{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T08:21:30Z","timestamp":1772785290542,"version":"3.50.1"},"publisher-location":"Cham","reference-count":26,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783031284502","type":"print"},{"value":"9783031284519","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-28451-9_15","type":"book-chapter","created":{"date-parts":[[2023,3,14]],"date-time":"2023-03-14T15:03:50Z","timestamp":1678806230000},"page":"171-182","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["A Vulnerability Risk Assessment Methodology Using Active Learning"],"prefix":"10.1007","author":[{"given":"Francisco R. P.","family":"da Ponte","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Emanuel B.","family":"Rodrigues","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"C\u00e9sar L. C.","family":"Mattos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,3,15]]},"reference":[{"key":"15_CR1","doi-asserted-by":"crossref","unstructured":"Afaq, S.A., Husain, M.S., Bello, A., Sadia, H.: A critical analysis of cyber threats and their global impact. In: Computational Intelligent Security in Wireless Communications, pp. 201\u2013220. CRC Press (2022)","DOI":"10.1201\/9781003323426-12"},{"key":"15_CR2","unstructured":"Spring, J., Hatleback, E., Manion, A., Shic, D.: Towards improving CVSS. Software Engineering Institute Carnegie Mellon University (2018)"},{"issue":"3","key":"15_CR3","doi-asserted-by":"publisher","first-page":"462","DOI":"10.1287\/ijoc.2014.0638","volume":"27","author":"D Dey","year":"2015","unstructured":"Dey, D., Lahiri, A., Zhang, G.: Optimal policies for security patch management. INFORMS J. Comput. 27(3), 462\u2013477 (2015)","journal-title":"INFORMS J. Comput."},{"key":"15_CR4","unstructured":"Lawson, C., Schneider, M., Bhajanka, P., Gardner, D.: Market Guide for Vulnerability Assessment (2019). https:\/\/www.gartner.com\/en\/documents\/3975388. Accessed 19 May 2022"},{"key":"15_CR5","volume-title":"Foundations of Information Security: A Straightforward Introduction","author":"J Andress","year":"2019","unstructured":"Andress, J.: Foundations of Information Security: A Straightforward Introduction. No Starch Press, San Francisco (2019)"},{"key":"15_CR6","doi-asserted-by":"crossref","unstructured":"Trifonov, R., Nakov, O., Mladenov, V.: Artificial intelligence in cyber threats intelligence. In: 2018 International Conference on Intelligent and Innovative Computing Applications (ICONIC), pp. 1\u20134. IEEE (2018)","DOI":"10.1109\/ICONIC.2018.8601235"},{"issue":"2","key":"15_CR7","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/S1361-3723(17)30013-1","volume":"2017","author":"S Furnell","year":"2017","unstructured":"Furnell, S., Fischer, P., Finch, A.: Can\u2019t get the staff? The growing need for cyber-security skills. Comput. Fraud Secur. 2017(2), 5\u201310 (2017)","journal-title":"Comput. Fraud Secur."},{"key":"15_CR8","unstructured":"Elbaz, C., Rilling, L., Morin, C.: Automated risk analysis of a vulnerability disclosure using active learning. In: Proceedings of the 28th Computer & Electronics Security Application Rendezvous (2021)"},{"key":"15_CR9","series-title":"Lecture Notes on Data Engineering and Communications Technologies","doi-asserted-by":"publisher","first-page":"739","DOI":"10.1007\/978-981-10-8681-6_67","volume-title":"International Conference on Computer Networks and Communication Technologies","author":"B Geluvaraj","year":"2019","unstructured":"Geluvaraj, B., Satwik, P.M., Ashok Kumar, T.A.: The future of cybersecurity: major role of artificial intelligence, machine learning, and deep learning in cyberspace. In: Smys, S., Bestak, R., Chen, J.I.-Z., Kotuliak, I. (eds.) International Conference on Computer Networks and Communication Technologies. LNDECT, vol. 15, pp. 739\u2013747. Springer, Singapore (2019). https:\/\/doi.org\/10.1007\/978-981-10-8681-6_67"},{"key":"15_CR10","doi-asserted-by":"publisher","first-page":"222310","DOI":"10.1109\/ACCESS.2020.3041951","volume":"8","author":"K Shaukat","year":"2020","unstructured":"Shaukat, K., Luo, S., Varadharajan, V., Hameed, I.A., Xu, M.: A survey on machine learning techniques for cyber security in the last decade. IEEE Access 8, 222310\u2013222354 (2020)","journal-title":"IEEE Access"},{"key":"15_CR11","unstructured":"Settles, B.: Active learning literature survey [White paper]. University of Wisconsin-Madison Department of Computer Sciences (2009)"},{"issue":"1","key":"15_CR12","doi-asserted-by":"publisher","first-page":"493","DOI":"10.1007\/s00521-021-06400-0","volume":"34","author":"HI Kure","year":"2022","unstructured":"Kure, H.I., Islam, S., Ghazanfar, M., Raza, A., Pasha, M.: Asset criticality and risk prediction for an effective cybersecurity risk management of cyber-physical system. Neural Comput. Appl. 34(1), 493\u2013514 (2022). https:\/\/doi.org\/10.1007\/s00521-021-06400-0","journal-title":"Neural Comput. Appl."},{"key":"15_CR13","doi-asserted-by":"crossref","unstructured":"Walkowski, M., Krakowiak, M., Jaroszewski, M., Oko, J., Sujecki, S.: Automatic CVSS-based vulnerability prioritization and response with context information. In: 2021 International Conference on Software, Telecommunications and Computer Networks (SoftCOM), pp. 1\u20136. IEEE (2021)","DOI":"10.23919\/SoftCOM52868.2021.9559094"},{"key":"15_CR14","doi-asserted-by":"publisher","first-page":"148315","DOI":"10.1109\/ACCESS.2020.3015551","volume":"8","author":"W Wang","year":"2020","unstructured":"Wang, W., Shi, F., Zhang, M., Xu, C., Zheng, J.: A vulnerability risk assessment method based on heterogeneous information network. IEEE Access 8, 148315\u2013148330 (2020)","journal-title":"IEEE Access"},{"key":"15_CR15","unstructured":"Gonzalez-Granadillo, G., Diaz, R., Veroni, E., Xenakis, C.: A Multi-factor Assessment Mechanism to Define Priorities on Vulnerabilities affecting Healthcare Organizations (2021)"},{"issue":"10","key":"15_CR16","first-page":"1043","volume":"8","author":"G Chawla","year":"2019","unstructured":"Chawla, G., Sharma, N., Rawal, N.: IVSEV: improved vulnerability scoring mechanism with environment representative and vulnerability type. Int. J. Sci. Technol. Res. 8(10), 1043\u20131047 (2019)","journal-title":"Int. J. Sci. Technol. Res."},{"key":"15_CR17","unstructured":"Tenable, Inc.: Whitepaper: Focus on the 3% of vulnerabilities likely to be exploited [White paper] (2020). https:\/\/lookbook.tenable.com\/predictive-prioritization\/technical-whitepaper-predictive-prioritization. Accessed 20 June 2022"},{"key":"15_CR18","unstructured":"Rapid7, Inc.: Rapid7 whitepaper: The four pillars of modern vulnerability management [White paper] (2021). https:\/\/www.rapid7.com\/info\/whitepaper-the-four-pillars-of-modern-vulnerability-management\/. Accessed 20 June 2022"},{"key":"15_CR19","unstructured":"Kenna Security, Inc.: Understanding the Kenna Risk Score Prioritizing Vulnerabilities with Data Science [White paper] (2020). https:\/\/www.vmware.com\/content\/dam\/digitalmarketing\/vmware\/en\/pdf\/docs\/vmwcb-whitepaper-understanding-the-kenna-security-vulnerability-risk-score.pdf. Accessed 20 June 2022"},{"key":"15_CR20","unstructured":"Bromander, S.: Understanding Cyber Threat Intelligence: Towards Automation [Doctoral\u2019s Thesis, University of Oslo]. The University of Oslo Institutt for informatikk (2021). https:\/\/www.duo.uio.no\/handle\/10852\/84713"},{"key":"15_CR21","unstructured":"Kenna Security Inc., Cyentia Institute.: Winning the Remediation Race [White paper] (2019). https:\/\/website.kennasecurity.com\/wp-content\/uploads\/2020\/09\/Kenna_Prioritization_to_Prediction_Vol3.pdf. Accessed 20 June 2022"},{"issue":"4","key":"15_CR22","doi-asserted-by":"publisher","first-page":"532","DOI":"10.1017\/pan.2020.4","volume":"28","author":"B Miller","year":"2020","unstructured":"Miller, B., Linder, F., Mebane, W.R.: Active learning approaches for labeling text: review and assessment of the performance of active learning approaches. Polit. Anal. 28(4), 532\u2013551 (2020)","journal-title":"Polit. Anal."},{"key":"15_CR23","doi-asserted-by":"publisher","unstructured":"Ponte, F.R.P., Rodrigues, E.B., Mattos, C.L.: CVEjoin: An Information Security Vulnerability and Threat Intelligence Dataset. figshare. Dataset (2022). https:\/\/doi.org\/10.6084\/m9.figshare.21586923.v3","DOI":"10.6084\/m9.figshare.21586923.v3"},{"key":"15_CR24","unstructured":"Adobe, Inc.: Adobe: Severity ratings (2022). https:\/\/helpx.adobe.com\/security\/severity-ratings.html. Accessed 16 Aug 2022"},{"key":"15_CR25","unstructured":"Microsoft, Inc.: Microsoft: Security update severity rating system (2022). https:\/\/www.microsoft.com\/en-us\/msrc\/security-update-severity-rating-system. Accessed 16 Aug 2022"},{"key":"15_CR26","volume-title":"Probabilistic Machine Learning: An Introduction","author":"K Murphy","year":"2022","unstructured":"Murphy, K.: Probabilistic Machine Learning: An Introduction. MIT Press, Cambridge (2022)"}],"container-title":["Lecture Notes in Networks and Systems","Advanced Information Networking and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-28451-9_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,4,19]],"date-time":"2023-04-19T06:25:45Z","timestamp":1681885545000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-28451-9_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031284502","9783031284519"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-28451-9_15","relation":{},"ISSN":["2367-3370","2367-3389"],"issn-type":[{"value":"2367-3370","type":"print"},{"value":"2367-3389","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"15 March 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"AINA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Advanced Information Networking and Applications","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Juiz de Fora","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Brazil","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 March 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31 March 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"37","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"aina2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/voyager.ce.fit.ac.jp\/conf\/aina\/2023\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}