{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,25]],"date-time":"2025-09-25T16:53:39Z","timestamp":1758819219037,"version":"3.40.3"},"publisher-location":"Cham","reference-count":53,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783031254598"},{"type":"electronic","value":"9783031254604"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-25460-4_8","type":"book-chapter","created":{"date-parts":[[2023,2,17]],"date-time":"2023-02-17T09:12:22Z","timestamp":1676625142000},"page":"134-152","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["A Hybrid Dynamic Risk Analysis Methodology for\u00a0Cyber-Physical Systems"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4481-1000","authenticated-orcid":false,"given":"Christos","family":"Lyvas","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8823-018X","authenticated-orcid":false,"given":"Konstantinos","family":"Maliatsos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2469-5535","authenticated-orcid":false,"given":"Andreas","family":"Menegatos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3453-1892","authenticated-orcid":false,"given":"Thrasyvoulos","family":"Giannakopoulos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3101-5347","authenticated-orcid":false,"given":"Costas","family":"Lambrinoudakis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8844-2596","authenticated-orcid":false,"given":"Christos","family":"Kalloniatis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1966-4937","authenticated-orcid":false,"given":"Athanasios","family":"Kanatas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,2,18]]},"reference":[{"key":"8_CR1","unstructured":"The H2020 CitySCAPE Project. https:\/\/www.cityscape-project.eu"},{"key":"8_CR2","unstructured":"BSI-Standard 200\u20131. Information Security Management Systems (ISMS) (2018).https:\/\/www.bsi.bund.de\/EN\/Topics\/ITGrundschutz\/itgrundschutz_node.htm"},{"key":"8_CR3","unstructured":"BSI-Standard 200\u20132. IT-Grundschutz-Methodology (2018). https:\/\/www.bsi.bund.de\/EN\/Topics\/ITGrundschutz\/itgrundschutz_node.htm"},{"key":"8_CR4","unstructured":"BSI-Standard 200\u20133. Risk Analysis based on IT-Grundschutz (2018). https:\/\/www.bsi.bund.de\/EN\/Topics\/ITGrundschutz\/itgrundschutz_node.htm"},{"key":"8_CR5","unstructured":"ISO 31000:2018 Risk Management - Guidelines (2018). https:\/\/www.iso.org\/standard\/65694.html"},{"key":"8_CR6","unstructured":"ISO\/IEC 27000:2018 Information technology - Security techniques - Information security management systems - Overview and vocabulary (2018). https:\/\/www.iso.org\/standard\/73906.html"},{"key":"8_CR7","unstructured":"ISO\/IEC 27005:2018 Information Technology - Security Techniques - Information Security Risk Management (2018). https:\/\/www.iso.org\/standard\/75281.html"},{"key":"8_CR8","unstructured":"IT-Grundschutz-Compendium (2021). https:\/\/www.bsi.bund.de\/EN\/Topics\/ITGrundschutz\/itgrundschutz_node.htm"},{"key":"8_CR9","unstructured":"Common Attack Pattern Enumeration and Classification (2022). https:\/\/capec.mitre.org"},{"key":"8_CR10","unstructured":"Common Vulnerabilities and Exposures (2022). https:\/\/cve.mitre.org"},{"key":"8_CR11","unstructured":"Common Weakness Enumeration (2022). https:\/\/cwe.mitre.org"},{"key":"8_CR12","unstructured":"Threat Modeling (2022). https:\/\/www.microsoft.com\/en-us\/securityengineering\/sdl\/threatmodeling"},{"key":"8_CR13","unstructured":"Spanish Ministry of Finance & Public Administration. MAGERIT - versi\u00f3n 3.0.Metodolog\u00eda de An\u00e1lisis y Gesti\u00f3n de Riesgos de los Sistemas de Informaci\u00f3n. Libro II - Cat\u00e1logo de Elementos (2012)"},{"key":"8_CR14","unstructured":"Spanish Ministry of Finance & Public Administration. MAGERIT - versi\u00f3n 3.0.Metodolog\u00eda de An\u00e1lisis y Gesti\u00f3n de Riesgos de los Sistemas de Informaci\u00f3n. Libro III - Gu\u00eda de T\u00e9cnicas (2012)"},{"key":"8_CR15","unstructured":"Spanish Ministry of Finance & Public Administration. MAGERIT-version 3.0.Methodology for Information Systems Risk Analysis and Management. Book I - The Method (2014)"},{"key":"8_CR16","doi-asserted-by":"crossref","unstructured":"Alberts, C., Behrens, S., Pethia, R., Wilson, W.: Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) Framework, Version 1.0. Tech. Rep. CMU\/SEI-99-TR-017, Software Engineering Institute, Carnegie Mellon University, Pittsburgh, PA (1999)","DOI":"10.21236\/ADA367718"},{"key":"8_CR17","doi-asserted-by":"crossref","unstructured":"Alberts, C., Dorofee, A., Stevens, J., Woody, C.: Introduction to the OCTAVE Approach (2003)","DOI":"10.21236\/ADA634134"},{"key":"8_CR18","unstructured":"Alexander, O., Belisle, M., Steele, J.: MITRE ATT &CK\u00ae for Industrial Control Systems: Design and Philosophy (2020)"},{"key":"8_CR19","unstructured":"ANNSI. EBIOS Risk Manager (2019). https:\/\/www.ssi.gouv.fr\/uploads\/2019\/11\/anssi-guide-ebios_risk_manager-en-v1.0.pdf"},{"key":"8_CR20","unstructured":"ANSSI. Label EBIOS Risk Manager: Solutions Logicielles Conformes Ebios Risk Manager (2018). https:\/\/www.ssi.gouv.fr\/entreprise\/management-du-risque\/la-methode-ebios-risk-manager\/label-ebios-risk-manager-des-outils-pour-faciliter-le-management-du-risque-numerique"},{"issue":"2","key":"8_CR21","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1080\/10429247.2013.11431972","volume":"25","author":"R Bojanc","year":"2013","unstructured":"Bojanc, R., Jerman-Bla\u017ei\u010d, B.: A quantitative model for information-security risk management. Eng. Manag. J. 25(2), 25\u201337 (2013)","journal-title":"Eng. Manag. J."},{"key":"8_CR22","doi-asserted-by":"crossref","unstructured":"Caralli, R., Stevens, J., Young, L., Wilson, W.: Introducing OCTAVE Allegro: Improving the Information Security Risk Assessment Process. Tech. Rep. CMU\/SEI-2007-TR-012, Software Engineering Institute, Carnegie Mellon University, Pittsburgh, PA (2007). http:\/\/resources.sei.cmu.edu\/library\/asset-view.cfm?AssetID=8419","DOI":"10.21236\/ADA470450"},{"key":"8_CR23","unstructured":"CASES. Optimised risk analysis method (2016). https:\/\/www.cases.lu\/assets\/docs\/CASES_Monarc2016EN-web.pdf"},{"key":"8_CR24","unstructured":"CASES MONARC. Technical Guide (2021). https:\/\/www.monarc.lu\/documentation\/technical-guide\/"},{"key":"8_CR25","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cose.2015.09.009","volume":"56","author":"Y Cherdantseva","year":"2016","unstructured":"Cherdantseva, Y., Burnap, P., Blyth, A., Eden, P., Jones, K., Soulsby, H., Stoddart, K.: A review of cyber security risk assessment methods for SCADA systems. Comput. Secur. 56, 1\u201327 (2016)","journal-title":"Comput. Secur."},{"key":"8_CR26","unstructured":"ENISA. Magerit. https:\/\/www.enisa.europa.eu\/topics\/threat-risk-management\/risk-management\/current-risk\/risk-management-inventory\/rm-ra-methods\/m_magerit.html"},{"key":"8_CR27","unstructured":"ENISA. Cloud Computing Risk Assessment (2009). https:\/\/www.enisa.europa.eu\/publications\/cloud-computing-risk-assessment"},{"key":"8_CR28","unstructured":"ENISA.. Smartphones: information security risks, opportunities and recommendations for users (2010). https:\/\/www.enisa.europa.eu\/publications\/smartphones-information-security-risks-opportunities-and-recommendations-for-users"},{"key":"8_CR29","unstructured":"ENISA. Smart Grid Threat Landscape and Good Practice Guide (2013). https:\/\/www.enisa.europa.eu\/publications\/smart-grid-threat-landscape-and-good-practice-guide"},{"key":"8_CR30","unstructured":"ENISA. Baseline Security Recommendations for IoT (2017). https:\/\/www.enisa.europa.eu\/publications\/baseline-security-recommendations-for-iot"},{"key":"8_CR31","unstructured":"ENISA. ENISA good practices for security of Smart Cars (2019). https:\/\/www.enisa.europa.eu\/publications\/smart-cars"},{"key":"8_CR32","unstructured":"ENISA. Port Cybersecurity - Good practices for cybersecurity in the maritime sector (2019). https:\/\/www.enisa.europa.eu\/publications\/port-cybersecurity-good-practices-for-cybersecurity-in-the-maritime-sector"},{"key":"8_CR33","unstructured":"ENISA. ENISA Threat Landscape for 5G Networks Report (2020). https:\/\/www.enisa.europa.eu\/publications\/enisa-threat-landscape-report-for-5g-networks"},{"key":"8_CR34","unstructured":"ENISA. Interoperable EU Risk Management Framework (2022). https:\/\/www.enisa.europa.eu\/publications\/interoperable-eu-risk-management-framework"},{"key":"8_CR35","unstructured":"ETSI. Telecommunications and internet converged services and protocols for advanced networking (tispan); methods and protocols; part 1: Method and proforma for threat, risk, vulnerability analysis (2011)"},{"key":"8_CR36","unstructured":"EUR-LEX. Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC (General Data Protection Regulation. https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX"},{"key":"8_CR37","unstructured":"Hamad, M., Nolte, M., Prevelakis, V.: Towards comprehensive threat modeling for vehicles. In: The 1st Workshop on Security and Dependability of Critical Embedded Real-Time Systems, p. 31 (2016)"},{"key":"8_CR38","unstructured":"Hernan, S., Lambert, S., Ostwald, T., Shostack, A.: Uncover security design flaws using the STRIDE approach (2006). https:\/\/docs.microsoft.com\/en-us\/archive\/msdn-magazine\/2006\/november\/uncover-security-design-flaws-using-the-stride-approach"},{"key":"8_CR39","doi-asserted-by":"publisher","DOI":"10.1016\/j.compind.2022.103611","volume":"137","author":"M Jbair","year":"2022","unstructured":"Jbair, M., Ahmad, B., Maple, C., Harrison, R.: Threat modelling for industrial cyber physical systems in the era of smart manufacturing. Comput. Indust. 137, 103611 (2022)","journal-title":"Comput. Indust."},{"key":"8_CR40","unstructured":"Mataracioglu, T.: Comparison of PCI DSS and ISO\/IEC 27001 Standards. ISACA 1 (2016). https:\/\/www.isaca.org\/resources\/isaca-journal\/issues\/2016\/volume-1\/comparison-of-pci-dss-and-isoiec-27001-standards#f1"},{"key":"8_CR41","unstructured":"NIST. Security and Privacy Controls for Information Systems and Organizations. Tech. rep. (2020). https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-53r5.pdf"},{"issue":"2","key":"8_CR42","first-page":"546","volume":"16","author":"J Petit","year":"2015","unstructured":"Petit, J., Shladover, S.E.: Potential cyberattacks on automated vehicles. IEEE Trans. Intell. Transp. Syst. 16(2), 546\u2013556 (2015)","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"8_CR43","doi-asserted-by":"crossref","unstructured":"Scarfone, K., Mell, P.: An analysis of CVSS version 2 vulnerability scoring. In: 2009 3rd International Symposium on Empirical Software Engineering and Measurement, pp. 516\u2013525. IEEE (2009)","DOI":"10.1109\/ESEM.2009.5314220"},{"key":"8_CR44","doi-asserted-by":"crossref","unstructured":"Semertzis, I., Rajkumar, V.S., \u015etefanov, A., Fransen, F., Palensky, P.: Quantitative risk assessment of cyber attacks on cyber-physical systems using attack graphs, pp. 1\u20136 (2022)","DOI":"10.1109\/MSCPES55116.2022.9770140"},{"key":"8_CR45","doi-asserted-by":"crossref","unstructured":"Stefan Sacala, I., Pop, E., Alexandru Moisescu, M., Dumitrache, I., Iuliana Caramihai, S., Culita, J.: Enhancing cps architectures with SOA for industry 4.0 enterprise systems. In: 2021 29th Mediterranean Conference on Control and Automation (MED), pp. 71\u201376 (2021)","DOI":"10.1109\/MED51440.2021.9480184"},{"key":"8_CR46","unstructured":"Tucker, B.: Advancing Risk Management Capability Using the OCTAVE FORTE Process. Tech. rep., Software Engineering Institute, Carnegie Mellon University, Pittsburgh, PA (2020). http:\/\/resources.sei.cmu.edu\/library\/asset-view.cfm?AssetID=644636"},{"key":"8_CR47","doi-asserted-by":"crossref","unstructured":"UcedaV\u00e9lez, T., Morana, M.M.: Risk Centric Threat Modeling: Process for attack simulation and threat analysis. Wiley (2015). https:\/\/www.wiley.com\/en-us\/Risk+Centric+Threat+Modeling%3A+Process+for+Attack+Simulation+and+Threat+Analysis-p-9780470500965","DOI":"10.1002\/9781118988374"},{"key":"8_CR48","first-page":"6741","volume":"12","author":"R Vega","year":"2017","unstructured":"Vega, R., Arroyo, R., Yoo, S.G.: Experience in applying the analysis and risk management methodology called Magerit to identify threats and vulnerabilities in an agro-industrial company. Int. J. Appl. Eng. Res. 12, 6741\u20136750 (2017)","journal-title":"Int. J. Appl. Eng. Res."},{"key":"8_CR49","first-page":"1195","volume":"2020","author":"A Wolf","year":"2021","unstructured":"Wolf, A., Simopoulos, D., D\u2019Avino, L., Schwaiger, P.: The PASTA threat model implementation in the IoT development life cycle. INFORMATIK 2020, 1195\u20131204 (2021)","journal-title":"INFORMATIK"},{"key":"8_CR50","unstructured":"Wuyts, K., Joosen, W.: Linddun privacy threat modeling: A tutorial (2015). https:\/\/lirias.kuleuven.be\/retrieve\/331950"},{"key":"8_CR51","doi-asserted-by":"crossref","unstructured":"Wuyts, K., Van Landuyt, D., Hovsepyan, A., Joosen, W.: Effective and efficient privacy threat modeling through domain refinements. In: Proceedings of the 33rd Annual ACM Symposium on Applied Computing (SAC \u201918), pp. 1175\u20131178. Association for Computing Machinery, New York (2018)","DOI":"10.1145\/3167132.3167414"},{"key":"8_CR52","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1016\/j.cose.2019.03.010","volume":"84","author":"W Xiong","year":"2019","unstructured":"Xiong, W., Lagerstr\u00f6m, R.: Threat modeling - A systematic literature review. Comput. Secur. 84, 53\u201369 (2019)","journal-title":"Comput. Secur."},{"key":"8_CR53","doi-asserted-by":"crossref","unstructured":"Zeddini, B., Maachaoui, M., Inedjaren, Y.: Security threats in intelligent transportation systems and their risk levels. Risks 10(5) (2022)","DOI":"10.3390\/risks10050091"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2022 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-25460-4_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,2,5]],"date-time":"2024-02-05T18:06:52Z","timestamp":1707156412000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-25460-4_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031254598","9783031254604"],"references-count":53,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-25460-4_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"18 February 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Copenhagen","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Denmark","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 September 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2022.compute.dtu.dk\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"80","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"38","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"48% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1.7","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}