{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:34:51Z","timestamp":1750307691641,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":7,"publisher":"ACM","license":[{"start":{"date-parts":[[2008,10,27]],"date-time":"2008-10-27T00:00:00Z","timestamp":1225065600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2008,10,27]]},"DOI":"10.1145\/1456362.1456365","type":"proceedings-article","created":{"date-parts":[[2008,11,6]],"date-time":"2008-11-06T13:49:50Z","timestamp":1225979390000},"page":"3-8","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Vulnerability scoring for security configuration settings"],"prefix":"10.1145","author":[{"given":"Karen","family":"Scarfone","sequence":"first","affiliation":[{"name":"NIST, Gaithersburg, MD, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peter","family":"Mell","sequence":"additional","affiliation":[{"name":"NIST, Gaithersburg, MD, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2008,10,27]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Forum of Incident Response and Security Teams. CVSS Adopters. http:\/\/www.first.org\/cvss\/eadopters.html  Forum of Incident Response and Security Teams. CVSS Adopters. http:\/\/www.first.org\/cvss\/eadopters.html"},{"key":"e_1_3_2_1_2_1","volume-title":"Forum of Incident Response and Security Teams","author":"Mell P.","year":"2007","unstructured":"Mell , P. , Scarfone , K. , and Romanosky , S . A Complete Guide to the Common Vulnerability Scoring System Version 2.0 . Forum of Incident Response and Security Teams , June 2007 . http:\/\/www.first.org\/cvss\/cvss-guide.html Mell, P., Scarfone, K., and Romanosky, S. A Complete Guide to the Common Vulnerability Scoring System Version 2.0. Forum of Incident Response and Security Teams, June 2007. http:\/\/www.first.org\/cvss\/cvss-guide.html"},{"key":"e_1_3_2_1_3_1","unstructured":"MITRE Corporation. Common Configuration Enumeration (CCE). http:\/\/cce.mitre.org\/  MITRE Corporation. Common Configuration Enumeration (CCE). http:\/\/cce.mitre.org\/"},{"key":"e_1_3_2_1_4_1","unstructured":"MITRE Corporation. Common Vulnerabilities and Exposures (CVE). http:\/\/cve.mitre.org\/  MITRE Corporation. Common Vulnerabilities and Exposures (CVE). http:\/\/cve.mitre.org\/"},{"key":"e_1_3_2_1_5_1","unstructured":"National Institute of Standards and Technology. National Vulnerability Database. http:\/\/nvd.nist.gov\/  National Institute of Standards and Technology. National Vulnerability Database. http:\/\/nvd.nist.gov\/"},{"volume-title":"Proceedings of the 2008 1st International Conference on Information Technology (Gdansk, Poland, May 19--21, 2008). IT 2008","author":"Scarfone K.","key":"e_1_3_2_1_6_1","unstructured":"Scarfone , K. and Grance , T . A Framework for Measuring the Vulnerability of Hosts . In Proceedings of the 2008 1st International Conference on Information Technology (Gdansk, Poland, May 19--21, 2008). IT 2008 . Gdansk University of Technology, Gdansk, Poland, 145--148. Scarfone, K. and Grance, T. A Framework for Measuring the Vulnerability of Hosts. In Proceedings of the 2008 1st International Conference on Information Technology (Gdansk, Poland, May 19--21, 2008). IT 2008. Gdansk University of Technology, Gdansk, Poland, 145--148."},{"key":"e_1_3_2_1_7_1","volume-title":"NIST","author":"Scarfone K.","year":"2008","unstructured":"Scarfone , K. and Mell , P . Draft NIST Interagency Report 7502: The Common Configuration Scoring System (CCSS) . NIST , May 2008 . http:\/\/csrc.nist.gov\/publications\/PubsNISTIRs.html Scarfone, K. and Mell, P. Draft NIST Interagency Report 7502: The Common Configuration Scoring System (CCSS). NIST, May 2008. http:\/\/csrc.nist.gov\/publications\/PubsNISTIRs.html"}],"event":{"name":"CCS08: 15th ACM Conference on Computer and Communications Security 2008","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control","ACM Association for Computing Machinery"],"location":"Alexandria Virginia USA","acronym":"CCS08"},"container-title":["Proceedings of the 4th ACM workshop on Quality of protection"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1456362.1456365","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1456362.1456365","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T13:29:53Z","timestamp":1750253393000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1456362.1456365"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008,10,27]]},"references-count":7,"alternative-id":["10.1145\/1456362.1456365","10.1145\/1456362"],"URL":"https:\/\/doi.org\/10.1145\/1456362.1456365","relation":{},"subject":[],"published":{"date-parts":[[2008,10,27]]},"assertion":[{"value":"2008-10-27","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}