{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,12]],"date-time":"2025-03-12T14:40:04Z","timestamp":1741790404054,"version":"3.38.0"},"publisher-location":"Berlin, Heidelberg","reference-count":26,"publisher":"Springer Berlin Heidelberg","isbn-type":[{"type":"print","value":"9783642224430"},{"type":"electronic","value":"9783642224447"}],"license":[{"start":{"date-parts":[[2011,1,1]],"date-time":"2011-01-01T00:00:00Z","timestamp":1293840000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2011]]},"DOI":"10.1007\/978-3-642-22444-7_3","type":"book-chapter","created":{"date-parts":[[2011,10,6]],"date-time":"2011-10-06T01:29:33Z","timestamp":1317864573000},"page":"35-50","source":"Crossref","is-referenced-by-count":3,"title":["Influence of Attribute Freshness on Decision Making in Usage Control"],"prefix":"10.1007","author":[{"given":"Leanid","family":"Krautsevich","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aliaksandr","family":"Lazouski","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fabio","family":"Martinelli","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Artsiom","family":"Yautsiukhin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"3_CR1","unstructured":"Alberts, C.J., Dorofee, A.J.: OCTAVE Criteria. Technical Report CMU\/SEI-2001-TR-016, CERT (December 2001)"},{"issue":"3","key":"3_CR2","doi-asserted-by":"crossref","first-page":"261","DOI":"10.3233\/HSN-2006-290","volume":"15","author":"A.B. Aziz","year":"2006","unstructured":"Aziz, A.B., Foley, A.S., Herbert, A.J., Swart, A.G.: Reconfiguring role based access control policies using risk semantics. Journal of High Speed Networks\u00a015(3), 261\u2013273 (2006)","journal-title":"Journal of High Speed Networks"},{"issue":"1","key":"3_CR3","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/504909.504910","volume":"5","author":"P. Bonatti","year":"2002","unstructured":"Bonatti, P., De Capitani di Vimercati, S., Samarati, P.: An algebra for composing access control policies. ACM Transactions on Information and System Security\u00a05(1), 1\u201335 (2002)","journal-title":"ACM Transactions on Information and System Security"},{"key":"3_CR4","doi-asserted-by":"crossref","unstructured":"Bouzeghoub, M., Peralta, V.: A framework for analysis of data freshness. In: Proceedings of the International Workshop on Information Quality in Information Systems, pp. 59\u201367 (2004)","DOI":"10.1145\/1012453.1012464"},{"key":"3_CR5","doi-asserted-by":"publisher","first-page":"232","DOI":"10.1109\/ICSE.2002.1007971","volume-title":"Proceedings of the 24th International Conference on Software Engineering (ICSE 2002)","author":"S.A. Butler","year":"2002","unstructured":"Butler, S.A.: Security attribute evaluation method: a cost-benefit approach. In: Proceedings of the 24th International Conference on Software Engineering (ICSE 2002), pp. 232\u2013240. ACM Press, New York (2002)"},{"key":"3_CR6","doi-asserted-by":"publisher","first-page":"222","DOI":"10.1109\/SP.2007.21","volume-title":"Proceedings of the 2007 IEEE Symposium on Security and Privacy","author":"P.-C. Cheng","year":"2007","unstructured":"Cheng, P.-C., Rohatgi, P., Keser, C., Karger, P.A., Wagner, G.M., Reninger, A.S.: Fuzzy multi-level security: An experiment on quantified risk-adaptive access control. In: Proceedings of the 2007 IEEE Symposium on Security and Privacy, pp. 222\u2013230. IEEE Computer Society, Washington, DC, USA (2007)"},{"key":"3_CR7","doi-asserted-by":"publisher","first-page":"419","DOI":"10.1109\/ECUMN.2007.19","volume-title":"Proceedings of the Fourth European Conference on Universal Multiservice Networks (ECUMN 2007)","author":"N.N. Diep","year":"2007","unstructured":"Diep, N.N., Hung, L.X., Zhung, Y., Lee, S., Lee, Y.-K., Lee, H.: Enforcing access control using risk assessment. In: Proceedings of the Fourth European Conference on Universal Multiservice Networks (ECUMN 2007), pp. 419\u2013424. IEEE Computer Society, Washington, DC, USA (2007)"},{"key":"3_CR8","first-page":"156","volume-title":"Proceedings of the 9th ACM Symposium on Access Control Models and Technologies","author":"N. Dimmock","year":"2004","unstructured":"Dimmock, N., Belokosztolszki, A., Eyers, D., Bacon, J., Moody, K.: Using trust and risk in role-based access control policies. In: Proceedings of the 9th ACM Symposium on Access Control Models and Technologies, pp. 156\u2013162. ACM, New York (2004)"},{"key":"3_CR9","volume-title":"Managing Cybersecurity Resources: a Cost-Benefit Analysis","author":"L.A. Gordon","year":"2006","unstructured":"Gordon, L.A., Loeb, M.P.: Managing Cybersecurity Resources: a Cost-Benefit Analysis. McGraw Hill, New York (2006)"},{"key":"3_CR10","doi-asserted-by":"publisher","first-page":"415","DOI":"10.1109\/ISA.2008.114","volume-title":"Proceedings of the 2008 International Conference on Information Security and Assurance (ISA 2008)","author":"Y. Han","year":"2008","unstructured":"Han, Y., Hori, Y., Sakurai, K.: Security policy pre-evaluation towards risk analysis. In: Proceedings of the 2008 International Conference on Information Security and Assurance (ISA 2008), pp. 415\u2013420. IEEE Computer Society, Washington, DC, USA (2008)"},{"key":"3_CR11","doi-asserted-by":"crossref","unstructured":"Hanson, S.O.: Decision theory: A brief introduction (August 1994)","DOI":"10.1007\/978-1-349-23381-6_1"},{"key":"3_CR12","volume-title":"Markov processes for stochastic modeling","author":"O.C. Ibe","year":"2009","unstructured":"Ibe, O.C.: Markov processes for stochastic modeling. Academic Press, London (2009)"},{"key":"3_CR13","doi-asserted-by":"crossref","unstructured":"Krautsevich, L., Lazouski, A., Martinelli, F., Yautsiukhin, A.: Risk-aware usage decision making in highly dynamic systems. In: Proceedings of the The Fifth International Conference on Internet Monitoring and Protection, Barcelona, Spain (May 2010)","DOI":"10.1109\/ICIMP.2010.13"},{"key":"3_CR14","volume-title":"Proceedings of the 18th Euromicro Conference on Parallel, Distributed and Network-Based Processing","author":"L. Krautsevich","year":"2010","unstructured":"Krautsevich, L., Lazouski, A., Martinelli, F., Yautsiukhin, A.: Risk-based usage control for service oriented architecture. In: Proceedings of the 18th Euromicro Conference on Parallel, Distributed and Network-Based Processing. IEEE Computer Society Press, Los Alamitos (2010)"},{"key":"3_CR15","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1109\/SecTech.2008.50","volume-title":"Proceedings of the 2008 International Conference on Security Technology","author":"Y. Li","year":"2008","unstructured":"Li, Y., Sun, H., Chen, Z., Ren, J., Luo, H.: Using trust and risk in access control for grid environment. In: Proceedings of the 2008 International Conference on Security Technology, pp. 13\u201316. IEEE Computer Society, Washington, DC, USA (2008)"},{"key":"3_CR16","doi-asserted-by":"crossref","unstructured":"Martinelli, F., Mori, P., Vaccarelli, A.: Towards continuous usage control on grid computational services. In: Proceedings of the Joint International Conference on Autonomic and Autonomous Systems and International Conference on Networking and Services, ICAS\/ICNS 2005 (2005)","DOI":"10.1109\/ICAS-ICNS.2005.93"},{"key":"3_CR17","unstructured":"McGraw, R.W.: Risk-adaptable access control (radac) (6\/08\/09), http:\/\/csrc.nist.gov\/news_events\/privilege_management_workshop\/radac-Paper0001.pdf"},{"key":"3_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/978-3-642-00587-9_5","volume-title":"Trusted Computing","author":"M. Nauman","year":"2009","unstructured":"Nauman, M., Alam, M., Zhang, X., Ali, T.: Remote attestation of attribute updates and information flows in a ucon system. In: Chen, L., Mitchell, C.J., Martin, A. (eds.) Trust 2009. LNCS, vol.\u00a05471, pp. 63\u201380. Springer, Heidelberg (2009)"},{"key":"3_CR19","doi-asserted-by":"crossref","first-page":"250","DOI":"10.1145\/1755688.1755719","volume-title":"Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security","author":"Q. Ni","year":"2010","unstructured":"Ni, Q., Bertino, E., Lobo, J.: Risk-based access control systems built on fuzzy inferences. In: Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security, pp. 250\u2013260. ACM, New York (2010)"},{"key":"3_CR20","first-page":"57","volume-title":"Proceedings of the 7th ACM Symposium on Access Control Models and Technologies","author":"J. Park","year":"2002","unstructured":"Park, J., Sandhu, R.: Towards usage control models: beyond traditional access control. In: Proceedings of the 7th ACM Symposium on Access Control Models and Technologies, pp. 57\u201364. ACM, New York (2002)"},{"issue":"4","key":"3_CR21","doi-asserted-by":"publisher","first-page":"447","DOI":"10.3233\/JCS-2007-15402","volume":"15","author":"C. Skalka","year":"2007","unstructured":"Skalka, C., Wang, X.S., Chapin, P.: Risk management for distributed authorization. J. Comput. Secur.\u00a015(4), 447\u2013489 (2007)","journal-title":"J. Comput. Secur."},{"key":"3_CR22","unstructured":"Stolen, K., den Braber, F., Dimitrakos, T., Fredriksen, R., Gran, B.A., Houmb, S.-H., Lund, M.S., Stamatiou, Y., Aagedal, J.O.: Model-based risk assessment - the coras approach. In: Proceedings of the Norsk Informatikkkonferanse, Tapir, pp. 239\u2013249 (2002)"},{"key":"3_CR23","unstructured":"Stoneburner, G., Goguen, A., Feringa, A.: Risk management guide for information technology systems. Technical Report 800-30, National Institute of Standards and Technology (2001), http:\/\/csrc.nist.gov\/publications\/nistpubs\/800-30\/sp800-30.pdf (13\/05\/2009)"},{"key":"3_CR24","doi-asserted-by":"publisher","DOI":"10.1002\/047001363X","volume-title":"A First Course in Stochastic Models","author":"H.C. Tijms","year":"2003","unstructured":"Tijms, H.C.: A First Course in Stochastic Models. Wiley, Chichester (2003)"},{"key":"3_CR25","doi-asserted-by":"publisher","first-page":"45","DOI":"10.1145\/1029133.1029140","volume-title":"Proceedings of the 2004 ACM workshop on Formal methods in security engineering (FMSE 2004)","author":"L. Wang","year":"2004","unstructured":"Wang, L., Wijesekera, D., Jajodia, S.: A logic-based framework for attribute based access control. In: Proceedings of the 2004 ACM workshop on Formal methods in security engineering (FMSE 2004), pp. 45\u201355. ACM, New York (2004)"},{"key":"3_CR26","first-page":"45","volume-title":"Proceedings of the 7th International Workshop on Policies for Distributed Systems and Networks","author":"L. Zhang","year":"2006","unstructured":"Zhang, L., Brodsky, A., Jajodia, S.: Toward information sharing: Benefit and risk access control (barac). In: Proceedings of the 7th International Workshop on Policies for Distributed Systems and Networks, pp. 45\u201353. IEEE Computer Society, Washington, DC, USA (2006)"}],"container-title":["Lecture Notes in Computer Science","Security and Trust Management"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-642-22444-7_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,12]],"date-time":"2025-03-12T14:11:17Z","timestamp":1741788677000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-642-22444-7_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011]]},"ISBN":["9783642224430","9783642224447"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-3-642-22444-7_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2011]]}}}