{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,16]],"date-time":"2025-05-16T05:24:15Z","timestamp":1747373055364,"version":"3.40.3"},"publisher-location":"Cham","reference-count":22,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030192228"},{"type":"electronic","value":"9783030192235"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-19223-5_17","type":"book-chapter","created":{"date-parts":[[2019,5,16]],"date-time":"2019-05-16T23:22:43Z","timestamp":1558048963000},"page":"238-253","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["AutoCVSS: An Approach for Automatic Assessment of Vulnerability Severity Based on Attack Process"],"prefix":"10.1007","author":[{"given":"Deqing","family":"Zou","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ju","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhen","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hai","family":"Jin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaojing","family":"Ma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"17_CR1","unstructured":"Common Vulnerability Scoring System. https:\/\/www.first.org\/cvss\/"},{"key":"17_CR2","unstructured":"Exploit database. https:\/\/www.exploit-db.com\/"},{"key":"17_CR3","unstructured":"National Vulnerability Database. https:\/\/nvd.nist.gov\/"},{"key":"17_CR4","doi-asserted-by":"crossref","unstructured":"Allodi, L., Banescu, S., Femmer, H., Beckers, K.: Identifying relevant information cues for vulnerability assessment using CVSS. In: Proceedings of the 8th ACM Conference on Data and Application Security and Privacy (CODASPY), pp. 119\u2013126. ACM (2018)","DOI":"10.1145\/3176258.3176340"},{"key":"17_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1007\/978-3-319-70004-5_2","volume-title":"Future Data and Security Engineering","author":"L Allodi","year":"2017","unstructured":"Allodi, L., Biagioni, S., Crispo, B., Labunets, K., Massacci, F., Santos, W.: Estimating the assessment difficulty of CVSS environmental metrics: an experiment. In: Dang, T.K., Wagner, R., K\u00fcng, J., Thoai, N., Takizawa, M., Neuhold, E.J. (eds.) FDSE 2017. LNCS, vol. 10646, pp. 23\u201339. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70004-5_2"},{"issue":"10","key":"17_CR6","doi-asserted-by":"publisher","first-page":"2159","DOI":"10.1016\/j.comnet.2013.03.011","volume":"57","author":"J Almasizadeh","year":"2013","unstructured":"Almasizadeh, J., Azgomi, M.A.: A stochastic model of attack process for the evaluation of security metrics. Comput. Netw. 57(10), 2159\u20132180 (2013)","journal-title":"Comput. Netw."},{"key":"17_CR7","doi-asserted-by":"crossref","unstructured":"Cheng, P., Wang, L., Jajodia, S., Singhal, A.: Aggregating CVSS base scores for semantics-rich network security metrics. In: Proceedings of the 31st Symposium on Reliable Distributed Systems (SRDS), pp. 31\u201340. IEEE (2012)","DOI":"10.1109\/SRDS.2012.4"},{"issue":"2","key":"17_CR8","doi-asserted-by":"publisher","first-page":"228","DOI":"10.1016\/j.mbs.2005.03.006","volume":"195","author":"S Del Valle","year":"2005","unstructured":"Del Valle, S., Hethcote, H., Hyman, J.M., Castillo-Chavez, C.: Effects of behavioral changes in a smallpox attack model. Math. Biosci. 195(2), 228\u2013251 (2005)","journal-title":"Math. Biosci."},{"key":"17_CR9","doi-asserted-by":"crossref","unstructured":"Gallon, L.: On the impact of environmental metrics on CVSS scores. In: Proceedings of the 2nd International Conference on Social Computing (SocialCom), pp. 987\u2013992. IEEE (2010)","DOI":"10.1109\/SocialCom.2010.146"},{"key":"17_CR10","doi-asserted-by":"crossref","unstructured":"Ghani, H., Luna, J., Khelil, A., Alkadri, N., Suri, N.: Predictive vulnerability scoring in the context of insufficient information availability. In: Proceedings of 2013 International Conference on Risks and Security of Internet and Systems (CRiSIS), pp. 1\u20138. IEEE (2013)","DOI":"10.1109\/CRiSIS.2013.6766359"},{"key":"17_CR11","first-page":"1","volume":"2017","author":"H Hu","year":"2017","unstructured":"Hu, H., Zhang, H., Liu, Y., Wang, Y.: Quantitative method for network security situation based on attack prediction. Secur. Commun. Netw. 2017, 1\u201319 (2017)","journal-title":"Secur. Commun. Netw."},{"key":"17_CR12","doi-asserted-by":"crossref","unstructured":"Huang, H., Zhao, F., Ye, M.: Estimate the influential level of vulnerability instance based on hybrid ranking for dynamic network attacking scenarios. In: Proceedings of the 10th International Conference on Information Sciences Signal Processing and their Applications (ISSPA), pp. 586\u2013589. IEEE (2010)","DOI":"10.1109\/ISSPA.2010.5605434"},{"issue":"1","key":"17_CR13","doi-asserted-by":"publisher","first-page":"89","DOI":"10.3233\/IFS-151733","volume":"30","author":"A Khazaei","year":"2016","unstructured":"Khazaei, A., Ghasemzadeh, M., Derhami, V.: An automatic method for CVSS score prediction using vulnerabilities description. J. Intell. Fuzzy Syst. 30(1), 89\u201396 (2016)","journal-title":"J. Intell. Fuzzy Syst."},{"key":"17_CR14","doi-asserted-by":"crossref","unstructured":"Luk, C., et al.: Pin: building customized program analysis tools with dynamic instrumentation. In: Proceedings of Conference on Programming Language Design and Implementation, pp. 190\u2013200. ACM (2005)","DOI":"10.1145\/1065010.1065034"},{"key":"17_CR15","doi-asserted-by":"publisher","first-page":"932397:1","DOI":"10.1155\/2014\/932397","volume":"2014","author":"J Luo","year":"2014","unstructured":"Luo, J., Lo, K., Qu, H.: A software vulnerability rating approach based on the vulnerability database. J. Appl. Math. 2014, 932397:1\u2013932397:9 (2014)","journal-title":"J. Appl. Math."},{"key":"17_CR16","unstructured":"Ross, D.M., Wollaber, A.B., Trepagnier, P.C.: Latent feature vulnerability ranking of CVSS vectors. In: Proceedings of the Summer Simulation Multi-Conference, pp. 19:1\u201319:12. Society for Computer Simulation International (2017)"},{"key":"17_CR17","doi-asserted-by":"crossref","unstructured":"Spanos, G., Sioziou, A., Angelis, L.: WIVSS: a new methodology for scoring information systems vulnerabilities. In: Proceedings of the 17th Panhellenic Conference on Informatics, pp. 83\u201390. ACM (2013)","DOI":"10.1145\/2491845.2491871"},{"issue":"4","key":"17_CR18","doi-asserted-by":"publisher","first-page":"272","DOI":"10.1504\/IJITST.2012.054059","volume":"4","author":"A Tripathi","year":"2012","unstructured":"Tripathi, A., Singh, U.K.: Estimating risk levels for vulnerability categories using CVSS. Int. J. Internet Technol. Secured Trans. 4(4), 272\u2013289 (2012)","journal-title":"Int. J. Internet Technol. Secured Trans."},{"key":"17_CR19","doi-asserted-by":"crossref","unstructured":"Younis, A.A., Malaiya, Y.K.: Comparing and evaluating CVSS base metrics and Microsoft rating system. In: Proceedings of the IEEE International Conference on Software Quality, Reliability and Security (QRS), pp. 252\u2013261. IEEE (2015)","DOI":"10.1109\/QRS.2015.44"},{"key":"17_CR20","doi-asserted-by":"crossref","unstructured":"Younis, A.A., Malaiya, Y.K., Ray, I.: Using attack surface entry points and reachability analysis to assess the risk of software vulnerability exploitability. In: Proceedings of the 15th International Symposium on High-Assurance Systems Engineering (HASE), pp. 1\u20138. IEEE (2014)","DOI":"10.1109\/HASE.2014.10"},{"issue":"1","key":"17_CR21","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1007\/s11219-015-9274-6","volume":"24","author":"AA Younis","year":"2016","unstructured":"Younis, A.A., Malaiya, Y.K., Ray, I.: Assessing vulnerability exploitability risk using software properties. Software Qual. J. 24(1), 159\u2013202 (2016)","journal-title":"Software Qual. J."},{"key":"17_CR22","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1007\/978-3-319-33630-5_5","volume-title":"ICT Systems Security and Privacy Protection","author":"A Younis","year":"2016","unstructured":"Younis, A., Malaiya, Y.K., Ray, I.: Evaluating CVSS base score using vulnerability rewards programs. In: Hoepman, J.-H., Katzenbeisser, S. (eds.) SEC 2016. IAICT, vol. 471, pp. 62\u201375. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-33630-5_5"}],"container-title":["Lecture Notes in Computer Science","Green, Pervasive, and Cloud Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-19223-5_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,15]],"date-time":"2023-09-15T11:12:47Z","timestamp":1694776367000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-19223-5_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030192228","9783030192235"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-19223-5_17","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"27 April 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"GPC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Green, Pervasive, and Cloud Computing","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Uberl\u00e2ndia","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Brazil","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 May 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28 May 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"gpc2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.gpc2019.facom.ufu.br\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"38","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"17","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"45% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"2","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}}]}}