{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:34:51Z","timestamp":1750307691582,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":19,"publisher":"ACM","license":[{"start":{"date-parts":[[2008,10,27]],"date-time":"2008-10-27T00:00:00Z","timestamp":1225065600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2008,10,27]]},"DOI":"10.1145\/1456362.1456376","type":"proceedings-article","created":{"date-parts":[[2008,11,6]],"date-time":"2008-11-06T13:49:50Z","timestamp":1225979390000},"page":"65-70","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["The risks with security metrics"],"prefix":"10.1145","author":[{"given":"Marco D.","family":"Aime","sequence":"first","affiliation":[{"name":"Politecnico di Torino, Turin, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrea","family":"Atzeni","sequence":"additional","affiliation":[{"name":"Politecnico di Torino, Turin, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paolo C.","family":"Pomi","sequence":"additional","affiliation":[{"name":"Politecnico di Torino, Turin, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2008,10,27]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/170035.170072"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314257.1314272"},{"key":"e_1_3_2_1_3_1","first-page":"1","volume-title":"First Int. Workshop on Quality of Protection","author":"Atzeni A.","year":"2005","unstructured":"A. Atzeni and A. Lioy . Why to adopt a security metric? A brief survey. In QoP2005 , First Int. Workshop on Quality of Protection , pages 1 -- 12 , 15 September 2005 . A. Atzeni and A. Lioy. Why to adopt a security metric? A brief survey. In QoP2005, First Int. Workshop on Quality of Protection, pages 1--12, 15 September 2005."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4020-8157-6_13"},{"key":"e_1_3_2_1_6_1","unstructured":"FIRST. Common Vulnerability Scoring System (CVSS). http:\/\/www.first.org\/cvss\/cvss-guide.html.  FIRST. Common Vulnerability Scoring System (CVSS). http:\/\/www.first.org\/cvss\/cvss-guide.html."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIM.2004.1288747"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"crossref","first-page":"109","DOI":"10.1007\/0-387-24006-3_8","volume-title":"Computer Security in the 21st Century","author":"Howard M.","year":"2005","unstructured":"M. Howard , J. Pincus , and J. Wing . Computer Security in the 21st Century , chapter 8, pages 109 -- 137 . Springer , March 2005 . M. Howard, J. Pincus, and J. Wing. Computer Security in the 21st Century, chapter 8, pages 109--137. Springer, March 2005."},{"key":"e_1_3_2_1_9_1","volume-title":"ISO\/IEC","author":"IEC","year":"2006","unstructured":"ISO\/ IEC 27004. Information technology - Security techniques - Information security management - Measurements - draft . ISO\/IEC , 2006 . ISO\/IEC 27004. Information technology - Security techniques - Information security management - Measurements - draft. ISO\/IEC, 2006."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SEW.2003.1270740"},{"key":"e_1_3_2_1_11_1","unstructured":"N. Kavantzas D. Burdett G. Ritzinger T. Fletcher Y. Lafon and C. Barreto. Web services choreography description language version 1.0. W3C Recommendation http:\/\/www.w3.org\/TR\/ws-cdl-10\/ November 2005.  N. Kavantzas D. Burdett G. Ritzinger T. Fletcher Y. Lafon and C. Barreto. Web services choreography description language version 1.0. W3C Recommendation http:\/\/www.w3.org\/TR\/ws-cdl-10\/ November 2005."},{"key":"e_1_3_2_1_12_1","first-page":"237","volume-title":"Safety ScienceVolume 42, Issue 4","author":"Leveson N.","year":"2004","unstructured":"N. Leveson . A new accident model for engineering safer systems . In Safety ScienceVolume 42, Issue 4 , pages 237 -- 270 , April 2004 . N. Leveson. A new accident model for engineering safer systems. In Safety ScienceVolume 42, Issue 4, pages 237--270, April 2004."},{"key":"e_1_3_2_1_13_1","unstructured":"B. Martin C. Sullo and J. Kouns. OSVDB: Open Source Vulnerability Database. http:\/\/www.osvdb.org\/database-info.php.  B. Martin C. Sullo and J. Kouns. OSVDB: Open Source Vulnerability Database. http:\/\/www.osvdb.org\/database-info.php."},{"key":"e_1_3_2_1_14_1","unstructured":"Ministerio de Administraciones Publicas. Methodology for information systems risk analysis and management (MAGERIT) version 2. http:\/\/www.csae.map.es\/.  Ministerio de Administraciones Publicas. Methodology for information systems risk analysis and management (MAGERIT) version 2. http:\/\/www.csae.map.es\/."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2004.11"},{"key":"e_1_3_2_1_16_1","unstructured":"NIST. National vulnerability database. http:\/\/nvd.nist.gov\/.  NIST. National vulnerability database. http:\/\/nvd.nist.gov\/."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180446"},{"key":"e_1_3_2_1_18_1","unstructured":"POSITIF Project. System Description Language (PSDL). http:\/\/www.positif.org\/.  POSITIF Project. System Description Language (PSDL). http:\/\/www.positif.org\/."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/882494.884423"},{"key":"e_1_3_2_1_21_1","unstructured":"The DMTF Technical Committee. The Common Information Model. http:\/\/www.dmtf.org\/standards\/cim.  The DMTF Technical Committee. The Common Information Model. http:\/\/www.dmtf.org\/standards\/cim."}],"event":{"name":"CCS08: 15th ACM Conference on Computer and Communications Security 2008","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control","ACM Association for Computing Machinery"],"location":"Alexandria Virginia USA","acronym":"CCS08"},"container-title":["Proceedings of the 4th ACM workshop on Quality of protection"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1456362.1456376","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1456362.1456376","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T13:29:53Z","timestamp":1750253393000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1456362.1456376"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2008,10,27]]},"references-count":19,"alternative-id":["10.1145\/1456362.1456376","10.1145\/1456362"],"URL":"https:\/\/doi.org\/10.1145\/1456362.1456376","relation":{},"subject":[],"published":{"date-parts":[[2008,10,27]]},"assertion":[{"value":"2008-10-27","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}