{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:51:09Z","timestamp":1750308669916,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","license":[{"start":{"date-parts":[[2011,10,12]],"date-time":"2011-10-12T00:00:00Z","timestamp":1318377600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2011,10,12]]},"DOI":"10.1145\/2179298.2179348","type":"proceedings-article","created":{"date-parts":[[2012,4,3]],"date-time":"2012-04-03T17:52:37Z","timestamp":1333475557000},"page":"1-1","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Can we measure security and how?"],"prefix":"10.1145","author":[{"given":"Janusz","family":"Zalewski","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Steve","family":"Drager","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"William","family":"Mckeever","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrew","family":"Kornecki","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2011,10,12]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/s102070100003"},{"key":"e_1_3_2_2_2_1","first-page":"1","article-title":"Why to Adopt a Security Metric? A Brief Survey. In Quality of Protection: Security Measurements and Metrics, D. Gollmann, F. Massacci and A. Yautsiukhin, Eds. Springer-Verlag","author":"Atzeni A.","year":"2006","journal-title":"New York."},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"crossref","unstructured":"Brotby W.K. 2009. Information Security Management Metrics: A Definitive Guide to Effective Security Monitoring and Measurement. CRC Press Boca Raton FL.   Brotby W.K. 2009. Information Security Management Metrics: A Definitive Guide to Effective Security Monitoring and Measurement . CRC Press Boca Raton FL.","DOI":"10.1201\/9781420052862"},{"key":"e_1_3_2_2_4_1","unstructured":"Herrmann D.S. 2011. Complete Guide to Security and Privacy Metrics: Measuring Regulatory Compliance Operational Resilience and ROI. Auerbach Publications London.   Herrmann D.S. 2011. Complete Guide to Security and Privacy Metrics: Measuring Regulatory Compliance Operational Resilience and ROI . Auerbach Publications London."},{"key":"e_1_3_2_2_5_1","unstructured":"Chew E. etal 2008. Performance Measurement Guide for Information Security. NIST Special Publication 800-55 Rev. 1. National Institute of Standards and Technology Gaithersburg MD.   Chew E. et al. 2008. Performance Measurement Guide for Information Security . NIST Special Publication 800-55 Rev. 1. National Institute of Standards and Technology Gaithersburg MD."},{"key":"e_1_3_2_2_6_1","unstructured":"A Community Website for Security Practitioners. URL: http:\/\/www.securitymetrics.org - accessed in Sept. 2011. A Community Website for Security Practitioners . URL: http:\/\/www.securitymetrics.org - accessed in Sept. 2011."},{"key":"e_1_3_2_2_7_1","unstructured":"Hinson G. 2006. Seven Myths about Security Metrics. URL: http:\/\/www.noticebored.com\/html\/metrics.html  Hinson G. 2006. Seven Myths about Security Metrics . URL: http:\/\/www.noticebored.com\/html\/metrics.html"},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"crossref","unstructured":"Luce R.D. Krantz D.H. Suppes P. and Tversky A. 1990. Foundations of Measurement. Vol. III. Representation Axiomatization and Invariance. Dover Publications Mineola NY.  Luce R.D. Krantz D.H. Suppes P. and Tversky A. 1990. Foundations of Measurement. Vol. III. Representation Axiomatization and Invariance . Dover Publications Mineola NY.","DOI":"10.1016\/B978-0-12-425403-9.50010-2"},{"key":"e_1_3_2_2_9_1","unstructured":"Zuse H. 1007. A Framework of Software Measurement. Walter de Gruyter Berlin.   Zuse H. 1007. A Framework of Software Measurement . Walter de Gruyter Berlin."},{"key":"e_1_3_2_2_10_1","unstructured":"ISO\/IEC 12207:2008 Systems and software engineering--Software life cycle processes. Geneva Switzerland. ISO\/IEC 12207:2008 Systems and software engineering--Software life cycle processes. Geneva Switzerland."},{"key":"e_1_3_2_2_11_1","unstructured":"ISO\/IEC 15288:2008 Systems and software engineering--System life cycle processes. Geneva Switzerland. ISO\/IEC 15288:2008 Systems and software engineering--System life cycle processes. Geneva Switzerland."},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1719030.1719036"},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1456362.1456376"},{"key":"e_1_3_2_2_14_1","first-page":"3","article-title":"Security Metrics: A Solution in Search of a Problem","volume":"31","author":"Rosenblatt J.","year":"2008","journal-title":"EDUCAUSE Quarterly"},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"crossref","unstructured":"Jansen W. 2009. Directions in Security Metrics Research. Report NISTIR 7564. National Institute of Standards and Technology Gaithersburg MD.  Jansen W. 2009. Directions in Security Metrics Research . Report NISTIR 7564. National Institute of Standards and Technology Gaithersburg MD.","DOI":"10.6028\/NIST.IR.7564"},{"key":"e_1_3_2_2_16_1","unstructured":"Bartol N. Bates B. Goertzel K.M. and T. Winograd 2009. Measuring Cyber Security and Information Assurance. State of the Art Report. Information Assurance Technology Analysis Center (IATAC) Herndon VA.  Bartol N. Bates B. Goertzel K.M. and T. Winograd 2009. Measuring Cyber Security and Information Assurance . State of the Art Report. Information Assurance Technology Analysis Center (IATAC) Herndon VA."},{"key":"e_1_3_2_2_17_1","first-page":"2","article-title":"The Applicability of Existing Metrics for Software Security","volume":"8","author":"Sree Ram Kumar T.","year":"2010","journal-title":"Int. J. of Computer Applications"},{"key":"e_1_3_2_2_18_1","first-page":"1","article-title":"On the Feasibility of Utilizing Security Metrics in Software-Intensive Systems","volume":"10","author":"Savola R.","year":"2010","journal-title":"Int. J. of Computer Science and Network Security"},{"volume-title":"Proc. ICCRTS'07","year":"2007","author":"Torgersen M.D.","key":"e_1_3_2_2_19_1"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2011.56"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISISE.2009.68"},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1842752.1842791"},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICICISYS.2009.5358114"},{"volume-title":"Proc. SCS 2010, 1st Workshop on Secure Control Systems","year":"2010","author":"L\u00f6f F.","key":"e_1_3_2_2_24_1"},{"key":"e_1_3_2_2_25_1","unstructured":"Anonymous 2009. Software Security Assessment Tools Review. Booz Allen Hamilton McLean VA.  Anonymous 2009. Software Security Assessment Tools Review . Booz Allen Hamilton McLean VA."},{"key":"e_1_3_2_2_26_1","unstructured":"Dowd M. McDonald J. and Schuh J. 2007. The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities. Addison-Wesley Boston MA.   Dowd M. McDonald J. and Schuh J. 2007. The Art of Software Security Assessment: Identifying and Preventing Software Vulnerabilities. Addison-Wesley Boston MA."},{"key":"e_1_3_2_2_27_1","first-page":"5","article-title":"Complex Fluid Mixing Flows: Simulation vs. Theory vs","volume":"39","author":"Glimm J.","year":"2006","journal-title":"Experiment. SIAM News."},{"key":"e_1_3_2_2_28_1","first-page":"126","volume-title":"Proc. PROMOTE IT 2002, 2nd Conference for the Promotion of Research in IT at New Universities and at University Colleges in Sweden","author":"Dodig-Crnkovic G.","year":"2002"},{"key":"e_1_3_2_2_29_1","first-page":"1","article-title":"On the Interaction Between Theory, Experiments, and Simulation in Developing Practical Learning Control","volume":"13","author":"Longman R.W.","year":"2003","journal-title":"Algorithms. Int. J. Appl. Math. Comput. Sci."},{"key":"e_1_3_2_2_30_1","first-page":"2","article-title":"Towards Operational Measures of Computer Security","volume":"2","author":"Littlewood B.","year":"1992","journal-title":"Journal of Computer Security"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF01001956"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/SITIS.2007.114"},{"key":"e_1_3_2_2_33_1","first-page":"4","article-title":"Synthetic Security Assessment Based on Variable Consistency Dominance-based Rough Set Approach","volume":"16","author":"Liang Z.","year":"2010","journal-title":"High Technology Letters"},{"key":"e_1_3_2_2_34_1","first-page":"2","article-title":"Experimental Evaluation of Software Development Tools for Safety-Critical Real-Time Systems","volume":"1","author":"Kornecki A.","year":"2005","journal-title":"Innovations in Systems and Software Engineering - A NASA Journal"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SEW.2011.12"},{"key":"e_1_3_2_2_36_1","unstructured":"PTC - The Product Development Company 2011. Relex Markov Modeling Tool. http:\/\/www.ptc.com\/products\/windchill\/markov  PTC - The Product Development Company 2011. Relex Markov Modeling Tool . http:\/\/www.ptc.com\/products\/windchill\/markov"}],"event":{"name":"CSIIRW '11: Cyber Security and Information Intelligence Research Workshop","sponsor":["Eurosis Eurosis","Oak Ridge National Laboratory","University of Tennessee University of Tennessee"],"location":"Oak Ridge Tennessee USA","acronym":"CSIIRW '11"},"container-title":["Proceedings of the Seventh Annual Workshop on Cyber Security and Information Intelligence Research"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2179298.2179348","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2179298.2179348","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T20:00:41Z","timestamp":1750276841000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2179298.2179348"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2011,10,12]]},"references-count":36,"alternative-id":["10.1145\/2179298.2179348","10.1145\/2179298"],"URL":"https:\/\/doi.org\/10.1145\/2179298.2179348","relation":{},"subject":[],"published":{"date-parts":[[2011,10,12]]},"assertion":[{"value":"2011-10-12","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}