{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,19]],"date-time":"2025-12-19T21:53:36Z","timestamp":1766181216866,"version":"3.37.3"},"reference-count":70,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/OAPA.html"}],"funder":[{"DOI":"10.13039\/100010418","name":"Defence Science and Technology Laboratory","doi-asserted-by":"publisher","award":["DSTLX1000048609"],"award-info":[{"award-number":["DSTLX1000048609"]}],"id":[{"id":"10.13039\/100010418","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2019]]},"DOI":"10.1109\/access.2019.2897923","type":"journal-article","created":{"date-parts":[[2019,2,6]],"date-time":"2019-02-06T19:49:17Z","timestamp":1549482557000},"page":"39305-39320","source":"Crossref","is-referenced-by-count":23,"title":["A Markov Multi-Phase Transferable Belief Model for Cyber Situational Awareness"],"prefix":"10.1109","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1986-5472","authenticated-orcid":false,"given":"Georgios","family":"Ioannou","sequence":"first","affiliation":[{"name":"Department of Computer Science, Brunel University London, Uxbridge, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7685-0309","authenticated-orcid":false,"given":"Panos","family":"Louvieris","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Brunel University London, Uxbridge, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Natalie","family":"Clewley","sequence":"additional","affiliation":[{"name":"Centre for Electronic Warfare, Information and Cyber, Defence Academy, Cranfield University, Shrivenham, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2013.03.004"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-0140-8_8"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2011.6127490"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SIECPC.2013.6551028"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/JSYST.2012.2221913"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CEEC.2012.6375395"},{"key":"ref30","doi-asserted-by":"crossref","first-page":"71s","DOI":"10.1016\/j.diin.2011.05.009","article-title":"Detecting data theft using stochastic forensics","volume":"8","author":"grier","year":"2011","journal-title":"Journal of digital investigation"},{"key":"ref37","doi-asserted-by":"crossref","first-page":"430","DOI":"10.1117\/12.341367","article-title":"Revisions to the JDL data fusion model","volume":"3719","author":"steinberg","year":"1999","journal-title":"Proc SPIE"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1518\/001872095779049543"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CyberSecurity.2012.16"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SOSE.2014.53"},{"article-title":"Distribution-free multiple comparisons","year":"1963","author":"nemenyi","key":"ref60"},{"key":"ref62","first-page":"44","volume":"10","year":"2016","journal-title":"WorldWide Infrastructure Security Report"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1145\/3098954.3098985"},{"key":"ref63","first-page":"1","article-title":"DAG-based attack and defense modeling: Don&#x2018;t miss the forest for the attack trees","volume":"13","author":"korby","year":"2014","journal-title":"Comput Sci Rev"},{"key":"ref28","first-page":"1","article-title":"SIDD: A framework for detecting sensitive data exfiltration by an insider attack","author":"liu","year":"2009","journal-title":"Proc 42nd Hawaii Int Conf Syst Sci"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.03.001"},{"key":"ref27","first-page":"10","article-title":"Towards mechanisms for detection and prevention of data exfiltration by insiders","author":"lafayette","year":"2011","journal-title":"Proc of ACM Symp on Inf Comp and Comm Sec"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.03.015"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1016\/0888-613X(93)90005-X"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CSC.2011.6138545"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1117\/12.720090"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/ICCSE.2009.5228485"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2008.4565048"},{"journal-title":"Global Risk Rep","year":"2016","key":"ref2"},{"journal-title":"Cyberattacks account for up to $1 trillion in global losses","year":"2013","key":"ref1"},{"key":"ref20","first-page":"2118","article-title":"An agile model for situation assessment: How to make evidence theory able to change idea about classifications","author":"digioia","year":"2012","journal-title":"Proc 15th Int Conf Inf Fusion"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1142\/S0218488511007404"},{"key":"ref21","first-page":"1146","article-title":"Insider cyber threat situational awareness framwork using dynamic bayesian networks","author":"tang","year":"2009","journal-title":"Proc 4th Int Conf Comput Sci Edu"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/S1566-2535(02)00053-2"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2008.08.007"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2006.04.003"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2007.02.003"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1016\/0020-0255(87)90007-7"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1007\/978-94-011-2438-6_13"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.2307\/2280779"},{"journal-title":"Multisensor Data Fusion","year":"2010","author":"waltz","key":"ref58"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TPWRS.2008.2002298"},{"article-title":"Attack modelling for information security and survivability","year":"2001","author":"moore","key":"ref56"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2009.07.008"},{"journal-title":"Schneier on Security Attack Trees","year":"1999","author":"schneier","key":"ref54"},{"key":"ref53","first-page":"508","article-title":"Decision-theoretic agent design","author":"russel","year":"1995","journal-title":"Artificial Intelligence A Modern Approach"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2013.04.038"},{"key":"ref10","first-page":"113","article-title":"Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains","author":"hutchins","year":"2011","journal-title":"Proc 6th Int Conf Inf Warf Secur"},{"journal-title":"Lifecycle of an Advanced Persistent Threat","year":"0","key":"ref11"},{"key":"ref40","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1007\/978-1-4419-0140-8_4","article-title":"Uncertainty and Risk Management in Cyber Situational Awareness","volume":"46","author":"li","year":"2010","journal-title":"Cyber Situational Awareness Advances in Information Security"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/332051.332079"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.proenv.2011.09.165"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICIF.2007.4408113"},{"key":"ref15","doi-asserted-by":"crossref","DOI":"10.1117\/12.665763","article-title":"Realizing situation awareness within a cyber environment","author":"tadda","year":"2006","journal-title":"Proc SPIE"},{"key":"ref16","doi-asserted-by":"crossref","DOI":"10.1515\/9780691214696","author":"shafer","year":"1976","journal-title":"A Mathematical Theory of Evidence"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1016\/0004-3702(94)90026-4"},{"key":"ref18","first-page":"1903","article-title":"An information fusion framework for threat assessment","author":"beaver","year":"2009","journal-title":"Proc 12th Int Conf Inform Fusion"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.4304\/jnw.6.12.1655-1661"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2017.10.004"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2015.2415032"},{"key":"ref6","first-page":"842","article-title":"A Markov multi-phase transferable belief model: An application for predicting data exfiltration APTs","author":"ioannou","year":"2013","journal-title":"Proc 16th Int Conf Inf Fusion"},{"journal-title":"Hacked in 2014 The Year of the Data Breach","year":"2014","author":"keane","key":"ref5"},{"journal-title":"MNE7 Access to the Global Commons Outcome 3 Cyber Domain Objective 3 5 Cyber Situational Awareness Concept of Employment for Cyber Situational Awareness Within the Global Commons Dated","year":"2013","key":"ref8"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(11)70086-1"},{"key":"ref49","first-page":"81","article-title":"Review of a mathematical theory of evidence","volume":"5","author":"zadeh","year":"1984","journal-title":"AI Mag"},{"year":"2010","key":"ref9","article-title":"The advanced persistent threat"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/5.554205"},{"key":"ref45","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1007\/978-1-4419-0140-8_2","volume":"46","author":"salerno","year":"2010","journal-title":"Overview of Cyber Situational Awareness Issues and Research"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177698950"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1049\/ecej:19970602"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/COGSIMA.2011.5753430"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CICYBS.2011.5949399"},{"key":"ref44","first-page":"46","article-title":"Developing systems for cyber situational awareness","author":"okolica","year":"2009","journal-title":"Proc 2nd Cyberspace Res Workshop"},{"key":"ref43","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1007\/978-1-4419-0140-8_1","article-title":"Cyber SA: Situational Awareness for Cyber Defense","volume":"46","author":"barford","year":"2010","journal-title":"Cyber Situational Awareness Advances in Information Security"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8600701\/08636494.pdf?arnumber=8636494","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,15]],"date-time":"2024-01-15T21:25:56Z","timestamp":1705353956000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8636494\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"references-count":70,"URL":"https:\/\/doi.org\/10.1109\/access.2019.2897923","relation":{},"ISSN":["2169-3536"],"issn-type":[{"type":"electronic","value":"2169-3536"}],"subject":[],"published":{"date-parts":[[2019]]}}}