{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,28]],"date-time":"2026-07-28T15:30:14Z","timestamp":1785252614509,"version":"3.55.0"},"reference-count":158,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2017,12,20]],"date-time":"2017-12-20T00:00:00Z","timestamp":1513728000000},"content-version":"vor","delay-in-days":365,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100005713","name":"Office of the Secretary of Defense","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100005713","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2017,12,31]]},"abstract":"<jats:p>\n                    Security metrics have received significant attention. However, they have not been systematically explored based on the understanding of attack-defense interactions, which are affected by various factors, including the degree of system vulnerabilities, the power of system defense mechanisms, attack (or threat) severity, and situations a system at risk faces. This survey particularly focuses on how a system security state can evolve as an outcome of cyber attack-defense interactions. This survey concerns how to measure system-level security by proposing a security metrics framework based on the following four sub-metrics: (1) metrics of\n                    <jats:italic toggle=\"yes\">system vulnerabilities<\/jats:italic>\n                    , (2) metrics of\n                    <jats:italic toggle=\"yes\">defense power<\/jats:italic>\n                    , (3) metrics of\n                    <jats:italic toggle=\"yes\">attack or threat severity<\/jats:italic>\n                    , and (4) metrics of\n                    <jats:italic toggle=\"yes\">situations<\/jats:italic>\n                    . To investigate the relationships among these four sub-metrics, we propose a hierarchical ontology with four sub-ontologies corresponding to the four sub-metrics and discuss how they are related to each other. Using the four sub-metrics, we discuss the state-of-art existing security metrics and their advantages and disadvantages (or limitations) to obtain lessons and insight in order to achieve an ideal goal in developing security metrics. Finally, we discuss open research questions in the security metrics research domain and we suggest key factors to enhance security metrics from a system security perspective.\n                  <\/jats:p>","DOI":"10.1145\/3005714","type":"journal-article","created":{"date-parts":[[2016,12,20]],"date-time":"2016-12-20T08:25:27Z","timestamp":1482222327000},"page":"1-35","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":220,"title":["A Survey on Systems Security Metrics"],"prefix":"10.1145","volume":"49","author":[{"given":"Marcus","family":"Pendleton","sequence":"first","affiliation":[{"name":"The University of Texas at San Antonio, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Richard","family":"Garcia-Lebron","sequence":"additional","affiliation":[{"name":"The University of Texas at San Antonio, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jin-Hee","family":"Cho","sequence":"additional","affiliation":[{"name":"US Army Research Laboratory, MD, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8034-0942","authenticated-orcid":false,"given":"Shouhuai","family":"Xu","sequence":"additional","affiliation":[{"name":"The University of Texas at San Antonio, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2016,12,20]]},"reference":[{"key":"e_1_2_2_1_1","doi-asserted-by":"crossref","unstructured":"M. Ahmed E. Al-Shaer and L. Khan. 2008. A novel quantitative approach for measuring network security. In IEEE INFOCOM\u20192008.","DOI":"10.1109\/INFOCOM.2007.260"},{"key":"e_1_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1413140.1413189"},{"key":"e_1_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.5555\/2354410.2355170"},{"key":"e_1_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1103\/RevModPhys.74.47"},{"key":"e_1_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586140"},{"key":"e_1_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/319709.319710"},{"key":"e_1_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.5555\/2671225.2671253"},{"key":"e_1_2_2_8_1","unstructured":"S. Berinato. 2002. Finally a Real Return on Security Spending. Retrieved from http:\/\/www.cio.com\/article\/2440999\/metrics\/finally--a-real-return-on-security-spending.html. (2002)."},{"key":"e_1_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2013.57"},{"key":"e_1_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382284"},{"key":"e_1_2_2_11_1","volume-title":"Proc. RAID\u201914","author":"Boggs N.","unstructured":"N. Boggs, S. Du, and S. Stolfo. 2014. Measuring drive-by download defense in depth. In Proc. RAID\u201914. 172--191."},{"key":"e_1_2_2_12_1","volume-title":"Proc. Layered Assurance Workshop (LAW\u201911)","author":"Boggs N.","year":"2011","unstructured":"N. Boggs and S. Stolfo. 2011. ALDR: A new metric for measuring effective layering of defenses. In Proc. Layered Assurance Workshop (LAW\u201911) (2011)."},{"key":"e_1_2_2_13_1","volume-title":"Dependability Metrics: Advanced Lectures, 7--13.","author":"B\u00f6hme R.","year":"2008","unstructured":"R. B\u00f6hme and F. Freiling. 2008. Dependability Metrics: Advanced Lectures, 7--13."},{"key":"e_1_2_2_14_1","doi-asserted-by":"crossref","unstructured":"R. B\u00f6hme and T. Nowey. 2008. Dependability metrics. Chapter Economic Security Metrics 176--187.","DOI":"10.1007\/978-3-540-68947-8_15"},{"key":"e_1_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.49"},{"key":"e_1_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-35694-0_10"},{"key":"e_1_2_2_17_1","unstructured":"N. Burow S. Carr S. Brunthaler M. Payer J. Nash P. Larsen and M. Franz. 2016. Control-flow integrity: Precision security and performance. CoRR abs\/1602.04056 (2016)."},{"key":"e_1_2_2_18_1","unstructured":"W. Burr D. Dodson and W. Polk. 2006. Electronic Authentication Guideline. NIST Publication 800-63 Version 1.0.2. Retrieved from http:\/\/csrc.nist.gov\/publications\/nistpubs\/800-63\/SP800-63V1_0_2.pdf."},{"key":"e_1_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2006.2"},{"key":"e_1_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2008.295"},{"key":"e_1_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.5555\/2831143.2831154"},{"key":"e_1_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.5555\/2671225.2671250"},{"key":"e_1_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/2739044"},{"key":"e_1_2_2_24_1","volume-title":"Proc. NDSS\u201912","author":"Castelluccia C.","unstructured":"C. Castelluccia, M. D\u00fcrmuth, and D. Perito. 2012. Adaptive password-strength meters from markov models. In Proc. NDSS\u201912."},{"key":"e_1_2_2_25_1","doi-asserted-by":"publisher","unstructured":"V. Chandola A. Banerjee and V. Kumar. 2009. Anomaly detection: A survey. ACM Comput. Surv. 41 3 (2009) 15:1--15:58. 10.1145\/1541880.1541882","DOI":"10.1145\/1541880.1541882"},{"key":"e_1_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2007.22"},{"key":"e_1_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/SRDS.2012.4"},{"key":"e_1_2_2_28_1","doi-asserted-by":"crossref","unstructured":"Y. Cheng J. Deng J. Li S. DeLoach A. Singhal and X. Ou. 2014. Metrics of security. In Cyber Defense and Situational Awareness. Vol. 62.","DOI":"10.1007\/978-3-319-11391-3_13"},{"key":"e_1_2_2_29_1","doi-asserted-by":"crossref","unstructured":"E. Chew M. Swanson K. Stine N. Bartol A. Brown and W. Robinson. 2008. NIST Special Publication 800-55 Revision 1: Performance Measurement Guide for Information Security.","DOI":"10.6028\/NIST.SP.800-55r1"},{"key":"e_1_2_2_30_1","volume-title":"Proc. IEEE CogSIMA\u201916","author":"Cho J.","unstructured":"J. Cho, H. Cam, and A. Oltramari. 2016. Effect of personality traits on trust and risk to phishing vulnerability: Modeling and analysis. In Proc. IEEE CogSIMA\u201916."},{"key":"e_1_2_2_31_1","unstructured":"CIS. 2010. The CIS Security Metrics (ver 1.1.0). Retrieved from http:\/\/benchmarks.cisecurity.org\/downloads\/metrics\/. (2010)."},{"key":"e_1_2_2_32_1","unstructured":"INFOSEC Research Council. 2007. Hard Problem List. Retrieved from http:\/\/www.infosec-research.org\/ docs_public\/20051130-IRC-HPL-FINAL.pdf. (2007)."},{"key":"e_1_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/2600176.2600184"},{"key":"e_1_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.5555\/265514.265530"},{"key":"e_1_2_2_35_1","volume-title":"Proc. ACSAC\u201907","author":"Dagon D.","unstructured":"D. Dagon, G. Gu, C. Lee, and W. Lee. 2007. A taxonomy of botnet structures. In Proc. ACSAC\u201907. 325--339."},{"key":"e_1_2_2_36_1","volume-title":"Proc. NDSS\u201906","author":"Dagon D.","unstructured":"D. Dagon, C. Zou, and W. Lee. 2006. Modeling botnet propagation using time zones. In Proc. NDSS\u201906."},{"key":"e_1_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014066"},{"key":"e_1_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.5555\/2671225.2671251"},{"key":"e_1_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.5555\/1833515.1833671"},{"key":"e_1_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.5555\/646754.705196"},{"key":"e_1_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663755"},{"key":"e_1_2_2_42_1","volume-title":"Proc WEIS\u201915","author":"Edwards B.","unstructured":"B. Edwards, S. Hofmeyr, and S. Forrest. 2015. Hype and heavy tails: A closer look at data breaches. In Proc WEIS\u201915. 67--78."},{"key":"e_1_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/2808475.2808486"},{"key":"e_1_2_2_44_1","unstructured":"FIRST. 2015. Forum of Incident Response and Security Teams: Common Vulnerability Scoring System (CVSS) Version 3.0. Retrieved from https:\/\/www.first.org\/cvss. (2015)."},{"key":"e_1_2_2_45_1","unstructured":"S. Frei and T. Kristensen. Feb. 2010. The Security Exposure of SOoftware Portfolios. Retrieved from https:\/\/secunia.com\/gfx\/pdf\/Secunia_RSA_Software_Portfolio_Security_Exposure.pdf. (Feb. 2010)."},{"key":"e_1_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.5555\/1444455.1446067"},{"key":"e_1_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/1456362.1456368"},{"key":"e_1_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.5555\/882495.884438"},{"key":"e_1_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.43"},{"key":"e_1_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/1107458.1107465"},{"key":"e_1_2_2_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/1368310.1368332"},{"key":"e_1_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128834"},{"key":"e_1_2_2_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/2600176.2600180"},{"key":"e_1_2_2_54_1","doi-asserted-by":"publisher","DOI":"10.5555\/2671225.2671259"},{"key":"e_1_2_2_55_1","doi-asserted-by":"publisher","DOI":"10.5555\/2671214.2671219"},{"key":"e_1_2_2_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2013.21"},{"key":"e_1_2_2_57_1","doi-asserted-by":"publisher","DOI":"10.5555\/2590624.2590627"},{"key":"e_1_2_2_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.23"},{"key":"e_1_2_2_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046684.2046692"},{"key":"e_1_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2010.61"},{"key":"e_1_2_2_61_1","doi-asserted-by":"crossref","unstructured":"W. Jansen. 2009. Directions in Security Metrics Research. Retrieved from http:\/\/csrc.nist.gov\/publications\/ nistir\/ir7564\/nistir-7564_metrics-research.pdf. (2009).","DOI":"10.6028\/NIST.IR.7564"},{"key":"e_1_2_2_62_1","doi-asserted-by":"publisher","DOI":"10.5555\/1214710"},{"key":"e_1_2_2_63_1","doi-asserted-by":"publisher","DOI":"10.5555\/794201.795177"},{"key":"e_1_2_2_64_1","volume-title":"Proc. FC\u201912","author":"Johnson B.","unstructured":"B. Johnson, J. Chuang, J. Grossklags, and N. Christin. 2012. Metrics for measuring ISP badness: The case of spam. In Proc. FC\u201912. 89--97."},{"key":"e_1_2_2_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.588541"},{"key":"e_1_2_2_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.38"},{"key":"e_1_2_2_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/2785956.2787494"},{"key":"e_1_2_2_68_1","volume-title":"Proc. RAID\u201914","author":"K\u00fchrer M.","unstructured":"M. K\u00fchrer, C. Rossow, and T. Holz. 2014. Paint it black: Evaluating the effectiveness of malware blacklists. In Proc. RAID\u201914. 1--21."},{"key":"e_1_2_2_69_1","unstructured":"B. Lampson. 2006. Practical Principles for Computer Security. (2006)."},{"key":"e_1_2_2_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/185403.185412"},{"key":"e_1_2_2_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.25"},{"key":"e_1_2_2_72_1","doi-asserted-by":"publisher","DOI":"10.5555\/597917.597919"},{"key":"e_1_2_2_73_1","doi-asserted-by":"publisher","DOI":"10.1109\/QEST.2011.34"},{"key":"e_1_2_2_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516747"},{"key":"e_1_2_2_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/DISCEX.2003.1194877"},{"key":"e_1_2_2_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2008.75"},{"key":"e_1_2_2_77_1","volume-title":"Technical Report IA-3. MIT Lincoln Laboratory.","author":"Lippmann R.","year":"2012","unstructured":"R. Lippmann, J. Riordan, T. Yu, and K. Watson. 2012. Continuous Security Metrics for Prevalent Network Threats: Introduction and First Four Metrics. Technical Report IA-3. MIT Lincoln Laboratory. Retrieved from https:\/\/www.ll.mit.edu\/mission\/cybersec\/publications\/publication-files\/full_papers\/2012_05_22_Lippmann_TechReport_FP.pdf."},{"key":"e_1_2_2_78_1","volume-title":"Dasarathy (Ed.)","volume":"5812","author":"Liu Y.","unstructured":"Y. Liu and H. Man. 2005. Network vulnerability assessment using Bayesian networks. In Data Mining, Intrusion Detection, Information Assurance, and Data Networks Security 2005, B. V. Dasarathy (Ed.), Vol. 5812. 61--71."},{"key":"e_1_2_2_79_1","doi-asserted-by":"publisher","DOI":"10.5555\/2831143.2831207"},{"key":"e_1_2_2_80_1","doi-asserted-by":"publisher","unstructured":"D. Lowd and C. Meek. 2005. Adversarial learning. In KDD\u201905. 641--647. 10.1145\/1081870.1081950","DOI":"10.1145\/1081870.1081950"},{"key":"e_1_2_2_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813694"},{"key":"e_1_2_2_82_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-02786-9_13"},{"key":"e_1_2_2_83_1","doi-asserted-by":"publisher","DOI":"10.5555\/647883.738399"},{"key":"e_1_2_2_84_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.60"},{"key":"e_1_2_2_85_1","doi-asserted-by":"publisher","DOI":"10.5555\/2671225.2671258"},{"key":"e_1_2_2_86_1","doi-asserted-by":"publisher","DOI":"10.1145\/1179494.1179495"},{"key":"e_1_2_2_87_1","doi-asserted-by":"publisher","DOI":"10.1145\/2746194.2746202"},{"key":"e_1_2_2_88_1","unstructured":"Microsoft. 2013-2014. Security Intelligence Report. Retrieved from http:\/\/www.microsoft.com\/security\/sir\/ default.aspx. (2013-2014)."},{"key":"e_1_2_2_89_1","doi-asserted-by":"publisher","unstructured":"A. Milenkoski M. Vieira S. Kounev A. Avritzer and B. Payne. 2015. Evaluating computer intrusion detection systems: A survey of common practices. ACM Comput. Surv. 48 1 (2015). 10.1145\/2808691","DOI":"10.1145\/2808691"},{"key":"e_1_2_2_90_1","unstructured":"MITRE. 2014. Common Weakness Scoring System (CWSS version 1.0.1). Retrieved from https:\/\/cwe.mitre. org\/cwss\/cwss_v1.0.1.html. (2014)."},{"key":"e_1_2_2_91_1","volume-title":"Proc. DIMVA\u20192014","author":"Mohaisen A.","unstructured":"A. Mohaisen and O. Alrawi. 2014. Av-meter: An evaluation of antivirus scans and labels. In Proc. DIMVA\u20192014. 112--131."},{"key":"e_1_2_2_92_1","unstructured":"J. Morales S. Xu and R. Sandhu. 2012. Analyzing malware detection eciency with multiple anti-malware programs. ASE Sci. J. 1 2 (2012) 56--66."},{"key":"e_1_2_2_93_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.48"},{"key":"e_1_2_2_94_1","volume-title":"Proc. RAID\u201914","author":"Nayak K.","unstructured":"K. Nayak, D. Marino, P. Efstathopoulos, and T. Dumitras. 2014. Some vulnerabilities are different than others. In Proc. RAID\u201914. 426--446."},{"key":"e_1_2_2_95_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813660"},{"key":"e_1_2_2_96_1","unstructured":"D. Nicol B. Sanders J. Katz B. Scherlis T. Dumitra L. Williams and M. Singh. 2015. The Science of Security 5 Hard Problems. Retrieved from http:\/\/cps-vo.org\/node\/21590. (2015)."},{"key":"e_1_2_2_97_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2004.11"},{"key":"e_1_2_2_98_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813644"},{"key":"e_1_2_2_99_1","doi-asserted-by":"publisher","DOI":"10.1145\/2602087.2602117"},{"key":"e_1_2_2_100_1","doi-asserted-by":"publisher","DOI":"10.1109\/32.815323"},{"key":"e_1_2_2_101_1","doi-asserted-by":"crossref","unstructured":"X. Ou and A. Singhal. 2011. Quantitative Security Risk Assessment of Enterprise Networks. Springer.","DOI":"10.1007\/978-1-4614-1860-3"},{"key":"e_1_2_2_102_1","doi-asserted-by":"publisher","DOI":"10.1145\/1179494.1179502"},{"key":"e_1_2_2_103_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2010.60"},{"key":"e_1_2_2_104_1","doi-asserted-by":"publisher","DOI":"10.1109\/MITP.2009.63"},{"key":"e_1_2_2_105_1","doi-asserted-by":"publisher","DOI":"10.1145\/310889.310919"},{"key":"e_1_2_2_106_1","doi-asserted-by":"publisher","DOI":"10.1145\/2808475.2808483"},{"key":"e_1_2_2_107_1","doi-asserted-by":"publisher","DOI":"10.5555\/1251398.1251413"},{"key":"e_1_2_2_108_1","doi-asserted-by":"publisher","DOI":"10.1145\/317087.317088"},{"key":"e_1_2_2_109_1","doi-asserted-by":"publisher","DOI":"10.5555\/882494.884423"},{"key":"e_1_2_2_110_1","volume-title":"Measurement Theory, with Applications to Decision Making, Utility and the Social Sciences","author":"Roberts F.","unstructured":"F. Roberts. 1979. Measurement Theory, with Applications to Decision Making, Utility and the Social Sciences. Addison-Wesley, Boston."},{"key":"e_1_2_2_111_1","doi-asserted-by":"publisher","DOI":"10.1145\/2522968.2522972"},{"key":"e_1_2_2_112_1","doi-asserted-by":"publisher","DOI":"10.5555\/2831143.2831209"},{"key":"e_1_2_2_113_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2014.31"},{"key":"e_1_2_2_114_1","doi-asserted-by":"publisher","DOI":"10.5555\/517959"},{"key":"e_1_2_2_115_1","volume-title":"Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program.","author":"National Science and Technology Council.","year":"2011","unstructured":"National Science and Technology Council. 2011. Trustworthy Cyberspace: Strategic Plan for the Federal Cybersecurity Research and Development Program. Retrieved from https:\/\/www.nitrd.gov\/SUBCOMMITTEE\/csia\/Fed_Cybersecurity_RD_Strategic_Plan_2011.pdf. (2011)."},{"key":"e_1_2_2_116_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030083.1030124"},{"key":"e_1_2_2_117_1","doi-asserted-by":"publisher","DOI":"10.1145\/1753326.1753383"},{"key":"e_1_2_2_118_1","doi-asserted-by":"publisher","DOI":"10.5555\/829514.830526"},{"key":"e_1_2_2_119_1","doi-asserted-by":"crossref","unstructured":"A. Singhal and X. Ou. 2011. Security Risk Analysis of Enterprise Networks Using Probabilistic Attack Graphs. National Institute of Standards and Technology. Retrieved from http:\/\/csrc.nist.gov\/publications\/nistir\/ir7788\/NISTIR-7788.pdf.","DOI":"10.6028\/NIST.IR.7788"},{"key":"e_1_2_2_120_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.45"},{"key":"e_1_2_2_121_1","doi-asserted-by":"publisher","DOI":"10.5555\/2590720.2590722"},{"key":"e_1_2_2_122_1","doi-asserted-by":"crossref","unstructured":"S. Stevens. 1946. On the theory of scales of measurement. (1946).","DOI":"10.1126\/science.103.2684.677"},{"key":"e_1_2_2_123_1","volume-title":"Proc. DISCEX\u201900","author":"Stolfo S.","unstructured":"S. Stolfo, W. Fan, W. Lee, A. Prodromidis, and P. Chan. 2000. Cost-based modeling for fraud and intrusion detection: Results from the JAM project. In Proc. DISCEX\u201900. 130--144."},{"key":"e_1_2_2_124_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2009.29"},{"key":"e_1_2_2_125_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2009.54"},{"key":"e_1_2_2_126_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813685"},{"key":"e_1_2_2_127_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSMCC.2010.2048428"},{"key":"e_1_2_2_128_1","unstructured":"U. Thakore. 2015. A quantitative methodology for evaluating and deploying security monitors. Retrieved from https:\/\/www.ideals.illinois.edu\/handle\/2142\/88103. (2015)."},{"key":"e_1_2_2_129_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.46"},{"key":"e_1_2_2_130_1","doi-asserted-by":"publisher","DOI":"10.5555\/2362793.2362798"},{"key":"e_1_2_2_131_1","doi-asserted-by":"publisher","DOI":"10.5555\/2831143.2831173"},{"key":"e_1_2_2_132_1","doi-asserted-by":"publisher","DOI":"10.1080\/00031305.1993.10475938"},{"key":"e_1_2_2_133_1","doi-asserted-by":"publisher","DOI":"10.1145\/1719030.1719036"},{"key":"e_1_2_2_134_1","volume-title":"Proc. ICEIS\u201904","author":"Villarrubia C.","unstructured":"C. Villarrubia, E. Fernandez-Medina, and M. Piattini. 2004. Towards a classification of security metrics. In Proc. ICEIS\u201904. 341--350."},{"key":"e_1_2_2_135_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.20"},{"key":"e_1_2_2_136_1","first-page":"00327","article-title":"Technical Privacy Metrics: A Systematic Survey","volume":"1512","author":"Wagner I.","year":"2015","unstructured":"I. Wagner and D. Eckhoff. 2015. Technical Privacy Metrics: A Systematic Survey. Technical Report 1512.00327. arXiv. Retrieved from http:\/\/arxiv.org\/abs\/1512.00327 arXiv: 1512.00327.","journal-title":"Technical Report"},{"key":"e_1_2_2_137_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70567-3_22"},{"key":"e_1_2_2_138_1","doi-asserted-by":"publisher","DOI":"10.5555\/1888881.1888926"},{"key":"e_1_2_2_139_1","volume-title":"Proceedings of the 28th Annual Computer Security Conference. Washington, D.C.","author":"Wei H.","unstructured":"H. Wei, D. Frinke, O. Carter, and C. Ritter. 2001. Cost-benefit analysis for network intrusion detection systems. In Proceedings of the 28th Annual Computer Security Conference. Washington, D.C."},{"key":"e_1_2_2_140_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866327"},{"key":"e_1_2_2_141_1","volume-title":"Proc. IEEE CNS\u201914","author":"Xu L.","unstructured":"L. Xu, Z. Zhan, S. Xu, and K. Ye. 2014b. An evasion and counter-evasion study in malicious websites detection. In Proc. IEEE CNS\u201914. 265--273."},{"key":"e_1_2_2_142_1","doi-asserted-by":"publisher","DOI":"10.1080\/15427951.2014.902407"},{"key":"e_1_2_2_143_1","doi-asserted-by":"publisher","DOI":"10.1080\/15427951.2012.654480"},{"key":"e_1_2_2_144_1","doi-asserted-by":"publisher","DOI":"10.1145\/2600176.2600190"},{"key":"e_1_2_2_145_1","doi-asserted-by":"publisher","DOI":"10.1145\/2600176.2600189"},{"key":"e_1_2_2_146_1","doi-asserted-by":"publisher","DOI":"10.1080\/15427951.2013.830583"},{"key":"e_1_2_2_147_1","doi-asserted-by":"publisher","unstructured":"S. Xu W. Lu and L. Xu. 2012a. Push- and pull-based epidemic spreading in arbitrary networks: Thresholds and deeper insights. ACM TAAS 7 3 (2012) 32:1--32:26. 10.1145\/2348832.2348835","DOI":"10.1145\/2348832.2348835"},{"key":"e_1_2_2_148_1","doi-asserted-by":"publisher","DOI":"10.1145\/2555613"},{"key":"e_1_2_2_149_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2011.33"},{"key":"e_1_2_2_150_1","volume-title":"Symantec Develops New Attack on Cyberhacking.","author":"Yardon D.","year":"2014","unstructured":"D. Yardon. May 4, 2014. Symantec Develops New Attack on Cyberhacking. Retrieved from http:\/\/www.wsj. com\/articles\/SB10001424052702303417104579542140235850578. (May 4, 2014)."},{"key":"e_1_2_2_151_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660330"},{"key":"e_1_2_2_152_1","doi-asserted-by":"publisher","DOI":"10.1145\/1644893.1644896"},{"key":"e_1_2_2_153_1","doi-asserted-by":"publisher","DOI":"10.1145\/2808475.2808476"},{"key":"e_1_2_2_154_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-27998-5_7"},{"key":"e_1_2_2_155_1","volume-title":"Proc. NDSS\u201914","author":"Zhang J.","unstructured":"J. Zhang, Z. Durumeric, M. Bailey, M. Liu, and M. Karir. 2014. On the mismanagement and maliciousness of networks. In Proc. NDSS\u201914."},{"key":"e_1_2_2_156_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2016.2516916"},{"key":"e_1_2_2_157_1","doi-asserted-by":"publisher","DOI":"10.1145\/2590296.2590300"},{"key":"e_1_2_2_158_1","doi-asserted-by":"publisher","DOI":"10.1145\/2746194.2746196"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3005714","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3005714","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3005714","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T09:22:22Z","timestamp":1763457742000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3005714"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,12,20]]},"references-count":158,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2017,12,31]]}},"alternative-id":["10.1145\/3005714"],"URL":"https:\/\/doi.org\/10.1145\/3005714","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,12,20]]},"assertion":[{"value":"2016-01-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2016-10-01","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2016-12-20","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}