{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T04:20:05Z","timestamp":1750306805480,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":29,"publisher":"ACM","license":[{"start":{"date-parts":[[2013,11,26]],"date-time":"2013-11-26T00:00:00Z","timestamp":1385424000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2013,11,26]]},"DOI":"10.1145\/2523514.2523537","type":"proceedings-article","created":{"date-parts":[[2014,1,7]],"date-time":"2014-01-07T14:49:20Z","timestamp":1389106160000},"page":"136-143","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Continuous security evaluation and auditing of remote platforms by combining trusted computing and security automation techniques"],"prefix":"10.1145","author":[{"given":"Mudassar","family":"Aslam","sequence":"first","affiliation":[{"name":"SICS Swedish ICT, Kista, Sweden and M\u00e4lardalen University, V\u00e4ster\u00e5s, Sweden"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian","family":"Gehrmann","sequence":"additional","affiliation":[{"name":"SICS Swedish ICT, Kista, Sweden"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mats","family":"Bj\u00f6rkman","sequence":"additional","affiliation":[{"name":"M\u00e4lardalen University, V\u00e4ster\u00e5s, Sweden"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2013,11,26]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"The United States Government Configuration Baseline (USGCB). http:\/\/usgcb.nist.gov\/index.html\/.  The United States Government Configuration Baseline (USGCB). http:\/\/usgcb.nist.gov\/index.html\/."},{"key":"e_1_3_2_1_2_1","volume-title":"January","author":"Baker J.","year":"2012","unstructured":"J. Baker , M. Hansbury , and D. Haynes . The OVAL Language Specification. https:\/\/oval.mitre.org\/language\/version5.10.1\/OVAL_Language_Specification_01-20-2012.pdf , January 2012 . J. Baker, M. Hansbury, and D. Haynes. The OVAL Language Specification. https:\/\/oval.mitre.org\/language\/version5.10.1\/OVAL_Language_Specification_01-20-2012.pdf, January 2012."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","unstructured":"H. Booth and A. Halbardier. The Trust Model for Security Automation Data (TMSAD) Version 1.0. http:\/\/csrc.nist.gov\/publications\/nistir\/ir7802\/NISTIR-7802.pdf September 2011.  H. Booth and A. Halbardier. The Trust Model for Security Automation Data (TMSAD) Version 1.0. http:\/\/csrc.nist.gov\/publications\/nistir\/ir7802\/NISTIR-7802.pdf September 2011.","DOI":"10.6028\/NIST.IR.7802"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-68979-9_2"},{"key":"e_1_3_2_1_5_1","volume-title":"A practical guide to trusted computing","author":"Challener D.","year":"2007","unstructured":"D. Challener , K. Yoder , R. Catherman , D. Safford , and L. Van Doorn . A practical guide to trusted computing . IBM Press , first edition, 2007 . D. Challener, K. Yoder, R. Catherman, D. Safford, and L. Van Doorn. A practical guide to trusted computing. IBM Press, first edition, 2007."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"crossref","unstructured":"B. A. Cheikes D. Waltermire and K. Scarfone. Common Platform Enumeration: Naming Specification Version 2.3. http:\/\/csrc.nist.gov\/publications\/nistir\/ir7695\/NISTIR-7695-CPE-Naming.pdf August 2011.  B. A. Cheikes D. Waltermire and K. Scarfone. Common Platform Enumeration: Naming Specification Version 2.3. http:\/\/csrc.nist.gov\/publications\/nistir\/ir7695\/NISTIR-7695-CPE-Naming.pdf August 2011.","DOI":"10.6028\/NIST.IR.7695"},{"key":"e_1_3_2_1_7_1","unstructured":"Common Platform Enumeration (CPE) Technical Use Case Analysis. http:\/\/cpe.mitre.org\/cpe\/archive\/cpe_technical_use_cases.pdf November 2008.  Common Platform Enumeration (CPE) Technical Use Case Analysis. http:\/\/cpe.mitre.org\/cpe\/archive\/cpe_technical_use_cases.pdf November 2008."},{"key":"e_1_3_2_1_8_1","first-page":"2012","author":"Extensible Configuration Checklist Description Specification","year":"2012","unstructured":"Specification for the Extensible Configuration Checklist Description Format (XCCDF) , Version 1.2. http:\/\/csrc.nist.gov\/publications\/nistir\/ir7275-rev4\/nistir-7275r4_updated-march- 2012 _clean.pdf, March 2012 . Specification for the Extensible Configuration Checklist Description Format (XCCDF), Version 1.2. http:\/\/csrc.nist.gov\/publications\/nistir\/ir7275-rev4\/nistir-7275r4_updated-march-2012_clean.pdf, March 2012.","journal-title":"Version 1.2. http:\/\/csrc.nist.gov\/publications\/nistir\/ir7275-rev4\/nistir-7275r4_updated-march-"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1506409.1506429"},{"key":"e_1_3_2_1_10_1","first-page":"80","volume-title":"An Effective Approach for Remote Attestation in Trusted Computing. In WISA 2009: Proceedings of the 2nd International Symposium on Web Information Systems and Applications","author":"Huang X.","year":"2009","unstructured":"X. Huang and Y. Peng . An Effective Approach for Remote Attestation in Trusted Computing. In WISA 2009: Proceedings of the 2nd International Symposium on Web Information Systems and Applications , pages 80 -- 83 , FIN-90571, OULU, FINLAND, 2009 . Academy Publisher. X. Huang and Y. Peng. An Effective Approach for Remote Attestation in Trusted Computing. In WISA 2009: Proceedings of the 2nd International Symposium on Web Information Systems and Applications, pages 80--83, FIN-90571, OULU, FINLAND, 2009. Academy Publisher."},{"key":"e_1_3_2_1_11_1","volume-title":"November","author":"Infrastructure Architecture TCG","year":"2006","unstructured":"TCG Infrastructure Architecture Part- II - Integrity Management . http:\/\/www.trustedcomputinggroup.org\/resources , November 2006 . TCG Infrastructure Architecture Part-II - Integrity Management. http:\/\/www.trustedcomputinggroup.org\/resources, November 2006."},{"key":"e_1_3_2_1_12_1","volume-title":"November","author":"Schema Specification Integrity Report","year":"2006","unstructured":"Integrity Report Schema Specification . http:\/\/www.trustedcomputinggroup.org\/resources , November 2006 . Integrity Report Schema Specification. http:\/\/www.trustedcomputinggroup.org\/resources, November 2006."},{"key":"e_1_3_2_1_13_1","volume-title":"July","author":"Mann D.","year":"2008","unstructured":"D. Mann . An Introduction to the Common Configuration Enumeration (CCE). http:\/\/cce.mitre.org\/documents\/Introduction_to_CCE_White_Paper_July_2008.pdf , July 2008 . D. Mann. An Introduction to the Common Configuration Enumeration (CCE). http:\/\/cce.mitre.org\/documents\/Introduction_to_CCE_White_Paper_July_2008.pdf, July 2008."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"P. Mell K. Scarfone and S. Romanosky. The Common Vulnerability Scoring System (CVSS) and Its Applicability to Federal Agency Systems. http:\/\/csrc.nist.gov\/publications\/nistir\/ir7435\/NISTIR-7435.pdf August 2007.  P. Mell K. Scarfone and S. Romanosky. The Common Vulnerability Scoring System (CVSS) and Its Applicability to Federal Agency Systems. http:\/\/csrc.nist.gov\/publications\/nistir\/ir7435\/NISTIR-7435.pdf August 2007.","DOI":"10.6028\/NIST.IR.7435"},{"key":"e_1_3_2_1_15_1","unstructured":"S. Munetoh. Open Platform Trust Services (OpenPTS) User's Guide. http:\/\/sourceforge.jp\/projects\/openpts\/wiki\/FrontPage\/attach\/userguide-0.2.3-OSS.pdf March 2011.  S. Munetoh. Open Platform Trust Services (OpenPTS) User's Guide. http:\/\/sourceforge.jp\/projects\/openpts\/wiki\/FrontPage\/attach\/userguide-0.2.3-OSS.pdf March 2011."},{"key":"e_1_3_2_1_16_1","volume-title":"April","author":"Scanning Virtual Machines Nessus","year":"2013","unstructured":"Nessus 5.0 and Scanning Virtual Machines . http:\/\/static.tenable.com\/documentation\/Nessus_5.0_and_Scanning_Virtual_Machines.pdf , April 2013 . Nessus 5.0 and Scanning Virtual Machines. http:\/\/static.tenable.com\/documentation\/Nessus_5.0_and_Scanning_Virtual_Machines.pdf, April 2013."},{"key":"e_1_3_2_1_17_1","unstructured":"Recommended Security Controls for Federal Information Systems and Organizations NIST Special Publication 800-53 Revision 3. http:\/\/csrc.nist.gov\/publications\/nistpubs\/800-53-Rev3\/sp800-53-rev3-final_updated-errata_05-01-2010.pdf January 2010.  Recommended Security Controls for Federal Information Systems and Organizations NIST Special Publication 800-53 Revision 3. http:\/\/csrc.nist.gov\/publications\/nistpubs\/800-53-Rev3\/sp800-53-rev3-final_updated-errata_05-01-2010.pdf January 2010."},{"key":"e_1_3_2_1_18_1","unstructured":"The National Vulnerability Database. http:\/\/nvd.nist.gov\/.  The National Vulnerability Database. http:\/\/nvd.nist.gov\/."},{"key":"e_1_3_2_1_19_1","volume-title":"October","author":"Payment Card Quick Reference","year":"2010","unstructured":"Quick Reference Guide to the Payment Card Industry (PCI) Data Security Standard (DSS). https:\/\/www.pcisecuritystandards.org\/documents\/PCISSCQuickReferenceGuide.pdf , October 2010 . Quick Reference Guide to the Payment Card Industry (PCI) Data Security Standard (DSS). https:\/\/www.pcisecuritystandards.org\/documents\/PCISSCQuickReferenceGuide.pdf, October 2010."},{"key":"e_1_3_2_1_20_1","first-page":"223","volume-title":"USENIX Security Symposium","author":"Sailer R.","year":"2004","unstructured":"R. Sailer , X. Zhang , T. Jaeger , and L. van Doorn . Design and Implementation of a TCG-based Integrity Measurement Architecture . In USENIX Security Symposium , pages 223 -- 238 , 2004 . R. Sailer, X. Zhang, T. Jaeger, and L. van Doorn. Design and Implementation of a TCG-based Integrity Measurement Architecture. In USENIX Security Symposium, pages 223--238, 2004."},{"key":"e_1_3_2_1_21_1","volume-title":"October","author":"SCAP","year":"2012","unstructured":"SCAP Messages for IF-M. http:\/\/www.trustedcomputinggroup.org\/resources\/tnc_scap_messages_for_ifm , October 2012 . SCAP Messages for IF-M. http:\/\/www.trustedcomputinggroup.org\/resources\/tnc_scap_messages_for_ifm, October 2012."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"crossref","unstructured":"K. Scarfone and P. Mell. The Common Configuration Scoring System (CCSS): Metrics for Software Security Configuration Vulnerabilities. http:\/\/csrc.nist.gov\/publications\/nistir\/ir7502\/nistir-7502_CCSS.pdf December 2010.  K. Scarfone and P. Mell. The Common Configuration Scoring System (CCSS): Metrics for Software Security Configuration Vulnerabilities. http:\/\/csrc.nist.gov\/publications\/nistir\/ir7502\/nistir-7502_CCSS.pdf December 2010.","DOI":"10.6028\/NIST.IR.7502"},{"key":"e_1_3_2_1_23_1","volume-title":"Morgan Kaufmann","author":"Smith J.","year":"2005","unstructured":"J. Smith and R. Nair . Virtual machines: versatile platforms for systems and processes . Morgan Kaufmann , 2005 . J. Smith and R. Nair. Virtual machines: versatile platforms for systems and processes. Morgan Kaufmann, 2005."},{"key":"e_1_3_2_1_24_1","volume-title":"January","author":"Common Towards","year":"1999","unstructured":"Towards a Common Enumeration of Vulnerabilities . http:\/\/cve.mitre.org\/docs\/docs-2000\/cerias.html , January 1999 . Towards a Common Enumeration of Vulnerabilities. http:\/\/cve.mitre.org\/docs\/docs-2000\/cerias.html, January 1999."},{"key":"e_1_3_2_1_25_1","unstructured":"TPM Specification TPM Main Part-III Design Principles. http:\/\/www.trustedcomputinggroup.org\/resources July 2007.  TPM Specification TPM Main Part-III Design Principles. http:\/\/www.trustedcomputinggroup.org\/resources July 2007."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314354.1314356"},{"key":"e_1_3_2_1_27_1","unstructured":"CVE and CCE Statistics. http:\/\/web.nvd.nist.gov\/view\/vuln\/statistics.  CVE and CCE Statistics. http:\/\/web.nvd.nist.gov\/view\/vuln\/statistics."},{"key":"e_1_3_2_1_28_1","first-page":"P800","article-title":"Security Content Automation Protocol (SCAP), NIST Special Publication 800-126","volume":"800","author":"Waltermire D.","year":"2011","unstructured":"D. Waltermire , S. Quinn , K. Scarfone , and A. Halbardier . Security Content Automation Protocol (SCAP), NIST Special Publication 800-126 , Version 1.2. http:\/\/csrc.nist.gov\/publications\/nistpubs\/ 800-126 -rev2\/S P800 - P126 r2.pdf, September 2011 . D. Waltermire, S. Quinn, K. Scarfone, and A. Halbardier. Security Content Automation Protocol (SCAP), NIST Special Publication 800-126, Version 1.2. http:\/\/csrc.nist.gov\/publications\/nistpubs\/800-126-rev2\/SP800-126r2.pdf, September 2011.","journal-title":"Version 1.2. http:\/\/csrc.nist.gov\/publications\/nistpubs\/"},{"key":"e_1_3_2_1_29_1","volume-title":"Security Automation Essentials - Streamlined Enterprise Security Management and Monitoring with SCAP","author":"Witte G.","year":"2012","unstructured":"G. Witte , M. Cook , M. Kerr , and S. Shaffer . Security Automation Essentials - Streamlined Enterprise Security Management and Monitoring with SCAP . McGraw-Hill Osborne Media , 2012 . G. Witte, M. Cook, M. Kerr, and S. Shaffer. Security Automation Essentials - Streamlined Enterprise Security Management and Monitoring with SCAP. McGraw-Hill Osborne Media, 2012."}],"event":{"name":"SIN '13: The 6th International Conference on Security of Information and Networks","sponsor":["Macquarie U., Austarlia","MNIT Malaviya National Institute of Technology","Aksaray Univ. Aksaray University","SFedU Southern Federal University","SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Aksaray Turkey","acronym":"SIN '13"},"container-title":["Proceedings of the 6th International Conference on Security of Information and Networks"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2523514.2523537","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2523514.2523537","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T07:34:55Z","timestamp":1750232095000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2523514.2523537"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,11,26]]},"references-count":29,"alternative-id":["10.1145\/2523514.2523537","10.1145\/2523514"],"URL":"https:\/\/doi.org\/10.1145\/2523514.2523537","relation":{},"subject":[],"published":{"date-parts":[[2013,11,26]]},"assertion":[{"value":"2013-11-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}