{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T16:51:35Z","timestamp":1783183895127,"version":"3.54.6"},"publisher-location":"New York, NY","reference-count":30,"publisher":"Springer New York","isbn-type":[{"value":"9781461409762","type":"print"},{"value":"9781461409779","type":"electronic"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-1-4614-0977-9_1","type":"book-chapter","created":{"date-parts":[[2011,8,19]],"date-time":"2011-08-19T16:24:22Z","timestamp":1313771062000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":41,"title":["A Formal Model for a System\u2019s Attack Surface"],"prefix":"10.1007","author":[{"given":"Pratyusa K.","family":"Manadhata","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jeannette M.","family":"Wing","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2011,8,5]]},"reference":[{"key":"1_CR1_1","doi-asserted-by":"crossref","unstructured":"J. Alves-Foss and S. Barbosa. Assessing computer security vulnerability. ACM SIGOPS Operating Systems Review, 29(3), 1995.","DOI":"10.1145\/206826.206829"},{"issue":"1","key":"1_CR2_1","first-page":"13","volume":"6","author":"E Asbeck","year":"1984","unstructured":"E. Asbeck and Y. Y. Haimes. The partitioned multiobjective risk method. Large Scale Systems, 6(1):13\u201338, 1984.","journal-title":"Large Scale Systems"},{"key":"1_CR3_1","doi-asserted-by":"crossref","unstructured":"M. Dacier and Y. Deswarte. Privilege graph: An extension to the typed access matrix model. In Proc. of European Symposium on Research in Computer Security, 1994.","DOI":"10.1007\/3-540-58618-0_72"},{"key":"1_CR4_1","doi-asserted-by":"crossref","unstructured":"N. E. Fenton and M. Neil. A critique of software defect prediction models. IEEE Transactions on Software Engineering, 25(5), 1999.","DOI":"10.1109\/32.815326"},{"key":"1_CR5_1","unstructured":"Norman E. Fenton and Shari Lawrence Pfleeger. Software Metrics: A Rigorous and Practical Approach. PWS Publishing Co., Boston, MA, USA, 1998."},{"key":"1_CR6_1","unstructured":"Virgil D. Gligor. Personal communication, 2008."},{"key":"1_CR7_1","volume-title":"editors","author":"SE Goodman","year":"2007","unstructured":"Seymour E. Goodman and Herbert S. Lin, editors. Toward a Safer and More Secure Cyberspace. The National Academics Press, 2007."},{"key":"1_CR8_1","unstructured":"R. Gopalakrishna, E. Spafford, and J. Vitek. Vulnerability likelihood: A probabilistic approach to software assurance. Technical Report 2005\u201306, CERIAS, Purdue Univeristy, 2005."},{"key":"1_CR9_1","doi-asserted-by":"crossref","unstructured":"Y. Y. Haimes. Risk Modeling, Assessment, and Management. Wiley, 2004.","DOI":"10.1002\/0471723908"},{"key":"1_CR10_1","volume-title":"editors","author":"CP Haugtvedt","year":"2008","unstructured":"Curtis P. Haugtvedt, Paul M. Herr, and Frank R. Kardes, editors. Handbook of Consumer Psychology. Psychology Press, 2008."},{"key":"1_CR11_1","unstructured":"M. Howard, J. Pincus, and J.M. Wing. Measuring relative attack surfaces. In Proc. of Workshop on Advanced Developments in Software and Systems Security, 2003."},{"key":"1_CR12_1","unstructured":"Michael Howard. Fending off future attacks by reducing attack surface. http: \/\/msdn.microsoft.com\/library\/default.asp?url=\/library\/en-us\/ dncode\/html\/secure02132003.asp, 2003."},{"key":"1_CR13_1","unstructured":"Michael Howard. Personal communication, 2005."},{"key":"1_CR14_1","doi-asserted-by":"crossref","unstructured":"Barbara Kitchenham, Shari Lawrence Pfleeger, and Norman Fenton. Towards a framework for software measurement validation. IEEE Transactions on Software Engineering, 21(12):929\u2013 944, 1995.","DOI":"10.1109\/32.489070"},{"key":"1_CR15_1","doi-asserted-by":"crossref","unstructured":"David John Leversage and Eric James Byres. Estimating a system\u2019s mean time-tocompromise. IEEE Security and Privacy, 6(1), 2008.","DOI":"10.1109\/MSP.2008.9"},{"key":"1_CR16_1","unstructured":"Jason Levitt. Windows 2000 security represents a quantum leap. http:\/\/www . informationweek.com\/834\/winsec.htm, April 2001."},{"issue":"2\/3","key":"1_CR17_1","doi-asserted-by":"crossref","first-page":"211","DOI":"10.3233\/JCS-1993-22-308","volume":"2","author":"B Littlewood","year":"1993","unstructured":"B. Littlewood, S. Brocklehurst, N. Fenton, P. Mellor, S. Page, D. Wright, J. Dobson J. Mc- Dermid, and D. Gollman. Towards operational measures of computer security. Journal of Computer Security, 2(2\/3):211\u2013230, 1993.","journal-title":"Journal of Computer Security"},{"key":"1_CR18_1","unstructured":"N. Lynch and M. Tuttle. An introduction to input\/output automata. CWI-Quarterly, 2(3), September 1989."},{"key":"1_CR19_1","doi-asserted-by":"crossref","unstructured":"Bharat B. Madan, Katerina Goseva-Popstojanova, Kalyanaraman Vaidyanathan, and Kishor S. Trivedi. Modeling and quantification of security attributes of software systems. In DSN, pages 505\u2013514, 2002.","DOI":"10.1109\/DSN.2002.1028941"},{"key":"1_CR20_1","unstructured":"Pratyusa K. Manadhata. An Attack Surface Metric. PhD thesis, Carnegie Mellon University, December 2008."},{"key":"1_CR21_1","unstructured":"Pratyusa K. Manadhata and Jeannette M. Wing. An attack surface metric. IEEE Transactions on Software Engineering, 99(PrePrints), 2010."},{"issue":"2","key":"1_CR22_1","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1109\/MSECP.2003.1193213","volume":"1","author":"G McGraw","year":"2003","unstructured":"Gary McGraw. From the ground up: The DIMACS software security workshop. IEEE Security and Privacy, 1(2):59\u201366, 2003.","journal-title":"IEEE Security and Privacy"},{"key":"1_CR23_1","volume-title":"Time-tocompromise model for cyber risk reduction estimation","author":"MA McQueen","year":"2005","unstructured":"Miles A. McQueen, Wayne F. Boyer, Mark A. Flynn, and George A. Beitel. Time-tocompromise model for cyber risk reduction estimation. In ACM CCS Workshop on Quality of Protection, September 2005."},{"issue":"5","key":"1_CR24_1","first-page":"71","volume":"3","author":"M David","year":"2005","unstructured":"David M. Nicol. Modeling and simulation in security evaluation. IEEE Security and Privacy, 3(5):71\u201374, 2005.","journal-title":"Modeling and simulation in security evaluation. IEEE Security and Privacy"},{"key":"1_CR25_1","doi-asserted-by":"crossref","unstructured":"R. Ortalo, Y. Deswarte, and M. Ka\u02c6aniche. Experimenting with quantitative evaluation tools for monitoring operational security. IEEE Transactions on Software Engineering, 25(5), 1999.","DOI":"10.1109\/32.815323"},{"key":"1_CR26_1","unstructured":"Stuart Edward Schechter. Computer Security Strength & Risk: A Quantitative Approach. PhD thesis, Harvard University, 2004."},{"key":"1_CR27_1","unstructured":"Bruce Schneier. Attack trees: Modeling security threats. Dr. Dobb\u2019s Journal, 1999."},{"key":"1_CR28_1","first-page":"69","volume":"2","author":"W Sean","year":"2004","unstructured":"Sean W. Smith and Eugene H. Spafford. Grand challenges in information security: Process and output. IEEE Security and Privacy, 2:69\u201371, 2004.","journal-title":"Spafford. Grand challenges in information security: Process and output. IEEE Security and Privacy"},{"key":"1_CR29_1","doi-asserted-by":"crossref","unstructured":"Rayford B. Vaughn, Ronda R. Henning, and Ambareen Siraj. Information assurance measures and metrics - state of practice and proposed taxonomy. In Proc. of Hawaii International Conference on System Sciences, 2003.","DOI":"10.1109\/HICSS.2003.1174904"},{"key":"1_CR30_1","unstructured":"J. Voas, A. Ghosh, G. McGraw, F. Charron, and K. Miller. Defining an adaptive software security metric from a dynamic software failure tolerance measure. In Proc. of Annual Conference on Computer Assurance, 1996."}],"container-title":["Advances in Information Security","Moving Target Defense"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-1-4614-0977-9_1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,8]],"date-time":"2025-03-08T23:21:34Z","timestamp":1741476094000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-1-4614-0977-9_1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9781461409762","9781461409779"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-1-4614-0977-9_1","relation":{},"ISSN":["1568-2633"],"issn-type":[{"value":"1568-2633","type":"print"}],"subject":[],"published":{"date-parts":[[2011]]},"assertion":[{"value":"5 August 2011","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}