{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T05:57:29Z","timestamp":1743055049578,"version":"3.40.3"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783031254598"},{"type":"electronic","value":"9783031254604"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-25460-4_35","type":"book-chapter","created":{"date-parts":[[2023,2,17]],"date-time":"2023-02-17T09:12:22Z","timestamp":1676625142000},"page":"605-624","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["SAEOn: An Ontological Metamodel for Quantitative Security Assurance Evaluation"],"prefix":"10.1007","author":[{"given":"Shao-Fang","family":"Wen","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Basel","family":"Katt","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,2,18]]},"reference":[{"issue":"5","key":"35_CR1","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1109\/MS.2003.1231149","volume":"20","author":"C Atkinson","year":"2003","unstructured":"Atkinson, C., Kuhne, T.: Model-driven development: a metamodeling foundation. IEEE Softw. 20(5), 36\u201341 (2003)","journal-title":"IEEE Softw."},{"issue":"5","key":"35_CR2","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1038\/scientificamerican0501-34","volume":"284","author":"T Berners-Lee","year":"2001","unstructured":"Berners-Lee, T., Hendler, J., Lassila, O.: The semantic web. Sci. Am. 284(5), 28\u201337 (2001)","journal-title":"Sci. Am."},{"key":"35_CR3","series-title":"IFIP International Federation for Information Processing","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1007\/978-0-387-72367-9_8","volume-title":"New Approaches for Security, Privacy and Trust in Complex Environments","author":"A Ekclhart","year":"2007","unstructured":"Ekclhart, A., Fenz, S., Goluch, G., Weippl, E.: Ontological mapping of common criteria\u2019s security assurance requirements. In: Venter, H., Eloff, M., Labuschagne, L., Eloff, J., von Solms, R. (eds.) SEC 2007. IIFIP, vol. 232, pp. 85\u201395. Springer, Boston, MA (2007). https:\/\/doi.org\/10.1007\/978-0-387-72367-9_8"},{"key":"35_CR4","doi-asserted-by":"crossref","unstructured":"Fenz, S., Ekelhart, A.: Formalizing information security knowledge. In: Proceedings of the 4th International Symposium on Information, Computer, and Communications Security. ACM (2009)","DOI":"10.1145\/1533057.1533084"},{"key":"35_CR5","series-title":"Advances in Intelligent Systems and Computing","doi-asserted-by":"publisher","first-page":"75","DOI":"10.1007\/978-3-319-77028-4_12","volume-title":"Information Technology \u2013 New Generations","author":"F de Franco Rosa","year":"2018","unstructured":"de Franco Rosa, F., Jino, M., Bonacin, R.: Towards an ontology of security assessment: a core model proposal. In: Latifi, S. (ed.) Information Technology \u2013 New Generations. AISC, vol. 738, pp. 75\u201380. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-77028-4_12"},{"issue":"5","key":"35_CR6","doi-asserted-by":"publisher","first-page":"554","DOI":"10.1007\/s12204-013-1439-5","volume":"18","author":"J-B Gao","year":"2013","unstructured":"Gao, J.-B., et al.: Ontology-based model of network and computer attacks for security assessment. J. Shanghai Jiaotong Univ. (Sci.) 18(5), 554\u2013562 (2013)","journal-title":"J. Shanghai Jiaotong Univ. (Sci.)"},{"key":"35_CR7","doi-asserted-by":"crossref","unstructured":"Gonzalez-Gil, P., Skarmeta, A.F., Martinez, J.A.: Towards an ontology for IoT context-based security evaluation. In: 2019 Global IoT Summit (GIoTS). IEEE (2019)","DOI":"10.1109\/GIOTS.2019.8766400"},{"issue":"2","key":"35_CR8","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1006\/knac.1993.1008","volume":"5","author":"TR Gruber","year":"1993","unstructured":"Gruber, T.R.: A translation approach to portable ontology specifications. Knowl. Acquisition 5(2), 199\u2013220 (1993)","journal-title":"Knowl. Acquisition"},{"key":"35_CR9","doi-asserted-by":"crossref","unstructured":"Heitlager, I., Kuipers, T., Visser, J.: A practical model for measuring maintainability. In: 6th International Conference on the Quality of Information and Communications Technology (QUATIC 2007). IEEE (2007)","DOI":"10.1109\/QUATIC.2007.8"},{"key":"35_CR10","doi-asserted-by":"publisher","DOI":"10.1201\/9781420031423","volume-title":"Using the Common Criteria for IT Security Evaluation","author":"DS Herrmann","year":"2002","unstructured":"Herrmann, D.S.: Using the Common Criteria for IT Security Evaluation. Auerbach Publications, Boca Raton (2002)"},{"key":"35_CR11","unstructured":"Hlomani, H., Stacey, D.J.S.W.J.: Approaches, methods, metrics, measures, and subjectivity in ontology evaluation: a survey. Semant. Web J. 1(5), 1\u201311 (2014)"},{"key":"35_CR12","unstructured":"Horrocks, I., et al.: SWRL: a semantic web rule language combining OWL and RuleML. W3C Member Submission 21(79), 1\u201331 (2004)"},{"issue":"1","key":"35_CR13","first-page":"1793","volume":"3","author":"T Jayalakshmi","year":"2011","unstructured":"Jayalakshmi, T., Santhakumaran, A.: Statistical normalization and back propagation for classification. Int. J. Comput. Theory Eng. 3(1), 1793\u20138201 (2011)","journal-title":"Int. J. Comput. Theory Eng."},{"key":"35_CR14","doi-asserted-by":"crossref","unstructured":"Katt, B., Prasher, N.: Quantitative security assurance metrics: REST API case studies. In: Proceedings of the 12th European Conference on Software Architecture: Companion Proceedings (2018)","DOI":"10.1145\/3241403.3241464"},{"key":"35_CR15","doi-asserted-by":"crossref","unstructured":"Katt, B., Prasher, N.: Quantitative security assurance. In: Exploring Security in Software Architecture and Design, pp. 15\u201346. IGI Global (2019)","DOI":"10.4018\/978-1-5225-6313-6.ch002"},{"key":"35_CR16","doi-asserted-by":"crossref","unstructured":"Koinig, U., Tjoa, S., Ryoo, J.: Contrology-an ontology-based cloud assurance approach. In: 2015 IEEE 24th International Conference on Enabling Technologies: Infrastructure for Collaborative Enterprises. IEEE (2015)","DOI":"10.1109\/WETICE.2015.43"},{"key":"35_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"974","DOI":"10.1007\/11574620_69","volume-title":"The Semantic Web \u2013 ISWC 2005","author":"M O\u2019Connor","year":"2005","unstructured":"O\u2019Connor, M., et al.: Supporting rule system interoperability on the semantic web with SWRL. In: Gil, Y., Motta, E., Benjamins, V.R., Musen, M.A. (eds.) ISWC 2005. LNCS, vol. 3729, pp. 974\u2013986. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11574620_69"},{"issue":"1","key":"35_CR18","doi-asserted-by":"publisher","first-page":"193","DOI":"10.1016\/j.jss.2011.08.013","volume":"85","author":"M Ouedraogo","year":"2012","unstructured":"Ouedraogo, M., et al.: Appraisal and reporting of security assurance at operational systems level. J. Syst. Softw. 85(1), 193\u2013208 (2012)","journal-title":"J. Syst. Softw."},{"key":"35_CR19","unstructured":"OWASP: OWASP Web Security Testing Guide. https:\/\/owasp.org\/www-project-web-security-testing-guide\/. Accessed 26 Jan 2022"},{"key":"35_CR20","doi-asserted-by":"crossref","unstructured":"Powley, S., et al.: An evaluation ontology applied to connected vehicle security assurance. In: INCOSE International Symposium. Wiley Online Library (2019)","DOI":"10.1002\/j.2334-5837.2019.00588.x"},{"key":"35_CR21","doi-asserted-by":"crossref","unstructured":"Raad, J., Cruz, C.: A survey on ontology evaluation methods. In: Proceedings of the International Conference on Knowledge Engineering and Ontology Development, part of the 7th International Joint Conference on Knowledge Discovery, Knowledge Engineering and Knowledge Management (2015)","DOI":"10.5220\/0005591001790186"},{"key":"35_CR22","doi-asserted-by":"crossref","unstructured":"Raskin, V., et al.: Ontology in information security: a useful theoretical foundation and methodological tool. In: Proceedings of the 2001 Workshop on New Security Paradigms (2001)","DOI":"10.1145\/508171.508180"},{"key":"35_CR23","unstructured":"Ross, R.S.: Managing information security risk: organization, mission, and information system view (2011)"},{"issue":"1","key":"35_CR24","first-page":"83","volume":"1","author":"TL Saaty","year":"2008","unstructured":"Saaty, T.L.: Decision making with the analytic hierarchy process. Int. J. Serv. Sci. 1(1), 83\u201398 (2008)","journal-title":"Int. J. Serv. Sci."},{"key":"35_CR25","unstructured":"Shukla, A., et al.: System security assurance: a systematic literature review. arXiv preprint arXiv:2110.01904 (2021)"},{"issue":"1","key":"35_CR26","doi-asserted-by":"publisher","first-page":"89","DOI":"10.3233\/SW-2012-0057","volume":"4","author":"T Tudorache","year":"2013","unstructured":"Tudorache, T., et al.: WebProt\u00e9g\u00e9: a collaborative ontology editor and knowledge acquisition tool for the web. Semant. Web 4(1), 89\u201399 (2013)","journal-title":"Semant. Web"},{"key":"35_CR27","unstructured":"W3C: RDF 1.1 XML Syntax. https:\/\/www.w3.org\/TR\/rdf-syntax-grammar\/. Accessed 26 Jan 2022"},{"key":"35_CR28","unstructured":"W3C: SPARQL 1.1 Query Language. https:\/\/www.w3.org\/TR\/sparql11-query\/. Accessed 27 Jan 2022"},{"issue":"4","key":"35_CR29","doi-asserted-by":"publisher","first-page":"494","DOI":"10.1145\/331983.331989","volume":"24","author":"Y Wand","year":"1999","unstructured":"Wand, Y., Storey, V.C., Weber, R.: An ontological analysis of the relationship construct in conceptual modeling. ACM Trans. Database Syst. (TODS) 24(4), 494\u2013528 (1999)","journal-title":"ACM Trans. Database Syst. (TODS)"},{"key":"35_CR30","doi-asserted-by":"crossref","unstructured":"Wang, J.A., Guo, M.: OVM: an ontology for vulnerability management. In: Proceedings of the 5th Annual Workshop on Cyber Security and Information Intelligence Research: Cyber Security and Information Intelligence Challenges and Strategies (2009)","DOI":"10.1145\/1558607.1558646"},{"key":"35_CR31","doi-asserted-by":"crossref","unstructured":"Wang, J.A., et al.: Ontology-based security assessment for software products. In: Proceedings of the 5th Annual Workshop on Cyber Security and Information Intelligence Research: Cyber Security and Information Intelligence Challenges and Strategies (2009)","DOI":"10.1145\/1558607.1558625"},{"issue":"3","key":"35_CR32","doi-asserted-by":"publisher","first-page":"587","DOI":"10.3390\/jcp2030030","volume":"2","author":"S-F Wen","year":"2022","unstructured":"Wen, S.-F., Shukla, A., Katt, B.: Developing security assurance metrics to support quantitative security assurance evaluation. J. Cybersecur. Priv. 2(3), 587\u2013605 (2022)","journal-title":"J. Cybersecur. Priv."},{"key":"35_CR33","doi-asserted-by":"crossref","unstructured":"Yavagal, D.S., et al.: Common criteria requirements modeling and its uses for quality of information assurance (QoIA). In: Proceedings of the 43rd Annual Southeast Regional Conference, vol. 2 (2005)","DOI":"10.1145\/1167253.1167287"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2022 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-25460-4_35","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,2,5]],"date-time":"2024-02-05T18:09:48Z","timestamp":1707156588000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-25460-4_35"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031254598","9783031254604"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-25460-4_35","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"18 February 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Copenhagen","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Denmark","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 September 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2022.compute.dtu.dk\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"80","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"38","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"48% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1.7","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}