{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,11]],"date-time":"2024-09-11T06:43:16Z","timestamp":1726036996725},"publisher-location":"Cham","reference-count":21,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030248994"},{"type":"electronic","value":"9783030249007"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-24900-7_2","type":"book-chapter","created":{"date-parts":[[2019,7,10]],"date-time":"2019-07-10T04:12:15Z","timestamp":1562731935000},"page":"20-34","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["A Weighted Risk Score Model for IoT Devices"],"prefix":"10.1007","author":[{"given":"Shachar","family":"Siboni","sequence":"first","affiliation":[]},{"given":"Chanan","family":"Glezer","sequence":"additional","affiliation":[]},{"given":"Asaf","family":"Shabtai","sequence":"additional","affiliation":[]},{"given":"Yuval","family":"Elovici","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2019,7,11]]},"reference":[{"issue":"15","key":"2_CR1","doi-asserted-by":"publisher","first-page":"2787","DOI":"10.1016\/j.comnet.2010.05.010","volume":"54","author":"L Atzori","year":"2010","unstructured":"Atzori, L., Iera, A., Morabito, G.: The Internet of Things: a survey. Comput. Netw. 54(15), 2787\u20132805 (2010)","journal-title":"Comput. Netw."},{"key":"2_CR2","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1016\/j.comnet.2014.11.008","volume":"76","author":"S Sicari","year":"2015","unstructured":"Sicari, S., Rizzardi, A., Grieco, L.A., Coen-Porisini, A.: Security, privacy and trust in Internet of Things: the road ahead. Comput. Netw. 76, 146\u2013164 (2015)","journal-title":"Comput. Netw."},{"issue":"1","key":"2_CR3","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1016\/j.clsr.2009.11.008","volume":"26","author":"RH Weber","year":"2010","unstructured":"Weber, R.H.: Internet of Things-New security and privacy challenges. Comput. Law Secur. Rev. 26(1), 23\u201330 (2010)","journal-title":"Comput. Law Secur. Rev."},{"issue":"10","key":"2_CR4","doi-asserted-by":"publisher","first-page":"2266","DOI":"10.1016\/j.comnet.2012.12.018","volume":"57","author":"R Roman","year":"2013","unstructured":"Roman, R., Zhou, J., Lopez, J.: On the features and challenges of security and privacy in distributed Internet of Things. Comput. Netw. 57(10), 2266\u20132279 (2013)","journal-title":"Comput. Netw."},{"key":"2_CR5","doi-asserted-by":"crossref","unstructured":"Abomhara, M. K\u00f8ien, G.M.: Security and privacy in the Internet of Things: current status and open issues. In: 2014 International Conference on Privacy and Security in Mobile Systems (PRISMS), pp. 1\u20138. IEEE, May 2014","DOI":"10.1109\/PRISMS.2014.6970594"},{"key":"2_CR6","unstructured":"Chang, S.I., Huang, A., Chang, L.M., Liao, J.C.: Risk factors of enterprise internal control: Governance refers to Internet of Things (IoT) environment, RISK (2016)"},{"issue":"2","key":"2_CR7","doi-asserted-by":"publisher","first-page":"1537","DOI":"10.1109\/TII.2014.2300338","volume":"10","author":"Z Bi","year":"2014","unstructured":"Bi, Z., Da Xu, L., Wang, C.: Internet of Things for enterprise systems of modern manufacturing. IEEE Trans. Ind. Inf. 10(2), 1537\u20131546 (2014)","journal-title":"IEEE Trans. Ind. Inf."},{"issue":"5","key":"2_CR8","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1109\/MITP.2017.3680959","volume":"19","author":"JR Nurse","year":"2017","unstructured":"Nurse, J.R., Creese, S., De Roure, D.: Security risk assessment in Internet of Things systems. IT Prof. 19(5), 20\u201326 (2017)","journal-title":"IT Prof."},{"key":"2_CR9","unstructured":"NIST: IoT security and privacy risk considerations (2017). \n                      https:\/\/www.nist.gov\/sites\/default\/files\/documents\/2017\/12\/20\/nist_iot_security_and_privacy_risk_considerations_discussion_draft.pdf\n                      \n                    . Accessed 10 Mar 2019"},{"key":"2_CR10","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1016\/j.ijcip.2017.04.001","volume":"19","author":"I Stine","year":"2017","unstructured":"Stine, I., Rice, M., Dunlap, S., Pecarina, J.: A cyber risk scoring system for medical devices. Int. J. Crit. Infrastruct. Prot. 19, 32\u201346 (2017)","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"issue":"3","key":"2_CR11","first-page":"57","volume":"14","author":"LA Watkins","year":"2015","unstructured":"Watkins, L.A., Hurley, J.S.: Cyber maturity as measured by scientific-based risk metrics. J. Inf. Warfare 14(3), 57\u201365 (2015)","journal-title":"J. Inf. Warfare"},{"key":"2_CR12","unstructured":"Rapid7: Nexpose, a weighted model for risk calculation (2018). \n                      https:\/\/help.rapid7.com\/nexpose\/en-us\/Files\/Risk_scoring_FAQ.html\n                      \n                    . Accessed 10 Mar 2019"},{"key":"2_CR13","doi-asserted-by":"crossref","unstructured":"Mohajerani, Z., et al.: Cyber-related risk assessment and critical asset identification within the power grid. In: IEEE PES on Transmission and Distribution Conference and Exposition (2010)","DOI":"10.1109\/TDC.2010.5484417"},{"key":"2_CR14","doi-asserted-by":"crossref","unstructured":"Abie, H., Balasingham, I.: Risk-based adaptive security for smart IoT in eHealth. In: Proceedings of the 7th International Conference on Body Area Networks, pp. 269\u2013275. Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering (2012)","DOI":"10.4108\/icst.bodynets.2012.250235"},{"key":"2_CR15","doi-asserted-by":"publisher","first-page":"719","DOI":"10.1016\/j.future.2015.09.003","volume":"56","author":"A Jacobsson","year":"2016","unstructured":"Jacobsson, A., Boldt, M., Carlsson, B.: A risk analysis of a smart home automation system. Future Gener. Comput. Syst. 56, 719\u2013733 (2016)","journal-title":"Future Gener. Comput. Syst."},{"key":"2_CR16","doi-asserted-by":"crossref","unstructured":"Rahmati, A., Fernandes, E., Eykholt, K., Prakash, A.: Tyche: a risk-based permission model for smart homes. In: 2018 IEEE Cybersecurity Development (SecDev), pp. 29\u201336. IEEE, September 2018","DOI":"10.1109\/SecDev.2018.00012"},{"key":"2_CR17","unstructured":"NIST: NVD vulnerability metrics and severity ratings for CVSS v3.0 (2019). \n                      https:\/\/nvd.nist.gov\/vuln-metrics\/cvss\n                      \n                    . Accessed 10 Mar 2019"},{"key":"2_CR18","unstructured":"Tenable: Nessus vulnerability scanner tool for network security (2018). \n                      https:\/\/www.tenable.com\/products\/nessus-home\n                      \n                    . Accessed 10 Mar 2019"},{"key":"2_CR19","unstructured":"Kdnuggets: Removing outliers using standard deviation in Python (2017). \n                      https:\/\/www.kdnuggets.com\/2017\/02\/removing-outliers-standard-deviation-python.html\n                      \n                    . Accessed 10 Mar 2019"},{"issue":"4","key":"2_CR20","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1145\/2981546","volume":"16","author":"S Siboni","year":"2016","unstructured":"Siboni, S., Shabtai, A., Tippenhauer, N.O., Lee, J., Elovici, Y.: Advanced security testbed framework for wearable IoT devices. ACM Trans. Internet Technol. (TOIT) 16(4), 26 (2016)","journal-title":"ACM Trans. Internet Technol. (TOIT)"},{"issue":"1","key":"2_CR21","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1109\/TR.2018.2864536","volume":"68","author":"S Siboni","year":"2018","unstructured":"Siboni, S., et al.: Security testbed for Internet-of-Things Devices. IEEE Trans. Reliab. 68(1), 23\u201344 (2018)","journal-title":"IEEE Trans. Reliab."}],"container-title":["Lecture Notes in Computer Science","Security, Privacy, and Anonymity in Computation, Communication, and Storage"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-24900-7_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,7,10]],"date-time":"2019-07-10T04:20:23Z","timestamp":1562732423000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-24900-7_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030248994","9783030249007"],"references-count":21,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-24900-7_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"11 July 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SpaCCS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security, Privacy and Anonymity in Computation, Communication and Storage","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Atlanta, GA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 July 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 July 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"spaccs2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/cse.stfx.ca\/~cybermatics\/2019\/spaccs\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}