{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T08:13:10Z","timestamp":1778227990461,"version":"3.51.4"},"reference-count":83,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/100008610","name":"Estonian Academy of Sciences","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100008610","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002301","name":"ETAg","doi-asserted-by":"publisher","award":["PRG2531"],"award-info":[{"award-number":["PRG2531"]}],"id":[{"id":"10.13039\/501100002301","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100011804","name":"APNIC Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100011804","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000921","name":"European Cooperation in Science and Technology","doi-asserted-by":"publisher","award":["CA22168"],"award-info":[{"award-number":["CA22168"]}],"id":[{"id":"10.13039\/501100000921","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Journal of Information Security and Applications"],"published-print":{"date-parts":[[2026,3]]},"DOI":"10.1016\/j.jisa.2025.104360","type":"journal-article","created":{"date-parts":[[2026,1,9]],"date-time":"2026-01-09T10:10:43Z","timestamp":1767953443000},"page":"104360","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["A taxonomy of graph-based risk, vulnerability, and attack assessment methods in IoT systems"],"prefix":"10.1016","volume":"97","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4347-0016","authenticated-orcid":false,"given":"Ferhat","family":"Arat","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6970-3239","authenticated-orcid":false,"given":"Aykut","family":"Karakaya","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7005-6489","authenticated-orcid":false,"given":"Sedat","family":"Akleylek","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.jisa.2025.104360_bib0001","doi-asserted-by":"crossref","first-page":"168825","DOI":"10.1109\/ACCESS.2020.3022842","article-title":"IoT vulnerability assessment for sustainable computing: threats, current solutions, and open challenges","volume":"8","author":"Anand","year":"2020","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2025.104360_bib0002","doi-asserted-by":"crossref","first-page":"9153","DOI":"10.1109\/TII.2022.3164066","article-title":"Evolution of industry and blockchain era: monitoring price hike and corruption using biot for smart government and industry","volume":"18","author":"Hasan","year":"2022","journal-title":"IEEE Trans Ind Inf"},{"key":"10.1016\/j.jisa.2025.104360_bib0003","doi-asserted-by":"crossref","first-page":"43586","DOI":"10.1109\/ACCESS.2018.2863244","article-title":"A graph-based securing industrial IoT networks from vulnerability exploitations","volume":"6","author":"George","year":"2018","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2025.104360_bib0004","doi-asserted-by":"crossref","first-page":"237","DOI":"10.1109\/JMW.2022.3228683","article-title":"Others next-generation IoT devices: sustainable eco-friendly manufacturing, energy harvesting, and wireless connectivity","volume":"3","author":"Rahmani","year":"2023","journal-title":"IEEE J Microwaves"},{"key":"10.1016\/j.jisa.2025.104360_bib0005","doi-asserted-by":"crossref","first-page":"7433","DOI":"10.3390\/s22197433","article-title":"Internet of things: security and solutions survey","volume":"22","author":"Sadhu","year":"2022","journal-title":"Sensors"},{"key":"10.1016\/j.jisa.2025.104360_bib0006","doi-asserted-by":"crossref","first-page":"1636","DOI":"10.1109\/COMST.2018.2874978","article-title":"Anatomy of threats to the internet of things","volume":"21","author":"Makhdoom","year":"2018","journal-title":"IEEE Commun Surv Tutor"},{"key":"10.1016\/j.jisa.2025.104360_bib0007","article-title":"Review on the application of knowledge graph in cyber security assessment","volume":"768","author":"Zhang","year":"2020","journal-title":"IOP Conf Ser Mater Sci Eng"},{"key":"10.1016\/j.jisa.2025.104360_bib0008","series-title":"A systematic security assessment and review of internet of things in the context of authentication","author":"Saqib","year":"2023"},{"key":"10.1016\/j.jisa.2025.104360_bib0009","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102494","article-title":"& Others the internet of things security: a survey encompassing unexplored areas and new insights","volume":"112","author":"Omolara","year":"2022","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2025.104360_bib0010","doi-asserted-by":"crossref","first-page":"198","DOI":"10.3390\/electronics11020198","article-title":"Detecting cybersecurity attacks in internet of things using artificial intelligence methods: a systematic literature review","volume":"11","author":"Abdullahi","year":"2022","journal-title":"Electronics"},{"key":"10.1016\/j.jisa.2025.104360_bib0011","doi-asserted-by":"crossref","first-page":"3753","DOI":"10.1007\/s10586-022-03776-z","article-title":"Internet of Things intrusion detection systems: A comprehensive review and future directions","volume":"vol. 26","author":"Heidari","year":"2023","journal-title":"Cluster Comput"},{"key":"10.1016\/j.jisa.2025.104360_bib0012","doi-asserted-by":"crossref","first-page":"2351","DOI":"10.1109\/COMST.2021.3106669","article-title":"A survey of honeypots and honeynets for internet of things, industrial internet of things, and cyber-physical systems","volume":"23","author":"Franco","year":"2021","journal-title":"IEEE Commun Surv Tutor"},{"key":"10.1016\/j.jisa.2025.104360_bib0013","series-title":"A review on attack graph analysis for IoT vulnerability assessment: challenges, open issues, and future directions","first-page":"44350","volume":"11","author":"Almazrouei","year":"2023"},{"key":"10.1016\/j.jisa.2025.104360_bib0014","doi-asserted-by":"crossref","first-page":"6852","DOI":"10.3390\/app12146852","article-title":"Network security node-edge scoring system using attack graph based on vulnerability correlation","volume":"12","author":"Shin","year":"2022","journal-title":"Appl Sci"},{"key":"10.1016\/j.jisa.2025.104360_bib0015","doi-asserted-by":"crossref","DOI":"10.1016\/j.cosrev.2019.100219","article-title":"A review of attack graph and attack tree visual syntax in cyber security","volume":"35","author":"Lallie","year":"2020","journal-title":"Comput Sci Rev"},{"key":"10.1016\/j.jisa.2025.104360_bib0016","author":"Foundation"},{"key":"10.1016\/j.jisa.2025.104360_bib0017","author":"Hedera"},{"key":"10.1016\/j.jisa.2025.104360_bib0018","doi-asserted-by":"crossref","first-page":"164803","DOI":"10.1109\/ACCESS.2019.2953075","article-title":"An intelligent communication warning vulnerability detection algorithm based on IoT technology","volume":"vol. 7","author":"Yi","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2025.104360_bib0019","doi-asserted-by":"crossref","first-page":"3488","DOI":"10.1109\/TSMC.2019.2915940","article-title":"A2g2v: automatic attack graph generation and visualization and its applications to computer and scada networks","volume":"50","author":"Ghazo","year":"2019","journal-title":"IEEE Trans Syst Man Cybern Syst"},{"key":"10.1016\/j.jisa.2025.104360_bib0020","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102316","article-title":"Assessing IoT enabled cyber-physical attack paths against critical systems","volume":"107","author":"Stellios","year":"2021","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2025.104360_bib0021","doi-asserted-by":"crossref","DOI":"10.1177\/15501329221097817","article-title":"Vulnerability association evaluation of internet of thing devices based on attack graph","volume":"18","author":"Ma","year":"2022","journal-title":"Int J Distrib Sens Netw"},{"key":"10.1016\/j.jisa.2025.104360_bib0022","doi-asserted-by":"crossref","first-page":"2394","DOI":"10.1049\/cmu2.12491","article-title":"Automatic generation of threat paths in internet of things-based systems","volume":"16","author":"Ramazanzadeh","year":"2022","journal-title":"IET Commun"},{"issue":"9","key":"10.1016\/j.jisa.2025.104360_bib0023","doi-asserted-by":"crossref","first-page":"5604","DOI":"10.1109\/TSMC.2023.3274613","article-title":"Critical attacks set identification in attack graphs for computer and SCADA\/ICS networks","volume":"53","author":"Ghazo","year":"2023","journal-title":"IEEE Tran Syst Man Cybern Syst"},{"key":"10.1016\/j.jisa.2025.104360_bib0024","doi-asserted-by":"crossref","DOI":"10.7717\/peerj-cs.1743","article-title":"Modified graph-based algorithm to analyze security threats in IoT","volume":"9","author":"Arat","year":"2023","journal-title":"PeerJ Comput Sci"},{"key":"10.1016\/j.jisa.2025.104360_bib0025","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2025.111122","article-title":"Security-aware RPL: designing a novel objective function for risk-based routing with rank evaluation","volume":"260","author":"Arat","year":"2025","journal-title":"Comput Netw"},{"key":"10.1016\/j.jisa.2025.104360_bib0026","series-title":"A vulnerability assessment method in industrial internet of things based on attack graph and maximum flow","first-page":"8","volume":"6","author":"Wang","year":"2018"},{"key":"10.1016\/j.jisa.2025.104360_bib0027","doi-asserted-by":"crossref","first-page":"74","DOI":"10.1016\/j.csi.2017.09.006","article-title":"Cyber-attack path discovery in a dynamic supply chain maritime risk management system","volume":"56","author":"Polatidis","year":"2018","journal-title":"Comput Stand Interf"},{"key":"10.1016\/j.jisa.2025.104360_bib0028","article-title":"Vulnerability-based risk assessment and mitigation strategies for edge devices in the internet of things","volume":"59","author":"George","year":"2019","journal-title":"Perv Mob Comput"},{"issue":"5","key":"10.1016\/j.jisa.2025.104360_bib0029","doi-asserted-by":"crossref","first-page":"1300","DOI":"10.3390\/s20051300","article-title":"Designing efficient sinkhole attack detection mechanism in edge-based IoT deployment","volume":"20","author":"Pundir","year":"2020","journal-title":"Sensors"},{"key":"10.1016\/j.jisa.2025.104360_bib0030","series-title":"A network attack path prediction method using attack graph","first-page":"1","author":"Liu","year":"2020"},{"key":"10.1016\/j.jisa.2025.104360_bib0031","series-title":"Effective modelling of sinkhole detection algorithm for edge-based Internet of Things (IoT) sensing devices","volume":"vol. 16","author":"Bilal","year":"2022"},{"key":"10.1016\/j.jisa.2025.104360_bib0032","series-title":"Automatic analysis of attack graphs for risk mitigation and prioritization on large-scale and complex networks in industry 4.0","first-page":"37","volume":"21","author":"Stergiopoulos","year":"2022"},{"key":"10.1016\/j.jisa.2025.104360_bib0033","doi-asserted-by":"crossref","first-page":"100","DOI":"10.3390\/fi15030100","article-title":"A vulnerability assessment approach for transportation networks subjected to cyber-physical attacks","volume":"15","author":"Ntafloukas","year":"2023","journal-title":"Future Internet"},{"key":"10.1016\/j.jisa.2025.104360_bib0034","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2023.110046","article-title":"A new method for vulnerability and risk assessment of IoT","volume":"vol. 237","author":"Arat","year":"2023","journal-title":"Comput Netw"},{"key":"10.1016\/j.jisa.2025.104360_bib0035","series-title":"A hybrid graph-based risk assessment and attack path detection model for IoT systems","author":"Arat","year":"2025"},{"key":"10.1016\/j.jisa.2025.104360_bib0036","series-title":"Cost-aware securing of IoT systems using attack graphs","volume":"vol. 86","author":"Yi\u011fit","year":"2019"},{"key":"10.1016\/j.jisa.2025.104360_bib0037","doi-asserted-by":"crossref","first-page":"207","DOI":"10.3390\/fi11100207","article-title":"Threat analysis for smart homes","volume":"11","author":"Kavallieratos","year":"2019","journal-title":"Future Internet"},{"key":"10.1016\/j.jisa.2025.104360_bib0038","doi-asserted-by":"crossref","first-page":"479","DOI":"10.1007\/s12530-018-9234-z","article-title":"From product recommendation to cyber-attack prediction: Generating attack graphs and predicting future attacks","volume":"vol. 11","author":"Polatidis","year":"2020","journal-title":"Evol Syst"},{"key":"10.1016\/j.jisa.2025.104360_bib0039","doi-asserted-by":"crossref","first-page":"105","DOI":"10.1007\/s10009-020-00594-9","article-title":"Graph-based technique for survivability assessment and optimization of IoT applications","volume":"23","author":"Shakhov","year":"2021","journal-title":"Int J Software Tools Technol Trans"},{"key":"10.1016\/j.jisa.2025.104360_bib0040","article-title":"Mfo-rpl: a secure rpl-based routing protocol utilizing moth-flame optimizer for the iot applications","volume":"82","author":"Seyfollahi","year":"2022","journal-title":"Comput Stan Interf"},{"key":"10.1016\/j.jisa.2025.104360_bib0041","doi-asserted-by":"crossref","first-page":"4795","DOI":"10.3390\/s22134795","article-title":"GridAttackAnalyzer: a cyber attack analysis framework for smart grids","volume":"22","author":"Le","year":"2022","journal-title":"Sensors"},{"key":"10.1016\/j.jisa.2025.104360_bib0042","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103174","article-title":"Attack path detection for IIoT enabled cyber physical systems revisited","volume":"128","author":"Arat","year":"2023","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2025.104360_bib0043","doi-asserted-by":"crossref","first-page":"29","DOI":"10.1016\/j.tcs.2022.08.018","article-title":"A mechanism to detecting flooding attacks in quantum enabled cloud-based lowpower and lossy networks","volume":"941","author":"Ankam","year":"2023","journal-title":"Theor Comput Sci"},{"key":"10.1016\/j.jisa.2025.104360_bib0044","doi-asserted-by":"crossref","first-page":"1142","DOI":"10.1109\/TMC.2022.3231567","article-title":"Towards system-level security analysis of IoT using attack graphs","volume":"23","author":"Fang","year":"2022","journal-title":"IEEE Trans Mob Comput"},{"key":"10.1016\/j.jisa.2025.104360_bib0045","doi-asserted-by":"crossref","first-page":"919","DOI":"10.1007\/s11390-011-1189-5","article-title":"Internet of things: objectives and scientific challenges","volume":"26","author":"Ma","year":"2011","journal-title":"J Comput Sci Technol"},{"key":"10.1016\/j.jisa.2025.104360_bib0046","series-title":"2018 6th international symposium on digital forensic and security (ISDFS)","first-page":"1","article-title":"A survey on security threats and authentication approaches in wireless sensor networks","author":"Karakaya","year":"2018"},{"key":"10.1016\/j.jisa.2025.104360_bib0047","doi-asserted-by":"crossref","first-page":"61","DOI":"10.1109\/SURV.2013.100713.00203","article-title":"M2m service platforms: survey, issues, and enabling technologies","volume":"16","author":"Kim","year":"2013","journal-title":"IEEE Commun Surv Tutor"},{"key":"10.1016\/j.jisa.2025.104360_bib0048","first-page":"2231","article-title":"An overview of wireless sensor networks applications and security","volume":"2","author":"Prasanna","year":"2012","journal-title":"Int J Soft Comput Eng"},{"key":"10.1016\/j.jisa.2025.104360_bib0049","doi-asserted-by":"crossref","first-page":"1644","DOI":"10.1002\/wics.1644","article-title":"A survey on post-quantum based approaches for edge computing security","volume":"16","author":"Karakaya","year":"2024","journal-title":"Wiley Interdiscip Rev Comput Stat"},{"key":"10.1016\/j.jisa.2025.104360_bib0050","first-page":"138","article-title":"A survey on security requirements, threats and protocols in industrial internet of things","volume":"10","author":"Karakaya","year":"2021","journal-title":"Int J Inf Secur Sci"},{"key":"10.1016\/j.jisa.2025.104360_bib0051","series-title":"2021 9th international symposium on digital forensics and security (ISDFS)","first-page":"1","article-title":"PQ-FLAT: a new quantum-resistant and lightweight authentication approach for M2M devices","author":"Karacan","year":"2021"},{"key":"10.1016\/j.jisa.2025.104360_bib0052","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.103053","article-title":"A systematic security assessment and review of internet of things in the context of authentication","volume":"125","author":"Saqib","year":"2023","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2025.104360_bib0053","series-title":"Tech. Rep.","article-title":"Designing and constructing internet-of-things systems: An overview of the ecosystem","author":"Dias","year":"2022"},{"key":"10.1016\/j.jisa.2025.104360_bib0054","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1596519.1596522","article-title":"Graph annotations in modeling complex network topologies","volume":"19","author":"Dimitropoulos","year":"2009","journal-title":"ACM Trans Model Comput Simul (TOMACS)"},{"key":"10.1016\/j.jisa.2025.104360_bib0055","doi-asserted-by":"crossref","first-page":"3549","DOI":"10.1109\/TKDE.2020.3028705","article-title":"A survey on knowledge graph-based recommender systems","volume":"34","author":"Guo","year":"2020","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"10.1016\/j.jisa.2025.104360_bib0056","doi-asserted-by":"crossref","DOI":"10.1016\/j.dss.2020.113303","article-title":"Fraud detection: a systematic literature review of graph-based anomaly detection approaches","volume":"133","author":"Pourhabibi","year":"2020","journal-title":"Decis Support Syst"},{"key":"10.1016\/j.jisa.2025.104360_bib0057","doi-asserted-by":"crossref","first-page":"626","DOI":"10.1007\/s10618-014-0365-y","article-title":"Graph based anomaly detection and description: a survey","volume":"29","author":"Akoglu","year":"2015","journal-title":"Data Min Knowl Discov"},{"key":"10.1016\/j.jisa.2025.104360_bib0058","doi-asserted-by":"crossref","first-page":"223","DOI":"10.1002\/wics.1347","article-title":"Anomaly detection in dynamic networks: a survey","volume":"7","author":"Ranshous","year":"2015","journal-title":"Wiley Interdiscip Rev Comput Stat"},{"key":"10.1016\/j.jisa.2025.104360_bib0059","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103602","article-title":"Survey: automatic generation of attack trees and attack graphs","volume":"137","author":"Konsta","year":"2024","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2025.104360_bib0060","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1155\/2019\/2031063","article-title":"Survey of attack graph analysis methods from the perspective of data and knowledge processing","volume":"2019","author":"Zeng","year":"2019","journal-title":"Secur Commun Netw"},{"key":"10.1016\/j.jisa.2025.104360_bib0061","series-title":"Proceedings DARPA information survivability conference and exposition II. DISCEX\u201901","first-page":"307","article-title":"Computer-attack graph generation tool","author":"Swiler","year":"2001"},{"key":"10.1016\/j.jisa.2025.104360_bib0062","first-page":"21","article-title":"Attack trees","volume":"24","author":"Schneier","year":"1999","journal-title":"Dr Dobb\u2019s J"},{"key":"10.1016\/j.jisa.2025.104360_bib0063","series-title":"Information Security And Cryptology-ICISC 2005: 8th International Conference","first-page":"186","article-title":"Foundations of attack trees","volume":"8","author":"Mauw","year":"2005"},{"issue":"13","key":"10.1016\/j.jisa.2025.104360_bib0064","first-page":"11224","article-title":"Advances in IoT security: vulnerabilities, enabled criminal services, attacks and countermeasures","volume":"10","author":"Siwakoti","year":"2023","journal-title":"IEEE Int Things J"},{"key":"10.1016\/j.jisa.2025.104360_bib0065","unstructured":"OWASP Internet of Things Project-OWASP 10. OWASP IoT Top."},{"issue":"2","key":"10.1016\/j.jisa.2025.104360_bib0066","doi-asserted-by":"crossref","first-page":"17","DOI":"10.1109\/MCE.2019.2953740","article-title":"Consumer IoT: security vulnerability case studies and solutions","volume":"9","author":"Alladi","year":"2020","journal-title":"IEEE Consum Electron Mag"},{"key":"10.1016\/j.jisa.2025.104360_bib0067","series-title":"IEEE International conference on intelligence and security informatics (ISI)","first-page":"179","article-title":"Identifying vulnerabilities of consumer internet of things (IoT) devices: a scalable approach","author":"Williams","year":"2017"},{"key":"10.1016\/j.jisa.2025.104360_bib0068","series-title":"Globecom 2017-2017 IEEE Global communications conference","first-page":"1","article-title":"An end-to-end view of IoT security and privacy","author":"Ling","year":"2017"},{"key":"10.1016\/j.jisa.2025.104360_bib0069","series-title":"20th international conference on advanced communication technology (ICACT)","first-page":"172","article-title":"IoT security vulnerability: a case study of a web camera","author":"Seralathan","year":"2018"},{"key":"10.1016\/j.jisa.2025.104360_bib0070","doi-asserted-by":"crossref","first-page":"3685","DOI":"10.1109\/JSEN.2013.2266399","article-title":"The impact of rank attack on network topology of routing protocol for low-power and lossy networks","volume":"13","author":"Le","year":"2013","journal-title":"IEEE Sens J"},{"key":"10.1016\/j.jisa.2025.104360_bib0071","doi-asserted-by":"crossref","first-page":"694","DOI":"10.1016\/j.matpr.2021.04.167","article-title":"Energy efficient thwarting rank attack from RPL based IoT networks: a review","volume":"81","author":"Nandhini","year":"2023","journal-title":"Mater Today Proc"},{"key":"10.1016\/j.jisa.2025.104360_bib0072","doi-asserted-by":"crossref","DOI":"10.1155\/2013\/794326","article-title":"Routing attacks and countermeasures in the RPL-based internet of things","volume":"9","author":"Wallgren","year":"2013","journal-title":"Int J Distrib Sens Netw"},{"key":"10.1016\/j.jisa.2025.104360_bib0073","doi-asserted-by":"crossref","first-page":"559","DOI":"10.1080\/19361610.2022.2031841","article-title":"Internet-of-things security and vulnerabilities: case study","volume":"18","author":"Alqarawi","year":"2023","journal-title":"J Appl Secur Res"},{"key":"10.1016\/j.jisa.2025.104360_bib0074","first-page":"1333","article-title":"A comprehensive review of cyber security vulnerabilities, threats, attacks, and solutions","volume":"12","author":"Aslan","year":"2023","journal-title":"Electronics)"},{"key":"10.1016\/j.jisa.2025.104360_bib0075","first-page":"482","article-title":"Denial of service attack detection through machine learning for the IoT","volume":"4","author":"Syed","year":"2020","journal-title":"J Inf Telecommun"},{"key":"10.1016\/j.jisa.2025.104360_bib0076","doi-asserted-by":"crossref","first-page":"107335","DOI":"10.1109\/ACCESS.2020.3000476","article-title":"Deep transfer learning for IoT attack detection","volume":"8","author":"Vu","year":"2020","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2025.104360_bib0077","doi-asserted-by":"crossref","first-page":"3930","DOI":"10.1109\/JIOT.2021.3100755","article-title":"Federated deep learning for zero-day botnet attack detection in IoT-edge devices","volume":"9","author":"Popoola","year":"2021","journal-title":"IEEE Internet Things J"},{"key":"10.1016\/j.jisa.2025.104360_bib0078","series-title":"Security, privacy and trust in Internet of Things: The road ahead","first-page":"146-164","volume":"vol. 76","author":"Sicari","year":"2015"},{"key":"10.1016\/j.jisa.2025.104360_bib0079","doi-asserted-by":"crossref","first-page":"2028","DOI":"10.1109\/COMST.2018.2798591","article-title":"Location of things (LoT): a review and taxonomy of sensors localization in IoT infrastructure","volume":"20","author":"Shit","year":"2018","journal-title":"IEEE Commun Sur Tutor"},{"key":"10.1016\/j.jisa.2025.104360_bib0080","doi-asserted-by":"crossref","first-page":"167123","DOI":"10.1109\/ACCESS.2020.3022661","article-title":"privacy and trust for smart mobile-internet of things (M-IoT): a survey","volume":"8","author":"Sharma","year":"2020","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2025.104360_bib0081","doi-asserted-by":"crossref","first-page":"5897","DOI":"10.3390\/s20205897","article-title":"Security requirements for the internet of things: a systematic approach","volume":"20","author":"Pal","year":"2020","journal-title":"Sensors"},{"key":"10.1016\/j.jisa.2025.104360_bib0082","article-title":"Design and implementation of automated IoT security testbed","volume":"88","author":"Waraga","year":"2020","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2025.104360_bib0083","doi-asserted-by":"crossref","first-page":"1176","DOI":"10.3390\/electronics12051176","article-title":"Analysis of consumer IoT device vulnerability quantification frameworks","volume":"12","author":"Baho","year":"2023","journal-title":"Electronics"}],"container-title":["Journal of Information Security and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212625003965?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212625003965?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T07:56:08Z","timestamp":1778226968000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2214212625003965"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3]]},"references-count":83,"alternative-id":["S2214212625003965"],"URL":"https:\/\/doi.org\/10.1016\/j.jisa.2025.104360","relation":{},"ISSN":["2214-2126"],"issn-type":[{"value":"2214-2126","type":"print"}],"subject":[],"published":{"date-parts":[[2026,3]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"A taxonomy of graph-based risk, vulnerability, and attack assessment methods in IoT systems","name":"articletitle","label":"Article Title"},{"value":"Journal of Information Security and Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.jisa.2025.104360","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"104360"}}