{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T16:13:42Z","timestamp":1759335222505,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":33,"publisher":"ACM","license":[{"start":{"date-parts":[[2012,2,7]],"date-time":"2012-02-07T00:00:00Z","timestamp":1328572800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2012,2,7]]},"DOI":"10.1145\/2133601.2133622","type":"proceedings-article","created":{"date-parts":[[2012,2,7]],"date-time":"2012-02-07T15:39:28Z","timestamp":1328629168000},"page":"157-168","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":44,"title":["Risk-based security decisions under uncertainty"],"prefix":"10.1145","author":[{"given":"Ian","family":"Molloy","sequence":"first","affiliation":[{"name":"IBM Research TJ Watson, Hawthorne, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Luke","family":"Dickens","sequence":"additional","affiliation":[{"name":"Imperial College, London, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Charles","family":"Morisset","sequence":"additional","affiliation":[{"name":"IIT-CNR, Pisa, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pau-Chen","family":"Cheng","sequence":"additional","affiliation":[{"name":"IBM Research TJ Watson, Hawthorne, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jorge","family":"Lobo","sequence":"additional","affiliation":[{"name":"IBM Research TJ Watson, Hawthorne, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alessandra","family":"Russo","sequence":"additional","affiliation":[{"name":"Imperial College, London, United Kingdom"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2012,2,7]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Pattern Recognition and Machine Learning (Information Science and Statistics)","author":"Bishop C. M.","year":"2007","unstructured":"C. M. Bishop . Pattern Recognition and Machine Learning (Information Science and Statistics) . Springer , 2007 . C. M. Bishop. Pattern Recognition and Machine Learning (Information Science and Statistics). Springer, 2007."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/352600.352620"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102142"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2007.21"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1133058.1133075"},{"key":"e_1_3_2_1_6_1","first-page":"165","volume":"109","author":"Eberlein E.","year":"2007","unstructured":"E. Eberlein , R. Frey , M. Kalkbrener , and L. Overbeck . Mathematics in Financial Risk Management. Jahresbericht der Deutschen Mathematiker Vereinigung , 109 : 165 -- 193 , 2007 . E. Eberlein, R. Frey, M. Kalkbrener, and L. Overbeck. Mathematics in Financial Risk Management. Jahresbericht der Deutschen Mathematiker Vereinigung, 109:165--193, 2007.","journal-title":"Mathematics in Financial Risk Management. Jahresbericht der Deutschen Mathematiker Vereinigung"},{"volume-title":"September","year":"1999","key":"e_1_3_2_1_7_1","unstructured":"Entrust. GetAccess design and administration guide , September 1999 . Entrust. GetAccess design and administration guide, September 1999."},{"key":"e_1_3_2_1_8_1","first-page":"554","volume-title":"Proceedings of the 15th National Computer Security Conference","author":"Ferraiolo D. F.","year":"1992","unstructured":"D. F. Ferraiolo and D. R. Kuhn . Role-based access control . In Proceedings of the 15th National Computer Security Conference , pages 554 -- 563 , 1992 . D. F. Ferraiolo and D. R. Kuhn. Role-based access control. In Proceedings of the 15th National Computer Security Conference, pages 554--563, 1992."},{"key":"e_1_3_2_1_9_1","volume-title":"November","author":"Godik S.","year":"2002","unstructured":"S. Godik and T. Moses . Oasis extensible access control markup language (XACML). OASIS Committee Secification cs-xacml-specification-1.0 , November 2002 , http:\/\/www.oasis-open.org\/committees\/xacml\/, 2002. S. Godik and T. Moses. Oasis extensible access control markup language (XACML). OASIS Committee Secification cs-xacml-specification-1.0, November 2002, http:\/\/www.oasis-open.org\/committees\/xacml\/, 2002."},{"key":"e_1_3_2_1_10_1","first-page":"139","volume-title":"Proceedings of the 17th conference on Security symposium","author":"Gu G.","year":"2008","unstructured":"G. Gu , R. Perdisci , J. Zhang , and W. Lee . Botminer: clustering analysis of network traffic for protocol- and structure-independent botnet detection . In Proceedings of the 17th conference on Security symposium , pages 139 -- 154 . USENIX Association , 2008 . G. Gu, R. Perdisci, J. Zhang, and W. Lee. Botminer: clustering analysis of network traffic for protocol- and structure-independent botnet detection. In Proceedings of the 17th conference on Security symposium, pages 139--154. USENIX Association, 2008."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/762476.762479"},{"key":"e_1_3_2_1_12_1","volume-title":"International Workshop, POLICY'11 Pisa","author":"Kephart J.","year":"2011","unstructured":"J. Kephart . The utility of utility: Policies for self-managing systems. In Policies for Distributed Systems and Networks , International Workshop, POLICY'11 Pisa , Italy , 2011 . To appear. J. Kephart. The utility of utility: Policies for self-managing systems. In Policies for Distributed Systems and Networks, International Workshop, POLICY'11 Pisa, Italy, 2011. To appear."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866353"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.5555\/353629.353659"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1595676.1595694"},{"volume-title":"Siteminder concepts guide","year":"2000","key":"e_1_3_2_1_16_1","unstructured":"Netegrity. Siteminder concepts guide , 2000 . Netegrity. Siteminder concepts guide, 2000."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542207.1542222"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1007568.1007631"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/863742.863750"},{"key":"e_1_3_2_1_20_1","volume-title":"Annual report for the fiscal year ended","author":"Safeway Inc.","year":"2009","unstructured":"Safeway Inc. Annual report for the fiscal year ended January 3, 2009 . http:\/\/http:\/\/www.sec.gov\/Archives\/edgar\/data\/86144\/\\newline0001193125090%43434\/d10k.htm. Safeway Inc. Annual report for the fiscal year ended January 3, 2009. http:\/\/http:\/\/www.sec.gov\/Archives\/edgar\/data\/86144\/\\newline0001193125090%43434\/d10k.htm."},{"key":"e_1_3_2_1_21_1","volume-title":"Annual report for the fiscal year ended","author":"Supervalu Inc.","year":"2009","unstructured":"Supervalu Inc. Annual report for the fiscal year ended February 28, 2009 . http:\/\/www.sec.gov\/Archives\/edgar\/data\/95521\/\\newline000095015209004223\/c%50531e10vk.htm. Supervalu Inc. Annual report for the fiscal year ended February 28, 2009. http:\/\/www.sec.gov\/Archives\/edgar\/data\/95521\/\\newline000095015209004223\/c%50531e10vk.htm."},{"key":"e_1_3_2_1_22_1","unstructured":"The Great Atlantic & Pacific Tea Company Inc. Fiscal 2008 Annual Report to Stockholders. http:\/\/www.sec.gov\/Archives\/edgar\/data\/43300\/\\newline000139843209000171\/e%x13.txt.  The Great Atlantic & Pacific Tea Company Inc. Fiscal 2008 Annual Report to Stockholders. http:\/\/www.sec.gov\/Archives\/edgar\/data\/43300\/\\newline000139843209000171\/e%x13.txt."},{"key":"e_1_3_2_1_23_1","volume-title":"ANNUAL REPORT for the fiscal year ended","author":"The Kroger Co.","year":"2009","unstructured":"The Kroger Co. ANNUAL REPORT for the fiscal year ended January 31, 2009 . http:\/\/www.sec.gov\/Archives\/edgar\/data\/56873\/\\newline000110465909021710\/a%09--1837\\_110k.htm. The Kroger Co. ANNUAL REPORT for the fiscal year ended January 31, 2009. http:\/\/www.sec.gov\/Archives\/edgar\/data\/56873\/\\newline000110465909021710\/a%09--1837\\_110k.htm."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.25"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/1542207.1542232"},{"key":"e_1_3_2_1_26_1","volume-title":"Statistical Learning Theory","author":"Vapnik V. N.","year":"1998","unstructured":"V. N. Vapnik . Statistical Learning Theory . Wiley-Interscience , Sep 1998 . ISBN 9780471030034. V. N. Vapnik. Statistical Learning Theory. Wiley-Interscience, Sep 1998. ISBN 9780471030034."},{"key":"e_1_3_2_1_27_1","unstructured":"Visa Debit Processing Service $|$ Transaction Processing $|$ Authorization Processing. http:\/\/www.visadps.com\/services\/\\newlineauthorization\\_processing.html.  Visa Debit Processing Service $|$ Transaction Processing $|$ Authorization Processing. http:\/\/www.visadps.com\/services\/\\newlineauthorization\\_processing.html."},{"key":"e_1_3_2_1_28_1","unstructured":"Card-Present $|$ Merchants $|$ Visa USA. \\newline http:\/\/usa.visa.com\/merchants\/risk\\_management\/\\newlinecard\\_present.html.  Card-Present $|$ Merchants $|$ Visa USA. \\newline http:\/\/usa.visa.com\/merchants\/risk\\_management\/\\newlinecard\\_present.html."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/1029133.1029140"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1377836.1377848"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1272366.1272375"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/11552338_4"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/POLICY.2006.36"}],"event":{"name":"CODASPY'12: Second ACM Conference on Data and Application Security and Privacy","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"San Antonio Texas USA","acronym":"CODASPY'12"},"container-title":["Proceedings of the second ACM conference on Data and Application Security and Privacy"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2133601.2133622","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2133601.2133622","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T10:05:52Z","timestamp":1750241152000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2133601.2133622"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,2,7]]},"references-count":33,"alternative-id":["10.1145\/2133601.2133622","10.1145\/2133601"],"URL":"https:\/\/doi.org\/10.1145\/2133601.2133622","relation":{},"subject":[],"published":{"date-parts":[[2012,2,7]]},"assertion":[{"value":"2012-02-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}