{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T11:30:50Z","timestamp":1780054250993,"version":"3.54.0"},"publisher-location":"Cham","reference-count":30,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031744426","type":"print"},{"value":"9783031744433","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-74443-3_16","type":"book-chapter","created":{"date-parts":[[2024,12,19]],"date-time":"2024-12-19T20:03:22Z","timestamp":1734638602000},"page":"271-280","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["A Comparative Analysis of\u00a0Threat Modelling Methods: STRIDE, DREAD, VAST, PASTA, OCTAVE, and\u00a0LINDDUN"],"prefix":"10.1007","author":[{"given":"Nitin","family":"Naik","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Paul","family":"Jenkins","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Paul","family":"Grace","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dishita","family":"Naik","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shaligram","family":"Prajapat","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jingping","family":"Song","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,12,20]]},"reference":[{"key":"16_CR1","unstructured":"Alberts, C., Dorofee, A., Stevens, J., Woody, C.: OCTAVE-S (2005)"},{"key":"16_CR2","doi-asserted-by":"crossref","unstructured":"Alberts, C.J., Behrens, S.G., Pethia, R.D., Wilson, W.R.: Operationally critical threat, asset, and vulnerability evaluation (OCTAVE) framework, version 1.0 (1999)","DOI":"10.21236\/ADA367718"},{"key":"16_CR3","doi-asserted-by":"crossref","unstructured":"Caralli, R.A., Stevens, J.F., Young, L.R., Wilson, W.R.: Introducing OCTAVE Allegro: improving the information security risk assessment process. Hansom AFB, MA (2007)","DOI":"10.21236\/ADA470450"},{"key":"16_CR4","unstructured":"Cyral.com: Threat modeling with DREAD (2024). https:\/\/cyral.com\/glossary\/threat-modeling-with-dread\/"},{"issue":"1","key":"16_CR5","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/s00766-010-0115-7","volume":"16","author":"M Deng","year":"2011","unstructured":"Deng, M., Wuyts, K., Scandariato, R., Preneel, B., Joosen, W.: A privacy threat analysis framework: supporting the elicitation and fulfillment of privacy requirements. Requirements Eng. 16(1), 3\u201332 (2011)","journal-title":"Requirements Eng."},{"key":"16_CR6","unstructured":"Eccouncil.org: Cyber threat modeling (2024). https:\/\/www.eccouncil.org\/threat-modeling\/"},{"key":"16_CR7","unstructured":"Gonzalez, C.: Threat modeling: 5 steps, 7 techniques, and tips for success (2023). https:\/\/www.exabeam.com\/blog\/infosec-trends\/top-8-threat-modeling-methodologies-and-techniques\/"},{"key":"16_CR8","unstructured":"Kirtley, N.: PASTA threat modeling (2022). https:\/\/threat-modeling.com\/pasta-threat-modeling\/"},{"key":"16_CR9","unstructured":"Kohnfelder, L., Garg, P.: The threats to our products (1999)"},{"key":"16_CR10","unstructured":"LeBlanc, D., Howard, M.: Writing secure code. Pearson Education (2002)"},{"key":"16_CR11","unstructured":"Linddun.com: LINDDUN privacy threat modelling: identify privacy threats in software systems (2024). https:\/\/linddun.org\/threat-types\/"},{"key":"16_CR12","unstructured":"Linddun.com: LINDDUN: Privacy threat types (2024). https:\/\/linddun.org\/"},{"key":"16_CR13","unstructured":"Microsoft.com: Microsoft threat modeling tool: Mitigations (2022). https:\/\/learn.microsoft.com\/en-us\/azure\/security\/develop\/threat-modeling-tool-mitigations"},{"key":"16_CR14","unstructured":"Microsoft.com: Microsoft threat modeling tool: Threats (2022). https:\/\/learn.microsoft.com\/en-us\/azure\/security\/develop\/threat-modeling-tool-threats"},{"key":"16_CR15","doi-asserted-by":"crossref","unstructured":"Naik, N., Grace, P., Jenkins, P.: An attack tree based risk analysis method for investigating attacks and facilitating their mitigations in self-sovereign identity. In: IEEE Symposium Series on Computational Intelligence (SSCI). IEEE (2021)","DOI":"10.1109\/SSCI50451.2021.9659929"},{"key":"16_CR16","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102808","volume":"120","author":"N Naik","year":"2022","unstructured":"Naik, N., Grace, P., Jenkins, P., Naik, K., Song, J.: An evaluation of potential attack surfaces based on attack tree modelling and risk matrix applied to self-sovereign identity. Comput. Secur. 120, 102808 (2022)","journal-title":"Comput. Secur."},{"key":"16_CR17","unstructured":"Naik, N., Jenkins, P., Grace, P.: Cyberattack analysis based on attack tree with weighted average probability and risk of attack. In: UK Workshop on Computational Intelligence (UKCI). Springer (2022)"},{"key":"16_CR18","doi-asserted-by":"crossref","unstructured":"Naik, N., Jenkins, P., Grace, P., Naik, D., Prajapat, S., Song, J.: An introduction to threat modelling: modelling steps, model types, benefits and challenges. In: The International Conference on Computing, Communication, Cybersecurity &AI (The C3AI 2024). Springer (2024)","DOI":"10.36227\/techrxiv.173014165.57428154\/v1"},{"key":"16_CR19","doi-asserted-by":"crossref","unstructured":"Naik, N., et al.: Analysing cyberattacks using attack tree and fuzzy rules. In: UK Workshop on Computational Intelligence (UKCI). Springer (2023)","DOI":"10.1007\/978-3-031-47508-5_29"},{"key":"16_CR20","doi-asserted-by":"crossref","unstructured":"Naik, N., et al.: Fuzzy attack tree: assessing cyberattack risk using attack tree and fuzzy logic. In: 2023 IEEE International Conference on ICT in Business Industry & Government (ICTBIG), pp.\u00a01\u20139. IEEE (2023)","DOI":"10.1109\/ICTBIG59752.2023.10456309"},{"key":"16_CR21","doi-asserted-by":"crossref","unstructured":"Naik, N., et al.: Cyberattack analysis utilising attack tree with weighted mean probability and risk of attack. In: UK Workshop on Computational Intelligence (UKCI). Springer (2023)","DOI":"10.1007\/978-3-031-47508-5_28"},{"key":"16_CR22","doi-asserted-by":"crossref","unstructured":"Naik, N., Jenkins, P., Grace, P., Song, J.: Comparing attack models for IT systems: lockheed martin\u2019s cyber kill chain, MITRE ATT &CK framework and diamond model. In: 2022 IEEE International Symposium on Systems Engineering (ISSE). IEEE (2022)","DOI":"10.1109\/ISSE54508.2022.10005490"},{"key":"16_CR23","unstructured":"Satoricyber.com: Threat modeling with microsoft DREAD (2022). https:\/\/satoricyber.com\/glossary\/threat-modeling-with-microsoft-dread\/#:~:text=DREAD"},{"key":"16_CR24","unstructured":"Threatmodeler.com: The evolution of threat modeling (2016). https:\/\/threatmodeler.com\/evolution-of-threat-modeling\/"},{"key":"16_CR25","unstructured":"Threatmodeler.com: Threat modeling methodologies: What is VAST? (2018). https:\/\/threatmodeler.com\/threat-modeling-methodologies-vast\/"},{"key":"16_CR26","unstructured":"Threatmodeler.com: Which threat modeling methodology is right for your organization? (2018). https:\/\/threatmodeler.com\/threat-modeling-methodology\/"},{"key":"16_CR27","unstructured":"Threatmodeler.com: The ultimate guide to threat modeling (2024). https:\/\/threatmodeler.com\/the-ultimate-guide-to-threat-modeling\/"},{"key":"16_CR28","unstructured":"UcedaVlez, T.: What is PASTA threat modeling? Why use PASTA? (2021). https:\/\/versprite.com\/blog\/what-is-pasta-threat-modeling\/"},{"key":"16_CR29","unstructured":"Versprite.com: Risk-based security threat modeling: 7-step process for risk analysis (2024). https:\/\/versprite.com\/security-resources\/risk-based-threat-modeling\/"},{"key":"16_CR30","unstructured":"Windriver.com: What is threat modeling? (2024). https:\/\/www.windriver.com\/solutions\/learning\/threat-modeling"}],"container-title":["Lecture Notes in Networks and Systems","Contributions Presented at The International Conference on Computing, Communication, Cybersecurity and AI, July 3\u20134, 2024, London, UK"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-74443-3_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,12,19]],"date-time":"2024-12-19T20:05:12Z","timestamp":1734638712000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-74443-3_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031744426","9783031744433"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-74443-3_16","relation":{},"ISSN":["2367-3370","2367-3389"],"issn-type":[{"value":"2367-3370","type":"print"},{"value":"2367-3389","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"20 December 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"C3AI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The International Conference on Computing, Communication, Cybersecurity & AI","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"London","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"United Kingdom","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3 July 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 July 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"c3ai2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.thec3ai.com\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}