and Yuliang Zheng. A framework for an active interface to characterize compositional security contracts of software components. 2001 Australian Software Engineering Conference (ASWECOl)-IEEE Computer Society Press, pages 117\u2013126."},{"key":"6_CR11","doi-asserted-by":"crossref","unstructured":"I.S. Moskowitz and M.H. Kang. An insecurity flow model. Proceedings of New Security Paradigms workshop, 1997.","DOI":"10.1145\/283699.283741"},{"key":"6_CR12","unstructured":"S. Noel, S. Jajoidia, B. O\u2018Berry, and M. Jacobs. Efficient minimum-cost network hardening via exploit dependency graphs. Proceedings of ACSAC\u201803."},{"issue":"3","key":"6_CR13","doi-asserted-by":"publisher","first-page":"177","DOI":"10.1111\/j.1539-6924.1984.tb00137.x","volume":"4","author":"M.E. Pate-Cornell","year":"1984","unstructured":"M. Elisabeth Pate-Cornell. Fault tree vs. event trees in reliability analysis. Risk Analysis, 4(3): 177\u2013186, 1984.","journal-title":"Risk Analysis"},{"key":"6_CR14","doi-asserted-by":"crossref","unstructured":"Mehmet Sahinoglu. Security meter:a pratical decision-tree model to quantify risk. IEEE Security & Privacy,3(3): 18\u201324, May\/June 2005.","DOI":"10.1109\/MSP.2005.81"},{"key":"6_CR15","unstructured":"Bruce Schneier. Modelling security threats. Dr. Dobb\u2019s Journal, dec 1999."},{"key":"6_CR16","doi-asserted-by":"crossref","unstructured":"Gunter P. Sharp, Philip H. Enslow, Shamkant B. Navathe, and Fariborz Farhmand. Managing vulnerabilities of information system to security incindets. ACM International Conference: 5th international conference on Electronic commerce, pages 348\u2013354, 2003.","DOI":"10.1145\/948005.948050"},{"key":"6_CR17","doi-asserted-by":"crossref","unstructured":"O. Sheyner, J. Haines, S.Jha, R. Lippmann, and J.M. Wing. Automated generation and analysis of attack graphs. Proceedings of the 2002 IEEE Symposium on Security and Privacy (S&P\u201802).","DOI":"10.1109\/SECPRI.2002.1004377"},{"key":"6_CR18","unstructured":"Thomas Siu. Risk-eye for IT security guy. Gsec, pages 1\u201320, 2004."}],"container-title":["Advances in Information Security","Quality of Protection"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-0-387-36584-8_6.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,30]],"date-time":"2025-01-30T02:31:41Z","timestamp":1738204301000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-0-387-36584-8_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[null]]},"ISBN":["9780387290164","9780387365848"],"references-count":18,"URL":"https:\/\/doi.org\/10.1007\/978-0-387-36584-8_6","relation":{},"subject":[]}}