{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,28]],"date-time":"2025-09-28T20:27:00Z","timestamp":1759091220990,"version":"3.37.3"},"reference-count":27,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2017,10,1]],"date-time":"2017-10-01T00:00:00Z","timestamp":1506816000000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Netw Syst Manage"],"published-print":{"date-parts":[[2017,10]]},"DOI":"10.1007\/s10922-017-9428-x","type":"journal-article","created":{"date-parts":[[2017,10,9]],"date-time":"2017-10-09T01:23:13Z","timestamp":1507512193000},"page":"759-783","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["ROI-Driven Cyber Risk Mitigation Using Host Compliance and Network Configuration"],"prefix":"10.1007","volume":"25","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5695-0556","authenticated-orcid":false,"given":"Mohammed Noraden","family":"Alsaleh","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ehab","family":"Al-Shaer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ghaith","family":"Husari","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,10,9]]},"reference":[{"unstructured":"NIST. The technical specification for the security content automation protocol (SCAP). http:\/\/csrc.nist.gov\/publications\/PubsDrafts.html#SP-800-126-Rev-3","key":"9428_CR1"},{"issue":"4","key":"9428_CR2","doi-asserted-by":"crossref","first-page":"561","DOI":"10.3233\/JCS-130475","volume":"21","author":"J Homer","year":"2013","unstructured":"Homer, J., Zhang, S., Ou, X., Schmidt, D., Du, Y., Raj Rajagopalan, S., Singhal, A.: Aggregating vulnerability metrics in enterprise networks using attack graphs. J. Comput. Secur. 21(4), 561\u2013597 (2013)","journal-title":"J. Comput. Secur."},{"doi-asserted-by":"crossref","unstructured":"Ou, X., Boyer, W.F., McQueen, M.A.: A scalable approach to attack graph generation. In: Proceedings of the 13th ACM Conference on Computer and communications Security, pp. 336\u2013345. ACM (2006)","key":"9428_CR3","DOI":"10.1145\/1180405.1180446"},{"doi-asserted-by":"crossref","unstructured":"Sheyner, O., Haines, J., Jha, S., Lippmann, R., Wing, J.M.: Automated generation and analysis of attack graphs. In: 2002 IEEE Symposium on Security and privacy, 2002. Proceedings, pp. 273\u2013284. IEEE (2002)","key":"9428_CR4","DOI":"10.1109\/SECPRI.2002.1004377"},{"doi-asserted-by":"crossref","unstructured":"Waltermire, D., Schmidt, C., Scarfone, K., Ziring, N.: Specification for the extensible configuration checklist description format (XCCDF) v1.2. http:\/\/csrc.nist.gov\/publications\/nistir\/ir7275-rev4\/NISTIR-7275r4.pdf (2012)","key":"9428_CR5","DOI":"10.6028\/NIST.IR.7275r4"},{"unstructured":"Common vulnerability scoring system v3.0: specification document. https:\/\/www.first.org\/cvss\/cvss-v30-specification-v1.8.pdf (2015)","key":"9428_CR6"},{"doi-asserted-by":"crossref","unstructured":"Scarfone, K., Mell, P.: The common configuration scoring system (CCSS): Metrics for software security configuration vulnerabilities. NIST interagency report (2010)","key":"9428_CR7","DOI":"10.6028\/NIST.IR.7502"},{"doi-asserted-by":"crossref","unstructured":"LeMay, E., Scarfone, K., Mell, P.: The common misuse scoring system (CMSS): Metrics for software feature misuse vulnerabilities.\u00a0US Department of Commerce, National Institute of Standards and Technology (2012)","key":"9428_CR8","DOI":"10.6028\/NIST.IR.7864"},{"doi-asserted-by":"crossref","unstructured":"De Moura, L., Bj\u00f8rner, N.: Z3: an efficient smt solver. In: Proceedings of the Theory and Practice of Software, 14th International Conference on Tools and Algorithms for the Construction and Analysis of Systems, TACAS\u201908\/ETAPS\u201908, pp. 337\u2013340. Springer, Berlin (2008)","key":"9428_CR9","DOI":"10.1007\/978-3-540-78800-3_24"},{"unstructured":"Jahoda, M., Gkioka, I., Krtk, R., Prpi, M., Apek, T., Wadeley, S., Ruseva, Y., Svoboda, M.: Red hat enterprise linux 7 security guide (2017)","key":"9428_CR10"},{"unstructured":"Common vulnerabilities and exposures (CVE). http:\/\/cve.mitre.org\/ (2017)","key":"9428_CR11"},{"unstructured":"Common configuration enumeration (CCE). http:\/\/cce.mitre.org\/ (2017)","key":"9428_CR12"},{"doi-asserted-by":"crossref","unstructured":"Al-Shaer, E., Marrero, W., El-Atawy, A., Elbadawi, K.: Network configuration in a box: towards end-to-end verification of network reachability and security. In: ICNP, pp. 123\u2013132 (2009)","key":"9428_CR13","DOI":"10.1109\/ICNP.2009.5339690"},{"unstructured":"Zeng, J.H., Kazemian, P.: Mini-stanford backbone. https:\/\/reproducingnetworkresearch.wordpress.com\/2012\/07\/11\/atpg\/ (2012)","key":"9428_CR14"},{"doi-asserted-by":"crossref","unstructured":"Medina, A., Lakhina, A., Matta, I., Byers, J.: Brite: an approach to universal topology generation. In: Ninth International Symposium on Modeling, Analysis and Simulation of Computer and Telecommunication Systems, 2001. Proceedings, pp 346\u2013353. IEEE (2001)","key":"9428_CR15","DOI":"10.1109\/MASCOT.2001.948886"},{"unstructured":"NOPSEC. State of vulnerability risk management. http:\/\/info.nopsec.com\/sov (2015)","key":"9428_CR16"},{"issue":"9","key":"9428_CR17","doi-asserted-by":"crossref","first-page":"1622","DOI":"10.1016\/j.jss.2009.08.023","volume":"83","author":"SH Houmb","year":"2010","unstructured":"Houmb, S.H., Franqueira, V.N.L., Engum, E.A.: Quantifying security risk level from CVSS estimates of frequency and impact. J. Syst. Softw. 83(9), 1622\u20131634 (2010)","journal-title":"J. Syst. Softw."},{"unstructured":"Joh, H., Malaiya, Y.K.: Defining and assessing quantitative security risk measures using vulnerability lifecycle and cvss metrics. In: The 2011 International Conference on Security and Management (sam) (2011)","key":"9428_CR18"},{"doi-asserted-by":"crossref","unstructured":"Ou, X., Singhal, A.: Security risk analysis of enterprise networks using attack graphs. In: Quantitative Security Risk Assessment of Enterprise Networks, pp. 13\u201323. Springer (2011)","key":"9428_CR19","DOI":"10.1007\/978-1-4614-1860-3"},{"doi-asserted-by":"crossref","unstructured":"Yin, X., Fang, Y., Liu, Y.: Real-time risk assessment of network security based on attack graphs. In: 2013 International Conference on Information Science and Computer Applications (ISCA 2013). Atlantis Press (2013)","key":"9428_CR20","DOI":"10.2991\/isca-13.2013.13"},{"doi-asserted-by":"crossref","unstructured":"Barrere, M., Badonnel, R., Festor, O.: A sat-based autonomous strategy for security vulnerability management. In: Network Operations and Management Symposium (NOMS), 2014 IEEE, pp. 1\u20139 (2014)","key":"9428_CR21","DOI":"10.1109\/NOMS.2014.6838309"},{"doi-asserted-by":"crossref","unstructured":"Ingols, K., Lippmann, R., Piwowarski, K.: Practical attack graph generation for network defense. In: Computer Security Applications Conference, 2006. ACSAC \u201906. 22nd Annual, pp. 121\u2013130 (2006)","key":"9428_CR22","DOI":"10.1109\/ACSAC.2006.39"},{"doi-asserted-by":"crossref","unstructured":"Albanese, M., Jajodia, S., Noel, S.: Time-efficient and cost-effective network hardening using attack graphs. In: 42nd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), 2012, pp. 1\u201312 (2012)","key":"9428_CR23","DOI":"10.1109\/DSN.2012.6263942"},{"issue":"1","key":"9428_CR24","doi-asserted-by":"crossref","first-page":"61","DOI":"10.1109\/TDSC.2011.34","volume":"9","author":"N Poolsappasit","year":"2012","unstructured":"Poolsappasit, N., Dewri, R., Ray, I.: Dynamic security risk management using bayesian attack graphs. IEEE Trans. Dependable Secur. Comput. 9(1), 61\u201374 (2012)","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"issue":"4","key":"9428_CR25","doi-asserted-by":"crossref","first-page":"198","DOI":"10.1109\/TDSC.2013.8","volume":"10","author":"CJ Chung","year":"2013","unstructured":"Chung, C.J., Khatkar, P., Xing, T., Lee, J., Huang, D.: Nice: network intrusion detection and countermeasure selection in virtual network systems. IEEE Trans. Dependable Secur. Comput. 10(4), 198\u2013211 (2013)","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"doi-asserted-by":"crossref","unstructured":"Chung, C.J., Cui, J., Khatkar, P., Huang, D.: Non-intrusive process-based monitoring system to mitigate and prevent VM vulnerability explorations. In: 9th International Conference Conference on Collaborative Computing: Networking, Applications and Worksharing (Collaboratecom), 2013, pp. 21\u201330. IEEE (2013)","key":"9428_CR26","DOI":"10.4108\/icst.collaboratecom.2013.254107"},{"doi-asserted-by":"crossref","unstructured":"Alsaleh, M.N., Husari, G., Al-Shaer, E. : Optimizing the roi of cyber risk mitigation. In: 12th International Conference on Network and Service Management (CNSM), 2016, pp. 223\u2013227. IEEE (2016)","key":"9428_CR27","DOI":"10.1109\/CNSM.2016.7818421"}],"container-title":["Journal of Network and Systems Management"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10922-017-9428-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-017-9428-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-017-9428-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,4]],"date-time":"2019-10-04T06:42:20Z","timestamp":1570171340000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10922-017-9428-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,10]]},"references-count":27,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2017,10]]}},"alternative-id":["9428"],"URL":"https:\/\/doi.org\/10.1007\/s10922-017-9428-x","relation":{},"ISSN":["1064-7570","1573-7705"],"issn-type":[{"type":"print","value":"1064-7570"},{"type":"electronic","value":"1573-7705"}],"subject":[],"published":{"date-parts":[[2017,10]]}}}