{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,7]],"date-time":"2026-02-07T08:20:18Z","timestamp":1770452418086,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,9,24]],"date-time":"2018-09-24T00:00:00Z","timestamp":1537747200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,9,24]]},"DOI":"10.1145\/3241403.3241464","type":"proceedings-article","created":{"date-parts":[[2018,9,19]],"date-time":"2018-09-19T12:16:51Z","timestamp":1537359411000},"page":"1-7","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":13,"title":["Quantitative security assurance metrics"],"prefix":"10.1145","author":[{"given":"Basel","family":"Katt","sequence":"first","affiliation":[{"name":"Norwegian University of Science and Technology (NTNU), Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nishu","family":"Prasher","sequence":"additional","affiliation":[{"name":"Statistics Norway, Division for Quality and Team Management, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,9,24]]},"reference":[{"issue":"1","key":"e_1_3_2_1_1_1","first-page":"1","volume":"3","year":"2006","journal-title":"Common Criteria for Information Technology Security Evaluation Part 3: Security Assurance components, Version"},{"key":"e_1_3_2_1_2_1","unstructured":"2012. Common Criteria for Information Technology Security Evaluation.  2012. Common Criteria for Information Technology Security Evaluation."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1166\/asl.2017.8901"},{"key":"e_1_3_2_1_4_1","unstructured":"Victor R. Basili Gianluigi Caldiera and H. Dieter Rombach. 1994. The goal question metric approach. Encyclopedia of software engineering 2 1994 (1994) 528--532.  Victor R. Basili Gianluigi Caldiera and H. Dieter Rombach. 1994. The goal question metric approach. Encyclopedia of software engineering 2 1994 (1994) 528--532."},{"key":"e_1_3_2_1_5_1","unstructured":"Steve Borgatti. accessed May 2018.. Normalizing Variables (Handout). Gatton College of Business and Economics. University of Kentucky.  Steve Borgatti. accessed May 2018.. Normalizing Variables (Handout). Gatton College of Business and Economics. University of Kentucky."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/1659141.1659158"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"Brajesh De. 2017. API Testing Strategy. Apress Berkeley CA 153--164.  Brajesh De. 2017. API Testing Strategy. Apress Berkeley CA 153--164.","DOI":"10.1007\/978-1-4842-1305-6_9"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.aap.2005.06.024"},{"key":"e_1_3_2_1_9_1","volume-title":"Advances in Computers","volume":"101","author":"Felderer Michael","year":"2016"},{"key":"e_1_3_2_1_10_1","unstructured":"First.org. {n. d.}. Common Vulnerability Scoring System. https:\/\/www.first.org\/cvss\/.  First.org. {n. d.}. Common Vulnerability Scoring System. https:\/\/www.first.org\/cvss\/."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/CRiSIS.2011.6061831"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.03.009"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Wayne Jansen. 2009. Directions in security metrics research- NISTIR 7564. (2009).  Wayne Jansen. 2009. Directions in security metrics research- NISTIR 7564. (2009).","DOI":"10.6028\/NIST.IR.7564"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2017.06.006"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2011.01.011"},{"key":"e_1_3_2_1_16_1","unstructured":"Richard L. Kissel. 2013. Glossary of Key Information Security Terms. NIST Pubs (2013). http:\/\/ws680.nist.gov\/publication\/get_pdf.cfm?pub_id=913810.  Richard L. Kissel. 2013. Glossary of Key Information Security Terms. NIST Pubs (2013). http:\/\/ws680.nist.gov\/publication\/get_pdf.cfm?pub_id=913810."},{"key":"e_1_3_2_1_17_1","unstructured":"Jim Manico. 2016. Open Web Application Security Project. https:\/\/www.owasp.org\/images\/3\/33\/OWASP_Application_Securitty_Verification_Standard_3.0.1.pdf.  Jim Manico. 2016. Open Web Application Security Project. https:\/\/www.owasp.org\/images\/3\/33\/OWASP_Application_Securitty_Verification_Standard_3.0.1.pdf."},{"key":"e_1_3_2_1_18_1","unstructured":"Becky Metivier. 2017. Fundamental Objectives of Information Security: The CIA Triad. https:\/\/www.sagedatasecurity.com\/blog\/fundamental-objectives-of-information-security-the-cia-triad. Sage Data Security.  Becky Metivier. 2017. Fundamental Objectives of Information Security: The CIA Triad. https:\/\/www.sagedatasecurity.com\/blog\/fundamental-objectives-of-information-security-the-cia-triad. Sage Data Security."},{"key":"e_1_3_2_1_19_1","volume-title":"Symposium on requirements engineering for information security (SREIS)","volume":"2005","author":"Myagmar Suvda","year":"2005"},{"key":"e_1_3_2_1_20_1","unstructured":"NCSC. 2016. Risk Management and risk analysis practice. https:\/\/www.ncsc.gov.uk\/guidance\/risk-management-and-risk-analysis-practice. National Cyber Security Centre (UK Government).  NCSC. 2016. Risk Management and risk analysis practice. https:\/\/www.ncsc.gov.uk\/guidance\/risk-management-and-risk-analysis-practice. National Cyber Security Centre (UK Government)."},{"key":"e_1_3_2_1_21_1","unstructured":"Statistics Norway. 2017. StatBank API User Guide. Statistics Norway. http:\/\/www.ssb.no\/en\/omssb\/tjenester-og-verktoy\/api\/px-api\/_attachment\/248250?_ts=15b48207778.  Statistics Norway. 2017. StatBank API User Guide. Statistics Norway. http:\/\/www.ssb.no\/en\/omssb\/tjenester-og-verktoy\/api\/px-api\/_attachment\/248250?_ts=15b48207778."},{"key":"e_1_3_2_1_22_1","unstructured":"NVD. 2018. Common Vulnerability Scoring System Calculater version 3. https:\/\/nvd.nist.gov\/vuln-metrics\/cvss\/v3-calculator. National Vulnerability Database (National Institute of Standards and Technology).  NVD. 2018. Common Vulnerability Scoring System Calculater version 3. https:\/\/nvd.nist.gov\/vuln-metrics\/cvss\/v3-calculator. National Vulnerability Database (National Institute of Standards and Technology)."},{"key":"e_1_3_2_1_23_1","unstructured":"Erlend Oftedal Andrew van der Stock Tony Hsu Hsiang Chih Johan Peeters Jan Wolff and Rocco Granitz. 2017. REST Security Cheat Sheet. https:\/\/www.owasp.org\/index.php\/REST_Security_Cheat_Sheet.  Erlend Oftedal Andrew van der Stock Tony Hsu Hsiang Chih Johan Peeters Jan Wolff and Rocco Granitz. 2017. REST Security Cheat Sheet. https:\/\/www.owasp.org\/index.php\/REST_Security_Cheat_Sheet."},{"key":"e_1_3_2_1_24_1","volume-title":"2014 11th International Conference on Security and Cryptography (SECRYPT). 1--8.","author":"Ouedraogo M."},{"key":"e_1_3_2_1_25_1","unstructured":"Moussa Ouedraogo Haralambos Mouratidis Djamel Khadraoui Eric Dubois and Dominic Palmer-Brown. 2009. Current trends and advances in IT service infrastructures security assurance evaluation. (2009).  Moussa Ouedraogo Haralambos Mouratidis Djamel Khadraoui Eric Dubois and Dominic Palmer-Brown. 2009. Current trends and advances in IT service infrastructures security assurance evaluation. (2009)."},{"key":"e_1_3_2_1_26_1","unstructured":"OWASP. {Accessed July 2017. OWASP top 10 project. https:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_Project  OWASP. {Accessed July 2017. OWASP top 10 project. https:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_Project"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3005714"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIMP.2008.28"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.05.002"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"crossref","unstructured":"R. M. Savola H. Pentik\u00e4inen and M. Ouedraogo. 2010. Towards security effectiveness measurement utilizing risk-based security assurance. In 2010 Information Security for South Africa. 1--8.  R. M. Savola H. Pentik\u00e4inen and M. Ouedraogo. 2010. Towards security effectiveness measurement utilizing risk-based security assurance. In 2010 Information Security for South Africa. 1--8.","DOI":"10.1109\/ISSA.2010.5588322"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.im.2013.08.004"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2016.03.009"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJBIS.2013.053213"},{"key":"e_1_3_2_1_34_1","volume-title":"2016 18th Asia-Pacific Network Operations and Management Symposium (APNOMS). 1--4.","author":"Tung Y. H."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3149572.3149580"}],"event":{"name":"ECSA '18: 12th European Conference on Software Architecture","location":"Madrid Spain","acronym":"ECSA '18"},"container-title":["Proceedings of the 12th European Conference on Software Architecture: Companion Proceedings"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3241403.3241464","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3241403.3241464","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T17:49:29Z","timestamp":1750268969000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3241403.3241464"}},"subtitle":["REST API case studies"],"short-title":[],"issued":{"date-parts":[[2018,9,24]]},"references-count":35,"alternative-id":["10.1145\/3241403.3241464","10.1145\/3241403"],"URL":"https:\/\/doi.org\/10.1145\/3241403.3241464","relation":{},"subject":[],"published":{"date-parts":[[2018,9,24]]},"assertion":[{"value":"2018-09-24","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}