{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,18]],"date-time":"2026-01-18T10:56:25Z","timestamp":1768733785646,"version":"3.49.0"},"reference-count":45,"publisher":"Springer Science and Business Media LLC","issue":"11","license":[{"start":{"date-parts":[[2022,11,2]],"date-time":"2022-11-02T00:00:00Z","timestamp":1667347200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2022,11,2]],"date-time":"2022-11-02T00:00:00Z","timestamp":1667347200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Multimed Tools Appl"],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1007\/s11042-022-14036-y","type":"journal-article","created":{"date-parts":[[2022,11,2]],"date-time":"2022-11-02T04:18:41Z","timestamp":1667362721000},"page":"16951-16971","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["Analysis and implementation of semi-automatic model for vulnerability exploitations of threat agents in NIST databases"],"prefix":"10.1007","volume":"82","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2523-1297","authenticated-orcid":false,"given":"Gaurav","family":"Sharma","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stilianos","family":"Vidalis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Catherine","family":"Menon","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Niharika","family":"Anand","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,11,2]]},"reference":[{"key":"14036_CR1","unstructured":"Addison S (2002) Introduction to security risk analysis and the cobra approach. C A Secure. Syst. Rep. (Online Ser. Available www.Secure.com"},{"key":"14036_CR2","doi-asserted-by":"crossref","unstructured":"Alberts CJ, Dorofee AJ, Allen JH (2001) OCTAVE catalog of practices, version 2.0. Carnegie-Mellon Univ Pittsburgh Pa Software Engineering Inst","DOI":"10.21236\/ADA389355"},{"key":"14036_CR3","doi-asserted-by":"crossref","unstructured":"Alfadel M, Costa DE, Shihab E (2021) Empirical Analysis of Security Vulnerabilities in Python Packages. In: 2021 IEEE international conference on software analysis, Evolution and Reengineering (SANER), pp. 446\u2013457","DOI":"10.1109\/SANER50967.2021.00048"},{"key":"14036_CR4","doi-asserted-by":"crossref","unstructured":"Allodi L (2017) Economic factors of vulnerability trade and exploitation. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security, pp. 1483\u20131499","DOI":"10.1145\/3133956.3133960"},{"key":"14036_CR5","doi-asserted-by":"crossref","unstructured":"Allodi L, Biagioni S, Crispo B, Labunets K, Massacci F, Santos W (2017) Estimating the assessment difficulty of CVSS environmental metrics: an experiment. In: International Conference on Future Data and Security Engineering, pp. 23\u201339","DOI":"10.1007\/978-3-319-70004-5_2"},{"key":"14036_CR6","unstructured":"Allodi L, Cremonini M, Massacci F, Shim W (2018) The effect of security education and expertise on security assessments: The case of software vulnerabilities. arXiv Prepr. arXiv1808.06547"},{"key":"14036_CR7","unstructured":"Alomar N, Wijesekera P, Qiu E, Egelman S (2020) \u2018You\u2019ve Got Your Nice List of Bugs, Now What?\u2019 Vulnerability Discovery and Management Processes in the Wild. In: Sixteenth Symposium on Usable Privacy and Security ({SOUPS} 2020), pp. 319\u2013339"},{"issue":"1","key":"14036_CR8","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/s10207-019-00445-y","volume":"19","author":"P Aufner","year":"2020","unstructured":"Aufner P (2020) The IoT security gap: a look down into the valley between threat models and their implementation. Int J Inf Secur 19(1):3\u201314","journal-title":"Int J Inf Secur"},{"key":"14036_CR9","unstructured":"Bagstad KJ, Villa F, Johnson GW, Voigt B (2011) ARIES\u2013Artificial Intelligence for Ecosystem Services: a guide to models and data, version 1.0. ARIES Rep. Ser., vol. 1"},{"key":"14036_CR10","doi-asserted-by":"crossref","unstructured":"Berhe S, Demurjian SA, Pavlich-Mariscal J, Saripalle RK, De la Rosa Algar\u00edn A (2021) Leveraging UML for Access Control Engineering in a Collaboration on Duty and Adaptive Workflow Model that Extends NIST RBAC. In: Research Anthology on Recent Trends, Tools, and Implications of Computer Programming, IGI Global, pp. 916\u2013939","DOI":"10.4018\/978-1-7998-3016-0.ch042"},{"issue":"2","key":"14036_CR11","first-page":"1","volume":"1","author":"M Boban","year":"2010","unstructured":"Boban M (2010) Building eGovernment model on the principles of new economic trends and international standards considering protection of citizen privacy and personal data. E-Society J Res Appl 1(2):1\u201315","journal-title":"E-Society J Res Appl"},{"issue":"3","key":"14036_CR12","first-page":"207","volume":"14","author":"P Cisar","year":"2016","unstructured":"Cisar P, Rajnai Z, Cisar SM, Pinter R (2016) Scoring system as a method of improving IT vulnerability status. Ann Fac Eng Hunedoara 14(3):207","journal-title":"Ann Fac Eng Hunedoara"},{"issue":"7","key":"14036_CR13","doi-asserted-by":"publisher","first-page":"1231","DOI":"10.5194\/nhess-17-1231-2017","volume":"17","author":"MC de Ruiter","year":"2017","unstructured":"de Ruiter MC, Ward PJ, Daniell JE, Aerts JCJH (2017) A comparison of flood and earthquake vulnerability assessment indicators. Nat Hazards Earth Syst Sci 17(7):1231\u20131251","journal-title":"Nat Hazards Earth Syst Sci"},{"key":"14036_CR14","volume-title":"The basics of hacking and penetration testing","author":"P Engebretson","year":"2013","unstructured":"Engebretson P (2013) The basics of hacking and penetration testing. Elsevier Hadnagy, Waltham"},{"key":"14036_CR15","doi-asserted-by":"crossref","unstructured":"Feutrill A, Ranathunga D, Yarom Y, Roughan M (2018) The effect of common vulnerability scoring system metrics on vulnerability exploit delay. In: 2018 Sixth International Symposium on Computing and Networking (CANDAR), pp. 1\u201310","DOI":"10.1109\/CANDAR.2018.00009"},{"key":"14036_CR16","doi-asserted-by":"crossref","unstructured":"Franklin J, Wergin C, Booth H (2014) CVSS implementation guidance. Natl Inst Stand Technol NISTIR-7946","DOI":"10.6028\/NIST.IR.7946"},{"key":"14036_CR17","doi-asserted-by":"crossref","unstructured":"Geerts E (2020) Book Review: Vulnerable Futures, Transformative Pasts: On Vulnerability, Temporality, and Ethics by Miri Rozmarin, Peter Lang, 2017, 194 pages. ISBN 978\u20131\u201378707-392-0 (ePub)(also available in print, ePDF and mobi). Helsinki University Press","DOI":"10.33134\/rds.336"},{"key":"14036_CR18","unstructured":"Grother PJ (1995) NIST special database 19. Handprinted forms characters database, Natl. Inst. Stand. Technol., p. 10"},{"key":"14036_CR19","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4842-3627-7","volume-title":"Asset attack vectors: building effective vulnerability management strategies to protect organizations","author":"MJ Haber","year":"2018","unstructured":"Haber MJ, Hibbert B (2018) Asset attack vectors: building effective vulnerability management strategies to protect organizations. Apress"},{"issue":"4","key":"14036_CR20","doi-asserted-by":"publisher","first-page":"3171","DOI":"10.1007\/s13369-019-04319-2","volume":"45","author":"M Humayun","year":"2020","unstructured":"Humayun M, Niazi M, Jhanjhi NZ, Alshayeb M, Mahmood S (2020) Cyber security threats and vulnerabilities: a systematic mapping study. Arab J Sci Eng 45(4):3171\u20133189","journal-title":"Arab J Sci Eng"},{"key":"14036_CR21","unstructured":"Humayun M, Jhanjhi NZ, Almufareh MF, Khalil MI (n.d.) Security Threat and Vulnerability Assessment and Measurement in Secure Software Development"},{"key":"14036_CR22","unstructured":"Ingoldsby TR (2010) Attack tree-based threat risk analysis. Amenaza Technol Ltd, pp. 3\u20139"},{"key":"14036_CR23","doi-asserted-by":"crossref","unstructured":"Jing Y, Ahn G-J, Zhao Z, Hu H (2014) Riskmon: Continuous and automated risk assessment of mobile applications. In: Proceedings of the 4th ACM Conference on Data and Application Security and Privacy, pp. 99\u2013110","DOI":"10.1145\/2557547.2557549"},{"issue":"8","key":"14036_CR24","doi-asserted-by":"publisher","first-page":"1445","DOI":"10.1002\/qre.1567","volume":"30","author":"H Joh","year":"2014","unstructured":"Joh H, Malaiya YK (2014) Modeling skewness in vulnerability discovery. Qual Reliab Eng Int 30(8):1445\u20131459","journal-title":"Qual Reliab Eng Int"},{"key":"14036_CR25","unstructured":"Jones A (2002) Identification of a Method for the Calculation of the Capability of Threat Agents in an Information Environment. Sch. Comput. Pontypridd, Univ. Glamorgan 0\u2013134"},{"key":"14036_CR26","doi-asserted-by":"crossref","unstructured":"Mahmud SMH, Hossin MA, Jahan H, Noori SRH, Bhuiyan T (2018) CSV-ANNOTATE: Generate annotated tables from CSV file. In: 2018 International Conference on Artificial Intelligence and Big Data (ICAIBD), pp. 71\u201375","DOI":"10.1109\/ICAIBD.2018.8396169"},{"key":"14036_CR27","doi-asserted-by":"crossref","unstructured":"Munaiah N, Meneely A (2016) Vulnerability severity scoring and bounties: Why the disconnect?. In: Proceedings of the 2nd International Workshop on Software Analytics, pp. 8\u201314","DOI":"10.1145\/2989238.2989239"},{"issue":"4","key":"14036_CR28","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3005714","volume":"49","author":"M Pendleton","year":"2016","unstructured":"Pendleton M, Garcia-Lebron R, Cho J-H, Xu S (2016) A survey on systems security metrics. ACM Comput Surv 49(4):1\u201335","journal-title":"ACM Comput Surv"},{"key":"14036_CR29","volume-title":"Security in computing","author":"CP Pfleeger","year":"2009","unstructured":"Pfleeger CP (2009) Security in computing. Pearson Education India"},{"key":"14036_CR30","unstructured":"Ralchenko Y, Kramida AE, Reader J (2008) NIST atomic spectra database. Natl. Inst. Stand. Technol. Gaithersburg, MD"},{"key":"14036_CR31","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1016\/j.infsof.2018.06.005","volume":"103","author":"J Ruohonen","year":"2018","unstructured":"Ruohonen J, Rauti S, Hyrynsalmi S, Lepp\u00e4nen V (2018) A case study on software vulnerability coordination. Inf Softw Technol 103:239\u2013257","journal-title":"Inf Softw Technol"},{"key":"14036_CR32","doi-asserted-by":"crossref","unstructured":"Samuel J, Aalab K, Jaskolka J (2020) Evaluating the soundness of security metrics from vulnerability scoring frameworks. In: 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), pp. 442\u2013449","DOI":"10.1109\/TrustCom50675.2020.00067"},{"issue":"3","key":"14036_CR33","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2856126","volume":"48","author":"D Sgandurra","year":"2016","unstructured":"Sgandurra D, Lupu E (2016) Evolution of attacks, threat models, and solutions for virtualized systems. ACM Comput Surv 48(3):1\u201338","journal-title":"ACM Comput Surv"},{"issue":"15","key":"14036_CR34","doi-asserted-by":"publisher","first-page":"1849","DOI":"10.3390\/electronics10151849","volume":"10","author":"G Sharma","year":"2021","unstructured":"Sharma G, Vidalis S, Menon C, Anand N, Kumar S (2021) Analysis and implementation of threat agents profiles in semi-automated manner for a network traffic in real-time information environment. Electronics 10(15):1849","journal-title":"Electronics"},{"key":"14036_CR35","doi-asserted-by":"crossref","unstructured":"Sharma G, Vidalis S, Menon C, Anand N, Pourmoafi S (2021) Study and Analysis of Threat Assessment Model and Methodology in Real-Time Informational Environment. In: 2021 IEEE Bombay Section Signature Conference (IBSSC), pp. 1\u20136","DOI":"10.1109\/IBSSC53889.2021.9673486"},{"key":"14036_CR36","unstructured":"Smith RM, Martell AE, Motekaitis RJ (2004) NIST standard reference database 46. NIST Crit. Sel. Stab. Constants Met. Complexes Database Ver, vol. 2"},{"key":"14036_CR37","unstructured":"Strom BE, Applebaum A, Miller DP, Nickels KC, Pennington AG, Thomas CB, (2018) Mitre att&ck: design and philosophy. Tech. Rep"},{"key":"14036_CR38","volume-title":"Secure computing: threats and safeguards","author":"RC Summers","year":"1997","unstructured":"Summers RC (1997) Secure computing: threats and safeguards. McGraw-Hill, Inc."},{"issue":"118","key":"14036_CR39","first-page":"1","volume":"21","author":"R Tavenard","year":"2020","unstructured":"Tavenard R et al (2020) Tslearn, a machine learning toolkit for time series data. J Mach Learn Res 21(118):1\u20136","journal-title":"J Mach Learn Res"},{"issue":"1","key":"14036_CR40","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1109\/MCS.2014.2364709","volume":"35","author":"A Teixeira","year":"2015","unstructured":"Teixeira A, Sou KC, Sandberg H, Johansson KH (2015) Secure control systems: A quantitative risk management approach. IEEE Control Syst Mag 35(1):24\u201345","journal-title":"IEEE Control Syst Mag"},{"key":"14036_CR41","doi-asserted-by":"crossref","unstructured":"Tevis J-EJ, Hamilton Jr JA (2006) Static analysis of anomalies and security vulnerabilities in executable files. In: Proceedings of the 44th annual Southeast regional conference, pp. 560\u2013565","DOI":"10.1145\/1185448.1185570"},{"key":"14036_CR42","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1016\/j.jnca.2017.10.016","volume":"101","author":"F Ullah","year":"2018","unstructured":"Ullah F, Edwards M, Ramdhany R, Chitchyan R, Babar MA, Rashid A (2018) Data exfiltration: a review of external attack vectors and countermeasures. J Netw Comput Appl 101:18\u201354","journal-title":"J Netw Comput Appl"},{"key":"14036_CR43","doi-asserted-by":"crossref","unstructured":"van Royen ME, Farla P, Mattern KA, Geverts B, Trapman J, Houtsmuller AB (2008) Fluorescence recovery after photobleaching (FRAP) to study nuclear protein dynamics in living cells. In: The nucleus, Springer, pp. 363\u2013385","DOI":"10.1007\/978-1-60327-461-6_20"},{"key":"14036_CR44","unstructured":"Vidalis S, Jones A (2003) Using vulnerability trees for decision making in threat assessment. Univ. Glamorgan, Sch. Comput. Tech. Rep. CS-03-2"},{"issue":"1","key":"14036_CR45","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1016\/j.dss.2010.11.017","volume":"51","author":"H Xu","year":"2011","unstructured":"Xu H, Luo XR, Carroll JM, Rosson MB (2011) The personalization privacy paradox: an exploratory study of the decision-making process for location-aware marketing. Decis Support Syst 51(1):42\u201352","journal-title":"Decis Support Syst"}],"container-title":["Multimedia Tools and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-022-14036-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11042-022-14036-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-022-14036-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,9]],"date-time":"2025-04-09T00:15:44Z","timestamp":1744157744000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11042-022-14036-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,2]]},"references-count":45,"journal-issue":{"issue":"11","published-print":{"date-parts":[[2023,5]]}},"alternative-id":["14036"],"URL":"https:\/\/doi.org\/10.1007\/s11042-022-14036-y","relation":{},"ISSN":["1380-7501","1573-7721"],"issn-type":[{"value":"1380-7501","type":"print"},{"value":"1573-7721","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,2]]},"assertion":[{"value":"8 March 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 June 2022","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 October 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 November 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}