{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,1,18]],"date-time":"2024-01-18T01:03:34Z","timestamp":1705539814624},"reference-count":35,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2016,7,19]],"date-time":"2016-07-19T00:00:00Z","timestamp":1468886400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2017,11]]},"DOI":"10.1007\/s10207-016-0345-x","type":"journal-article","created":{"date-parts":[[2016,7,19]],"date-time":"2016-07-19T13:26:59Z","timestamp":1468934819000},"page":"673-690","update-policy":"http:\/\/dx.doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["Periodicity in software vulnerability discovery, patching and exploitation"],"prefix":"10.1007","volume":"16","author":[{"given":"HyunChul","family":"Joh","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yashwant K.","family":"Malaiya","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2016,7,19]]},"reference":[{"issue":"1","key":"345_CR1","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1109\/TR.2008.916872","volume":"57","author":"OH Alhazmi","year":"2008","unstructured":"Alhazmi, O.H., Malaiya, Y.K.: Application of vulnerability discovery models to major operating systems. IEEE Trans. Reliab. 57(1), 14\u201322 (2008)","journal-title":"IEEE Trans. Reliab."},{"key":"345_CR2","doi-asserted-by":"crossref","unstructured":"Anbalagan, P., Vouk, M.: \u201cDays of the week\u201d effect in predicting the time taken to fix defects. In: DEFECTS\u201909: Proceedings of the 2nd International Workshop on Defects in Large Software Systems, pp. 29\u201330, New York, NY, USA. ACM (2009)","DOI":"10.1145\/1555860.1555871"},{"key":"345_CR3","unstructured":"Anderson, R: Security in open versus closed systems\u2014the dance of boltzmann, coase and moore. In: Conference on Open Source Software, Economics, Law and Policy, pp. 1\u201315 (2002)"},{"issue":"1","key":"345_CR4","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1109\/MSP.2005.12","volume":"3","author":"A Arora","year":"2005","unstructured":"Arora, A., Telang, R.: Economics of software vulnerability disclosure. IEEE Secur. Priv. 3(1), 20\u201325 (2005)","journal-title":"IEEE Secur. Priv."},{"key":"345_CR5","volume-title":"Time Series Forecsting: Unified Concepts and Computer Implementation","author":"BL Bowerman","year":"1987","unstructured":"Bowerman, B.L., O\u2019connell, R.T.: Time Series Forecsting: Unified Concepts and Computer Implementation, 2nd edn. Duxbury Press, Boston (1987)","edition":"2"},{"key":"345_CR6","doi-asserted-by":"crossref","unstructured":"Bozorgi, M., Saul, L.K., Savage, S., Voelker, G.M.: Beyond heuristics: learning to classify vulnerabilities and predict exploits. In: Proceedings of the 16th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD\u201910, pp. 105\u2013114, New York, NY, USA. ACM (2010)","DOI":"10.1145\/1835804.1835821"},{"issue":"1","key":"345_CR7","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1016\/j.psychres.2004.04.017","volume":"142","author":"JR Carrion-Baralt","year":"2006","unstructured":"Carrion-Baralt, J.R., Smith, C.J., Rossy-Fullana, E., Lewis-Femandez, R., Davis, K.L., Silverman, J.M.: Seasonality effects on schizophrenic births in multiplex families in a tropical island. Psychiatry Res. 142(1), 93\u201397 (2006)","journal-title":"Psychiatry Res."},{"issue":"9","key":"345_CR8","first-page":"2367","volume":"21","author":"K Chen","year":"2010","unstructured":"Chen, K., Feng, D.-G., Su, P.-R., Nie, C.-J., Zhang, X.-F.: Multi-cycle vulnerability discovery model for prediction. J. Softw. 21(9), 2367\u20132375 (2010)","journal-title":"J. Softw."},{"key":"345_CR9","doi-asserted-by":"crossref","unstructured":"Condon, E., He, A., Cukier, M.: Analysis of computer security incident data using time series models. In: ISSRE\u201908: Proceedings of the 2008 19th International Symposium on Software Reliability Engineering, pp. 77\u201386, Washington, DC, USA. IEEE Computer Society (2008)","DOI":"10.1109\/ISSRE.2008.39"},{"issue":"1","key":"345_CR10","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/32.895984","volume":"27","author":"SG Eick","year":"2001","unstructured":"Eick, S.G., Graves, T.L., Karr, A.F., Marron, J.S., Mockus, A.: Does code decay? Assessing the evidence from change management data. IEEE Trans. Softw. Eng. 27(1), 1\u201312 (2001)","journal-title":"IEEE Trans. Softw. Eng."},{"key":"345_CR11","first-page":"255","volume":"23","author":"R Goonatilake","year":"2007","unstructured":"Goonatilake, R., Herath, A., Herath, S., Herath, S., Herath, J.: Intrusion detection using the chi-square goodness-of-fit test for information assurance, network, forensics and software security. J. Comput. Small Coll. 23, 255\u2013263 (2007)","journal-title":"J. Comput. Small Coll."},{"issue":"2","key":"345_CR12","doi-asserted-by":"crossref","first-page":"418","DOI":"10.1016\/j.jfineco.2007.02.003","volume":"87","author":"SL Heston","year":"2008","unstructured":"Heston, S.L., Sadka, R.: Seasonality in the cross-section of stock returns. J. Financ. Econ. 87(2), 418\u2013445 (2008)","journal-title":"J. Financ. Econ."},{"key":"345_CR13","volume-title":"Security Metrics: Replacing Fear, Uncertainty and Doubt","author":"A Jaquith","year":"2007","unstructured":"Jaquith, A.: Security Metrics: Replacing Fear, Uncertainty and Doubt. Addison-Wesley Professional, Boston (2007)"},{"issue":"3","key":"345_CR14","doi-asserted-by":"crossref","first-page":"881-98","DOI":"10.1111\/j.1540-6261.1990.tb05110.x","volume":"45","author":"N Jegadeesh","year":"1990","unstructured":"Jegadeesh, N.: Evidence of predictable behavior of security returns. J. Finance 45(3), 881-98 (1990)","journal-title":"J. Finance"},{"key":"345_CR15","unstructured":"Joh, H., Chaichana, S., Malaiya, Y.K.: Short-term periodicity in security vulnerability activity. In: International Symposium on Software Reliability Engineering, pp. 408\u2013409 (2010)"},{"key":"345_CR16","doi-asserted-by":"crossref","unstructured":"Joh, H., Malaiya, Y. K.: Seasonal variation in the vulnerability discovery process. In: ICST\u201909: International Conference on Software Testing, Verification, and Validation, pp. 191\u2013200, Los Alamitos, CA, USA. IEEE Computer Society (2009)","DOI":"10.1109\/ICST.2009.9"},{"key":"345_CR17","doi-asserted-by":"publisher","unstructured":"Joh, H., Malaiya, Y.K.: Modeling skewness in vulnerability discovery. Qual. Reliab. Eng. Int. 30(8), 1445\u20131459 (2014). doi: 10.1002\/qre.1567","DOI":"10.1002\/qre.1567"},{"key":"345_CR18","doi-asserted-by":"crossref","unstructured":"Kim, J., Malaiya, Y.K., Ray, I.: Vulnerability discovery in multi-version software systems. In: HASE\u201907: Proceedings of the 10th IEEE High Assurance Systems Engineering Symposium, pp. 141\u2013148, Washington, DC, USA. IEEE Computer Society (2007)","DOI":"10.1109\/HASE.2007.55"},{"issue":"1","key":"345_CR19","doi-asserted-by":"crossref","first-page":"227","DOI":"10.1016\/j.tourman.2006.01.003","volume":"28","author":"E Koc","year":"2007","unstructured":"Koc, E., Altinay, G.: An analysis of seasonality in monthly per person tourist spending in Turkish inbound tourism from a market segmentation perspective. Tour. Manag. 28(1), 227\u2013237 (2007)","journal-title":"Tour. Manag."},{"issue":"6","key":"345_CR20","doi-asserted-by":"crossref","first-page":"455","DOI":"10.1007\/s10207-009-0092-3","volume":"8","author":"M Kozina","year":"2009","unstructured":"Kozina, M., Golub, M., Gro\u0161, S.: A method for identifying web applications. Int. J. Inf. Secur. 8(6), 455\u2013467 (2009)","journal-title":"Int. J. Inf. Secur."},{"key":"345_CR21","doi-asserted-by":"crossref","first-page":"1033","DOI":"10.1007\/s00227-004-1394-7","volume":"145","author":"J Maes","year":"2004","unstructured":"Maes, J., Van Damme, S., Meire, P., Ollevier, F.: Statistical modeling of seasonal and environmental influences on the population dynamics of an estuarine fish community. Mar. Biol. 145, 1033\u20131042 (2004)","journal-title":"Mar. Biol."},{"key":"345_CR22","doi-asserted-by":"crossref","unstructured":"Massacci, F., Nguyen, V.H.: Which is the Right Source for Vulnerability Studies? An Empirical Analysis on Mozilla Firefox. Technical report. University of Trento, Italy (2010)","DOI":"10.1145\/1853919.1853925"},{"key":"345_CR23","volume-title":"An Introduction to Statistical Methods and Data Analysis","author":"RL Ott","year":"2000","unstructured":"Ott, R.L., Longnecker, M.T.: An Introduction to Statistical Methods and Data Analysis, 5th edn. Duxbury press, North Scituate (2000)","edition":"5"},{"key":"345_CR24","doi-asserted-by":"crossref","unstructured":"Ozment, A.: Improving vulnerability discovery models. In: QoP\u201907: Proceedings of the 2007 ACM Workshop on Quality of Protection, pp. 6\u201311, New York, NY, USA. ACM (2007)","DOI":"10.1145\/1314257.1314261"},{"key":"345_CR25","unstructured":"Ozment, A., Schechter, S.E.: Milk or wine: does software security improve with age? In: USENIX-SS\u201906: Proceedings of the 15th Conference on USENIX Security Symposium, Berkeley, CA, USA. USENIX Association (2006)"},{"key":"345_CR26","volume-title":"Security in Computing","author":"CP Pfleeger","year":"2003","unstructured":"Pfleeger, C.P., Pfleeger, S.L.: Security in Computing, 3rd edn. Prentice Hall PTR, Upper Saddle River (2003)","edition":"3"},{"key":"345_CR27","unstructured":"Qualys, I.: The laws of vulnerabilities 2.0. In Black Hat 2009, Presented by Wolfgang Kandek (CTO) (July 28, 2009)"},{"key":"345_CR28","unstructured":"Rescorla, E.: Security holes. who cares? In: SSYM\u201903: Proceedings of the 12th Conference on USENIX Security Symposium, pp. 75\u201390, Berkeley, CA, USA. USENIX Association (2003)"},{"key":"345_CR29","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1109\/MSP.2005.17","volume":"3","author":"E Rescorla","year":"2005","unstructured":"Rescorla, E.: Is finding security holes a good idea? IEEE Secur. Priv. 3, 14\u201319 (2005)","journal-title":"IEEE Secur. Priv."},{"issue":"5","key":"345_CR30","doi-asserted-by":"crossref","first-page":"483-8","DOI":"10.1023\/A:1007653329972","volume":"16","author":"M Rios","year":"2000","unstructured":"Rios, M., Garcia, J.M., Sanchez, J.A., Perez, D.: A statistical analysis of the seasonality in pulmonary tuberculosis. Eur. J. Epidemiol. 16(5), 483-8 (2000)","journal-title":"Eur. J. Epidemiol."},{"key":"345_CR31","first-page":"213","volume":"18","author":"A Romanov","year":"2010","unstructured":"Romanov, A., Tsubaki, H., Okamoto, E.: An approach to perform quantitative information security risk assessment in it landscapes. JIP 18, 213\u2013226 (2010)","journal-title":"JIP"},{"key":"345_CR32","doi-asserted-by":"crossref","unstructured":"Salehian, A.: Arima time series modeling for forecasting thermal rating of transmission lines. In: Transmission and Distribution Conference and Exposition, 2003 IEEE PES, vol. 3, pp. 875\u2013879 (2003)","DOI":"10.1109\/TDC.2003.1335052"},{"key":"345_CR33","unstructured":"Symantec. Symantec global internet security threat report: trends for 2009, vol. XV (2010)"},{"issue":"4","key":"345_CR34","doi-asserted-by":"crossref","first-page":"362","DOI":"10.1109\/TPDS.2004.1271185","volume":"15","author":"N Tran","year":"2004","unstructured":"Tran, N., Reed, D.: Automatic arima time series modeling for adaptive i\/o prefetching. IEEE Trans. Parallel Distrib. Syst. 15(4), 362\u2013377 (2004)","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"345_CR35","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Zheng, X., Zeng, D., Cui, K., Luo, C., He, S., Leischow, S.: Discovering seasonal patterns of smoking behavior using online search information. In: Intelligence and Security Informatics (ISI), 2013 IEEE International Conference on, pp. 371\u2013373 (2013)","DOI":"10.1109\/ISI.2013.6578861"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10207-016-0345-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-016-0345-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-016-0345-x","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-016-0345-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,11]],"date-time":"2019-09-11T07:08:34Z","timestamp":1568185714000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10207-016-0345-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,7,19]]},"references-count":35,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2017,11]]}},"alternative-id":["345"],"URL":"https:\/\/doi.org\/10.1007\/s10207-016-0345-x","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,7,19]]}}}