{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,17]],"date-time":"2026-05-17T23:06:23Z","timestamp":1779059183122,"version":"3.51.4"},"publisher-location":"Cham","reference-count":34,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032200174","type":"print"},{"value":"9783032200181","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-20018-1_12","type":"book-chapter","created":{"date-parts":[[2026,5,17]],"date-time":"2026-05-17T22:16:09Z","timestamp":1779056169000},"page":"216-235","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Automatic Attack Script Generation: A MDA Approach"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9924-1837","authenticated-orcid":false,"given":"Quentin","family":"Goux","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2966-5300","authenticated-orcid":false,"given":"Nadira","family":"Lammari","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,1]]},"reference":[{"key":"12_CR1","doi-asserted-by":"publisher","unstructured":"Naik, N., Jenkins, P., Grace, P., Song, J.: Comparing attack models for IT systems: lockheed martin\u2019s cyber kill chain, MITRE ATT&CK framework and diamond model. In: International Symposium on Systems Engineering, pp. 1\u20137. IEEE (2022). https:\/\/doi.org\/10.1109\/ISSE54508.2022.10005490","DOI":"10.1109\/ISSE54508.2022.10005490"},{"key":"12_CR2","doi-asserted-by":"publisher","first-page":"2287","DOI":"10.3390\/electronics11152287","volume":"11","author":"K Liu","year":"2022","unstructured":"Liu, K., Wang, F., Ding, Z., Liang, S., Yu, Z., Zhou, Y.: Recent progress of using knowledge graph for cybersecurity. Electronics 11, 2287 (2022). https:\/\/doi.org\/10.3390\/electronics11152287","journal-title":"Electronics"},{"key":"12_CR3","unstructured":"Goux, Q., Lammari, N.: Formalizing Attack Scenario Description: A Proposed Model. In: Proceedings of the 45th International Business Information Management Association Computer Science Conference (IBIMA), pp. 433\u2013444. International Business Information Management Association, C\u00f3rdoba, Spain (2025)"},{"key":"12_CR4","doi-asserted-by":"publisher","unstructured":"Lallie, H.S., Debattista, K., Bal, J.: A review of attack graph and attack tree visual syntax in cyber security. Comput. Sci. Rev. 35 (2020). https:\/\/doi.org\/10.1016\/j.cosrev.2019.100219","DOI":"10.1016\/j.cosrev.2019.100219"},{"key":"12_CR5","unstructured":"Weiss, J.D.: A system security engineering process. In: 14th National Computer Security Conference, pp. 572\u2013581 (1991)"},{"key":"12_CR6","first-page":"21","volume":"24","author":"B Schneier","year":"1999","unstructured":"Schneier, B.: Attack trees. Dr Dobb\u2019s J. 24, 21\u201329 (1999)","journal-title":"Attack trees. Dr Dobb\u2019s J."},{"key":"12_CR7","doi-asserted-by":"publisher","unstructured":"Mauw, S., Oostdijk, M.: Foundations of Attack Trees. In: Won, D.H., Kim, S. (eds.) Information Security and Cryptology - ICISC 2005, pp. 186\u2013198. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11734727_17","DOI":"10.1007\/11734727_17"},{"key":"12_CR8","doi-asserted-by":"crossref","unstructured":"Moore, A., Ellison, R., Linger, R.: Attack Modeling for Information Security and Survivability. Software Engineering Institute (2001)","DOI":"10.21236\/ADA387544"},{"key":"12_CR9","doi-asserted-by":"publisher","unstructured":"Swiler, L.P., Phillips, C.: A graph-based system for network-vulnerability analysis. Sandia National Lab. (SNL-NM), Albuquerque, NM (United States) (1998). https:\/\/doi.org\/10.2172\/573291","DOI":"10.2172\/573291"},{"key":"12_CR10","doi-asserted-by":"publisher","unstructured":"Dacier, M., Deswarte, Y.: Privilege graph: An extension to the typed access matrix model. In: Gollmann, D. (ed.) Third European Symposium on Research in Computer Security, pp. 319\u2013334. Springer, Heidelberg (1994). https:\/\/doi.org\/10.1007\/3-540-58618-0_72","DOI":"10.1007\/3-540-58618-0_72"},{"key":"12_CR11","unstructured":"Louthan, G.R.: Hybrid attack graphs for modeling cyber-physical systems (2011)"},{"key":"12_CR12","doi-asserted-by":"publisher","unstructured":"Nichols, W., Hill, Z., Hawrylak, P., Hale, J., Papa, M.: Automatic generation of attack scripts from attack graphs. In: 2018 1st International Conference on Data Intelligence and Security (ICDIS), pp. 267\u2013274. IEEE, South Padre Island, TX (2018). https:\/\/doi.org\/10.1109\/ICDIS.2018.00050","DOI":"10.1109\/ICDIS.2018.00050"},{"key":"12_CR13","unstructured":"Morais, A., Cavalli, A.R., Martins, E.: Attack scripts generation for security validation. In: SEC-SY \u201910\u202f: S\u00e9curit\u00e9 des Syst\u00e8mes d\u2019Information et les Environnements Collaboratifs, Marseille, France (2010)"},{"key":"12_CR14","unstructured":"Vigna, G., Eckmann, S., Kemmerer, R.: Attack Languages. In: In Proceedings of the IEEE Information Survivability Workshop. Citeseer (2000)"},{"key":"12_CR15","doi-asserted-by":"publisher","unstructured":"Michel, C., M\u00e9, L.: ADeLe: An Attack Description Language for Knowledge-Based Intrusion Detection. In: Dupuy, M. and Paradinas, P. (eds.) Trusted Information. pp. 353\u2013368. Springer US, Boston, MA (2001). https:\/\/doi.org\/10.1007\/0-306-46998-7_25","DOI":"10.1007\/0-306-46998-7_25"},{"key":"12_CR16","doi-asserted-by":"publisher","unstructured":"Johnson, P., Lagerstr\u00f6m, R., Ekstedt, M.: A meta language for threat modeling and attack simulations. In: Proceedings of the 13th International Conference on Availability, Reliability and Security, pp. 1\u20138. Association for Computing Machinery, New York (2018). https:\/\/doi.org\/10.1145\/3230833.3232799","DOI":"10.1145\/3230833.3232799"},{"key":"12_CR17","doi-asserted-by":"publisher","unstructured":"Hacks, S., Katsikeas, S., Rencelj Ling, E., Xiong, W., Pfeiffer, J., Wortmann, A.: Towards a systematic method for developing meta attack language instances. In: Augusto, A., Gill, A., Bork, D., Nurcan, S., Reinhartz-Berger, I., and Schmidt, R. (eds.) Enterprise, Business-Process and Information Systems Modeling. pp. 139\u2013154. Springer International Publishing, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-07475-2_10","DOI":"10.1007\/978-3-031-07475-2_10"},{"key":"12_CR18","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103284","volume":"130","author":"W Wide\u0142","year":"2023","unstructured":"Wide\u0142, W., Hacks, S., Ekstedt, M., Johnson, P., Lagerstr\u00f6m, R.: The meta attack language - a formal description. Comput. Secur. 130, 103284 (2023). https:\/\/doi.org\/10.1016\/j.cose.2023.103284","journal-title":"Comput. Secur."},{"key":"12_CR19","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2025.104454","volume":"155","author":"C Skandylas","year":"2025","unstructured":"Skandylas, C., Asplund, M.: Automated penetration testing: formalization and realization. Comput. Secur. 155, 104454 (2025). https:\/\/doi.org\/10.1016\/j.cose.2025.104454","journal-title":"Comput. Secur."},{"key":"12_CR20","doi-asserted-by":"publisher","unstructured":"Simon, R., Mees, W.: SoK: A Comparison of Autonomous Penetration Testing Agents. In: Proceedings of the 19th International Conference on Availability, Reliability and Security, pp. 1\u201310. ACM, Vienna Austria (2024). https:\/\/doi.org\/10.1145\/3664476.3664484","DOI":"10.1145\/3664476.3664484"},{"key":"12_CR21","doi-asserted-by":"publisher","first-page":"7148","DOI":"10.3390\/s20247148","volume":"20","author":"E Ukwandu","year":"2020","unstructured":"Ukwandu, E., et al.: A review of cyber-ranges and test-beds: current and future trends. Sensors. 20, 7148 (2020). https:\/\/doi.org\/10.3390\/s20247148","journal-title":"Sensors."},{"key":"12_CR22","doi-asserted-by":"publisher","first-page":"1005","DOI":"10.1007\/s10207-023-00680-4","volume":"22","author":"MN Katsantonis","year":"2023","unstructured":"Katsantonis, M.N., Manikas, A., Mavridis, I., Gritzalis, D.: Cyber range design framework for cyber security education and training. Int. J. Inf. Secur. 22, 1005\u20131027 (2023). https:\/\/doi.org\/10.1007\/s10207-023-00680-4","journal-title":"Int. J. Inf. Secur."},{"key":"12_CR23","doi-asserted-by":"publisher","unstructured":"Boyens, J., Paulsen, C., Bartol, N., Shankles, S.A., Moorthy, R.: Notional supply chain risk management practices for federal information systems. National Institute of Standards and Technology, Gaithersburg, MD (2012). https:\/\/doi.org\/10.6028\/NIST.IR.7622","DOI":"10.6028\/NIST.IR.7622"},{"key":"12_CR24","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2024.103917","volume":"88","author":"V Kampourakis","year":"2025","unstructured":"Kampourakis, V., Gkioulos, V., Katsikas, S.: A step-by-step definition of a reference architecture for cyber ranges. J. Inf. Secur. Appl. 88, 103917 (2025). https:\/\/doi.org\/10.1016\/j.jisa.2024.103917","journal-title":"J. Inf. Secur. Appl."},{"key":"12_CR25","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1145\/1218776.1226833","volume":"31","author":"J Kramer","year":"2006","unstructured":"Kramer, J., Hazzan, O.: The role of abstraction in software engineering. ACM SIGSOFT Softw. Eng. Notes. 31, 38\u201339 (2006). https:\/\/doi.org\/10.1145\/1218776.1226833","journal-title":"ACM SIGSOFT Softw. Eng. Notes."},{"key":"12_CR26","unstructured":"OMG: MDA Guide Version 1.0.1. Object Management Group, Inc. (2003)"},{"key":"12_CR27","doi-asserted-by":"publisher","unstructured":"Zimmermann, M., Breitenb\u00fccher, U., Leymann, F.: A method and programming model for developing interacting cloud applications based on the TOSCA standard. In: Hammoudi, S., \u015amia\u0142ek, M., Camp, O., and Filipe, J. (eds.) Enterprise Information Systems, pp. 265\u2013290. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-93375-7_13","DOI":"10.1007\/978-3-319-93375-7_13"},{"key":"12_CR28","volume-title":"Practical ansible: learn how to automate infrastructure, manage configuration, and deploy applications","author":"J Freeman","year":"2023","unstructured":"Freeman, J., Locati, F.A., Oh, D.: Practical ansible: learn how to automate infrastructure, manage configuration, and deploy applications. Packt Publishing, Place of publication not identified (2023)"},{"key":"12_CR29","unstructured":"Odarchenko, R., Pinchuk, A., Polihenko, O., Skurativskyi, A.: A comparative analysis of cyber threat intelligence models. In: Gnatyuk, S., Iavich, M., Odarchenko, R., Al-Azzeh, J., and Zaliskyi, M. (eds.) Proceedings of the Third International Conference on Cyber Hygiene & Conflict Management in Global Information Networks (CH&CMiGIN 2024), pp. 3\u201312. CEUR, Kyiv, Ukraine (2024)"},{"key":"12_CR30","unstructured":"Topology and Orchestration Specification for Cloud Applications Version 1.0. OASIS Standard (2013)"},{"key":"12_CR31","unstructured":"Rutkowski, M., Lauwers, C., Noshpitz, C., Curescu, C. eds: TOSCA Simple Profile in YAML Version 1.3. OASIS Standard (2020)"},{"key":"12_CR32","doi-asserted-by":"publisher","unstructured":"Merle, P., Sylla, A.N., Ouzzif, M., Klamm, F., Guillouard, K.: A lightweight toolchain to validate, visualize, analyze, and deploy ETSI NFV Topologies Behaviors. In: 2019 IEEE Conference on Network Softwarization (NetSoft), pp. 260\u2013262 (2019). https:\/\/doi.org\/10.1109\/NETSOFT.2019.8806632","DOI":"10.1109\/NETSOFT.2019.8806632"},{"key":"12_CR33","unstructured":"Merle, P., Coulin, J.-L., Klamm, F., Moulet, X.-F., Guillouard, K., YBE-Orange, Yffick: Cloudnet TOSCA toolbox, https:\/\/github.com\/Orange-OpenSource\/Cloudnet-TOSCA-toolbox (2024)"},{"key":"12_CR34","doi-asserted-by":"publisher","unstructured":"Breitenb\u00fccher, U., Endres, C., K\u00e9pes, K., Kopp, O., Leymann, F., Wagner, S., Wettinger, J., Zimmermann, M.: The OpenTOSCA Ecosystem - Concepts & Tools. In: European Space project on Smart Systems, Big Data, Future Internet - Towards Serving the Grand Societal Challenges. pp. 112\u2013130. SCITEPRESS - Science and Technology Publications, Rome, Italy (2016). https:\/\/doi.org\/10.5220\/0007903201120130","DOI":"10.5220\/0007903201120130"}],"container-title":["Lecture Notes in Computer Science","Foundations and Practice of Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-20018-1_12","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,17]],"date-time":"2026-05-17T22:16:12Z","timestamp":1779056172000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-20018-1_12"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032200174","9783032200181"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-20018-1_12","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"1 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"FPS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Foundations and Practice of Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Brest","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 November 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 November 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"fps2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/hub.imt-atlantique.fr\/fps2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}