{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:52:47Z","timestamp":1784303567334,"version":"3.55.0"},"reference-count":39,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179447","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"1980-1996","source":"Crossref","is-referenced-by-count":12,"title":["No One Drinks From the Firehose: How Organizations Filter and Prioritize Vulnerability Information"],"prefix":"10.1109","author":[{"given":"Stephanie","family":"de Smale","sequence":"first","affiliation":[{"name":"National Cyber Security Centre,The Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rik","family":"van Dijk","sequence":"additional","affiliation":[{"name":"National Cyber Security Centre,The Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xander","family":"Bouwman","sequence":"additional","affiliation":[{"name":"Delft University of Technology"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jeroen","family":"van der Ham","sequence":"additional","affiliation":[{"name":"National Cyber Security Centre,The Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michel","family":"van Eeten","sequence":"additional","affiliation":[{"name":"Delft University of Technology"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Focus on the Biggest Security Threats, Not the Most Publicized","author":"Moore","year":"2018"},{"key":"ref2","volume-title":"Failure to patch two-month-old bug led to massive Equifax breach","author":"Goodin","year":"2017"},{"key":"ref3","volume-title":"The Untold Story of NotPetya, the Most Devastating Cyberattack in History","author":"Greenberg","year":"2018"},{"key":"ref4","volume-title":"The Microsoft Exchange Server hack: A timeline","author":"Carlson","year":"2021"},{"key":"ref5","volume-title":"CSIRT Services Framework 2.1","year":"2021"},{"key":"ref6","first-page":"319","article-title":"\"You\u2019ve Got Your Nice List of Bugs, Now What?\u201d Vulnerability Discovery and Management Processes in the Wild","volume-title":"Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020)","author":"Alomar"},{"key":"ref7","volume-title":"VulnDB Vulnerability Statistics"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/tnsm.2021.3078727"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/1162666.1162671"},{"key":"ref10","first-page":"1041","article-title":"Vulnerability Disclosure in the Age of Social Media: Exploiting Twitter for Predicting Real-World Exploits","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Sabottke"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1080\/19393555.2015.1111961"},{"key":"ref12","article-title":"Keepers of the Machines: Examining How System Administrators Manage Software Updates For Multiple Machines","volume-title":"Fifteenth Symposium on Usable Privacy and Security (SOUPS 2019)","author":"Li"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/PST47121.2019.8949012"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243794"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23522"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134072"},{"key":"ref17","volume-title":"CVSS v3.1 Specification Document"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/msec.2020.3044475"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/2630069"},{"key":"ref20","volume-title":"Towards Improving CVSS","author":"Spring","year":"2018"},{"key":"ref21","first-page":"1","article-title":"The Effect of Security Education and Expertise on Security Assessments: the Case of Software Vulnerabilities","author":"Allodi","year":"2018"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/cns48642.2020.9162225"},{"key":"ref23","doi-asserted-by":"crossref","DOI":"10.1145\/3338501.3357365","volume-title":"Risk Prioritization by Leveraging Latent Vulnerability Features in a Contested Environment","author":"Alperin","year":"2019"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/lcn44214.2019.8990847"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyaa015"},{"key":"ref26","first-page":"903","article-title":"From Patching Delays to Infection Symptoms: Using Risk Profiles for an Early Discovery of Vulnerabilities Exploited in the Wild","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Xiao"},{"key":"ref27","first-page":"433","article-title":"A different cup of TI? The added value of commercial threat intelligence","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Bouwman"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1191\/1478088706qp0630a"},{"key":"ref29","volume-title":"Qualitative data analysis with ATLAS.TI","author":"Friese","year":"2019"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3359174"},{"key":"ref31","article-title":"Historical analysis of exploit availability timelines","volume-title":"13th USENIX Workshop on Cyber Security Experimentation and Test (CSET 20)","author":"Householder"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/2382416.2382427"},{"key":"ref33","volume-title":"CRR Supplemental Resource Guide: Volume 4 Vulnerability Management","author":"Mellon","year":"2016"},{"key":"ref34","volume-title":"Framework for Improving Critical Infrastructure Cybersecurity","year":"2018"},{"key":"ref35","volume-title":"The Five Stages of Vulnerability Management Maturity","year":"2019"},{"key":"ref36","volume-title":"The Five Stages of Vulnerability Management Maturity","author":"Risto","year":"2020"},{"key":"ref37","volume-title":"Known Exploited Vulnerabilities Catalog","year":"2021"},{"key":"ref38","volume-title":"Binding Operational Directive 22-01","year":"2021"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-349-20568-4_5"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,5,21]]},"end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179447.pdf?arnumber=10179447","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T05:17:58Z","timestamp":1721452678000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179447\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":39,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179447","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}