{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:34:10Z","timestamp":1750221250990,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":47,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,8,27]],"date-time":"2018-08-27T00:00:00Z","timestamp":1535328000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,8,27]]},"DOI":"10.1145\/3230833.3233260","type":"proceedings-article","created":{"date-parts":[[2018,8,13]],"date-time":"2018-08-13T12:29:48Z","timestamp":1534163388000},"page":"1-8","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Determination of Security Threat Classes on the basis of Vulnerability Analysis for Automated Countermeasure Selection"],"prefix":"10.1145","author":[{"given":"Elena","family":"Doynikova","sequence":"first","affiliation":[{"name":"St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences, St. Petersburg"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrey","family":"Fedorchenko","sequence":"additional","affiliation":[{"name":"St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences, St. Petersburg"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Igor","family":"Kotenko","sequence":"additional","affiliation":[{"name":"St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences, St. Petersburg"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,8,27]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"M.Blowers J.Iribarne E.Colbert A. Kott. 2016. The future Internet of things and security of its control systems. Web: https:\/\/arxiv.org\/ftp\/arxiv\/papers\/1610\/1610.01953.pdf  M.Blowers J.Iribarne E.Colbert A. Kott. 2016. The future Internet of things and security of its control systems. Web: https:\/\/arxiv.org\/ftp\/arxiv\/papers\/1610\/1610.01953.pdf"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/PDP.2016.96"},{"key":"e_1_3_2_1_3_1","volume-title":"Lecture Notes in Computer Science (LNCS)","author":"Doynikova E.","year":"2016","unstructured":"E. Doynikova , I. Kotenko . 2016. Countermeasure selection based on the attack and service dependency graphs for security incident management. In Lecture Notes in Computer Science (LNCS) , Vol. 9572 , Springer , 2016 . 107--124. http:\/\/link.springer.com\/chapter\/10.1007\/978-3-319-31811-07 E. Doynikova, I. Kotenko. 2016.Countermeasure selection based on the attack and service dependency graphs for security incident management. In Lecture Notes in Computer Science (LNCS), Vol. 9572, Springer, 2016. 107--124. http:\/\/link.springer.com\/chapter\/10.1007\/978-3-319-31811-07"},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of the 11th International Symposium on Intelligent Distributed Computing - IDC'2017","author":"Kotenko I.","year":"2017","unstructured":"I. Kotenko , A. Chechulin , E. Doynikova , A. Fedorchenko . 2017 . Ontological hybrid storage for security data . In Proceedings of the 11th International Symposium on Intelligent Distributed Computing - IDC'2017 , Belgrade, Serbia , 11-13 October 2017. Springer-Verlag, Studies in Computational Intelligence, 2017, 159--171. I. Kotenko, A. Chechulin, E. Doynikova, A. Fedorchenko. 2017. Ontological hybrid storage for security data. In Proceedings of the 11th International Symposium on Intelligent Distributed Computing - IDC'2017, Belgrade, Serbia, 11-13 October 2017. Springer-Verlag, Studies in Computational Intelligence, 2017, 159--171."},{"key":"e_1_3_2_1_5_1","unstructured":"Common Vulnerabilities and Exposures (CVE). Web: https:\/\/cve.mitre.org\/  Common Vulnerabilities and Exposures (CVE). Web: https:\/\/cve.mitre.org\/"},{"key":"e_1_3_2_1_6_1","unstructured":"National Vulnerability Database (NVD) official website. Web: https:\/\/nvd.nist.gov  National Vulnerability Database (NVD) official website. Web: https:\/\/nvd.nist.gov"},{"key":"e_1_3_2_1_7_1","unstructured":"Open Source Vulnerability Database (OSVDB) blog. Web: https:\/\/blog.osvdb.org\/  Open Source Vulnerability Database (OSVDB) blog. Web: https:\/\/blog.osvdb.org\/"},{"key":"e_1_3_2_1_8_1","unstructured":"US Computer Emergency Readiness Team (US-CERT). Web: http:\/\/www.us-cert.gov\/  US Computer Emergency Readiness Team (US-CERT). Web: http:\/\/www.us-cert.gov\/"},{"key":"e_1_3_2_1_9_1","unstructured":"SecurityFocus (BugTraq database) official website. Web: http:\/\/securityfocus.com\/  SecurityFocus (BugTraq database) official website. Web: http:\/\/securityfocus.com\/"},{"key":"e_1_3_2_1_10_1","unstructured":"IBM X-Force exchange project official website. Web: http:\/\/xforce.iss.net.  IBM X-Force exchange project official website. Web: http:\/\/xforce.iss.net."},{"key":"e_1_3_2_1_11_1","unstructured":"Common Platform Enumeration (CPE) official website. Web: https:\/\/nvd.nist.gov\/cpe.cfm  Common Platform Enumeration (CPE) official website. Web: https:\/\/nvd.nist.gov\/cpe.cfm"},{"key":"e_1_3_2_1_12_1","unstructured":"Offensive security's exploit database archive. Web: https:\/\/www.exploit-db.com\/  Offensive security's exploit database archive. Web: https:\/\/www.exploit-db.com\/"},{"key":"e_1_3_2_1_13_1","unstructured":"Common Attack Pattern Enumeration and Classification (CAPEC) official website. Web: https:\/\/capec.mitre.org\/  Common Attack Pattern Enumeration and Classification (CAPEC) official website. Web: https:\/\/capec.mitre.org\/"},{"key":"e_1_3_2_1_14_1","unstructured":"Common Weakness Enumeration (CWE) official website. Web: https:\/\/cwe.mitre.org\/  Common Weakness Enumeration (CWE) official website. Web: https:\/\/cwe.mitre.org\/"},{"key":"e_1_3_2_1_15_1","unstructured":"Common Configuration Enumeration (CCE). Web: https:\/\/nvd.nist.gov\/cce\/index.cfm  Common Configuration Enumeration (CCE). Web: https:\/\/nvd.nist.gov\/cce\/index.cfm"},{"key":"e_1_3_2_1_16_1","unstructured":"Common Vulnerability Scoring System (CVSS) official website. Web: https:\/\/www.first.org\/cvss  Common Vulnerability Scoring System (CVSS) official website. Web: https:\/\/www.first.org\/cvss"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2016039.2016074"},{"key":"e_1_3_2_1_18_1","volume-title":"Security, Risk and Trust (PASSAT) and 2011 IEEE Third Inernational Conference on Social Computing (SocialCom).","author":"Chang Y.-Y.","year":"2011","unstructured":"Y.-Y. Chang , P. Zavarsky , Ron Ruhl , Dale Lindskog . 2011. Trend Analysis of the CVE for Software Vulnerability Management. In 2011 IEEE Third International Conference on Privacy , Security, Risk and Trust (PASSAT) and 2011 IEEE Third Inernational Conference on Social Computing (SocialCom). Boston, MA, USA , 2011 . Y.-Y. Chang, P. Zavarsky, Ron Ruhl, Dale Lindskog. 2011. Trend Analysis of the CVE for Software Vulnerability Management. In 2011 IEEE Third International Conference on Privacy, Security, Risk and Trust (PASSAT) and 2011 IEEE Third Inernational Conference on Social Computing (SocialCom). Boston, MA, USA, 2011."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3176258.3176339"},{"key":"e_1_3_2_1_20_1","volume-title":"Estimating ToE Risk Level Using CVSS. In International Conference on Availability, Reliability and Security","author":"Houmb S.H.","year":"2009","unstructured":"S.H. Houmb and V.N.L. Franqueira . 2009 . Estimating ToE Risk Level Using CVSS. In International Conference on Availability, Reliability and Security , Fukuoka, Japan. 2009. S.H. Houmb and V.N.L.Franqueira. 2009. Estimating ToE Risk Level Using CVSS. In International Conference on Availability, Reliability and Security, Fukuoka, Japan. 2009."},{"key":"e_1_3_2_1_21_1","volume-title":"CHS","author":"Das R.","year":"2012","unstructured":"R. Das , S. Sarkani , T.A. Mazzuchi . 2012 . Software Selection based on Quantitative Security Risk Assessment. IJCA Special Issue on \"Computational Intelligence & Information Security \". CHS 2012. 45--56. R. Das, S. Sarkani, T.A. Mazzuchi. 2012. Software Selection based on Quantitative Security Risk Assessment. IJCA Special Issue on \"Computational Intelligence & Information Security\". CHS 2012. 45--56."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1080\/19393555.2015.1111961"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/MITP.2011.11"},{"key":"e_1_3_2_1_24_1","unstructured":"FISMA Background. NIST official website. Web: https:\/\/csrc.nist.gov\/projects\/risk-management\/detailed-overview  FISMA Background. NIST official website. Web: https:\/\/csrc.nist.gov\/projects\/risk-management\/detailed-overview"},{"key":"e_1_3_2_1_25_1","unstructured":"Federal Desktop Core Configuration (FDCC). NIST official website. Web: https:\/\/www.nist.gov\/programs-projects\/federal-desktop-core-configuration-fdcc  Federal Desktop Core Configuration (FDCC). NIST official website. Web: https:\/\/www.nist.gov\/programs-projects\/federal-desktop-core-configuration-fdcc"},{"key":"e_1_3_2_1_26_1","volume-title":"Requirements and Security Assessment Procedures Version 3.2","author":"Data Security Standard Payment Card","year":"2016","unstructured":"Payment Card Industry (PCI) Data Security Standard . Requirements and Security Assessment Procedures Version 3.2 April 2016 . PCI Security Standards Council , LLC. Payment Card Industry (PCI) Data Security Standard. Requirements and Security Assessment Procedures Version 3.2 April 2016. PCI Security Standards Council, LLC."},{"key":"e_1_3_2_1_27_1","unstructured":"National Checklist Program Repository. NVD official website. Web: https:\/\/nvd.nist.gov\/ncp\/repository  National Checklist Program Repository. NVD official website. Web: https:\/\/nvd.nist.gov\/ncp\/repository"},{"key":"e_1_3_2_1_28_1","unstructured":"Nessus vulnerability scanner. tenable official website. Web: https:\/\/www.tenable.com\/products\/nessus\/nessus-professional  Nessus vulnerability scanner. tenable official website. Web: https:\/\/www.tenable.com\/products\/nessus\/nessus-professional"},{"key":"e_1_3_2_1_29_1","unstructured":"Digital Bond official web site. Web: http:\/\/www.digitalbond.com\/scadapedia\/standards\/common-attack-pattern-enumerationand-classification-capec\/.  Digital Bond official web site. Web: http:\/\/www.digitalbond.com\/scadapedia\/standards\/common-attack-pattern-enumerationand-classification-capec\/."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ITNG.2008.23"},{"key":"e_1_3_2_1_31_1","volume-title":"A Software Weakness Analysis Technique for Secure Software. Advanced Science and Technology Letters","author":"Son Y.","year":"2015","unstructured":"Y. Son , Y. Lee , S. Oh. 2015. A Software Weakness Analysis Technique for Secure Software. Advanced Science and Technology Letters Vol. 93 (Security, Reliability and Safety 2015 ), 5--8. Y. Son, Y. Lee, S. Oh. 2015. A Software Weakness Analysis Technique for Secure Software. Advanced Science and Technology Letters Vol.93 (Security, Reliability and Safety 2015), 5--8."},{"issue":"6","key":"e_1_3_2_1_32_1","first-page":"505","article-title":"A security analysis framework powered by an expert system","volume":"4","author":"Gamal M. M.","year":"2011","unstructured":"M. M. Gamal , D. Hasan , A. F. Hegazy . 2011 . A security analysis framework powered by an expert system . International Journal of Computer Science and Security , vol. 4 , no. 6 , 505 -- 526 , 2011. M. M. Gamal, D. Hasan, A. F. Hegazy. 2011. A security analysis framework powered by an expert system. International Journal of Computer Science and Security, vol. 4, no. 6, 505--526, 2011.","journal-title":"International Journal of Computer Science and Security"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/1558607.1558646"},{"key":"e_1_3_2_1_34_1","volume-title":"International Journal of Computer Applications (0975-8887)","author":"Tripathi A.","year":"2011","unstructured":"A. Tripathi , U. K. Singh . 2011. Analyzing Trends in Vulnerability Classes across CVSS Metrics . International Journal of Computer Applications (0975-8887) Volume 36 No .3, December 2011 . 38--44. A. Tripathi, U. K. Singh. 2011. Analyzing Trends in Vulnerability Classes across CVSS Metrics. International Journal of Computer Applications (0975-8887) Volume 36 No.3, December 2011. 38--44."},{"key":"e_1_3_2_1_35_1","volume-title":"2011 6th International Conference on Computer Sciences and Convergence Information Technology (ICCIT)","author":"Tripathi A.","year":"2011","unstructured":"A. Tripathi , U. K. Singh . 2011 . Taxonomic analysis of classification schemes in vulnerability databases . 2011 6th International Conference on Computer Sciences and Convergence Information Technology (ICCIT) . Seogwipo, South Korea. 2012. A. Tripathi, U. K. Singh. 2011. Taxonomic analysis of classification schemes in vulnerability databases. 2011 6th International Conference on Computer Sciences and Convergence Information Technology (ICCIT). Seogwipo, South Korea. 2012."},{"key":"e_1_3_2_1_36_1","volume-title":"2011 6th International Conference on Computer Sciences and Convergence Information Technology (ICCIT)","author":"Tripathi A.","year":"2011","unstructured":"A. Tripathi , U. K. Singh . 2011 . On prioritization of vulnerability categories based on CVSS scores . 2011 6th International Conference on Computer Sciences and Convergence Information Technology (ICCIT) . Seogwipo, South Korea , 2011. A. Tripathi, U. K. Singh. 2011. On prioritization of vulnerability categories based on CVSS scores. 2011 6th International Conference on Computer Sciences and Convergence Information Technology (ICCIT). Seogwipo, South Korea, 2011."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1852666.1852699"},{"key":"e_1_3_2_1_38_1","unstructured":"ISO\/IEC 27002:2013. Information technology --- Security techniques --- Code of practice for information security controls  ISO\/IEC 27002:2013. Information technology --- Security techniques --- Code of practice for information security controls"},{"key":"e_1_3_2_1_39_1","volume-title":"The 10th International Symposium on Foundations & Practice of Security (FPS 2017","author":"Gonzalez-Granadillo G.","year":"2017","unstructured":"G. Gonzalez-Granadillo , E. Doynikova , I. Kotenko , and J. Garcia-Alfaro . 2018. Attack Graph-based Countermeasure Selection using a Stateful Return on Investment Metric . In The 10th International Symposium on Foundations & Practice of Security (FPS 2017 ). October 23-24 -25 , 2017 . Nancy, France. Lecture Notes in Computer Science, Springer-Verlag, 2018. G. Gonzalez-Granadillo, E. Doynikova, I. Kotenko, and J. Garcia-Alfaro. 2018. Attack Graph-based Countermeasure Selection using a Stateful Return on Investment Metric. In The 10th International Symposium on Foundations & Practice of Security (FPS 2017). October 23-24-25, 2017. Nancy, France. Lecture Notes in Computer Science, Springer-Verlag, 2018."},{"issue":"2","key":"e_1_3_2_1_40_1","first-page":"2015","article-title":"Integrated repository of security information for network security evaluation","volume":"6","author":"Kotenko I.","year":"2015","unstructured":"I. Kotenko , A. Fedorchenko , A. Chechulin . 2015 . Integrated repository of security information for network security evaluation . Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications (JoWUA) , Vol. 6 , No. 2 , June , 2015 . 41--57. http:\/\/jowua.yolasite.com\/vol6no2.php I. Kotenko, A. Fedorchenko, A. Chechulin. 2015. Integrated repository of security information for network security evaluation. Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications (JoWUA), Vol.6, No.2, June, 2015. 41--57. http:\/\/jowua.yolasite.com\/vol6no2.php","journal-title":"Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications (JoWUA)"},{"key":"e_1_3_2_1_41_1","volume-title":"A Complete Guide to the Common Vulnerability Scoring System (CVSS) Version 2.0","author":"Mell P.","year":"2007","unstructured":"P. Mell , K. Scarforne , S. Romanosky . 2007. A Complete Guide to the Common Vulnerability Scoring System (CVSS) Version 2.0 . 2007 . Web : https:\/\/www.first.org\/cvss\/v2\/guide P. Mell, K. Scarforne, S. Romanosky. 2007. A Complete Guide to the Common Vulnerability Scoring System (CVSS) Version 2.0. 2007. Web: https:\/\/www.first.org\/cvss\/v2\/guide"},{"key":"e_1_3_2_1_42_1","volume-title":"Common Vulnerability Scoring System v3.0: Specification Document","author":"Org FIRST","year":"2015","unstructured":"FIRST Org . Inc , Common Vulnerability Scoring System v3.0: Specification Document . 2015 . Web : https:\/\/www.first.org\/cvss\/specification-document. FIRST Org. Inc, Common Vulnerability Scoring System v3.0: Specification Document. 2015. Web: https:\/\/www.first.org\/cvss\/specification-document."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.23919\/FRUCT.2017.8071292"},{"key":"e_1_3_2_1_44_1","unstructured":"MITRE. CWE Schema Documentation. Web: https:\/\/cwe.mitre.org\/documents\/schema\/schema_d9.pdf  MITRE. CWE Schema Documentation. Web: https:\/\/cwe.mitre.org\/documents\/schema\/schema_d9.pdf"},{"key":"e_1_3_2_1_45_1","unstructured":"Introducing JSON. Official website. Web: https:\/\/www.json.org\/  Introducing JSON. Official website. Web: https:\/\/www.json.org\/"},{"key":"e_1_3_2_1_46_1","unstructured":"CSV Comma Separated Values (RFC 4180). Web: https:\/\/www.loc.gov\/preservation\/digital\/formats\/fdd\/fdd000323.shtml  CSV Comma Separated Values (RFC 4180). Web: https:\/\/www.loc.gov\/preservation\/digital\/formats\/fdd\/fdd000323.shtml"},{"key":"e_1_3_2_1_47_1","unstructured":"scikit-learn. Official website. Web: http:\/\/scikit-learn.org\/stable\/  scikit-learn. Official website. Web: http:\/\/scikit-learn.org\/stable\/"}],"event":{"name":"ARES 2018: International Conference on Availability, Reliability and Security","sponsor":["Universit\u00e4t Hamburg Universit\u00e4t Hamburg"],"location":"Hamburg Germany","acronym":"ARES 2018"},"container-title":["Proceedings of the 13th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3230833.3233260","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3230833.3233260","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T02:07:51Z","timestamp":1750212471000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3230833.3233260"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,8,27]]},"references-count":47,"alternative-id":["10.1145\/3230833.3233260","10.1145\/3230833"],"URL":"https:\/\/doi.org\/10.1145\/3230833.3233260","relation":{},"subject":[],"published":{"date-parts":[[2018,8,27]]},"assertion":[{"value":"2018-08-27","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}