{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,7]],"date-time":"2025-11-07T09:15:20Z","timestamp":1762506920214},"publisher-location":"Cham","reference-count":28,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319474120"},{"type":"electronic","value":"9783319474137"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-47413-7_17","type":"book-chapter","created":{"date-parts":[[2016,10,4]],"date-time":"2016-10-04T16:20:15Z","timestamp":1475598015000},"page":"294-313","source":"Crossref","is-referenced-by-count":15,"title":["A Game-Theoretic Approach to Respond to Attacker Lateral Movement"],"prefix":"10.1007","author":[{"given":"Mohammad A.","family":"Noureddine","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ahmed","family":"Fawaz","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"William H.","family":"Sanders","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tamer","family":"Ba\u015far","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,10,5]]},"reference":[{"key":"17_CR1","unstructured":"The Bro network security monitor (2014). https:\/\/www.bro.org\/"},{"key":"17_CR2","unstructured":"Lateral movement: How do threat actors move deeper into your network. Technical report, Trend Micro (2003)"},{"key":"17_CR3","doi-asserted-by":"crossref","first-page":"47","DOI":"10.1103\/RevModPhys.74.47","volume":"74","author":"R Albert","year":"2002","unstructured":"Albert, R., Barab\u00e1si, A.: Statistical mechanics of complex networks. Rev. Mod. Phys. 74, 47\u201397 (2002)","journal-title":"Rev. Mod. Phys."},{"key":"17_CR4","doi-asserted-by":"crossref","unstructured":"Alpcan, T., Ba\u015far, T.: A game theoretic approach to decision and analysis in network intrusion detection. In: Proceedings of the 42nd IEEE Conference on Decision and Control, vol. 3, pp. 2595\u20132600, December 2003","DOI":"10.1109\/CDC.2003.1273013"},{"key":"17_CR5","doi-asserted-by":"crossref","DOI":"10.1017\/CBO9780511760778","volume-title":"Network Security: A Decision and Game-Theoretic Approach","author":"T Alpcan","year":"2010","unstructured":"Alpcan, T., Ba\u015far, T.: Network Security: A Decision and Game-Theoretic Approach. Cambridge University Press, New York (2010)"},{"key":"17_CR6","doi-asserted-by":"crossref","unstructured":"Bloem, M., Alpcan, T., Ba\u015far, T.: Intrusion response as a resource allocation problem. In: Proceedings of the 45th IEEE Conference on Decision and Control, pp. 6283\u20136288, December 2006","DOI":"10.1109\/CDC.2006.376981"},{"issue":"4","key":"17_CR7","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1016\/S1353-4858(14)70040-6","volume":"2014","author":"R Brewer","year":"2014","unstructured":"Brewer, R.: Advanced persistent threats: minimizing the damage. Netw. Secur. 2014(4), 5\u20139 (2014)","journal-title":"Netw. Secur."},{"key":"17_CR8","doi-asserted-by":"crossref","unstructured":"Bronk, C., Tikk-Rangas, E.: Hack or attack? Shamoon and the evolution of cyber conflict, February 2013. http:\/\/ssrn.com\/abstract=2270860","DOI":"10.2139\/ssrn.2270860"},{"issue":"5","key":"17_CR9","first-page":"1","volume":"1695","author":"G Csardi","year":"2006","unstructured":"Csardi, G., Nepusz, T.: The iGraph software package for complex network research. InterJ. Complex Syst. 1695(5), 1\u20139 (2006)","journal-title":"InterJ. Complex Syst."},{"volume-title":"Intrusion Detection Systems","year":"2008","key":"17_CR10","unstructured":"Di Pietro, R., Mancini, L.V. (eds.): Intrusion Detection Systems. Springer, New York (2008)"},{"key":"17_CR11","unstructured":"Hutchins, E.M., Cloppert, M.J., Amin, R.M.: Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. In: Leading Issues in Information Warfare and Security Research, vol. 1, p. 80 (2011)"},{"key":"17_CR12","unstructured":"Jones, E., Oliphant, T., Peterson, P.: SciPy: open source scientific tools for Python (2001). http:\/\/www.scipy.org\/ . Accessed 16 June 2016"},{"issue":"3","key":"17_CR13","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1109\/MSP.2011.67","volume":"9","author":"R Langner","year":"2011","unstructured":"Langner, R.: Stuxnet: dissecting a cyberwarfare weapon. IEEE Secur. Priv. 9(3), 49\u201351 (2011)","journal-title":"IEEE Secur. Priv."},{"key":"17_CR14","unstructured":"Lee, R.M., Assante, M.J., Conway, T.: Analysis of the cyber attack on the Ukrainian power grid. SANS Industrial Control Systems (2016)"},{"issue":"3","key":"17_CR15","doi-asserted-by":"crossref","first-page":"25:1","DOI":"10.1145\/2480741.2480742","volume":"45","author":"MH Manshaei","year":"2013","unstructured":"Manshaei, M.H., Zhu, Q., Alpcan, T., Ba\u015far, T., Hubaux, J.: Game theory meets network security, privacy. ACM Comput. Surv. 45(3), 25:1\u201325:39 (2013)","journal-title":"ACM Comput. Surv."},{"key":"17_CR16","unstructured":"McKelvey, R.D., McLennan, A.M., Turocy, T.L.: Gambit: software tools for game theory. Technical report, Version 15.1.0 (2016)"},{"issue":"6","key":"17_CR17","doi-asserted-by":"crossref","first-page":"189","DOI":"10.1088\/1367-2630\/9\/6\/189","volume":"9","author":"M Nekovee","year":"2007","unstructured":"Nekovee, M.: Worm epidemics in wireless ad hoc networks. New J. Phys. 9(6), 189 (2007)","journal-title":"New J. Phys."},{"key":"17_CR18","doi-asserted-by":"crossref","unstructured":"Nguyen, K.C., Alpcan, T., Ba\u015far, T.: Fictitious play with time-invariant frequency update for network security. In: Proceedings of the IEEE International Conference on Control Applications, pp. 65\u201370, September 2010","DOI":"10.1109\/CCA.2010.5611248"},{"key":"17_CR19","doi-asserted-by":"crossref","DOI":"10.1093\/acprof:oso\/9780198506263.001.0001","volume-title":"Random Geometric Graphs","author":"M Penrose","year":"2003","unstructured":"Penrose, M.: Random Geometric Graphs, vol. 5. Oxford University Press, Oxford (2003)"},{"key":"17_CR20","unstructured":"Roesch, M.: Snort: lightweight intrusion detection for networks. In: Proceedings of USENIX, LISA 1999, pp. 229\u2013238 (1999)"},{"issue":"1","key":"17_CR21","first-page":"1","volume":"12","author":"A Shameli-Sendi","year":"2012","unstructured":"Shameli-Sendi, A., Ezzati-Jivan, N., Jabbarifar, M., Dagenais, M.: Intrusion response systems: survey and taxonomy. Int. J. Comput. Sci. Netw. Secur 12(1), 1\u201314 (2012)","journal-title":"Int. J. Comput. Sci. Netw. Secur"},{"key":"17_CR22","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"344","DOI":"10.1007\/978-3-642-39218-4_26","volume-title":"Security and Privacy Protection in Information Processing Systems","author":"CB Simmons","year":"2013","unstructured":"Simmons, C.B., Shiva, S.G., Bedi, H.S., Shandilya, V.: ADAPT: a game inspired attack-defense and performance metric taxonomy. In: Janczewski, L.J., Wolfe, H.B., Shenoi, S. (eds.) SEC 2013. IAICT, vol. 405, pp. 344\u2013365. Springer, Heidelberg (2013). doi: 10.1007\/978-3-642-39218-4_26"},{"issue":"1\u20132","key":"17_CR23","first-page":"169","volume":"1","author":"N Stakhanova","year":"2007","unstructured":"Stakhanova, N., Basu, S., Wong, J.: A taxonomy of intrusion response systems. Int. J. Inf. Comput. Secur. 1(1\u20132), 169\u2013184 (2007)","journal-title":"Int. J. Inf. Comput. Secur."},{"key":"17_CR24","unstructured":"Trend Micro: Understanding targeted attacks: six components oftargeted attacks, November 2015. http:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/cyber-attacks\/targeted-attacks-six-components . Accessed 06 May 2016"},{"issue":"9","key":"17_CR25","doi-asserted-by":"crossref","first-page":"1617","DOI":"10.1109\/49.12889","volume":"6","author":"BM Waxman","year":"1988","unstructured":"Waxman, B.M.: Routing of multipoint connections. IEEE J. Sel. Areas Commun. 6(9), 1617\u20131622 (1988)","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"17_CR26","doi-asserted-by":"crossref","unstructured":"Weaver, N., Paxson, V., Staniford, S., Cunningham, R.: A taxonomy of computer worms. In: Proceedings of the 2003 ACM Workshop on Rapid Malcode, pp. 11\u201318. ACM, New York (2003)","DOI":"10.1145\/948187.948190"},{"key":"17_CR27","doi-asserted-by":"crossref","unstructured":"Zhu, Q., Ba\u015far, T.: Dynamic policy-based IDS configuration. In: Proceedings of the 48th IEEE Conference on Decision and Control, pp. 8600\u20138605, December 2009","DOI":"10.1109\/CDC.2009.5399894"},{"issue":"2","key":"17_CR28","doi-asserted-by":"crossref","first-page":"395","DOI":"10.1109\/TPDS.2013.211","volume":"25","author":"SA Zonouz","year":"2014","unstructured":"Zonouz, S.A., Khurana, H., Sanders, W.H., Yardley, T.M.: RRE: a game-theoretic intrusion response and recovery engine. IEEE Trans. Parallel Distrib. Syst. 25(2), 395\u2013406 (2014)","journal-title":"IEEE Trans. Parallel Distrib. Syst."}],"container-title":["Lecture Notes in Computer Science","Decision and Game Theory for Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-47413-7_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,14]],"date-time":"2019-09-14T03:56:42Z","timestamp":1568433402000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-47413-7_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319474120","9783319474137"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-47413-7_17","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2016]]}}}