{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T11:05:32Z","timestamp":1782903932939,"version":"3.54.5"},"reference-count":41,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2012,3,29]],"date-time":"2012-03-29T00:00:00Z","timestamp":1332979200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2012,6]]},"DOI":"10.1007\/s10207-012-0160-y","type":"journal-article","created":{"date-parts":[[2012,3,28]],"date-time":"2012-03-28T13:40:20Z","timestamp":1332942020000},"page":"167-188","source":"Crossref","is-referenced-by-count":80,"title":["Optimal security hardening on attack tree models of networks: a cost-benefit analysis"],"prefix":"10.1007","volume":"11","author":[{"given":"Rinku","family":"Dewri","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Indrajit","family":"Ray","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nayot","family":"Poolsappasit","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Darrell","family":"Whitley","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2012,3,29]]},"reference":[{"key":"160_CR1","doi-asserted-by":"crossref","unstructured":"Ammann, P., Wijesekera, D., Kaushik, S.: Scalable, graph-based network vulnerability analysis. In: Proceedings of the 9th Conference on Computer and Communications Security, pp. 217\u2013224 (2002)","DOI":"10.1145\/586110.586140"},{"key":"160_CR2","unstructured":"Jha, S., Sheyner, O., Wing, J.M.: Two formal analysis of attack graphs. In: Proceedings of the 15th IEEE Computer Security Foundations Workshop, pp. 49\u201363 (2002)"},{"key":"160_CR3","doi-asserted-by":"crossref","unstructured":"Phillips, C., Swiler, L. P.: A graph-based system for network-vulnerability analysis. In: Proceedings of the 1998 New Security Paradigms Workshop, pp. 71\u201379 (1998)","DOI":"10.1145\/310889.310919"},{"key":"160_CR4","doi-asserted-by":"crossref","unstructured":"Sheyner, O., Haines, J., Jha, S., Lippmann, R., Wing, J.M.: Automated generation and analysis of attack graphs. In: Proceedings of the IEEE Symposium on Security and Privacy, pp. 273\u2013284 (2002)","DOI":"10.1109\/SECPRI.2002.1004377"},{"key":"160_CR5","doi-asserted-by":"crossref","unstructured":"Swiler, L., Phillips, C., Ellis, D., Chakerian, S.: Computer-attack graph generation tool. In: Proceedings of the DARPA Information Survivability Conference and Exposition II, pp. 307\u2013321 (2001)","DOI":"10.1109\/DISCEX.2001.932182"},{"key":"160_CR6","unstructured":"Dawkins, J., Campbell, C., Hale, J.: Modeling network attacks: extending the attack tree paradigm. In: Proceedings of the Workshop on Statistical Machine Learning Techniques in Computer Intrusion Detection. Johns Hopkins University (2002)"},{"key":"160_CR7","doi-asserted-by":"crossref","unstructured":"Moore, A.P., Ellison, R.J., Linger, R.C.: Attack modeling for information survivability. Technical Note CMU\/SEI-2001-TN-001, Carnegie Melon University\/Software Engineering Institute, March (2001)","DOI":"10.21236\/ADA387544"},{"key":"160_CR8","doi-asserted-by":"crossref","unstructured":"Ray, I., Poolsappasit, N.: Using attack trees to identify malicious attacks from authorized insiders. In: Proceedings of the 10th European Symposium On Research In Computer Security, pp. 231\u2013246 (2005)","DOI":"10.1007\/11555827_14"},{"issue":"12","key":"160_CR9","first-page":"21","volume":"24","author":"B. Schneier","year":"1999","unstructured":"Schneier B.: Attack Trees. Dr. Dobb\u2019s J. 24(12), 21\u201329 (1999)","journal-title":"Dr. Dobb\u2019s J."},{"key":"160_CR10","doi-asserted-by":"crossref","unstructured":"Noel, S., Jajodia, S., O\u2019Berry, B., Jacobs, M.: Efficient minimum-cost network hardening via exploit dependency graphs. In: Proceedings of the 19th Annual Computer Security Applications Conference, pp. 86\u201395 (2003)","DOI":"10.1109\/CSAC.2003.1254313"},{"key":"160_CR11","doi-asserted-by":"crossref","unstructured":"Dewri, R., Poolsappasit, N., Ray, I., Whitley, D.: Optimal security hardening using multi-objective optimization on attack tree models of networks. In: Proceedings of the 14th Conference on Computer and Communications Security, pp. 204\u2013213 (2007)","DOI":"10.1145\/1315245.1315272"},{"issue":"3","key":"160_CR12","doi-asserted-by":"crossref","first-page":"592","DOI":"10.1016\/j.dss.2004.06.004","volume":"41","author":"M. Gupta","year":"2006","unstructured":"Gupta M., Rees J., Chaturvedi A., Chi J.: Matching information security vulnerabilities to organizational security policies: a genetic algorithm approach. Decis. Supp. Syst. 41(3), 592\u2013603 (2006)","journal-title":"Decis. Supp. Syst."},{"key":"160_CR13","doi-asserted-by":"crossref","unstructured":"Bistarelli, S., Dall\u2019Aglio, M., Perretti, P.: Strategic Games on Defense Trees. Formal Aspects in Security and Trust, pp. 1\u201315. Springer, Berlin (2006)","DOI":"10.1007\/978-3-540-75227-1_1"},{"key":"160_CR14","doi-asserted-by":"crossref","unstructured":"Syverson, P.F.: A different look at secure distributed computation. In: Proceedings of the 10th Computer Security Foundations Workshop, pp. 109\u2013115 (1997)","DOI":"10.1109\/CSFW.1997.596797"},{"issue":"1\u20132","key":"160_CR15","doi-asserted-by":"crossref","first-page":"71","DOI":"10.1007\/s10207-004-0060-x","volume":"4","author":"K. Lye","year":"2005","unstructured":"Lye K., Wing J.M.: Game strategies in network security. Int. J. Inf. Secur. 4(1\u20132), 71\u201386 (2005)","journal-title":"Int. J. Inf. Secur."},{"key":"160_CR16","doi-asserted-by":"crossref","unstructured":"Sallhammar, K., Knapskog, S.J., Helvik, B.E.: Using stochastic game theory to compute the expected behavior of attackers. In: Proceedings of the 2005 Symposium on Applications and the Internet Workshops, pp. 102\u2013105 (2005)","DOI":"10.1109\/SAINTW.2005.1619988"},{"key":"160_CR17","doi-asserted-by":"crossref","unstructured":"Sallhammar, K., Helvik, B.E., Knapskog, S.J.: Towards a stochastic model for integrated security and dependability evaluation. In: Proceedings of the First International Conference on Availability, Reliability and Security, pp. 156\u2013165 (2006)","DOI":"10.1109\/ARES.2006.137"},{"issue":"1","key":"160_CR18","doi-asserted-by":"crossref","first-page":"78","DOI":"10.1145\/1053283.1053288","volume":"8","author":"P. Liu","year":"2005","unstructured":"Liu P., Zang W., Yu M.: Incentive-based modeling and inference of attacker intent, objectives, and strategies. ACM Trans. Inf. Syst. Secur. 8(1), 78\u2013118 (2005)","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"160_CR19","doi-asserted-by":"crossref","first-page":"235","DOI":"10.1007\/11962977_19","volume":"4347","author":"A. Buldas","year":"2006","unstructured":"Buldas A., Laud P., Priisalu J., Saarepera M., Willemson J.: Rational choice of security measures via multi-parameter attack trees. Crit. Inf. Infrastruct. Secur. 4347, 235\u2013248 (2006)","journal-title":"Crit. Inf. Infrastruct. Secur."},{"key":"160_CR20","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Nait-Abdesselam, F., Ho, P.: Boosting Markov Reward models for probabilistic security evaluation by characterizing behaviors of attacker and defender. In: Proceedings of the 3rd International Conference on Availability, Reliability and Security, pp. 352\u2013359 (2008)","DOI":"10.1109\/ARES.2008.75"},{"key":"160_CR21","doi-asserted-by":"crossref","unstructured":"Jiang, W., Zhang, H., Tian, Z., Song, X.: A game theoretic method for decision and analysis of the optimal active defense strategy. In: Proceedings of the 2007 International Conference on Computational Intelligence and Security, pp. 819\u2013823 (2007)","DOI":"10.1109\/CIS.2007.31"},{"issue":"2","key":"160_CR22","doi-asserted-by":"crossref","first-page":"109","DOI":"10.1145\/358923.358929","volume":"32","author":"C.A. Coello Coello","year":"2000","unstructured":"Coello Coello C.A.: An updated survey of GA-based multiobjective optimization techniques. ACM Comput. Surv. 32(2), 109\u2013143 (2000)","journal-title":"ACM Comput. Surv."},{"key":"160_CR23","volume-title":"Multi-objective Optimization Using Evolutionary Algorithms","author":"K. Deb","year":"2001","unstructured":"Deb K.: Multi-objective Optimization Using Evolutionary Algorithms. Wiley, New York (2001)"},{"issue":"2","key":"160_CR24","doi-asserted-by":"crossref","first-page":"182","DOI":"10.1109\/4235.996017","volume":"6","author":"K. Deb","year":"2002","unstructured":"Deb K., Pratap A., Agarwal S., Meyarivan T.: A fast and elitist multiobjective genetic algorithm: NSGA\u2013II . IEEE Trans. Evolut. Comput. 6(2), 182\u2013197 (2002)","journal-title":"IEEE Trans. Evolut. Comput."},{"key":"160_CR25","unstructured":"Axelrod, R.: Evolution of Strategies in the Iterated Prisoner\u2019s Dilemma. Genetic Algorithms and Simulated Annealing, pp. 32\u201341. Morgan Kaufmann, Los Altos (1987)"},{"key":"160_CR26","doi-asserted-by":"crossref","DOI":"10.1017\/CBO9780511806292","volume-title":"Evolution and the Theory of Games","author":"J.M. Smith","year":"1982","unstructured":"Smith J.M.: Evolution and the Theory of Games. Cambridge University Press, Cambridge (1982)"},{"key":"160_CR27","doi-asserted-by":"crossref","unstructured":"Rosin, C.D., Blew, R.K.: Methods for competitive co-evolution: finding opponents worth beating. In: Proceedings of the 6th International Conference on Genetic Algorithms, pp. 373\u2013381 (1995)","DOI":"10.1049\/cp:19951077"},{"key":"160_CR28","unstructured":"Hillis, W.D.: Co-evolving parasites improve simulated evolution as an optimization procedure. Artificial Life II. Addison-Wesley, London (1991)"},{"key":"160_CR29","unstructured":"Bull, L.: Coevolutionary Computation: An Introduction. http:\/\/www.cems.uwe.ac.uk\/~lbull\/intro.pdf (1998)"},{"key":"160_CR30","volume-title":"The Blind Watchmaker","author":"R. Dawkins","year":"1986","unstructured":"Dawkins R.: The Blind Watchmaker. Norton & Company, Inc, New York (1986)"},{"issue":"1","key":"160_CR31","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1162\/evco.1997.5.1.1","volume":"5","author":"C.D. Rosin","year":"1997","unstructured":"Rosin C.D., Blew R.K.: New methods for competitive coevolution. Evolut. Comput. 5(1), 1\u201329 (1997)","journal-title":"Evolut. Comput."},{"key":"160_CR32","doi-asserted-by":"crossref","unstructured":"Ficici, S.G., Pollack, J.B.: A game-theoretic memory mechanism for coevolution. In: Proceedings of the Genetic and Evolutionary Computation Conference, pp. 286\u2013297 (2003)","DOI":"10.1007\/3-540-45105-6_35"},{"key":"160_CR33","unstructured":"Stanley, K.O., Miikkulainen, R.: The dominance tournament method of monitoring progress in coevolution. In: Proceedings of the Genetic and Evolutionary Computation Conference Workshop Program, pp. 242\u2013248 (2002)"},{"key":"160_CR34","doi-asserted-by":"crossref","unstructured":"Stoneburner, G., Goguen, A., Feringa, A.: Risk management guide for information technology systems. NIST Special Publication, pp. 800\u2013830 (2002)","DOI":"10.6028\/NIST.SP.800-30"},{"key":"160_CR35","unstructured":"Berger, B.: Data-centric Quantitative Computer Security Risk Assessment. Information Security Reading Room, SANS (2003)"},{"issue":"1","key":"160_CR36","doi-asserted-by":"crossref","first-page":"5","DOI":"10.3233\/JCS-2002-101-202","volume":"10","author":"W. Lee","year":"2002","unstructured":"Lee W.: Toward cost-sensitive modeling for intrusion detection and response. J. Comput. Secur. 10(1), 5\u201322 (2002)","journal-title":"J. Comput. Secur."},{"key":"160_CR37","doi-asserted-by":"crossref","unstructured":"Butler, S.A.: Security attribute evaluation method: a cost-benefit approach. In: Proceedings of the 24rd International Conference on Software Engineering, pp. 232\u2013240 (2002)","DOI":"10.1145\/581339.581370"},{"key":"160_CR38","unstructured":"Butler, S.A., Fischbeck, P.: Multi-attribute risk assessment. In: Proceedings of SREIS02 in conjunction with the 10th IEEE International Requirements Engineering Conference (2002)"},{"issue":"2","key":"160_CR39","doi-asserted-by":"crossref","first-page":"286","DOI":"10.2307\/1969529","volume":"54","author":"J. Nash","year":"1950","unstructured":"Nash J.: Non-cooperative games. Ann. Math. 54(2), 286\u2013295 (1950)","journal-title":"Ann. Math."},{"key":"160_CR40","volume-title":"Genetic Algorithms in Search, Optimization, and Machine Learning","author":"D.E. Goldberg","year":"1989","unstructured":"Goldberg D.E.: Genetic Algorithms in Search, Optimization, and Machine Learning. Addison-Wesley, New York (1989)"},{"issue":"5","key":"160_CR41","doi-asserted-by":"crossref","first-page":"443","DOI":"10.1109\/TEVC.2002.800880","volume":"6","author":"E. Alba","year":"2002","unstructured":"Alba E., Tomassini M.: Parallelism and evolutionary algorithms. IEEE Trans. Evolut. Comput. 6(5), 443\u2013462 (2002)","journal-title":"IEEE Trans. Evolut. Comput."}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-012-0160-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-012-0160-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-012-0160-y","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,24]],"date-time":"2025-03-24T05:45:40Z","timestamp":1742795140000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-012-0160-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,3,29]]},"references-count":41,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2012,6]]}},"alternative-id":["160"],"URL":"https:\/\/doi.org\/10.1007\/s10207-012-0160-y","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,3,29]]}}}