{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T09:57:47Z","timestamp":1773655067423,"version":"3.50.1"},"publisher-location":"Cham","reference-count":35,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319318103","type":"print"},{"value":"9783319318110","type":"electronic"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-31811-0_7","type":"book-chapter","created":{"date-parts":[[2016,4,1]],"date-time":"2016-04-01T10:59:22Z","timestamp":1459508362000},"page":"107-124","source":"Crossref","is-referenced-by-count":14,"title":["Countermeasure Selection Based on the Attack and Service Dependency Graphs for Security Incident Management"],"prefix":"10.1007","author":[{"given":"Elena","family":"Doynikova","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Igor","family":"Kotenko","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,4,2]]},"reference":[{"key":"7_CR1","unstructured":"ISO\/IEC TR 13335-4:2000. Information technology \u2014 Guidelines for the management of IT Security \u2014 Part 4: Selection of safeguards"},{"key":"7_CR2","doi-asserted-by":"publisher","DOI":"10.1201\/EBK1439839560","volume-title":"Information Security Risk Analysis","author":"TR Peltier","year":"2010","unstructured":"Peltier, T.R.: Information Security Risk Analysis, 3rd edn. CRC Press, Boca Raton (2010)","edition":"3"},{"key":"7_CR3","doi-asserted-by":"crossref","unstructured":"Caralli, R., Stevens, J.F., Young, L.R., Wilson, W.R.: Introducing OCTAVE Allegro: improving the information security risk assessment process. Technical report (2007)","DOI":"10.21236\/ADA470450"},{"key":"7_CR4","unstructured":"Visintine, V.: Global Information Assurance Certification Paper. SANS Institute (2003). http:\/\/www.giac.org\/paper\/gsec\/3156\/introduction-information-risk-assessment\/105258"},{"key":"7_CR5","unstructured":"RiskWatch. http:\/\/www.riskwatch.com\/"},{"key":"7_CR6","unstructured":"CRAMM. www.cramm.com"},{"issue":"3","key":"7_CR7","first-page":"14","volume":"5","author":"I Kotenko","year":"2014","unstructured":"Kotenko, I., Doynikova, E.: Evaluation of computer network security based on attack graphs and security event processing. J. Wirel. Mob. Netw. Ubiquit. Comput. Dependable Appl. (JoWUA) 5(3), 14\u201329 (2014)","journal-title":"J. Wirel. Mob. Netw. Ubiquit. Comput. Dependable Appl. (JoWUA)"},{"key":"7_CR8","first-page":"129","volume":"8","author":"I Kotenko","year":"2012","unstructured":"Kotenko, I., Chechulin, A.: Attack modeling and security evaluation in SIEM systems. Int. Trans. Syst. Sci. Appl. 8, 129\u2013147 (2012)","journal-title":"Int. Trans. Syst. Sci. Appl."},{"key":"7_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"337","DOI":"10.1007\/978-3-642-16342-5_25","volume-title":"Information Security and Cryptology","author":"E Bursztein","year":"2010","unstructured":"Bursztein, E., Mitchell, J.C.: Using strategy objectives for network security analysis. In: Bao, F., Yung, M., Lin, D., Jing, J. (eds.) Inscrypt 2009. LNCS, vol. 6151, pp. 337\u2013349. Springer, Heidelberg (2010)"},{"key":"7_CR10","doi-asserted-by":"crossref","unstructured":"He, W., Xia, C., Zhang, C., Ji, Y., Ma, X.: A network security risk assessment framework based on game theory. In: Proceedings of the Second International Conference on Future Generation Communication and Networking, vol. 2, pp. 249\u2013253. IEEE (2008)","DOI":"10.1109\/FGCN.2008.166"},{"key":"7_CR11","doi-asserted-by":"crossref","unstructured":"Noel, S., Jajodia, S., O\u2019Berry, B., Jacobs, M.: Efficient minimum-cost network hardening via exploit dependency graphs. In: Proceedings of the 19th Annual Computer Security Applications Conference, pp. 86\u201395. IEEE (2003)","DOI":"10.1109\/CSAC.2003.1254313"},{"key":"7_CR12","doi-asserted-by":"crossref","unstructured":"Ingols, K., Lippmann, R., Piwowarski, K.:\u00a0Pratical Attack Graph Generation for Network Defense. Computer Security Applications Conference. Miami Beach, Florida (2006)","DOI":"10.1109\/ACSAC.2006.39"},{"issue":"1","key":"7_CR13","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1109\/TDSC.2011.34","volume":"9","author":"N Poolsappasit","year":"2012","unstructured":"Poolsappasit, N., Dewri, R., Ray, I.: Dynamic security risk management using Bayesian attack graphs. IEEE Trans. Dependable Secur. Comput. 9(1), 61\u201374 (2012)","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"issue":"1","key":"7_CR14","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1002\/sec.58","volume":"2","author":"R Dantu","year":"2009","unstructured":"Dantu, R., Kolan, P., Cangussu, J.: Network risk management using attacker profiling. Secur. Commun. Netw. 2(1), 83\u201396 (2009)","journal-title":"Secur. Commun. Netw."},{"key":"7_CR15","doi-asserted-by":"crossref","unstructured":"Chunlu, W., Yancheng, W., Yingfei, D., Tianle, Z.: A novel comprehensive network security assessment approach. In: IEEE International Conference on Communications, pp. 1\u20136. IEEE, Kyoto (2011)","DOI":"10.1109\/icc.2011.5963092"},{"key":"7_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"216","DOI":"10.1007\/11909033_20","volume-title":"Communications and Multimedia Security","author":"I Kotenko","year":"2006","unstructured":"Kotenko, I., Stepashkin, M.: Attack graph based evaluation of network security. In: Leitold, H., Markatos, E.P. (eds.) CMS 2006. LNCS, vol. 4237, pp. 216\u2013227. Springer, Heidelberg (2006)"},{"key":"7_CR17","unstructured":"Cremonini, M., Martini, P.: Evaluating information security investments from attackers perspective: the Return-On-Attack (ROA). In: Workshop on the Economics of Information Security (2005)"},{"key":"7_CR18","doi-asserted-by":"crossref","unstructured":"Kanoun, W., Cuppens-Boulahia, N., Cuppens, F.: Automated reaction based on risk analysis and attackers skills in intrusion detection systems. In: Proceedings of the CRiSIS 2008, pp. 117\u2013124. IEEE, Tozeur (2008)","DOI":"10.1109\/CRISIS.2008.4757471"},{"issue":"5","key":"7_CR19","first-page":"1334","volume":"51","author":"Y-S Wu","year":"2007","unstructured":"Wu, Y.-S., Foo, B., Mao, Y.-C., Bagchi, S., Spafford, E.: Automated adaptive intrusion containment in systems of interacting services. Comput. Netw. Int. J. Comput. Telecommun. Netw. 51(5), 1334\u20131360 (2007). Elsevier North-Holland, Inc. New York, NY, USA","journal-title":"Comput. Netw. Int. J. Comput. Telecommun. Netw."},{"key":"7_CR20","unstructured":"Hoo, K.J.S.: How much is enough? a risk-management approach to computer security. Ph.D. thesis, Stanford University (2000)"},{"key":"7_CR21","unstructured":"Kheir, N.: Response policies and counter-measures: management of service dependencies and intrusion and reaction impacts. Ph.D. thesis (2010)"},{"key":"7_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"156","DOI":"10.1007\/978-3-642-33704-8_14","volume-title":"Computer Network Security","author":"G Gonzalez Granadillo","year":"2012","unstructured":"Gonzalez Granadillo, G., D\u00e9bar, H., Jacob, G., Gaber, C., Achemlal, M.: Individual countermeasure selection based on the return on response investment index. In: Kotenko, I., Skormin, V. (eds.) MMM-ACNS 2012. LNCS, vol. 7531, pp. 156\u2013170. Springer, Heidelberg (2012)"},{"key":"7_CR23","unstructured":"Kotenko, I., Chechulin, A.: A cyber attack modeling and impact assessment framework. In: CyCon 2013, pp. 119\u2013142. IEEE and NATO COE Publications (2013)"},{"key":"7_CR24","doi-asserted-by":"crossref","unstructured":"Waltermire, D., Quinn, S., Scarfone, K., Halbardier, A.: The Technical Specification for the Security Content Automation Protocol (SCAP): SCAP Version 1.2 (2011)","DOI":"10.6028\/NIST.SP.800-126r2"},{"key":"7_CR25","unstructured":"McGuire, G.T., Waltermire, D., Baker, J.O.: Common Remediation Enumeration (CRE) Version 1.0 (Draft). NIST Interagency Report 7831 (Draft) (2011)"},{"key":"7_CR26","unstructured":"Johnson, C.: Enterprise remediation automation. In: NIST, Proceedings of the IT Security Automation Conference (2010)"},{"key":"7_CR27","doi-asserted-by":"crossref","unstructured":"Kotenko, I., Doynikova, E.: Countermeasure selection in SIEM systems based on the integrated complex of security metrics. In: 23rd Euromicro International Conference on Parallel, Distributed and Network-Based Processing (PDP 2015), pp. 567\u2013574. IEEE (2015)","DOI":"10.1109\/PDP.2015.34"},{"key":"7_CR28","unstructured":"Common Vulnerabilities and Exposures (CVE). http:\/\/cve.mitre.org\/"},{"key":"7_CR29","unstructured":"Common Platform Enumeration (CPE). http:\/\/cpe.mitre.org\/"},{"key":"7_CR30","unstructured":"Common Configuration Enumeration (CCE). https:\/\/cce.mitre.org\/"},{"key":"7_CR31","unstructured":"MASSIF FP7 Project. MAnagement of Security information and events in Service Infrastructures. http:\/\/www.massif-project.eu"},{"key":"7_CR32","doi-asserted-by":"crossref","unstructured":"Strasburg, C., Stakhanova, N., Basu, S., Wong, J.: Intrusion response cost assessment methodology. In: Proceedings of the 4th International Symposium on Information, Computer, and Communications Security, New York, NY, USA, pp. 388\u2013391 (2009)","DOI":"10.1145\/1533057.1533112"},{"key":"7_CR33","unstructured":"National Vulnerability Database. https:\/\/nvd.nist.gov\/"},{"key":"7_CR34","doi-asserted-by":"crossref","unstructured":"Mell, P., Scarfone, K.: A Complete Guide to the Common Vulnerability Scoring System Version 2.0 (2007)","DOI":"10.1049\/iet-ifs:20060055"},{"key":"7_CR35","unstructured":"Common Attack Pattern Enumeration and Classification (CAPEC) [Internet resource]. https:\/\/capec.mitre.org"}],"container-title":["Lecture Notes in Computer Science","Risks and Security of Internet and Systems"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-31811-0_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,2]],"date-time":"2025-06-02T02:27:52Z","timestamp":1748831272000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-31811-0_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319318103","9783319318110"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-31811-0_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016]]}}}