{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T10:41:28Z","timestamp":1785926488731,"version":"3.56.0"},"reference-count":149,"publisher":"Oxford University Press (OUP)","issue":"1","license":[{"start":{"date-parts":[[2021,3,14]],"date-time":"2021-03-14T00:00:00Z","timestamp":1615680000000},"content-version":"vor","delay-in-days":72,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc\/4.0\/"}],"funder":[{"name":"Office of the Assistant Secretary of Defense for Research and Engineering [OASD(R&E)]","award":["FAB750-15-2-0120"],"award-info":[{"award-number":["FAB750-15-2-0120"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,2,16]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>In this article, we provide an introduction to simulation for cybersecurity and focus on three themes: (1) an overview of the cybersecurity domain; (2) a summary of notable simulation research efforts for cybersecurity; and (3) a proposed way forward on how simulations could broaden cybersecurity efforts. The overview of cybersecurity provides readers with a foundational perspective of cybersecurity in the light of targets, threats, and preventive measures. The simulation research section details the current role that simulation plays in cybersecurity, which mainly falls on representative environment building; test, evaluate, and explore; training and exercises; risk analysis and assessment; and humans in cybersecurity research. The proposed way forward section posits that the advancement of collecting and accessing sociotechnological data to inform models, the creation of new theoretical constructs, and the integration and improvement of behavioral models are needed to advance cybersecurity efforts.<\/jats:p>","DOI":"10.1093\/cybsec\/tyab005","type":"journal-article","created":{"date-parts":[[2021,3,14]],"date-time":"2021-03-14T15:39:56Z","timestamp":1615736396000},"source":"Crossref","is-referenced-by-count":86,"title":["Simulation for cybersecurity: state of the art and future directions"],"prefix":"10.1093","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4307-2381","authenticated-orcid":false,"given":"Hamdi","family":"Kavak","sequence":"first","affiliation":[{"name":"Department of Computational and Data Sciences, George Mason University, 4400 University Drive, Fairfax, MS, 6A12, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jose J","family":"Padilla","sequence":"additional","affiliation":[{"name":"Virginia Modeling, Analysis and Simulation Center, Old Dominion University, 1030 University Blvd., Suffolk, VA, 23435, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daniele","family":"Vernon-Bido","sequence":"additional","affiliation":[{"name":"Computational Modeling and Simulation Engineering, Old Dominion University, 1300 Engineering & Computational Sciences Building, Norfolk, VA, 23529, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Saikou Y","family":"Diallo","sequence":"additional","affiliation":[{"name":"Virginia Modeling, Analysis and Simulation Center, Old Dominion University, 1030 University Blvd., Suffolk, VA, 23435, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ross","family":"Gore","sequence":"additional","affiliation":[{"name":"Virginia Modeling, Analysis and Simulation Center, Old Dominion University, 1030 University Blvd., Suffolk, VA, 23435, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sachin","family":"Shetty","sequence":"additional","affiliation":[{"name":"Virginia Modeling, Analysis and Simulation Center, Old Dominion University, 1030 University Blvd., Suffolk, VA, 23435, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"286","published-online":{"date-parts":[[2021,3,14]]},"reference":[{"key":"2021031415395327300_tyab005-B1","author":"Radack","year":"2011"},{"key":"2021031415395327300_tyab005-B2","doi-asserted-by":"crossref","first-page":"29","DOI":"10.1145\/1646353.1646365","article-title":"The need for a national cybersecurity research and development agenda","volume":"53","author":"Maughan","year":"2010","journal-title":"Communications of the ACM"},{"key":"2021031415395327300_tyab005-B3","first-page":"48","volume-title":"Identity Theft and the Internet","author":"Good","year":"2019"},{"key":"2021031415395327300_tyab005-B4","author":"Poyraz","year":"2020"},{"key":"2021031415395327300_tyab005-B5","volume-title":"ID Theft down 28 Percent in U.S. in 2010: Survey","author":"Sheppard","year":"2011"},{"key":"2021031415395327300_tyab005-B6","first-page":"45","author":"Marchini","year":"2019"},{"key":"2021031415395327300_tyab005-B7","doi-asserted-by":"crossref","first-page":"616","DOI":"10.1057\/s41288-020-00185-4","article-title":"Cyber assets at risk: monetary impact of US personally identifiable information mega data breaches","volume":"45","author":"Poyraz","year":"2020","journal-title":"The Geneva Papers on Risk and Insurance-Issues and Practice"},{"key":"2021031415395327300_tyab005-B8","author":"Lewis","year":"2018","journal-title":"Economic Impact of Cybercrime \u2013 No Slowing Down"},{"key":"2021031415395327300_tyab005-B9","first-page":"3","article-title":"Electricity grid in U.S. penetrated by spies","author":"Gorman","year":"2009","journal-title":"The Wall Street Journal"},{"key":"2021031415395327300_tyab005-B10","author":"Thakur","year":"2016"},{"key":"2021031415395327300_tyab005-B11","author":"Ottis","year":"2008"},{"key":"2021031415395327300_tyab005-B12","doi-asserted-by":"crossref","first-page":"97","DOI":"10.1016\/j.cose.2013.04.004","article-title":"From information security to cyber security","volume":"38","author":"Von","year":"2013","journal-title":"Comput Secur"},{"key":"2021031415395327300_tyab005-B13","volume-title":"National Cyber Security Strategy 2016-2021","author":"Office UC.","year":"2016"},{"key":"2021031415395327300_tyab005-B14","author":"DoD","year":"1998"},{"key":"2021031415395327300_tyab005-B15","author":"Leeuwen","year":"2015"},{"key":"2021031415395327300_tyab005-B16","first-page":"204","author":"Guruprasad","year":"2005"},{"key":"2021031415395327300_tyab005-B17","author":"Rimondini","year":"2007"},{"key":"2021031415395327300_tyab005-B18","doi-asserted-by":"publisher","first-page":"133","DOI":"10.1002\/spe.2273","article-title":"Netkit: network emulation for education","volume":"46","author":"Pizzonia","year":"2016","journal-title":"Software: Practice and Experience"},{"key":"2021031415395327300_tyab005-B19","first-page":"643","author":"Turnitsa","year":"2010"},{"key":"2021031415395327300_tyab005-B20","doi-asserted-by":"crossref","first-page":"380","DOI":"10.1016\/j.jag.2016.07.007","article-title":"The simulation and prediction of spatio-temporal urban growth trends using cellular automata models: a review","volume":"52","author":"Aburas","year":"2016","journal-title":"Int J Appl Earth Obs Geoinf"},{"key":"2021031415395327300_tyab005-B21","doi-asserted-by":"crossref","first-page":"183","DOI":"10.1007\/s10100-011-0210-y","article-title":"Agent-based simulation of innovation diffusion: a review","volume":"20","author":"Kiesling","year":"2012","journal-title":"Cent Eur J Oper Res"},{"key":"2021031415395327300_tyab005-B22","doi-asserted-by":"crossref","first-page":"3179","DOI":"10.1016\/j.comnet.2011.05.007","article-title":"Simulation of vehicular ad-hoc networks: challenges, review of tools and recommendations","volume":"55","author":"Stanica","year":"2011","journal-title":"Comput Netw"},{"key":"2021031415395327300_tyab005-B23","volume-title":"In Collins English Dictionary","author":"Dictionary","year":"2020"},{"key":"2021031415395327300_tyab005-B24","author":"Studies, N.I.f.C.C.a","year":"2020"},{"key":"2021031415395327300_tyab005-B25","year":"2008"},{"key":"2021031415395327300_tyab005-B26","author":"CNNS. Committee on National Security Systems (CNNS) Glossary","year":"2015"},{"key":"2021031415395327300_tyab005-B27","author":"Cebula","year":"2014"},{"key":"2021031415395327300_tyab005-B28","first-page":"191","article-title":"Cybersecurity: challenges from a systems, complexity, knowledge management and business intelligence perspective","volume":"16","author":"Tisdale","year":"2015","journal-title":"Issues Infor Syst"},{"key":"2021031415395327300_tyab005-B29","first-page":"80","article-title":"Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains","volume":"1","author":"Hutchins","year":"2011","journal-title":"Leading Iss Inform Warf Secur Res"},{"key":"2021031415395327300_tyab005-B30","author":"Caltagirone","year":"2013"},{"key":"2021031415395327300_tyab005-B31","first-page":"87","article-title":"A framework for malware & cyber weapons PrEP","volume":"13","author":"Herr","year":"2014","journal-title":"J Inform Warf"},{"key":"2021031415395327300_tyab005-B32","first-page":"68","article-title":"Method of early staged cyber attacks detection in IT and telecommunication networks","volume":"24","author":"Japertas","year":"2018","journal-title":"E. ir Elekt,"},{"key":"2021031415395327300_tyab005-B33","volume-title":"JPMorgan Hack Exposed Data of 83 Million, among Biggest Breaches in History, in Reuters","author":"Agarwal","year":"2014"},{"key":"2021031415395327300_tyab005-B34","first-page":"63","article-title":"The 2008 Russian cyber campaign against Georgia","volume":"91","author":"Shakarian","year":"2011","journal-title":"Military Rev"},{"key":"2021031415395327300_tyab005-B35","author":"ITRC","year":"2020"},{"key":"2021031415395327300_tyab005-B36","author":"IBM","year":"2015"},{"key":"2021031415395327300_tyab005-B37","author":"Menn","year":"2015"},{"key":"2021031415395327300_tyab005-B38","first-page":"113","article-title":"Advanced social engineering attacks","volume":"22","author":"Krombholz","year":"2015","journal-title":"J Inform Secur Appl"},{"key":"2021031415395327300_tyab005-B39","volume-title":"Twenty-Ninth AAAI Conference on Artificial Intelligence","author":"Laszka","year":"2015"},{"key":"2021031415395327300_tyab005-B40","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.IR.7298r2","volume-title":"Glossary of Key Information Security Terms","author":"Kissel","year":"2013"},{"key":"2021031415395327300_tyab005-B41","author":"Kucuk","year":"2018"},{"key":"2021031415395327300_tyab005-B42","first-page":"11","article-title":"Massive cyber attack at anthem","volume":"96","author":"Balbi","year":"2015","journal-title":"Strat Financ"},{"key":"2021031415395327300_tyab005-B43","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1145\/2699026.2699127","volume-title":"Proceedings of the 5th ACM Conference on Data and Application Security and Privacy","author":"Snyder","year":"2015"},{"key":"2021031415395327300_tyab005-B44","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1109\/MC.2015.116","article-title":"Protecting websites from attack with secure delivery networks","volume":"48","author":"Gillman","year":"2015","journal-title":"Computer"},{"key":"2021031415395327300_tyab005-B45","author":"Sang-Hun","year":"2013"},{"key":"2021031415395327300_tyab005-B46","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1109\/MSP.2011.67","article-title":"Stuxnet: dissecting a cyberwarfare weapon","volume":"9","author":"Langner","year":"2011","journal-title":"IEEE Secur Priv"},{"key":"2021031415395327300_tyab005-B47","volume-title":"The Art of Computer Virus Research and Defense","author":"Szor","year":"2005"},{"key":"2021031415395327300_tyab005-B48","doi-asserted-by":"crossref","first-page":"171","DOI":"10.1108\/OIR-12-2015-0394","article-title":"Internet attacks and intrusion detection system: a review of the literature","volume":"41","author":"Singh","year":"2017","journal-title":"Online Inform Rev"},{"key":"2021031415395327300_tyab005-B49","author":"Dierks","year":"2008"},{"key":"2021031415395327300_tyab005-B50","volume-title":"SSH, the Secure Shell: The Definitive Guide: The Definitive Guide","author":"Barrett","year":"2005"},{"key":"2021031415395327300_tyab005-B51","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1109\/TCSS.2017.2719705","article-title":"Creation and management of social network honeypots for detecting targeted cyber attacks","volume":"4","author":"Paradise","year":"2017","journal-title":"IEEE Trans Comput Soc Syst"},{"key":"2021031415395327300_tyab005-B52","volume-title":"A Characterization of Cybersecurity Simulation Scenarios","author":"Kavak","year":"2016"},{"key":"2021031415395327300_tyab005-B53","first-page":"1","article-title":"EMUSIM: an Integrated Emulation and Simulation Environment for Modeling, Evaluation, and Validation of Performance of Cloud Computing Applications","volume":"39","author":"Calheiros","year":"2012","journal-title":"Softw Pract Exp"},{"key":"2021031415395327300_tyab005-B54","volume-title":"Summer Computer Simulation Conference","author":"Damodaran","year":"2015"},{"key":"2021031415395327300_tyab005-B55","volume-title":"REAL: A Network Simulator","author":"Keshav","year":"1988"},{"key":"2021031415395327300_tyab005-B56","author":"Varga","year":"2008"},{"key":"2021031415395327300_tyab005-B57","author":"INET","year":"2020"},{"key":"2021031415395327300_tyab005-B58","first-page":"527","article-title":"Network simulations with the ns-3 simulator","volume":"14","author":"Henderson","year":"2008","journal-title":"SIGCOMM Demonst"},{"key":"2021031415395327300_tyab005-B59","first-page":"19","author":"Issariyakul","year":"2009"},{"key":"2021031415395327300_tyab005-B60","author":"Yoon","year":"2009"},{"key":"2021031415395327300_tyab005-B61","author":"Riley","year":"2003"},{"key":"2021031415395327300_tyab005-B62","author":"Barr","year":"2004"},{"key":"2021031415395327300_tyab005-B63","first-page":"10","article-title":"A review of simulation of telecommunication networks: simulators, classification, comparison, methodologies, and recommendations","volume":"2","author":"Sarkar","year":"2011","journal-title":"Cyber J"},{"key":"2021031415395327300_tyab005-B64","author":"Ojie","year":"2017"},{"key":"2021031415395327300_tyab005-B65","first-page":"1387","author":"Varshney","year":"2011"},{"key":"2021031415395327300_tyab005-B66","doi-asserted-by":"crossref","first-page":"383","DOI":"10.1177\/1548512915593528","article-title":"Cyber-attack and defense simulation framework","volume":"12","author":"Bergin","year":"2015","journal-title":"J Defens Model Simul"},{"key":"2021031415395327300_tyab005-B67","first-page":"52","volume-title":"A Frequency-based","year":"2003"},{"key":"2021031415395327300_tyab005-B68","first-page":"1535","author":"Hancock","year":"2011"},{"key":"2021031415395327300_tyab005-B69","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2043635.2043640","article-title":"A decision support system for placement of intrusion detection and prevention devices in large-scale networks","volume":"22","author":"Puzis","year":"2011","journal-title":"ACM Trans Model Comput Simul"},{"key":"2021031415395327300_tyab005-B70","author":"Wagner","year":"2016"},{"key":"2021031415395327300_tyab005-B71","author":"Bah\u015fi","year":"2018"},{"key":"2021031415395327300_tyab005-B72","doi-asserted-by":"crossref","first-page":"479","DOI":"10.1016\/S0167-4048(99)80115-1","article-title":"Simulating cyber attacks, defences, and consequences","volume":"18","author":"Cohen","year":"1999","journal-title":"Comput Secur"},{"key":"2021031415395327300_tyab005-B73","first-page":"320","volume-title":"Network security modeling and cyber attack simulation methodology. In: Information Security and Privacy","author":"Chi","year":"2001"},{"key":"2021031415395327300_tyab005-B74","doi-asserted-by":"crossref","first-page":"147","DOI":"10.1177\/1548512917699725","article-title":"Cyber defense in breadth: modeling and analysis of integrated defense systems","volume":"15","author":"Cho","year":"2018","journal-title":"J Def Model Simul"},{"key":"2021031415395327300_tyab005-B75","first-page":"327","author":"Kotenko","year":"2006"},{"key":"2021031415395327300_tyab005-B76","author":"Almajali","year":"2012"},{"key":"2021031415395327300_tyab005-B77","author":"Sonchack","year":"2014"},{"key":"2021031415395327300_tyab005-B78","author":"Hassell","year":"2012"},{"key":"2021031415395327300_tyab005-B79","doi-asserted-by":"crossref","first-page":"835","DOI":"10.1109\/TSG.2011.2163829","article-title":"Cyber attack exposure evaluation framework for the smart grid","volume":"2","author":"Hahn","year":"2011","journal-title":"IEEE Trans Smart Grid"},{"key":"2021031415395327300_tyab005-B80","author":"Garetto","year":"2003"},{"key":"2021031415395327300_tyab005-B81","doi-asserted-by":"crossref","first-page":"709","DOI":"10.1177\/0037549716656060","article-title":"Agent-based simulation of the dynamics of malware propagation in scale-free networks","volume":"92","author":"Hosseini","year":"2016","journal-title":"Simulation"},{"key":"2021031415395327300_tyab005-B82","volume-title":"Spring Simulation Multi-Conference","author":"Kavak","year":"2017"},{"key":"2021031415395327300_tyab005-B83","doi-asserted-by":"crossref","first-page":"109","DOI":"10.1007\/s11416-018-0325-y","article-title":"Malware propagation in smart grid networks: metrics, simulation and comparison of three malware types","volume":"15","author":"Eder-Neuhauser","year":"2019","journal-title":"J Comput Virol Hack Tech"},{"key":"2021031415395327300_tyab005-B84","doi-asserted-by":"crossref","first-page":"233","DOI":"10.1177\/1548512916683451","article-title":"Markov chain modeling of cyber threats","volume":"14","author":"Gore","year":"2017","journal-title":"J Def Model Simul"},{"key":"2021031415395327300_tyab005-B85","first-page":"1","author":"Barnum","year":"2012"},{"key":"2021031415395327300_tyab005-B86","author":"Lu","year":"2019"},{"key":"2021031415395327300_tyab005-B87","author":"Kucuk","year":"2020"},{"key":"2021031415395327300_tyab005-B88","author":"Rajbahadur","year":"2018"},{"key":"2021031415395327300_tyab005-B89","author":"CISA. National Cyber Exercise And Planning Program","year":"2020"},{"key":"2021031415395327300_tyab005-B90","author":"NCSC. National Cyber Srcurity Centre","year":"2020"},{"key":"2021031415395327300_tyab005-B91","author":"NATO","year":"2020"},{"key":"2021031415395327300_tyab005-B92","author":"CISA","year":"2020"},{"key":"2021031415395327300_tyab005-B93","author":"Keeling","year":"2013"},{"key":"2021031415395327300_tyab005-B94","doi-asserted-by":"crossref","first-page":"431","DOI":"10.1007\/0-387-33406-8_37","article-title":"Cyber security training and awareness through game play","volume":"201","author":"Cone","year":"2006","journal-title":"IFIP Int Feder for Inform Process"},{"key":"2021031415395327300_tyab005-B95","first-page":"256","author":"Nagarajan","year":"2012"},{"key":"2021031415395327300_tyab005-B96","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1109\/MSP.2011.180","article-title":"Basing cybersecurity training on user perceptions","volume":"10","author":"Furman","year":"2012","journal-title":"IEEE Secur Priv"},{"key":"2021031415395327300_tyab005-B97","volume-title":"Managing Cybersecurity Resources: A Cost-Benefit Analysis","author":"Gordon","year":"2006"},{"key":"2021031415395327300_tyab005-B98","doi-asserted-by":"crossref","first-page":"659","DOI":"10.1016\/j.cose.2010.02.002","article-title":"A probabilistic relational model for security risk analysis","volume":"29","author":"Sommestad","year":"2010","journal-title":"Comput Secur"},{"key":"2021031415395327300_tyab005-B99","author":"Tatar","year":"2012"},{"key":"2021031415395327300_tyab005-B100","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1177\/1548512917707077","article-title":"Prioritizing investment in military cyber capability using risk analysis","volume":"16","author":"Rowe","year":"2019","journal-title":"J Def Model Simul"},{"key":"2021031415395327300_tyab005-B101","doi-asserted-by":"crossref","first-page":"315","DOI":"10.1109\/TSMCC.1999.760576","article-title":"Risk modeling, assessment, and management","volume":"29","author":"Haimes","year":"1999","journal-title":"IEEE Trans Syst Man Cybernetics C (Appl Rev)"},{"key":"2021031415395327300_tyab005-B102","author":"Taylor","year":"2002"},{"key":"2021031415395327300_tyab005-B103","author":"Keskin","year":"2018"},{"key":"2021031415395327300_tyab005-B104","doi-asserted-by":"crossref","first-page":"154","DOI":"10.1016\/j.cose.2016.04.003","article-title":"A problem shared is a problem halved: a survey on the dimensions of collective cyber defense through security information sharing","volume":"60","author":"Skopik","year":"2016","journal-title":"Comput Secur"},{"key":"2021031415395327300_tyab005-B105","author":"V\u00e1zquez","year":"2012"},{"key":"2021031415395327300_tyab005-B106","author":"Tosh","year":"2015"},{"key":"2021031415395327300_tyab005-B107","author":"Tosh","year":"2015"},{"key":"2021031415395327300_tyab005-B108","first-page":"21","article-title":"Attack trees","volume":"24","author":"Schneier","year":"1999","journal-title":"Dr Dobb\u2019s J"},{"key":"2021031415395327300_tyab005-B109","first-page":"175","volume-title":"Attack tree construction and its application to the connected vehicle. In: Cyber-Physical Systems Security","author":"Karray","year":"2018"},{"key":"2021031415395327300_tyab005-B110","volume-title":"Information Assurance Workshop","author":"Dalton","year":"2006"},{"key":"2021031415395327300_tyab005-B111","doi-asserted-by":"crossref","first-page":"583","DOI":"10.1016\/j.isatra.2007.04.003","article-title":"Cyber security risk assessment for SCADA and DCS networks","volume":"46","author":"Ralston","year":"2007","journal-title":"ISA Trans"},{"key":"2021031415395327300_tyab005-B112","first-page":"558","author":"Charitoudi","year":"2013"},{"key":"2021031415395327300_tyab005-B113","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1007\/978-3-662-44860-1_8","article-title":"Simulation-based cyber-attack assessment of critical infrastructures marlies","volume":"191","author":"Rybnicek","year":"2014","journal-title":"Lect Notes Bus Inf Process"},{"key":"2021031415395327300_tyab005-B114","author":"Wang","year":"2010"},{"key":"2021031415395327300_tyab005-B115","doi-asserted-by":"crossref","first-page":"127","DOI":"10.1177\/1548512917699724","article-title":"A game theoretic approach to cyber security risk management","volume":"15","author":"Musman","year":"2018","journal-title":"J Def Model Simul"},{"key":"2021031415395327300_tyab005-B116","author":"Vernon-Bido","year":"2018"},{"key":"2021031415395327300_tyab005-B117","volume-title":"Fighting Computer Crime: A New Framework for Protecting Information","author":"Parker","year":"1998"},{"key":"2021031415395327300_tyab005-B118","first-page":"614","author":"Kotenko","year":"2007"},{"key":"2021031415395327300_tyab005-B119","author":"Razak","year":"2002"},{"key":"2021031415395327300_tyab005-B120","first-page":"461","article-title":"Adversary modeling and simulation in cyber warfare","volume":"278","author":"Hamilton","year":"2008","journal-title":"IFIP Int Feder Inf Process"},{"key":"2021031415395327300_tyab005-B121","doi-asserted-by":"crossref","first-page":"605","DOI":"10.1177\/0018720812464045","article-title":"Cyber situation awareness: modeling detection of cyber attacks with instance-based learning theory","volume":"55","author":"Dutt","year":"2013","journal-title":"Hum Fact"},{"key":"2021031415395327300_tyab005-B122","author":"Hemberg","year":"2018"},{"key":"2021031415395327300_tyab005-B123","doi-asserted-by":"crossref","first-page":"526","DOI":"10.1016\/S0167-4048(02)01009-X","article-title":"A framework for understanding and predicting insider attacks","volume":"21","author":"Schultz","year":"2002","journal-title":"Comput Secur"},{"key":"2021031415395327300_tyab005-B124","volume-title":"Towards Modeling Factors That Enable an Attacker","author":"Vernon-Bido","year":"2016"},{"key":"2021031415395327300_tyab005-B125","doi-asserted-by":"crossref","first-page":"549","DOI":"10.2307\/3054128","article-title":"Sanction threats and appeals to morality: testing a rational choice model of corporate crime","volume":"30","author":"Paternoster","year":"1996","journal-title":"Law and Society Review"},{"key":"2021031415395327300_tyab005-B126","doi-asserted-by":"crossref","first-page":"467","DOI":"10.2307\/3054102","article-title":"Enduring individual differences and rational choice theories of crime","volume":"27","author":"Nagin","year":"1993","journal-title":"Law Soc Rev"},{"key":"2021031415395327300_tyab005-B127","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1145\/1953122.1953142","article-title":"Does deterrence work in reducing information security policy abuse by employees?","volume":"54","author":"Hu","year":"2011","journal-title":"Commun ACM"},{"key":"2021031415395327300_tyab005-B128","author":"Nurse","year":"2011"},{"key":"2021031415395327300_tyab005-B129","author":"Rajivan","year":"2013"},{"key":"2021031415395327300_tyab005-B130","volume-title":"Modeling and Tools for Network Simulation","author":"Pussep"},{"key":"2021031415395327300_tyab005-B131","first-page":"1622","author":"Blythe","year":"2011"},{"key":"2021031415395327300_tyab005-B132","author":"Tatar","year":"2016"},{"key":"2021031415395327300_tyab005-B133","volume-title":"Insider Attack and Cyber Security","author":"Moore"},{"key":"2021031415395327300_tyab005-B134","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1177\/1548512917725408","article-title":"Cyber threat assessment via attack scenario simulation using an integrated adversary and network modeling approach","volume":"15","author":"Moskal","year":"2018","journal-title":"J Def Model Simul"},{"key":"2021031415395327300_tyab005-B135","author":"Haines","year":"2001"},{"key":"2021031415395327300_tyab005-B136","article-title":"Empirical validation of agent-based models: alternatives and prospects","volume":"10","author":"Windrum","year":"2007","journal-title":"J Artif Soc Soc Simul"},{"key":"2021031415395327300_tyab005-B137","doi-asserted-by":"crossref","first-page":"43","DOI":"10.1016\/j.ress.2013.06.040","article-title":"Review on modeling and simulation of interdependent critical infrastructure systems","volume":"121","author":"Ouyang","year":"2014","journal-title":"Reliab Eng Syst Safe"},{"key":"2021031415395327300_tyab005-B138","author":"Moore","year":"2019"},{"key":"2021031415395327300_tyab005-B139","doi-asserted-by":"crossref","first-page":"436","DOI":"10.1038\/nature14539","article-title":"Deep learning","volume":"521","author":"LeCun","year":"2015","journal-title":"Nature"},{"key":"2021031415395327300_tyab005-B140","doi-asserted-by":"crossref","first-page":"688","DOI":"10.1016\/j.clinthera.2015.12.001","article-title":"IBM Watson: how cognitive computing can be applied to big data challenges in life sciences research","volume":"38","author":"Chen","year":"2016","journal-title":"Clin Ther"},{"key":"2021031415395327300_tyab005-B141","author":"McMorrow","year":"2010"},{"key":"2021031415395327300_tyab005-B142","volume-title":"Network Science and Cybersecurity","author":"Kott"},{"key":"2021031415395327300_tyab005-B143","author":"Zhang","year":"2014"},{"key":"2021031415395327300_tyab005-B144","author":"Liang","year":"2017"},{"key":"2021031415395327300_tyab005-B145","first-page":"11","article-title":"General system theory","volume":"1","author":"Von Bertalanffy","year":"1956","journal-title":"Gen Syst"},{"key":"2021031415395327300_tyab005-B146","doi-asserted-by":"crossref","first-page":"298","DOI":"10.1016\/j.leaqua.2007.04.002","article-title":"Complexity leadership theory: shifting leadership from the industrial age to the knowledge era","volume":"18","author":"Uhl-Bien","year":"2007","journal-title":"Leadersh Q"},{"key":"2021031415395327300_tyab005-B147","doi-asserted-by":"crossref","first-page":"588","DOI":"10.2307\/2094589","article-title":"Social change and crime rate trends: a routine activity approach","volume":"44","author":"Cohen","year":"1979","journal-title":"Am Sociol Rev"},{"key":"2021031415395327300_tyab005-B148","author":"Tolk","year":"2018"},{"key":"2021031415395327300_tyab005-B149","first-page":"160","article-title":"Maritime cyber security: system analysis and evolution of AIS","volume":"48","author":"Kucukkaya","year":"2017","journal-title":"Strat Cyber Def"}],"container-title":["Journal of Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/academic.oup.com\/cybersecurity\/article-pdf\/7\/1\/tyab005\/36597586\/tyab005.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"http:\/\/academic.oup.com\/cybersecurity\/article-pdf\/7\/1\/tyab005\/36597586\/tyab005.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,3,14]],"date-time":"2021-03-14T15:40:49Z","timestamp":1615736449000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/cybersecurity\/article\/doi\/10.1093\/cybsec\/tyab005\/6170701"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,1,1]]},"references-count":149,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,2,16]]}},"URL":"https:\/\/doi.org\/10.1093\/cybsec\/tyab005","relation":{},"ISSN":["2057-2085","2057-2093"],"issn-type":[{"value":"2057-2085","type":"print"},{"value":"2057-2093","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2021,1,1]]},"published":{"date-parts":[[2021,1,1]]},"article-number":"tyab005"}}