{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,22]],"date-time":"2025-10-22T10:45:57Z","timestamp":1761129957815,"version":"3.40.3"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030900182"},{"type":"electronic","value":"9783030900199"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-90019-9_4","type":"book-chapter","created":{"date-parts":[[2021,11,2]],"date-time":"2021-11-02T18:47:48Z","timestamp":1635878868000},"page":"62-81","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Towards Automated Assessment of Vulnerability Exposures in Security Operations"],"prefix":"10.1007","author":[{"given":"Philip","family":"Huff","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qinghua","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,11,3]]},"reference":[{"key":"4_CR1","unstructured":"Common product enumeration standard. https:\/\/nvd.nist.gov\/products\/cpe. Accessed 28 Jan 2020"},{"key":"4_CR2","unstructured":"Common vulnerability scoring system specification. https:\/\/www.first.org\/cvss\/v3.1\/specification-document. Accessed 28 Jan 2020"},{"key":"4_CR3","unstructured":"Common vulnerability scoring system v3.1: Specification document. https:\/\/www.first.org\/cvss\/v3.1\/specification-document. Accessed 1 Feb 2020"},{"key":"4_CR4","unstructured":"Common weakness enumeration. https:\/\/cwe.mitre.org\/. Accessed 28 Jan 2020"},{"key":"4_CR5","unstructured":"National vulnerability database data feed. https:\/\/nvd.nist.gov\/general\/visualizations\/vulnerability-visualizations\/cvss-severity-distribution-over-time. Accessed 1 Feb 2020"},{"key":"4_CR6","unstructured":"National vulnerability database data feed. https:\/\/nvd.nist.gov\/vuln\/data-feeds. Accessed 28 Jan 2020"},{"key":"4_CR7","unstructured":"North American electric reliability corporation (NERC) critical infrastructure protection (CIP) standards. https:\/\/www.nerc.com\/pa\/Stand\/Pages\/CIPStandards.aspx. Accessed 1 Feb 2020"},{"key":"4_CR8","unstructured":"Spacy and prodigy network language processing tools. https:\/\/explosion.ai\/. Accessed 2 Feb 2020"},{"key":"4_CR9","unstructured":"Vulnerability and patch management resources. http:\/\/cybersecurity.ddns.uark.edu\/vpm\/. Accessed 25 June 2021"},{"key":"4_CR10","unstructured":"Stix version 2.1, March 2020. https:\/\/docs.oasis-open.org\/cti\/stix\/v2.1\/cs01\/stix-v2.1-cs01.html. Accessed 9 Mar 2021"},{"key":"4_CR11","doi-asserted-by":"crossref","unstructured":"Ammann, P., Wijesekera, D., Kaushik, S.: Scalable, graph-based network vulnerability analysis. In: ACM Conference on Computer and Communications Security, pp. 217\u2013224 (2002)","DOI":"10.1145\/586110.586140"},{"key":"4_CR12","doi-asserted-by":"crossref","unstructured":"Audinot, M., Pinchinat, S., Kordy, B.: Guided design of attack trees: a system-based approach. In: 2018 IEEE 31st Computer Security Foundations Symposium (CSF), pp. 61\u201375, July 2018","DOI":"10.1109\/CSF.2018.00012"},{"key":"4_CR13","unstructured":"Collins, K.: The hackers who broke into Equifax exploited a flaw in open-source server software. Quartz. https:\/\/qz.com\/1073221\/the-hackers-who-broke-into-equifax-exploited-a-nine-year-old-security-flaw\/"},{"issue":"ARTICLE","key":"4_CR14","first-page":"2493","volume":"12","author":"R Collobert","year":"2011","unstructured":"Collobert, R., Weston, J., Bottou, L., Karlen, M., Kavukcuoglu, K., Kuksa, P.: Natural language processing (almost) from scratch. J. Mach. Learn. Res. 12(ARTICLE), 2493\u20132537 (2011)","journal-title":"J. Mach. Learn. Res."},{"key":"4_CR15","doi-asserted-by":"crossref","unstructured":"Fila, B., Wide, W.: Efficient attack-defense tree analysis using pareto attribute domains. In: 2019 IEEE 32nd Computer Security Foundations Symposium (CSF), June 2019","DOI":"10.1109\/CSF.2019.00021"},{"key":"4_CR16","doi-asserted-by":"crossref","unstructured":"Gamarra, M., Shetty, S., Nicol, D.M., Gonzalez, O., Kamhoua, C.A., Njilla, L.: Analysis of stepping stone attacks in dynamic vulnerability graphs, pp. 1\u20137, May 2018","DOI":"10.1109\/ICC.2018.8422723"},{"key":"4_CR17","doi-asserted-by":"crossref","unstructured":"Ghosh, N., Ghosh, S.K.: An approach for security assessment of network configurations using attack graph. In: International Conference on Networks & Communications, pp. 283\u2013288 (2010)","DOI":"10.1109\/NetCoM.2009.83"},{"key":"4_CR18","doi-asserted-by":"crossref","unstructured":"Huff, P., Li, Q.: A recommender system for tracking vulnerabilities. In: International Workshop on Next Generation Security Operations Centers (NG-SOC) (2021)","DOI":"10.1145\/3465481.3470039"},{"key":"4_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1007\/978-3-642-19751-2_6","volume-title":"Formal Aspects of Security and Trust","author":"B Kordy","year":"2011","unstructured":"Kordy, B., Mauw, S., Radomirovi\u0107, S., Schweitzer, P.: Foundations of attack\u2013defense trees. In: Degano, P., Etalle, S., Guttman, J. (eds.) FAST 2010. LNCS, vol. 6561, pp. 80\u201395. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-19751-2_6"},{"issue":"3","key":"4_CR20","doi-asserted-by":"publisher","first-page":"247","DOI":"10.1145\/356850.356852","volume":"13","author":"CE Landwehr","year":"1981","unstructured":"Landwehr, C.E.: Formal models for computer security. ACM Comput. Surv. (CSUR) 13(3), 247\u2013278 (1981)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"4_CR21","doi-asserted-by":"crossref","unstructured":"Le, H.T., Loh, P.K.K.: Using natural language tool to assist VPRG automated extraction from textual vulnerability description. In: 2011 IEEE Workshops of International Conference on Advanced Information Networking and Applications, March 2011","DOI":"10.1109\/WAINA.2011.56"},{"key":"4_CR22","doi-asserted-by":"crossref","unstructured":"Le, T.H.M., Sabir, B., Babar, M.A.: Automated software vulnerability assessment with concept drift. In: 2019 IEEE\/ACM 16th International Conference on Mining Software Repositories (MSR), pp. 371\u2013382 (2019)","DOI":"10.1109\/MSR.2019.00063"},{"key":"4_CR23","doi-asserted-by":"crossref","unstructured":"Mantel, H., Probst, C.W.: On the meaning and purpose of attack trees. In: 2019 IEEE 32nd Computer Security Foundations Symposium (CSF), pp. 184\u201318415, June 2019","DOI":"10.1109\/CSF.2019.00020"},{"key":"4_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"186","DOI":"10.1007\/11734727_17","volume-title":"Information Security and Cryptology - ICISC 2005","author":"S Mauw","year":"2006","unstructured":"Mauw, S., Oostdijk, M.: Foundations of attack trees. In: Won, D.H., Kim, S. (eds.) ICISC 2005. LNCS, vol. 3935, pp. 186\u2013198. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11734727_17"},{"key":"4_CR25","doi-asserted-by":"crossref","unstructured":"McClanahan, K., Li, Q.: Automatically locating mitigation information for security vulnerabilities. In: IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm) (2020)","DOI":"10.1109\/SmartGridComm47815.2020.9303019"},{"key":"4_CR26","doi-asserted-by":"crossref","unstructured":"Noel, S., Jajodia, S.: Metrics suite for network attack graph analytics. In: Proceedings of the 9th Annual Cyber and Information Security Research Conference, pp. 5\u20138 (2014)","DOI":"10.1145\/2602087.2602117"},{"key":"4_CR27","doi-asserted-by":"crossref","unstructured":"Phillips, C., Swiler, L.P.: A graph-based system for network-vulnerability analysis. In: Proceedings of the 1998 Workshop on New security paradigms, pp. 71\u201379 (1998)","DOI":"10.1145\/310889.310919"},{"issue":"12","key":"4_CR28","first-page":"21","volume":"24","author":"B Schneier","year":"1999","unstructured":"Schneier, B.: Attack trees. Dr. Dobb\u2019s J. 24(12), 21\u201329 (1999)","journal-title":"Dr. Dobb\u2019s J."},{"key":"4_CR29","series-title":"Intelligent Systems Reference Library","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-319-98842-9_1","volume-title":"AI in Cybersecurity","author":"LF Sikos","year":"2019","unstructured":"Sikos, L.F.: OWL ontologies in cybersecurity: conceptual modeling of cyber-knowledge. In: Sikos, L.F. (ed.) AI in Cybersecurity. ISRL, vol. 151, pp. 1\u201317. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-319-98842-9_1"},{"key":"4_CR30","unstructured":"Syed, Z., Padia, A., Finin, T., Mathews, L., Joshi, A.: UCO: a unified cybersecurity ontology. In: UMBC Student Collection (2016)"},{"key":"4_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"573","DOI":"10.1007\/978-3-642-15497-3_35","volume-title":"Computer Security \u2013 ESORICS 2010","author":"L Wang","year":"2010","unstructured":"Wang, L., Jajodia, S., Singhal, A., Noel, S.: k-zero day safety: measuring the security risk of networks against unknown attacks. In: Gritzalis, D., Preneel, B., Theoharidou, M. (eds.) ESORICS 2010. LNCS, vol. 6345, pp. 573\u2013587. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-15497-3_35"},{"key":"4_CR32","doi-asserted-by":"crossref","unstructured":"Wang, P., Zhou, Y., Sun, B., Zhang, W.: Intelligent prediction of vulnerability severity level based on text mining and XGBboost. In: 2019 Eleventh International Conference on Advanced Computational Intelligence (ICACI), pp. 72\u201377 (2019)","DOI":"10.1109\/ICACI.2019.8778469"},{"key":"4_CR33","doi-asserted-by":"crossref","unstructured":"Wing, J.M., et al.: Scenario graphs applied to network security. In: Information Assurance: Survivability and Security in Networked Systems, pp. 247\u2013277 (2008)","DOI":"10.1016\/B978-012373566-9.50011-2"},{"key":"4_CR34","doi-asserted-by":"crossref","unstructured":"Xie, A., Wen, W., Zhang, L., Hu, J., Chen, Z.: Applying attack graphs to network security metric. In: Proceedings of the 2009 International Conference on Multimedia Information Networking and Security, vol. 01, pp. 427\u2013431 (2009)","DOI":"10.1109\/MINES.2009.136"},{"key":"4_CR35","doi-asserted-by":"crossref","unstructured":"Xu, M., et al.: Dominance as a new trusted computing primitive for the internet of things. In: 2019 IEEE Symposium on Security and Privacy (SP) (2019)","DOI":"10.1109\/SP.2019.00084"},{"key":"4_CR36","doi-asserted-by":"crossref","unstructured":"Zhang, F., Huff, P., McClanahan, K., Li, Q.: A machine learning-based approach for automated vulnerability remediation analysis. In: IEEE Conference on Communications and Network Security (CNS) (2020)","DOI":"10.1109\/CNS48642.2020.9162309"},{"key":"4_CR37","doi-asserted-by":"crossref","unstructured":"Zhang, F., Li, Q.: Dynamic risk-aware patch scheduling. In: IEEE Conference on Communications and Network Security (CNS) (2020)","DOI":"10.1109\/CNS48642.2020.9162225"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-90019-9_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,11,2]],"date-time":"2021-11-02T18:50:21Z","timestamp":1635879021000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-90019-9_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030900182","9783030900199"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-90019-9_4","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"3 November 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SecureComm","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security and Privacy in Communication Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 September 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 September 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"securecomm2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/securecomm.eai-conferences.org\/2021\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Confy +","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"143","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"56","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"39% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}