{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T16:25:51Z","timestamp":1783700751080,"version":"3.55.0"},"reference-count":173,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"funder":[{"DOI":"10.13039\/501100000780","name":"European Commission Horizon 2020 Programme SELFNET","doi-asserted-by":"publisher","award":["H2020-ICT-2014-2\/671672"],"award-info":[{"award-number":["H2020-ICT-2014-2\/671672"]}],"id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100010686","name":"Spanish MICINN (Project DHARMA), Dynamic Heterogeneous Threats Risk Management and Assessment","doi-asserted-by":"publisher","award":["TIN2014-59023-C2-1-R"],"award-info":[{"award-number":["TIN2014-59023-C2-1-R"]}],"id":[{"id":"10.13039\/100010686","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000780","name":"European Commission","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003329","name":"Ram\u00f3n y Cajal Research Contract through the MINECO","doi-asserted-by":"publisher","award":["RYC-2015-18210"],"award-info":[{"award-number":["RYC-2015-18210"]}],"id":[{"id":"10.13039\/501100003329","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004895","name":"European Social Fund","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004895","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Leonardo Grant 2017 for Researchers and Cultural Creators Awarded by the BBVA Foundation"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Commun. Surv. Tutorials"],"published-print":{"date-parts":[[2018]]},"DOI":"10.1109\/comst.2017.2781126","type":"journal-article","created":{"date-parts":[[2017,12,7]],"date-time":"2017-12-07T19:30:18Z","timestamp":1512675018000},"page":"1361-1396","source":"Crossref","is-referenced-by-count":120,"title":["Optimal Countermeasures Selection Against Cyber Attacks: A Comprehensive Survey on Reaction Frameworks"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4041-1205","authenticated-orcid":false,"given":"Pantaleone","family":"Nespoli","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dimitrios","family":"Papamartzivanos","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Felix","family":"Gomez Marmol","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6348-5031","authenticated-orcid":false,"given":"Georgios","family":"Kambourakis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref170","first-page":"156","article-title":"Computing the shortest path: A search meets graph theory","author":"goldberg","year":"2005","journal-title":"Proc 17th Ann ACM-SIAM Symp Discrete Algorithms (SODA)"},{"key":"ref172","article-title":"CPE, common platform enumeration: Applicability language specification","author":"waltermire","year":"2011"},{"key":"ref171","year":"2016","journal-title":"Cognitive Security (White Paper)"},{"key":"ref173","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2011.12.012"},{"key":"ref168","article-title":"Dynamic optimal countermeasure selection for intrusion response system","author":"shameli-sendi","year":"0","journal-title":"IEEE Trans Depend Secure Comput"},{"key":"ref169","doi-asserted-by":"publisher","DOI":"10.1016\/S0004-3702(01)00106-0"},{"key":"ref39","year":"2005"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3064814.3064824"},{"key":"ref33","year":"2016","journal-title":"Suricata Open source IDS\/IPS\/NSM engine"},{"key":"ref32","year":"2016","journal-title":"SNORT network intrusion detection system"},{"key":"ref31","author":"miller","year":"2010","journal-title":"Security Information and Event Management (SIEM) Implementation"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.60"},{"key":"ref37","author":"pescatore","year":"2009","journal-title":"Defining the Next-Generation Firewall"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2014.2336610"},{"key":"ref35","year":"2016","journal-title":"Bro Network Security Monitor"},{"key":"ref34","year":"2016","journal-title":"OSSEC Open Source HIDS Security"},{"key":"ref28","year":"2016","journal-title":"Nessus Vulnerability Scanner"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/IAS.2007.67"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1108\/09685221111173058"},{"key":"ref20","year":"2016","journal-title":"Cyber Definitions"},{"key":"ref22","year":"2016","journal-title":"Open Source Firewall"},{"key":"ref21","year":"2016","journal-title":"Open Source Firewall"},{"key":"ref24","year":"2016","journal-title":"McAfee Network Security Platform"},{"key":"ref23","year":"2016","journal-title":"HID Secure Identity Solutions"},{"key":"ref101","year":"2016","journal-title":"Extensible Configuration Checklist Description Format (XCCDF)"},{"key":"ref26","article-title":"Network-based risk-assessment tool for remotely detecting local computer vulnerabilities","author":"magdych","year":"2006"},{"key":"ref100","year":"2016","journal-title":"CybOX Cyber Observable Expression"},{"key":"ref25","year":"2016","journal-title":"Cisco Next Generation Intrusion Prevention System (NGIPS)"},{"key":"ref50","year":"2016","journal-title":"CVE Common Vulnerabilities and Exposures"},{"key":"ref51","year":"2016","journal-title":"ArchC architecture description language"},{"key":"ref154","doi-asserted-by":"publisher","DOI":"10.1007\/s00158-003-0368-6"},{"key":"ref153","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1007\/978-3-642-48318-9_3","author":"hwang","year":"1981","journal-title":"Multiple attribute decision making[M]"},{"key":"ref156","first-page":"14","article-title":"Evaluation of computer network security based on attack graphs and security event processing","volume":"5","author":"kotenko","year":"2014","journal-title":"J Wireless Mobile Netw Ubiquitous Comput Dependable Appl"},{"key":"ref155","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2013.84"},{"key":"ref150","first-page":"1005","article-title":"Epistemic uncertainty quantification tutorial","author":"swiler","year":"2009","journal-title":"Proc 27th Int Modal Anal Conf"},{"key":"ref152","year":"2016","journal-title":"Department of Homeland Security Science and Technology Moving Target Defense"},{"key":"ref151","doi-asserted-by":"publisher","DOI":"10.1145\/2808475.2808482"},{"key":"ref146","doi-asserted-by":"publisher","DOI":"10.1109\/2.485845"},{"key":"ref147","doi-asserted-by":"publisher","DOI":"10.1109\/POLICY.2003.1206966"},{"key":"ref148","year":"1991","journal-title":"Federation of American Scientists Special Operations Forces Intelligence and Electronic Warfare Operations Appendix D Target Analysis Process"},{"key":"ref149","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-013-0207-8"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2011.34"},{"key":"ref58","first-page":"8","article-title":"MulVal: A logic-based network security analyzer","volume":"14","author":"ou","year":"2005","journal-title":"Proce 14th Conf USENIX Security Symp (SSYM'05)"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2009.21"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180446"},{"key":"ref55","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.cosrev.2014.07.001","article-title":"DAG-based attack and defense modeling: Don&#x2019;t miss the forest for the attack trees","volume":"13","author":"kordy","year":"2014","journal-title":"Comput Sci Rev"},{"key":"ref54","first-page":"1773","article-title":"Game-theoretic algorithms for optimal network security hardening using attack graphs","author":"durkota","year":"2015","journal-title":"Proc 1st Int Conf Autonomous Agents Multiagent Syst"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1016\/j.ejor.2015.06.048"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/IWSSD.1996.501143"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2013.211"},{"key":"ref167","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2008.260"},{"key":"ref166","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-31833-7_14"},{"key":"ref165","doi-asserted-by":"publisher","DOI":"10.13052\/jcsm2245-1439.312"},{"key":"ref164","doi-asserted-by":"publisher","DOI":"10.1109\/IDAACS.2013.6662998"},{"key":"ref163","first-page":"1","article-title":"A cyber attack modeling and impact assessment framework","author":"kotenko","year":"2013","journal-title":"Proc 5th Int Conf Cyber Conflict (CyCon)"},{"key":"ref162","doi-asserted-by":"publisher","DOI":"10.1109\/PDP.2013.84"},{"key":"ref161","doi-asserted-by":"publisher","DOI":"10.1109\/GreenCom.2012.24"},{"key":"ref160","first-page":"129","article-title":"Attack modeling and security evaluation in SIEM systems","volume":"8","author":"kotenko","year":"2012","journal-title":"Int Trans Syst Sci Appl"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2015.2402161"},{"key":"ref3","first-page":"61","article-title":"Big data","volume":"90","author":"mcafee","year":"2012","journal-title":"The management revolution Harvard Bus Review"},{"key":"ref6","first-page":"199","author":"lenin","year":"2014","journal-title":"Attacker Profiling in Quantitative Security Assessment Based on Attack Trees"},{"key":"ref5","first-page":"573","article-title":"K-zero day safety: Measuring the security risk of networks against unknown attacks","author":"wang","year":"2010","journal-title":"Proc Eur Conf Res Comput Secur (ESORICS)"},{"key":"ref159","doi-asserted-by":"publisher","DOI":"10.1109\/PDP.2016.96"},{"key":"ref8","year":"2016","journal-title":"Internet Security Threat Report | Government"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315272"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2008.08.003"},{"key":"ref157","first-page":"107","article-title":"Countermeasure selection based on the attack and service dependency graphs for security incident management","author":"doynikova","year":"2015","journal-title":"Proc Int Conf Risks Security Internet Syst"},{"key":"ref158","doi-asserted-by":"publisher","DOI":"10.1109\/PDP.2015.34"},{"key":"ref9","author":"greco","year":"2005","journal-title":"Multiple Criteria Decision Analysis State of the Art Surveys"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2010.02.003"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2012.04.001"},{"key":"ref48","article-title":"Polymorphic blending attacks","volume":"15","author":"fogla","year":"2006","journal-title":"Proc 15th Conf USENIX Security Symp (USENIX-SS'06)"},{"key":"ref47","year":"2016","journal-title":"AlienVault Open Threat Exchange (OTX)"},{"key":"ref42","year":"2016","journal-title":"LogRhythm SIEM"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2007.9"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2002.1176302"},{"key":"ref43","year":"2016","journal-title":"Gartner Magic Quadrant for Security Information and Event Management"},{"key":"ref127","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2004.06.004"},{"key":"ref126","article-title":"Securing the U.S. defense information infrastructure: A proposed approach","author":"anderson","year":"1999"},{"key":"ref125","year":"2016","journal-title":"PTA a Practical Threat Analysis Case Study Next Generation Call Accounting"},{"key":"ref124","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-30"},{"key":"ref73","author":"jaquith","year":"2007","journal-title":"Security Metrics"},{"key":"ref72","doi-asserted-by":"crossref","DOI":"10.4324\/9780203726389","author":"pedhazur","year":"2013","journal-title":"Measurement Design and Analysis An Integrated Approach"},{"key":"ref129","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2013.8"},{"key":"ref71","doi-asserted-by":"crossref","first-page":"80","DOI":"10.1007\/978-3-642-19751-2_6","article-title":"Foundations of attack-defense trees","volume":"6561","author":"kordy","year":"0","journal-title":"Formal Aspects in Security and Trust"},{"key":"ref128","first-page":"345","author":"sarala","year":"2016","journal-title":"Optimal Selection of Security Countermeasures for Effective Information Security"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1137\/0311020"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1098\/rspb.1979.0081"},{"key":"ref130","doi-asserted-by":"publisher","DOI":"10.1145\/1721654.1721672"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/3477.484436"},{"key":"ref74","first-page":"17","author":"bandyopadhyay","year":"2013","journal-title":"Some Single- and Multiobjective Optimization Techniques"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1145\/2330784.2330914"},{"key":"ref133","first-page":"1","article-title":"BotSniffer: Detecting botnet command and control channels in network traffic","author":"gu","year":"2008","journal-title":"Proc 15th Annu Netw Distrib Syst Secur Symp"},{"key":"ref134","doi-asserted-by":"publisher","DOI":"10.1109\/ARES.2008.138"},{"key":"ref131","year":"2012","journal-title":"Software-Defined Networking The New Norm for Networks"},{"key":"ref78","first-page":"1","article-title":"Principles of Tabu search","author":"glover","year":"2007","journal-title":"Handbook of Approximation Algorithms and Metaheuristics"},{"key":"ref132","year":"2016","journal-title":"Openflow"},{"key":"ref79","volume":"2","author":"bertsekas","year":"2007","journal-title":"Dynamic Programming and Optimal Control"},{"key":"ref136","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2011.08.009"},{"key":"ref135","doi-asserted-by":"publisher","DOI":"10.1145\/2484402.2484406"},{"key":"ref138","author":"bellman","year":"1957","journal-title":"Dynamic Programming"},{"key":"ref137","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.07.003"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1002\/sec.299"},{"key":"ref139","doi-asserted-by":"publisher","DOI":"10.1145\/584091.584093"},{"key":"ref62","first-page":"173","author":"kordy","year":"2013","journal-title":"ADTool Security Analysis With Attack&#x2013;Defense Trees"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CRIS.2009.5071485"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1016\/S0004-3702(98)00023-X"},{"key":"ref64","first-page":"626","author":"kheir","year":"2010","journal-title":"A Service Dependency Model for Cost-Sensitive Intrusion Response"},{"key":"ref140","author":"owen","year":"1995","journal-title":"Game Theory"},{"key":"ref65","doi-asserted-by":"crossref","first-page":"89","DOI":"10.1016\/j.jnca.2015.05.004","article-title":"ORCEF: Online response cost evaluation framework for intrusion response system","volume":"55","author":"shameli-sendi","year":"2015","journal-title":"J Netw Comput Appl"},{"key":"ref141","doi-asserted-by":"publisher","DOI":"10.1109\/TFUZZ.2002.806316"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1512\/iumj.1957.6.56038"},{"key":"ref142","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2009.05.005"},{"key":"ref67","volume":"356","author":"kemeny","year":"1960","journal-title":"Finite Markov Chains"},{"key":"ref143","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2015.07.023"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/CSFW.2002.1021806"},{"key":"ref144","first-page":"156","article-title":"Individual countermeasure selection based on the return on response investment index","author":"granadillo","year":"2012","journal-title":"Proc 6th Int Conf Math Methods Models Archit Comput Netw Security Comput Netw Security (MMM-ACNS)"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/69.917566"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4612-4054-9"},{"key":"ref145","doi-asserted-by":"publisher","DOI":"10.1109\/INTECH.2012.6457801"},{"key":"ref1","year":"2015","journal-title":"connected devices to almost triple to over 38 billion units by 2020"},{"key":"ref109","year":"2016","journal-title":"MITRE Corporation"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.17487\/rfc4765"},{"key":"ref108","year":"2016","journal-title":"Security Content Automation Protocol"},{"key":"ref94","article-title":"Proposed open specifications for an enterprise remediation automation framework (draft)","author":"david","year":"2011"},{"key":"ref107","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2012.09.013"},{"key":"ref93","year":"2016","journal-title":"CRE Common Remediation Enumeration"},{"key":"ref106","doi-asserted-by":"publisher","DOI":"10.1109\/ICCKE.2013.6682816"},{"key":"ref92","year":"2016","journal-title":"CAPEC Common Attack Pattern Enumeration and Classification"},{"key":"ref105","year":"2016","journal-title":"Common Vulnerability Scoring System"},{"key":"ref91","year":"2016","journal-title":"CWRAF Common Weakness Risk Analysis Framework"},{"key":"ref104","author":"maynor","year":"2007","journal-title":"Metasploit Toolkit for Penetration Testing Exploit Development and Vulnerability Research"},{"key":"ref90","article-title":"The common misuse scoring system (CMSS): Metrics for software feature misuse vulnerabilities","author":"lemay","year":"2010"},{"key":"ref103","year":"2016","journal-title":"Malware Attribute Enumeration and Characterization"},{"key":"ref102","article-title":"IODEF, the incident object description exchange format","author":"danyliw","year":"2007"},{"key":"ref111","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511779183"},{"key":"ref112","doi-asserted-by":"publisher","DOI":"10.1109\/UIC-ATC-ScalCom-CBDCom-IoP-SmartWorld.2016.0080"},{"key":"ref110","doi-asserted-by":"publisher","DOI":"10.1080\/001401399185595"},{"key":"ref98","year":"2016","journal-title":"Structured threat information expression"},{"key":"ref99","year":"2016","journal-title":"The Trusted Automated EXchange of Indicator Information (TAXII)"},{"key":"ref96","year":"2016","journal-title":"TMSAD Trust Model for Security Automation Data"},{"key":"ref97","year":"2016","journal-title":"OpenIOC Open Indicator of Compromise"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1016\/j.dss.2016.02.012"},{"key":"ref11","first-page":"21","article-title":"Attack trees","volume":"24","author":"schneier","year":"1999","journal-title":"Dr Dobb&#x2019;s J"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2014.10.012"},{"key":"ref13","doi-asserted-by":"crossref","first-page":"867","DOI":"10.1016\/j.jnca.2011.03.005","article-title":"Trust mechanisms in wireless sensor networks: Attack analysis and countermeasures","volume":"35","author":"yu","year":"2012","journal-title":"J Netw Comput Appl"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/SMARTGRID.2010.5622045"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2012.021312.00138"},{"key":"ref118","author":"kanclirz","year":"2008","journal-title":"Netcat Power Tools"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1504\/IJICS.2007.012248"},{"key":"ref82","year":"2016","journal-title":"NVD national vulnerability database"},{"key":"ref117","year":"2017","journal-title":"CERT Coordination Center"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.04.009"},{"key":"ref81","year":"2016","journal-title":"CVRF Common Vulnerability Report Format"},{"key":"ref18","first-page":"1","article-title":"Intrusion response systems: Survey and taxonomy","volume":"12","author":"shameli-sendi","year":"2012","journal-title":"Int J Comput Sci Netw Security"},{"key":"ref84","year":"2016","journal-title":"CCE Common Configuration Enumeration"},{"key":"ref119","doi-asserted-by":"publisher","DOI":"10.1109\/4235.996017"},{"key":"ref19","first-page":"129","article-title":"I don&#x2019;t trust ICT: Research challenges in cyber security","volume":"473","author":"m\u00e1rmol","year":"2016","journal-title":"Proc 10th IFIP WG 11 11 Int Conf Trust Manag (IFIPTM)"},{"key":"ref83","year":"2016","journal-title":"Open Vulnerability and Assessment Language (OVAL)"},{"key":"ref114","author":"sipser","year":"2006","journal-title":"Introduction to the Theory of Computation"},{"key":"ref113","doi-asserted-by":"publisher","DOI":"10.1145\/350391.350432"},{"key":"ref116","year":"2017","journal-title":"BUGTRAQ Security Focus Mailing List"},{"key":"ref80","volume":"116","author":"sutton","year":"1998","journal-title":"Reinforcement Learning An Introduction"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-012-0160-y"},{"key":"ref120","doi-asserted-by":"publisher","DOI":"10.1145\/581339.581370"},{"key":"ref89","year":"2016","journal-title":"CWSS Common Weakness Scoring System"},{"key":"ref121","first-page":"1","article-title":"Multi-attribute risk assessment","author":"butler","year":"2002","journal-title":"Proc 3rd Symp Requirements Eng Inf Security (CERIAS)"},{"key":"ref122","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2012.6263940"},{"key":"ref123","doi-asserted-by":"publisher","DOI":"10.1287\/opre.15.6.1171"},{"key":"ref85","article-title":"The common configuration scoring system (CCSS): Metrics for software security configuration vulnerabilities","author":"mell","year":"2010"},{"key":"ref86","year":"2016","journal-title":"Common Platform Enumeration"},{"key":"ref87","year":"2016","journal-title":"ASR Asset Summary Report"},{"key":"ref88","year":"2016","journal-title":"Common Weakness Enumeration"}],"container-title":["IEEE Communications Surveys &amp; Tutorials"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9739\/8362823\/08169023.pdf?arnumber=8169023","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,26]],"date-time":"2022-01-26T07:31:26Z","timestamp":1643182286000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8169023\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"references-count":173,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/comst.2017.2781126","relation":{},"ISSN":["1553-877X","2373-745X"],"issn-type":[{"value":"1553-877X","type":"electronic"},{"value":"2373-745X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]}}}