{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T05:13:06Z","timestamp":1779167586689,"version":"3.51.4"},"publisher-location":"Singapore","reference-count":13,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819568567","type":"print"},{"value":"9789819568574","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-6857-4_10","type":"book-chapter","created":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T04:52:15Z","timestamp":1779166335000},"page":"128-140","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Automated VEX Generation and Vulnerability Prioritization Using Inter-Module Symbol Graphs"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-8071-852X","authenticated-orcid":false,"given":"Jeongho","family":"Lee","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8277-8486","authenticated-orcid":false,"given":"Seyoung","family":"Lee","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,1]]},"reference":[{"key":"10_CR1","unstructured":"Cybersecurity, Agency, I.S.: Vulnerability exploitability exchange (vex)-status justifications. Tech. rep., CISA (2022), https:\/\/www.cisa.gov\/sites\/default\/files\/publications\/VEX_Status_Justification_Jun22.pdf"},{"key":"10_CR2","unstructured":"Cybersecurity, Agency, I.S.: Vulnerability exploitability exchange (vex)-use cases. Tech. rep., CISA (2022), https:\/\/www.cisa.gov\/sites\/default\/files\/publications\/VEX_Use_Cases_Aprill2022.pdf"},{"key":"10_CR3","unstructured":"CycloneDX: cyclonedx-node-npm.: https:\/\/github.com\/CycloneDX\/cyclonedx-node-npm, gitHub repository (2022)"},{"key":"10_CR4","unstructured":"Koishybayev, I., Kapravelos, A.: Mininode: Reducing the attack surface of node. js applications. In: 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020). pp. 121\u2013134 (2020)"},{"key":"10_CR5","doi-asserted-by":"crossref","unstructured":"Nielsen, B.B., Torp, M.T., M\u00f8ller, A.: Modular call graph construction for security scanning of node. js applications. In: Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis. pp. 29\u201341 (2021)","DOI":"10.1145\/3460319.3464836"},{"key":"10_CR6","unstructured":"Node.js Foundation: Ecmascript modules. https:\/\/nodejs.org\/api\/esm.html (2024), node.js v24.2.0 Documentation"},{"key":"10_CR7","unstructured":"OWASP Foundation: CycloneDX Bill of Materials Standard. Web page (2024), https:\/\/cyclonedx.org\/"},{"key":"10_CR8","doi-asserted-by":"crossref","unstructured":"Rabbi, M.F., Champa, A.I., Nachuma, C., Zibran, M.F.: Sbom generation tools under microscope: A focus on the npm ecosystem. In: Proceedings of the 39th ACM\/SIGAPP Symposium on Applied Computing. pp. 1233\u20131241 (2024)","DOI":"10.1145\/3605098.3635927"},{"key":"10_CR9","doi-asserted-by":"crossref","unstructured":"Rush, J.L., Ibrahim, J., Saul, K., Brodell, R.T.: Improving patient safety by combating alert fatigue (2016)","DOI":"10.4300\/JGME-D-16-00186.1"},{"key":"10_CR10","doi-asserted-by":"crossref","unstructured":"Szab\u00f3, T.: Incrementalizing production codeql analyses. In: Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering. pp. 1716\u20131726 (2023)","DOI":"10.1145\/3611643.3613860"},{"issue":"9","key":"10_CR11","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3723158","volume":"57","author":"S Tariq","year":"2025","unstructured":"Tariq, S., Baruwal Chhetri, M., Nepal, S., Paris, C.: Alert fatigue in security operations centres: Research challenges and opportunities. ACM Comput. Surv. 57(9), 1\u201338 (2025)","journal-title":"ACM Comput. Surv."},{"key":"10_CR12","doi-asserted-by":"crossref","unstructured":"Zhao, Y., Zhang, Y., Chacko, D., Cappos, J.: Covsbom: Enhancing software bill of materials with integrated code coverage analysis. In: 2024 IEEE 35th International Symposium on Software Reliability Engineering (ISSRE). pp. 228\u2013237. IEEE (2024)","DOI":"10.1109\/ISSRE62328.2024.00031"},{"key":"10_CR13","unstructured":"Zimmermann, M., Staicu, C.A., Tenny, C., Pradel, M.: Small world with high risks: A study of security threats in the npm ecosystem. In: 28th USENIX security symposium (USENIX Security 19). pp. 995\u20131010 (2019)"}],"container-title":["Lecture Notes in Computer Science","Information Security Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-6857-4_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T04:52:21Z","timestamp":1779166341000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-6857-4_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9789819568567","9789819568574"],"references-count":13,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-6857-4_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"1 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"WISA 2025","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information Security Applications","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Jeju Island","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Korea (Republic of)","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"wisa2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.wisa.or.kr\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}