{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T10:25:23Z","timestamp":1777890323923,"version":"3.51.4"},"reference-count":107,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2019,8,30]],"date-time":"2019-08-30T00:00:00Z","timestamp":1567123200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2020,7,31]]},"abstract":"<jats:p>Attack trees are a well established and commonly used framework for security modeling. They provide a readable and structured representation of possible attacks against a system to protect. Their hierarchical structure reveals common features of the attacks and enables quantitative evaluation of security, thus highlighting the most severe vulnerabilities to focus on while implementing countermeasures. Since in real-life studies attack trees have a large number of nodes, their manual creation is a tedious and error-prone process, and their analysis is a computationally challenging task. During the last half decade, the attack tree community witnessed a growing interest in employing formal methods to deal with the aforementioned difficulties. We survey recent advances in graphical security modeling with focus on the application of formal methods to the interpretation, (semi-)automated creation, and quantitative analysis of attack trees and their extensions. We provide a unified description of existing frameworks, compare their features, and outline interesting open questions.<\/jats:p>","DOI":"10.1145\/3331524","type":"journal-article","created":{"date-parts":[[2019,9,3]],"date-time":"2019-09-03T12:47:00Z","timestamp":1567514820000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":50,"title":["Beyond 2014"],"prefix":"10.1145","volume":"52","author":[{"given":"Wojciech","family":"Wide\u0142","sequence":"first","affiliation":[{"name":"Univ Rennes, INSA Rennes, CNRS, IRISA, Rennes Cedex, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maxime","family":"Audinot","sequence":"additional","affiliation":[{"name":"Univ Rennes, CNRS, IRISA, Rennes Cedex, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1824-7621","authenticated-orcid":false,"given":"Barbara","family":"Fila","sequence":"additional","affiliation":[{"name":"Univ Rennes, INSA Rennes, CNRS, IRISA, Rennes, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sophie","family":"Pinchinat","sequence":"additional","affiliation":[{"name":"Univ Rennes, CNRS, IRISA, Rennes Cedex, France"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2019,8,30]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"2005. Uppaal Cora. Retrieved May 29 2018 from: http:\/\/people.cs.aau.dk\/adavid\/cora\/."},{"key":"e_1_2_1_2_1","unstructured":"2014. ATSyRA. Retrieved May 29 2018 from: https:\/\/gforge.inria.fr\/plugins\/mediawiki\/wiki\/building\/index.php\/."},{"key":"e_1_2_1_3_1","unstructured":"2018. ATSyRA Studio. Retrieved November 16 2018 from: http:\/\/atsyra2.irisa.fr\/."},{"key":"e_1_2_1_4_1","volume-title":"Proceedings of the ICALP (LNCS)","volume":"3142","author":"Alur Rajeev","unstructured":"Rajeev Alur, Mikhail Bernadsky, and P. Madhusudan. 2004. Optimal reachability for weighted timed games. In Proceedings of the ICALP (LNCS), Vol. 3142. Springer, 122--133."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.5555\/646244.684357"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-40903-8_8"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40793-2_27"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-54792-8_16"},{"key":"e_1_2_1_9_1","unstructured":"Zaruhi Aslanyan. 2016. Stochastic Model Checking of Socio-Technical Models. Ph.D. Dissertation. Technical University of Denmark Denmark."},{"key":"e_1_2_1_10_1","volume-title":"Retrieved","author":"Aslanyan Zaruhi","year":"2016","unstructured":"Zaruhi Aslanyan. 2016. TREsPASS toolbox: Attack Tree Evaluator. Retrieved May 29, 2018, from: https:\/\/vimeo.com\/145070436."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-46666-7_6"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-54455-6_10"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2016.15"},{"key":"e_1_2_1_14_1","unstructured":"Maxime Audinot. 2018. Assisted Design and Analysis of Attack Trees. Ph.D. Dissertation. University Rennes 1 France."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66402-6_7"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00012"},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the GraMSec 2018 (LNCS)","volume":"11086","author":"Audinot Maxime","year":"2018","unstructured":"Maxime Audinot, Sophie Pinchinat, Fran\u00e7ois Schwarzentruber, and Florence Wacheux. 2018. Deciding the non-emptiness of attack trees. In Proceedings of the GraMSec 2018 (LNCS), Vol. 11086. Springer, 13--30."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.4018\/jsse.2012040101"},{"key":"e_1_2_1_19_1","unstructured":"Matteo Beccaro. 2018. Attack trees methodology and application in red teaming operations. In Proceedings of the D-HITBSecConf. Retrieved from: https:\/\/conference.hitb.org\/hitbsecconf2018pek\/materials\/D1T1%20-%20Attac%k%20Trees%20-%20Methodology%20and%20Application%20in%20Red%20Teaming%20Operati%ons%20-%20Matteo%20Beccaro.pdf."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30080-9_7"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/11561163_8"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1059816.1059823"},{"key":"e_1_2_1_23_1","volume-title":"Retrieved","author":"Berkelaar Michel","year":"2005","unstructured":"Michel Berkelaar, Kjell Eikland, and Peter Notebaert. 2005. lp_solve: Open source (Mixed-Integer) Linear Programming system. Retrieved June 10, 2018, from: http:\/\/lpsolve.sourceforge.net\/5.5\/ Version 5.5.2.5, dated September 24, 2016."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.5555\/548834"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1080\/13623079.2011.587206"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2006.104"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-74860-3_2"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-02930-1_9"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30206-3_20"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-64200-0_3"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10703-013-0183-7"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40313-2_25"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.5555\/1808998"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.5555\/1792734.1792766"},{"key":"e_1_2_1_35_1","volume-title":"Retrieved","author":"Advisory Board EAC","year":"2009","unstructured":"EAC Advisory Board and Standards Board. 2009. Election Operations Assessment\u2014Threat Trees and Matrices and Threat Instance Risk Analyzer (TIRA). Retrieved June 13, 2018, from: https:\/\/www.eac.gov\/assets\/1\/28\/Election_Operations_Assessment_Threat_Trees_and_Matrices_and_Threat_Instance_Risk_Analyzer_(TIRA).pdf."},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-36537-0_6"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-48393-1_24"},{"key":"e_1_2_1_38_1","volume-title":"Proceedings of the GraMSec 2015 (LNCS)","volume":"9390","author":"Gadyatskaya Olga","year":"2015","unstructured":"Olga Gadyatskaya. 2015. How to generate security cameras: Towards defence generation for socio-technical systems. In Proceedings of the GraMSec 2015 (LNCS), Vol. 9390. Springer, 50--65."},{"key":"e_1_2_1_39_1","volume-title":"Kim Guldstrand Larsen, Axel Legay, Mads Chr. Olesen, and Danny B\u00f8gsted Poulsen.","author":"Gadyatskaya Olga","year":"2016","unstructured":"Olga Gadyatskaya, Ren\u00e9 Rydhof Hansen, Kim Guldstrand Larsen, Axel Legay, Mads Chr. Olesen, and Danny B\u00f8gsted Poulsen. 2016. Modelling attack--defense trees using timed automata. In Proceedings of the FORMATS (LNCS), Vol. 9884. Springer, 35--50."},{"key":"e_1_2_1_40_1","volume-title":"Sjouke Mauw, C\u00e9dric Muller, and Steve Muller.","author":"Gadyatskaya Olga","year":"2016","unstructured":"Olga Gadyatskaya, Carlo Harpes, Sjouke Mauw, C\u00e9dric Muller, and Steve Muller. 2016. Bridging two worlds: Reconciling practical risk assessment methodologies with theory of attack trees. In Proceedings of the GraMSec 2016 (LNCS), Vol. 9987. Springer, 80--93."},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-43425-4_10"},{"key":"e_1_2_1_42_1","volume-title":"Willemse","author":"Gadyatskaya Olga","year":"2017","unstructured":"Olga Gadyatskaya, Ravi Jhawar, Sjouke Mauw, Rolando Trujillo-Rasua, and Tim A. C. Willemse. 2017. Refinement-aware generation of attack trees. In Proceedings of the STM (LNCS), Vol. 10547. Springer, 164--179."},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1016\/0304-3975(87)90045-4"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.entcs.2014.12.014"},{"key":"e_1_2_1_45_1","volume-title":"Goldberg","author":"Haasl David F.","year":"1981","unstructured":"David F. Haasl, Norman H. Roberts, William E. Veselay, and Francine F. Goldberg. 1981. Fault Tree Handbook. Technical Report. Systems and Reliability Research, Office of Nuclear Regulatory Research, U.S. Nuclear Regulatory Comission."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10703-012-0167-z"},{"key":"e_1_2_1_47_1","volume-title":"Kim Guldstrand Larsen, Axel Legay, and Danny B\u00f8gsted Poulsen.","author":"Hansen Ren\u00e9 Rydhof","year":"2018","unstructured":"Ren\u00e9 Rydhof Hansen, Peter Gj\u00f8l Jensen, Kim Guldstrand Larsen, Axel Legay, and Danny B\u00f8gsted Poulsen. 2018. Quantitative evaluation of attack defense trees using stochastic timed automata. In Proceedings of the GraMSec 2017 (LNCS), Vol. 10744. Springer, 75--90."},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF01211866"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-54862-8_51"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.5555\/648143.749987"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-49635-0_9"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2017.09.001"},{"key":"e_1_2_1_53_1","first-page":"245","article-title":"The consistency and complexity of multiplicative additive system virtual. Sci","volume":"25","author":"Horne Ross","year":"2015","unstructured":"Ross Horne. 2015. The consistency and complexity of multiplicative additive system virtual. Sci. Ann. Comp. Sci. 25, 2 (2015), 245--316.","journal-title":"Ann. Comp. Sci."},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.3233\/FI-2017-1531"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24018-3_16"},{"key":"e_1_2_1_56_1","volume-title":"Ren\u00e9 Rydhof Hansen, and Florian Kamm\u00fcller","author":"Ivanova Marieta Georgieva","year":"2015","unstructured":"Marieta Georgieva Ivanova, Christian W. Probst, Ren\u00e9 Rydhof Hansen, and Florian Kamm\u00fcller. 2015. Transforming graphical system models to graphical attack models. In Proceedings of the GraMSec 2015 (LNCS), Vol. 9390. Springer, 82--96."},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-18467-8_23"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46598-2_10"},{"key":"e_1_2_1_59_1","volume-title":"Taaffe","author":"Johnson Mary A.","year":"1988","unstructured":"Mary A. Johnson and Michael R. Taaffe. 1988. The denseness of phase distributions. School of Industrial Engineering Research Memoranda 88-20, Purdue University."},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88873-4_8"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-67816-0_1"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01950-1_36"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2013.36"},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2014.45"},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-68270-9_19"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/360248.360251"},{"key":"e_1_2_1_67_1","volume-title":"Proceedings of the CRiSIS (LNCS)","author":"Kordy Barbara","unstructured":"Barbara Kordy, Piotr Kordy, and Yoann van den Boom. 2016. SPTool\u2014Equivalence checker for SAND attack trees. In Proceedings of the CRiSIS (LNCS), Vol. 10158. Springer, 105--113."},{"key":"e_1_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1093\/logcom\/exs029"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2014.07.001"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10181-1_16"},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2016.01.010"},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66845-1_22"},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-89722-6_14"},{"key":"e_1_2_1_74_1","unstructured":"Rajesh Kumar. 2018. Truth or Dare: Quantitative Security Risk Analysis Via Attack Trees. Ph.D. Dissertation. University of Twente The Netherlands."},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-22975-1_11"},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-89363-1_4"},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-49674-9_35"},{"key":"e_1_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1007\/s100090050010"},{"key":"e_1_2_1_79_1","unstructured":"Aleksandr Lenin. 2015. Reliable and Efficient Determination of the Likelihood of Rational Attacks. Ph.D. Dissertation. Tallinn University of Technology Estonia."},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11599-3_12"},{"key":"e_1_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1007\/11734727_17"},{"key":"e_1_2_1_82_1","volume-title":"Retrieved","author":"National Electric Sector Cybersecurity Organization Resource (NESCOR).","year":"2015","unstructured":"National Electric Sector Cybersecurity Organization Resource (NESCOR). 2015. Analysis of Selected Electric Sector High Risk Failure Scenarios, Version 2.0. Retrieved June 13, 2018, from: http:\/\/smartgrid.epri.com\/doc\/NESCOR%20Detailed%20Failure%20Scenarios%20v%2.pdf."},{"key":"e_1_2_1_83_1","volume-title":"Stochastic Games and Applications. NATO Science Series ASIC","author":"Neyman Abraham","unstructured":"Abraham Neyman and Sylvain Sorin. 2003. Stochastic Games and Applications. NATO Science Series ASIC, Vol. 570. Kluwer Academic Publishers."},{"key":"e_1_2_1_84_1","volume-title":"Proceedings of the IEEE Mediteranean Control Conference. IEEE, 8.","author":"Niebert Peter","year":"2000","unstructured":"Peter Niebert, Stavros Tripakis, and Sergio Yovine. 2000. Minimum-time reachability for timed automata. In Proceedings of the IEEE Mediteranean Control Conference. IEEE, 8."},{"key":"e_1_2_1_85_1","volume-title":"Proceedings of the FACS (LNCS)","volume":"7684","author":"Nielson Hanne Riis","year":"2012","unstructured":"Hanne Riis Nielson, Flemming Nielson, and Roberto Vigo. 2012. A calculus for quality. In Proceedings of the FACS (LNCS), Vol. 7684. Springer, 188--204."},{"key":"e_1_2_1_86_1","doi-asserted-by":"publisher","unstructured":"Judea Pearl. 1988. Probabilistic Reasoning in Intelligent Systems: Networks of Plausible Inference. Morgan Kaufmann.","DOI":"10.5555\/52121"},{"key":"e_1_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0166-218X(03)00333-0"},{"key":"e_1_2_1_88_1","doi-asserted-by":"publisher","DOI":"10.5555\/1885194.1885203"},{"key":"e_1_2_1_89_1","volume-title":"Proceedings of the SEFM Workshops (LNCS)","volume":"8938","author":"Pinchinat Sophie","year":"2014","unstructured":"Sophie Pinchinat, Mathieu Acher, and Didier Vojtisek. 2014. Towards synthesis of attack trees for supporting computer-aided risk analysis. In Proceedings of the SEFM Workshops (LNCS), Vol. 8938. Springer, 363--375."},{"key":"e_1_2_1_90_1","volume-title":"Proceedings of the GraMSec 2015 (LNCS)","volume":"9390","author":"Pinchinat Sophie","year":"2015","unstructured":"Sophie Pinchinat, Mathieu Acher, and Didier Vojtisek. 2015. ATSyRa: An integrated environment for synthesizing attack trees\u2014(Tool Paper). In Proceedings of the GraMSec 2015 (LNCS), Vol. 9390. Springer, 97--101."},{"key":"e_1_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1142\/S0218213010000042"},{"key":"e_1_2_1_92_1","volume-title":"Understanding Markov Chains: Examples and Applications","author":"Privault Nicolas","unstructured":"Nicolas Privault. 2013. Discrete-time Markov chains. In Understanding Markov Chains: Examples and Applications. Springer, 77--94."},{"key":"e_1_2_1_93_1","volume-title":"Proceedings of the GraMSec 2015 (LNCS)","volume":"9390","author":"Probst Christian W.","year":"2015","unstructured":"Christian W. Probst, Jan Willemson, and Wolter Pieters. 2015. The attack navigator. In Proceedings of the GraMSec 2015 (LNCS), Vol. 9390. Springer, 1--17."},{"key":"e_1_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1109\/QEST.2009.45"},{"key":"e_1_2_1_95_1","volume-title":"Markov Decision Processes: Discrete Stochastic Dynamic Programming","author":"Puterman Martin L.","unstructured":"Martin L. Puterman. 2014. Markov Decision Processes: Discrete Stochastic Dynamic Programming. John Wiley 8 Sons."},{"key":"e_1_2_1_96_1","unstructured":"Loukmen Regainia. 2018. Assisting in the Development and Testing of Secure Applications. Ph.D. Dissertation. University Clermont Auvergne France."},{"key":"e_1_2_1_97_1","doi-asserted-by":"publisher","DOI":"10.5220\/0006198301360146"},{"key":"e_1_2_1_98_1","doi-asserted-by":"publisher","DOI":"10.1016\/0095-8956(83)90079-5"},{"key":"e_1_2_1_99_1","doi-asserted-by":"publisher","DOI":"10.1002\/sec.299"},{"key":"e_1_2_1_100_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2015.03.001"},{"key":"e_1_2_1_101_1","volume-title":"Attack trees. Dr. Dobb\u2019s J. 24, 12","author":"Schneier Bruce","year":"1999","unstructured":"Bruce Schneier. 1999. Attack trees. Dr. Dobb\u2019s J. 24, 12 (1999), 21--29."},{"key":"e_1_2_1_102_1","volume-title":"University of Luxembourg","author":"Schweitzer Patrick","unstructured":"Patrick Schweitzer. 2013. Attack--Defense Trees. Ph.D. Dissertation. University of Luxembourg, Luxembourg."},{"key":"e_1_2_1_103_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-46681-0_20"},{"key":"e_1_2_1_104_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2006.27"},{"key":"e_1_2_1_105_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2014.31"},{"key":"e_1_2_1_106_1","volume-title":"quantifying, and displaying attacks. Log. Meth. Comput. Sci. 12, 4","author":"Vigo Roberto","year":"2016","unstructured":"Roberto Vigo, Flemming Nielson, and Hanne Riis Nielson. 2016. Discovering, quantifying, and displaying attacks. Log. Meth. Comput. Sci. 12, 4 (2016)."},{"key":"e_1_2_1_107_1","volume-title":"Proceedings of the NCSC\/NIST National Computer Security Conference. 572--581","author":"Weiss Jonathan D.","year":"1991","unstructured":"Jonathan D. Weiss. 1991. A system security engineering process. In Proceedings of the NCSC\/NIST National Computer Security Conference. 572--581."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3331524","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3331524","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,25]],"date-time":"2025-06-25T13:23:31Z","timestamp":1750857811000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3331524"}},"subtitle":["Formal Methods for Attack Tree--based Security Modeling"],"short-title":[],"issued":{"date-parts":[[2019,8,30]]},"references-count":107,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2020,7,31]]}},"alternative-id":["10.1145\/3331524"],"URL":"https:\/\/doi.org\/10.1145\/3331524","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,8,30]]},"assertion":[{"value":"2018-06-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-05-01","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-08-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}