{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,31]],"date-time":"2025-10-31T07:29:28Z","timestamp":1761895768165,"version":"3.40.4"},"publisher-location":"Cham","reference-count":38,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319039633"},{"type":"electronic","value":"9783319039640"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013]]},"DOI":"10.1007\/978-3-319-03964-0_13","type":"book-chapter","created":{"date-parts":[[2013,12,17]],"date-time":"2013-12-17T02:34:56Z","timestamp":1387247696000},"page":"142-154","source":"Crossref","is-referenced-by-count":5,"title":["Determining Risks from Advanced Multi-step Attacks to Critical Information Infrastructures"],"prefix":"10.1007","author":[{"given":"Zhendong","family":"Ma","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paul","family":"Smith","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"13_CR1","unstructured":"Common vulnerabilities and exposures, http:\/\/cve.mitre.org\/"},{"key":"13_CR2","unstructured":"Common vulnerability scoring system, http:\/\/www.first.org\/cvss"},{"key":"13_CR3","unstructured":"CVE-compatible products and services, http:\/\/cve.mitre.org\/compatible\/compatible.html"},{"key":"13_CR4","unstructured":"CVE Details, http:\/\/www.cvedetails.com\/"},{"key":"13_CR5","unstructured":"ISO\/IEC 27000-series Information Security Management System Family of Standards"},{"key":"13_CR6","unstructured":"Ammann, P., Pamula, J., Street, J., Ritchey, R.: A host-based approach to network attack chaining analysis. In: 21st Annual Computer Security Applications Conference (2005)"},{"key":"13_CR7","unstructured":"Bencs\u00e1th, B., P\u00e9k, G., Butty\u00e1n, L., Felegyhazi, M.: Duqu: A Stuxnet-like malware found in the wild Technical report (October 2011), http:\/\/www.crysys.hu\/publications\/files\/bencsathPBF11duqu.pdf"},{"issue":"6","key":"13_CR8","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1109\/MSP.2008.150","volume":"6","author":"M. Brundle","year":"2008","unstructured":"Brundle, M., Naedele, M.: Security for Process Control Systems: An Overview. IEEE Security & Privacy\u00a06(6), 24\u201329 (2008)","journal-title":"IEEE Security & Privacy"},{"key":"13_CR9","unstructured":"Byres, E., Ginter, A., Langill, J.: How Stuxnet Spreads A Study of Infection Paths in Best Practice Systems, White paper (February 2011)"},{"key":"13_CR10","doi-asserted-by":"crossref","unstructured":"\u00c7amtepe, S.A., Yener, B.: Modeling and detection of complex attacks. In: SecureComm., pp. 234\u2013243 (2007)","DOI":"10.1109\/SECCOM.2007.4550338"},{"issue":"2","key":"13_CR11","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1109\/TII.2009.2018627","volume":"5","author":"M. Cheminod","year":"2009","unstructured":"Cheminod, M., et al.: Detecting chains of vulnerabilities in industrial networks. IEEE Transactions on Industrial Informatics\u00a05(2), 181\u2013193 (2009)","journal-title":"IEEE Transactions on Industrial Informatics"},{"key":"13_CR12","doi-asserted-by":"crossref","unstructured":"Daley, K., Larson, R., Dawkins, J.: A structural framework for modeling multi-stage network attacks. In: ICPP Workshops, pp. 5\u201310 (2002)","DOI":"10.1109\/ICPPW.2002.1039705"},{"key":"13_CR13","unstructured":"Falliere, N., Murchu, L.O., Chien, E.: W32.Stuxnet dossier. Symantec white paper (September 2010)"},{"issue":"7","key":"13_CR14","doi-asserted-by":"publisher","first-page":"498","DOI":"10.1016\/j.cose.2006.03.001","volume":"25","author":"V.M. Igure","year":"2006","unstructured":"Igure, V.M., Laughter, S.A., Williams, R.D.: Security issues in SCADA networks. Computers & Security\u00a025(7), 498\u2013506 (2006)","journal-title":"Computers & Security"},{"key":"13_CR15","unstructured":"International Society of Automation: ANSI\/ISA-99.00.01-2007 Security for Industrial Automation and Control Systems (2007)"},{"issue":"3","key":"13_CR16","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1109\/MSP.2011.67","volume":"9","author":"R. Langner","year":"2011","unstructured":"Langner, R.: Stuxnet: Dissecting a cyberwarfare weapon. IEEE Security & Privacy\u00a09(3), 49\u201351 (2011)","journal-title":"IEEE Security & Privacy"},{"key":"13_CR17","doi-asserted-by":"crossref","unstructured":"Lippmann, R.P., Ingols, K.W.: An annotated review of past papers on attck graphs. Lincoln Laboratory Technical Report ESC-TR-2005-054 (March 2005)","DOI":"10.21236\/ADA431826"},{"key":"13_CR18","doi-asserted-by":"crossref","unstructured":"Maggi, P., Pozza, D., Sisto, R.: Vulnerability modelling for the analysis of network attacks. In: Third International Conference on Dependability of Computer Systems, DepCos-RELCOMEX 2008, pp. 15\u201322 (2008)","DOI":"10.1109\/DepCoS-RELCOMEX.2008.49"},{"key":"13_CR19","unstructured":"McAfee: In the Dark: Crucial Industries Confront Cyberattacks (2011)"},{"key":"13_CR20","doi-asserted-by":"crossref","unstructured":"Moore, A.P., Ellison, R.J., Linger, R.C.: Attack modeling for information security and survivability (2001)","DOI":"10.21236\/ADA387544"},{"key":"13_CR21","unstructured":"NIST: National vulnerability database, http:\/\/nvd.nist.gov\/"},{"key":"13_CR22","first-page":"336","volume-title":"Proceedings of the 13th ACM Conference on Computer and Communications Security, CCS 2006","author":"X. Ou","year":"2006","unstructured":"Ou, X., Boyer, W.F., McQueen, M.A.: A scalable approach to attack graph generation. In: Proceedings of the 13th ACM Conference on Computer and Communications Security, CCS 2006, pp. 336\u2013345. ACM, New York (2006)"},{"key":"13_CR23","unstructured":"Ou, X., Govindavajhala, S., Appel, A.W.: MulVAL: a logic-based network security analyzer. In: 14th Conference on USENIX Security Symposium (2005)"},{"key":"13_CR24","doi-asserted-by":"crossref","unstructured":"Phillips, C., Swiler, L.P.: A graph-based system for network-vulnerability analysis. In: Proceedings of the 1998 Workshop on New Security Paradigms (1998)","DOI":"10.1145\/310889.310919"},{"key":"13_CR25","unstructured":"Ritchey, R.W., Ammann, P.: Using model checking to analyze network vulnerabilities. In: IEEE Symposium on Security and Privacy (2000)"},{"key":"13_CR26","doi-asserted-by":"crossref","unstructured":"Sawilla, R.E., Ou, X.: Identifying critical attack assets in dependency attack graphs. In: Proceedings of the 13th European Symposium on Research in Computer Security: Computer Security (2008)","DOI":"10.1007\/978-3-540-88313-5_2"},{"key":"13_CR27","unstructured":"SecurityFocus: Bugtraq, http:\/\/www.securityfocus.com\/"},{"key":"13_CR28","unstructured":"Sheyner, O., et\u00a0al.: Automated generation and analysis of attack graphs. In: Proceedings of the 2002 IEEE Symposium on Security and Privacy (2002)"},{"key":"13_CR29","unstructured":"SIEMENS: Security concept PCS 7 and WinCC - Basic document, white paper (August 2008)"},{"key":"13_CR30","doi-asserted-by":"crossref","unstructured":"Singhal, A., Ou, X.: Security risk analysis analysis of enterprise networks using probabilistic attack graphs. NIST Interagency Report 7788 (August 2011)","DOI":"10.6028\/NIST.IR.7788"},{"key":"13_CR31","unstructured":"sKyWIper Analysis Team: sKyWIper (a.k.a. Flame a.k.a. Flamer): A complex malware for targeted attacks Technical report (May 2012), http:\/\/www.crysys.hu\/skywiper\/skywiper.pdf"},{"key":"13_CR32","doi-asserted-by":"crossref","unstructured":"Stoneburner, G., Goguen, A., Feringa, A.: NIST special publication 800-30 risk management guide for information technology systems (2002)","DOI":"10.6028\/NIST.SP.800-30"},{"key":"13_CR33","unstructured":"Stouffer, K., Falco, J., Kent, K.: Guide to Industrial Control Systems (ICS) Security. NIST SP 800-82 (June 2011)"},{"key":"13_CR34","unstructured":"Symantec: Symantec Critical Infrastrucutrre Protection Survey (2011)"},{"issue":"4","key":"13_CR35","doi-asserted-by":"publisher","first-page":"1836","DOI":"10.1109\/TPWRS.2008.2002298","volume":"23","author":"C.W. Ten","year":"2008","unstructured":"Ten, C.W., Manimaran, G., Liu, C.C.: Vulnerability Assessment of Cybersecurity for SCADA Systems. IEEE Trans. on Power Systems\u00a023(4), 1836\u20131846 (2008)","journal-title":"IEEE Trans. on Power Systems"},{"issue":"4","key":"13_CR36","doi-asserted-by":"publisher","first-page":"853","DOI":"10.1109\/TSMCA.2010.2048028","volume":"40","author":"C.W. Ten","year":"2010","unstructured":"Ten, C.W., Manimaran, G., Liu, C.C.: Cybersecurity for critical infrastructures: attack and defense modeling. Trans. Sys. Man Cyber. Part A\u00a040(4), 853\u2013865 (2010)","journal-title":"Trans. Sys. Man Cyber. Part A"},{"key":"13_CR37","unstructured":"Tenable Network Security, Inc.: Boosting your network defenses with Tenable\u2019s integral attack path analytics, white paper, www.tenable.com"},{"key":"13_CR38","unstructured":"US-CERT: Security bulletins, http:\/\/www.us-cert.gov\/ncas\/bulletins\/"}],"container-title":["Lecture Notes in Computer Science","Critical Information Infrastructures Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-03964-0_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,1]],"date-time":"2025-05-01T06:09:12Z","timestamp":1746079752000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-03964-0_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013]]},"ISBN":["9783319039633","9783319039640"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-03964-0_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2013]]}}}