{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,11]],"date-time":"2024-09-11T18:59:22Z","timestamp":1726081162896},"publisher-location":"Singapore","reference-count":34,"publisher":"Springer Singapore","isbn-type":[{"type":"print","value":"9789811548246"},{"type":"electronic","value":"9789811548253"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-981-15-4825-3_4","type":"book-chapter","created":{"date-parts":[[2020,4,25]],"date-time":"2020-04-25T08:02:53Z","timestamp":1587801773000},"page":"41-59","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["A Proximity-Based Measure for Quantifying the Risk of Vulnerabilities"],"prefix":"10.1007","author":[{"given":"Ghanshyam S.","family":"Bopche","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gopal N.","family":"Rai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"D. R. Denslin","family":"Brabin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"B. M.","family":"Mehtre","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,4,26]]},"reference":[{"key":"4_CR1","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1109\/TDSC.2011.34","volume":"9","author":"N Poolsappasit","year":"2012","unstructured":"Poolsappasit, N., Dewri, R., Ray, I.: Dynamic security risk management using Bayesian attack graphs. IEEE Trans. Depend. Secur. Comput. 9, 61\u201374 (2012)","journal-title":"IEEE Trans. Depend. Secur. Comput."},{"key":"4_CR2","unstructured":"US-CERT: United states computer emergency response team. https:\/\/www.us-cert.gov\/"},{"key":"4_CR3","unstructured":"SANS. http:\/\/www.sans.org\/newsletters\/cva\/"},{"key":"4_CR4","unstructured":"NVD. https:\/\/nvd.nist.gov\/"},{"key":"4_CR5","unstructured":"Vupen-Security. http:\/\/www.vupen.com\/english\/"},{"key":"4_CR6","unstructured":"Secunia. http:\/\/secunia.com\/about_secunia_advisories\/"},{"key":"4_CR7","unstructured":"Microsoft. http:\/\/www.microsoft.com\/technet\/"},{"key":"4_CR8","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1109\/MSP.2006.145","volume":"4","author":"P Mell","year":"2006","unstructured":"Mell, P., Scarfone, K., Romanosky, S.: Common vulnerability scoring system. IEEE Secur. Privacy 4, 85\u201389 (2006)","journal-title":"IEEE Secur. Privacy"},{"key":"4_CR9","doi-asserted-by":"crossref","unstructured":"Mell, P., Scarfone, K., Romanosky, S.: A complete guide to the common vulnerability scoring system version 2.0, June 2007","DOI":"10.1049\/iet-ifs:20060055"},{"key":"4_CR10","unstructured":"FIRST: Common vulnerability scoring system v3.0: Specification doc, June 2015"},{"key":"4_CR11","unstructured":"MITRE: Common weakness scoring system (2016). https:\/\/cwe.mitre.org\/cwss\/"},{"key":"4_CR12","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1016\/j.cose.2015.04.012","volume":"53","author":"H Holm","year":"2015","unstructured":"Holm, H., Afridi, K.K.: An expert-based investigation of the common vulnerability scoring system. Comput. Secur. 53, 18\u201330 (2015)","journal-title":"Comput. Secur."},{"key":"4_CR13","unstructured":"Holm, H.: Baltic cyber shield: research from a red team versus blue team exercise (2012)"},{"key":"4_CR14","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1109\/TDSC.2013.24","volume":"11","author":"L Wang","year":"2014","unstructured":"Wang, L., Jajodia, S., Singhal, A., Cheng, P., Noel, S.: k-zero day safety: a network security metric for measuring the risk of unknown vulnerabilities. IEEE Trans. Depend. Secur. Comput. 11, 30\u201344 (2014)","journal-title":"IEEE Trans. Depend. Secur. Comput."},{"key":"4_CR15","unstructured":"Sheyner, O., Haines, J., Jha, S., Lippmann, R., Wing, J.: Automated generation and analysis of attack graphs. In: Proceedings of the IEEE Symposium on Security and Privacy, pp. 273\u2013284 (2002)"},{"key":"4_CR16","doi-asserted-by":"crossref","unstructured":"Ammann, P.: Scalable, graph-based network vulnerability analysis. In: Proceedings of the 9th ACM Conference on Computer and Communications Security, pp. 217\u2013224. ACM Press (2002)","DOI":"10.1145\/586110.586140"},{"key":"4_CR17","doi-asserted-by":"crossref","unstructured":"Ou, X., Boyer, W.F.: A scalable approach to attack graph generation. In: Proceedings of the 13th ACM Conference on Computer and Communications Security (CCS), pp. 336\u2013345. ACM Press (2006)","DOI":"10.1145\/1180405.1180446"},{"key":"4_CR18","doi-asserted-by":"crossref","unstructured":"Jajodia, S., Noel, S.: Topological vulnerability analysis: a powerful new approach for network attack prevention, detection, and response. In: Proceedings of Algorithms, Architectures, and Information System Security, Indian Statistical Institute Platinum Jubilee Series, pp. 285\u2013305 (2009)","DOI":"10.1142\/9789812836243_0013"},{"key":"4_CR19","doi-asserted-by":"publisher","first-page":"369","DOI":"10.1007\/s10489-010-0266-8","volume":"36","author":"N Ghosh","year":"2012","unstructured":"Ghosh, N., Ghosh, S.: A planner-based approach to generate and analyze minimal attack graph. Appl. Intell. 36, 369\u2013390 (2012)","journal-title":"Appl. Intell."},{"key":"4_CR20","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cosrev.2014.07.001","volume":"13\u201314","author":"B Kordy","year":"2014","unstructured":"Kordy, B., Pi\u00e8tre-Cambac\u00e9d\u00e8s, L., Schweitzer, P.: DAG-based attack and defense modeling: don\u2019t miss the forest for the attack trees. Comput. Sci. Rev. 13\u201314, 1\u201338 (2014)","journal-title":"Comput. Sci. Rev."},{"key":"4_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1007\/978-3-540-70567-3_22","volume-title":"Data and Applications Security XXII","author":"L Wang","year":"2008","unstructured":"Wang, L., Islam, T., Long, T., Singhal, A., Jajodia, S.: An attack graph-based probabilistic security metric. In: Atluri, V. (ed.) DBSec 2008. LNCS, vol. 5094, pp. 283\u2013296. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-70567-3_22"},{"key":"4_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"98","DOI":"10.1007\/978-3-540-73538-0_9","volume-title":"Data and Applications Security XXI","author":"L Wang","year":"2007","unstructured":"Wang, L., Singhal, A., Jajodia, S.: Measuring the overall security of network configurations using attack graphs. In: Barker, S., Ahn, G.-J. (eds.) DBSec 2007. LNCS, vol. 4602, pp. 98\u2013112. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-73538-0_9"},{"key":"4_CR23","doi-asserted-by":"crossref","unstructured":"Chen, F., Liu, D., Zhang, Y., Su, J.: A scalable approach to analyzing network security using compact attack graphs. J. Netw. 5, 543 (2010)","DOI":"10.4304\/jnw.5.5.543-550"},{"key":"4_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"573","DOI":"10.1007\/978-3-642-15497-3_35","volume-title":"Computer Security \u2013 ESORICS 2010","author":"L Wang","year":"2010","unstructured":"Wang, L., Jajodia, S., Singhal, A., Noel, S.: k-zero day safety: measuring the security risk of networks against unknown attacks. In: Gritzalis, D., Preneel, B., Theoharidou, M. (eds.) ESORICS 2010. LNCS, vol. 6345, pp. 573\u2013587. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-15497-3_35"},{"key":"4_CR25","doi-asserted-by":"crossref","unstructured":"Suh-Lee, C., Jo, J.: Quantifying security risk by measuring network risk conditions. In: 2015 IEEE\/ACIS Proceedings of the 14th International Conference on Computer and Information Science (ICIS), pp. 9\u201314 (2015)","DOI":"10.1109\/ICIS.2015.7166562"},{"key":"4_CR26","doi-asserted-by":"crossref","unstructured":"Mukherjee, P., Mazumdar, C.: Attack difficulty metric for assessment of network security. In: Proceedings of the 13th International Conference on Availability, Reliability and Security, p. 44. ACM (2018)","DOI":"10.1145\/3230833.3232817"},{"key":"4_CR27","doi-asserted-by":"publisher","first-page":"3812","DOI":"10.1016\/j.comcom.2006.06.018","volume":"29","author":"L Wang","year":"2006","unstructured":"Wang, L., Noel, S., Jajodia, S.: Minimum-cost network hardening using attack graphs. Comput. Commun. 29, 3812\u20133824 (2006)","journal-title":"Comput. Commun."},{"key":"4_CR28","doi-asserted-by":"crossref","unstructured":"Phillips, C., Swiler, L.P.: A graph-based system for network-vulnerability analysis. In: Proceedings of the Workshop on New Security Paradigms. NSPW 1998, pp. 71\u201379. ACM, New York (1998)","DOI":"10.1145\/310889.310919"},{"key":"4_CR29","doi-asserted-by":"publisher","first-page":"135","DOI":"10.1007\/s11416-007-0042-4","volume":"3","author":"J Preu\u00df","year":"2007","unstructured":"Preu\u00df, J., Furnell, S.M., Papadaki, M.: Considering the potential of criminal profiling to combat hacking. J. Comput. Virol. 3, 135\u2013141 (2007)","journal-title":"J. Comput. Virol."},{"key":"4_CR30","doi-asserted-by":"crossref","unstructured":"Ghosh, N., Ghosh, S.: An approach for security assessment of network configurations using attack graph. In: 1st International Conference on Networks and Communications, NETCOM 2009, pp. 283\u2013288 (2009)","DOI":"10.1109\/NetCoM.2009.83"},{"key":"4_CR31","doi-asserted-by":"crossref","unstructured":"Ghosh, N., Ghosh, S.: An approach for security assessment of network configurations using attack graph. In: Proceedings of the International Conference on Networks & amp; Communications, pp. 283\u2013288 (2009)","DOI":"10.1109\/NetCoM.2009.83"},{"key":"4_CR32","doi-asserted-by":"crossref","unstructured":"Bopche, G.S., Mehtre, B.M.: Exploiting curse of diversity for improved network security. In: Proceedings of the International Conference on Advances in Computing, Communications and Informatics (ICACCI), pp. 1975\u20131981 (2015)","DOI":"10.1109\/ICACCI.2015.7275907"},{"key":"4_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"295","DOI":"10.1007\/978-3-319-41483-6_21","volume-title":"Data and Applications Security and Privacy XXX","author":"D Borbor","year":"2016","unstructured":"Borbor, D., Wang, L., Jajodia, S., Singhal, A.: Diversifying network services under cost constraints for better resilience against unknown attacks. In: Ranise, S., Swarup, V. (eds.) DBSec 2016. LNCS, vol. 9766, pp. 295\u2013312. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-41483-6_21"},{"key":"4_CR34","doi-asserted-by":"publisher","first-page":"4308","DOI":"10.1016\/j.camwa.2011.09.031","volume":"62","author":"F Zhao","year":"2011","unstructured":"Zhao, F., Huang, H., Jin, H., Zhang, Q.: A hybrid ranking approach to estimate vulnerability for dynamic attacks. Comput. Math. Appl. 62, 4308\u20134321 (2011)","journal-title":"Comput. Math. Appl."}],"container-title":["Communications in Computer and Information Science","Security in Computing and Communications"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-15-4825-3_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,22]],"date-time":"2022-10-22T08:16:16Z","timestamp":1666426576000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-981-15-4825-3_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9789811548246","9789811548253"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-981-15-4825-3_4","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"26 April 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SSCC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Security in Computing and Communication","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Trivandrum","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"India","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 December 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 December 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"sscc2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.acn-conference.org\/sscc2019\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EDAS","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"61","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"22","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"36% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.2","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}