{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,6]],"date-time":"2024-09-06T01:04:01Z","timestamp":1725584641265},"publisher-location":"Berlin, Heidelberg","reference-count":27,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642210396"},{"type":"electronic","value":"9783642210402"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-21040-2_22","type":"book-chapter","created":{"date-parts":[[2011,6,3]],"date-time":"2011-06-03T01:11:43Z","timestamp":1307063503000},"page":"304-319","source":"Crossref","is-referenced-by-count":6,"title":["Formal Analysis of Security Metrics and Risk"],"prefix":"10.1007","author":[{"given":"Leanid","family":"Krautsevich","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fabio","family":"Martinelli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Artsiom","family":"Yautsiukhin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"issue":"5","key":"22_CR1","doi-asserted-by":"publisher","first-page":"601","DOI":"10.1016\/j.ress.2006.02.002","volume":"92","author":"S.J. Bae","year":"2007","unstructured":"Bae, S.J., et al.: Degradation models and implied lifetime distributions. Reliability Engineering & System Safety\u00a092(5), 601\u2013608 (2007)","journal-title":"Reliability Engineering & System Safety"},{"key":"22_CR2","doi-asserted-by":"publisher","first-page":"232","DOI":"10.1109\/ICSE.2002.1007971","volume-title":"Proceedings of the 24th International Conference on Software Engineering (ICSE 2002)","author":"S.A. Butler","year":"2002","unstructured":"Butler, S.A.: Security attribute evaluation method: a cost-benefit approach. In: Proceedings of the 24th International Conference on Software Engineering (ICSE 2002), pp. 232\u2013240. ACM Press, New York (2002)"},{"key":"22_CR3","volume-title":"Proceedings of the 1st Workshop on Quality of Protection","author":"V. Casola","year":"2005","unstructured":"Casola, V., et al.: A SLA evaluation methodology in Service Oriented Architectures. In: Proceedings of the 1st Workshop on Quality of Protection, Milan, Italy. Springer, Heidelberg (2005)"},{"issue":"8","key":"22_CR4","doi-asserted-by":"publisher","first-page":"609","DOI":"10.1016\/S0167-4048(00)08019-6","volume":"19","author":"M.M. Eloff","year":"2000","unstructured":"Eloff, M.M., von Solms, S.H.: Information security management: An approach to combine process certification and product evaluation. Computers & Security\u00a019(8), 609\u2013698 (2000)","journal-title":"Computers & Security"},{"issue":"4","key":"22_CR5","doi-asserted-by":"publisher","first-page":"438","DOI":"10.1145\/581271.581274","volume":"5","author":"L. Gordon","year":"2003","unstructured":"Gordon, L., Loeb, M.: The economics of information security investment. ACM Transactions on Information and System Security\u00a05(4), 438\u2013457 (2003)","journal-title":"ACM Transactions on Information and System Security"},{"key":"22_CR6","volume-title":"Managing Cybersecurity Resources: a Cost-Benefit Analysis","author":"L.A. Gordon","year":"2006","unstructured":"Gordon, L.A., Loeb, M.P.: Managing Cybersecurity Resources: a Cost-Benefit Analysis. McGraw-Hill, New York (2006)"},{"key":"22_CR7","doi-asserted-by":"crossref","unstructured":"Herrmann, D.S.: Complete Guide to Security and Privacy Metrics. Measuring Regulatory Compliance, Operational Resilience, and ROI. Auerbach Publications (2007)","DOI":"10.1201\/9781420013283"},{"key":"22_CR8","unstructured":"ISO\/IEC. ISO\/IEC 27002:2005 Information technology \u2013 Security techniques \u2013 Code of Practice for Information Security Management (2005)"},{"key":"22_CR9","unstructured":"Jansen, W.: Directions in security metric research. Technical Report NISTIR 7564, National institute of Standards and Technology (2009)"},{"key":"22_CR10","volume-title":"Security metrics: replacing fear, uncertainty, and doubt","author":"A. Jaquith","year":"2007","unstructured":"Jaquith, A.: Security metrics: replacing fear, uncertainty, and doubt. Addison-Wesley, Reading (2007)"},{"issue":"4","key":"22_CR11","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1109\/32.588541","volume":"23","author":"E. Jonsson","year":"1997","unstructured":"Jonsson, E., Olovsson, T.: A quantitative model of the security intrusion process based on attacker behavior. IEEE Transactions on Software Engineering\u00a023(4), 235\u2013245 (1997)","journal-title":"IEEE Transactions on Software Engineering"},{"key":"22_CR12","volume-title":"Proceedings of the 1st Workshop on Quality of Protection","author":"G. Karjoth","year":"2005","unstructured":"Karjoth, G., et al.: Service-oriented assurance comprehensive security by explicit assurances. In: Proceedings of the 1st Workshop on Quality of Protection, Milan, Italy, Springer, Heidelberg (2005)"},{"key":"22_CR13","volume-title":"Proceedings of the 1st International Workshop on Measurability of Security in Software Architectures","author":"L. Krautsevich","year":"2010","unstructured":"Krautsevich, L., et al.: Formal approach to security metrics. what does \u201cmore secure\u201d mean for you? In: Proceedings of the 1st International Workshop on Measurability of Security in Software Architectures, ACM Press, New York (2010)"},{"issue":"56","key":"22_CR14","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1016\/j.peva.2003.07.008","volume":"4","author":"B.B. Madan","year":"2004","unstructured":"Madan, B.B., Goseva-Popstojanova, K., Vaidyanathan, K., Trivedi, K.S.: A method for modeling and quantifying the security attributes of intrusion tolerant systems. Performance Evaluatin Journal\u00a04(56), 167\u2013186 (2004)","journal-title":"Performance Evaluatin Journal"},{"key":"22_CR15","doi-asserted-by":"crossref","unstructured":"Manadhata, P., Wing, J.: Measuring a system\u2019s attack surface. Technical Report CMU-TR-04-102, Carnegie Mellon University (2004)","DOI":"10.21236\/ADA458115"},{"key":"22_CR16","doi-asserted-by":"crossref","unstructured":"Manadhata, P., Wing, J.M.: An attack surface metric. Technical Report CMU-CS-05-155, School of Computer Science. Carnegie Mellon University (2005)","DOI":"10.21236\/ADA457096"},{"key":"22_CR17","doi-asserted-by":"crossref","unstructured":"Manadhata, P.K., et al.: An approach to measuring a systems attack surface. Technical Report CMU-CS-07-146, School of Computer Science. Carnegie Mellon University (2007)","DOI":"10.21236\/ADA476977"},{"key":"22_CR18","doi-asserted-by":"crossref","unstructured":"Mullen, R.: The lognormal distribution of software failure rates: application to software reliability growth modeling. In: The Ninth International Symposium on Software Reliability Engineering, pp. 134\u2013142 (November 1998)","DOI":"10.1109\/ISSRE.1998.730872"},{"issue":"5","key":"22_CR19","doi-asserted-by":"publisher","first-page":"633","DOI":"10.1109\/32.815323","volume":"25","author":"R. Ortalo","year":"1999","unstructured":"Ortalo, R., et al.: Experimenting with quantitative evaluation tools for monitoring operational security. IEEE Transactions on Software Engineering\u00a025(5), 633\u2013650 (1999)","journal-title":"IEEE Transactions on Software Engineering"},{"key":"22_CR20","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1145\/1179494.1179502","volume-title":"QoP 2006: Proceedings of the 2nd ACM workshop on Quality of Protection","author":"J. Pamula","year":"2006","unstructured":"Pamula, J., et al.: A weakest-adversary security metric for network configuration security analysis. In: QoP 2006: Proceedings of the 2nd ACM workshop on Quality of Protection, pp. 31\u201338. ACM Press, New York (2006)"},{"key":"22_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1007\/3-540-45831-X_6","volume-title":"Infrastructure Security","author":"S.E. Schechter","year":"2002","unstructured":"Schechter, S.E.: How to buy better testing. In: Davida, G.I., Frankel, Y., Rees, O. (eds.) InfraSec 2002. LNCS, vol.\u00a02437, pp. 73\u201387. Springer, Heidelberg (2002)"},{"issue":"5","key":"22_CR22","doi-asserted-by":"publisher","first-page":"362","DOI":"10.1016\/j.cose.2004.05.003","volume":"23","author":"A. Stewart","year":"2004","unstructured":"Stewart, A.: On risk: perception and direction. Computers & Security\u00a023(5), 362\u2013370 (2004)","journal-title":"Computers & Security"},{"key":"22_CR23","doi-asserted-by":"crossref","unstructured":"Stoneburner, G., et al.: Risk management guide for information technology systems. Technical Report 800-30, National Institute of Standards and Technology (2001)","DOI":"10.6028\/NIST.SP.800-30"},{"key":"22_CR24","doi-asserted-by":"crossref","unstructured":"Swanson, M., et al.: Security metrics guide for information technology systems. Technical Report 800-55, National Institute of Standards and Technology (2003)","DOI":"10.6028\/NIST.SP.800-55"},{"key":"22_CR25","doi-asserted-by":"crossref","unstructured":"Vaughn, R.B., et al.: Information assurance measures and metrics - state of practice and proposed taxonomy. In: Proceedings of the 36th Annual Hawaii International Conference on System Sciences (January 2003)","DOI":"10.1109\/HICSS.2003.1174904"},{"key":"22_CR26","first-page":"283","volume-title":"Proceeedings of the 22nd annual IFIP WG 11.3 working conference on Data and Applications Security","author":"L. Wang","year":"2008","unstructured":"Wang, L., et al.: An attack graph-based probabilistic security metric. In: Proceeedings of the 22nd annual IFIP WG 11.3 working conference on Data and Applications Security, pp. 283\u2013296. Springer-, Heidelberg (2008)"},{"issue":"18","key":"22_CR27","doi-asserted-by":"publisher","first-page":"3812","DOI":"10.1016\/j.comcom.2006.06.018","volume":"29","author":"L. Wang","year":"2006","unstructured":"Wang, L., et al.: Minimum-cost network hardening using attack graphs. Computer Communications\u00a029(18), 3812\u20133824 (2006)","journal-title":"Computer Communications"}],"container-title":["Lecture Notes in Computer Science","Information Security Theory and Practice. Security and Privacy of Mobile Devices in Wireless Communication"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-21040-2_22.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,23]],"date-time":"2020-11-23T22:01:51Z","timestamp":1606168911000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-21040-2_22"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642210396","9783642210402"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-21040-2_22","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2011]]}}}