{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T04:11:50Z","timestamp":1760242310568,"version":"build-2065373602"},"reference-count":57,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2017,3,21]],"date-time":"2017-03-21T00:00:00Z","timestamp":1490054400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The prospect of Line-of-Business Services (LoBSs) for infrastructure of Emerging Sensor Networks (ESNs) is exciting. Access control remains a top challenge in this scenario as the service provider\u2019s server contains a lot of valuable resources. LoBSs\u2019 users are very diverse as they may come from a wide range of locations with vastly different characteristics. Cost of joining could be low and in many cases, intruders are eligible users conducting malicious actions. As a result, user access should be adjusted dynamically. Assessing LoBSs\u2019 risk dynamically based on both frequency and threat degree of malicious operations is therefore necessary. In this paper, we proposed a Quantitative Risk Assessment Model (QRAM) involving frequency and threat degree based on value at risk. To quantify the threat degree as an elementary intrusion effort, we amend the influence coefficient of risk indexes in the network security situation assessment model. To quantify threat frequency as intrusion trace effort, we make use of multiple behavior information fusion. Under the influence of intrusion trace, we adapt the historical simulation method of value at risk to dynamically access LoBSs\u2019 risk. Simulation based on existing data is used to select appropriate parameters for QRAM. Our simulation results show that the duration influence on elementary intrusion effort is reasonable when the normalized parameter is 1000. Likewise, the time window of intrusion trace and the weight between objective risk and subjective risk can be set to 10 s and 0.5, respectively. While our focus is to develop QRAM for assessing the risk of LoBSs for infrastructure of ESNs dynamically involving frequency and threat degree, we believe it is also appropriate for other scenarios in cloud computing.<\/jats:p>","DOI":"10.3390\/s17030642","type":"journal-article","created":{"date-parts":[[2017,3,21]],"date-time":"2017-03-21T12:22:22Z","timestamp":1490098942000},"page":"642","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["A Quantitative Risk Assessment Model Involving Frequency and Threat Degree under Line-of-Business Services for Infrastructure of Emerging Sensor Networks"],"prefix":"10.3390","volume":"17","author":[{"given":"Xu","family":"Jing","sequence":"first","affiliation":[{"name":"College of Information Engineering, Northwest A &amp; F University, Yangling 712100, China"},{"name":"Department of Computing, The Hong Kong Polytechnic University, Hong Kong 999077, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3294-7464","authenticated-orcid":false,"given":"Hanwen","family":"Hu","sequence":"additional","affiliation":[{"name":"College of Information Engineering, Northwest A &amp; F University, Yangling 712100, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Huijun","family":"Yang","sequence":"additional","affiliation":[{"name":"College of Information Engineering, Northwest A &amp; F University, Yangling 712100, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Man","family":"Au","sequence":"additional","affiliation":[{"name":"Department of Computing, The Hong Kong Polytechnic University, Hong Kong 999077, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shuqin","family":"Li","sequence":"additional","affiliation":[{"name":"College of Information Engineering, Northwest A &amp; F University, Yangling 712100, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Naixue","family":"Xiong","sequence":"additional","affiliation":[{"name":"Department of Mathematics and Computer Science, Northeastern State University, Tahlequah, OK 74464, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muhammad","family":"Imran","sequence":"additional","affiliation":[{"name":"College of Computer and Information Sciences, Almuzahmiyah, King Saud University, Riyadh 11451, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Athanasios","family":"Vasilakos","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Electrical and Space Engineering, Lulea University of Technology, Lulea 97187, Sweden"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2017,3,21]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"373","DOI":"10.1109\/TNSM.2012.113012.120310","article-title":"A survey on service-oriented network virtualization toward convergence of networking and cloud computing","volume":"9","author":"Duan","year":"2012","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Mell, P., and Grance, T. (2011). The NIST Definition of Cloud Computing.","DOI":"10.6028\/NIST.SP.800-145"},{"key":"ref_3","unstructured":"Chong, F., and Carraro, G. Architecture Strategies for Catching the Long Tail. Available online: https:\/\/msdn.microsoft.com\/en-us\/library\/aa479069."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1109\/CC.2016.7489970","article-title":"Efficient algorithm for k-barrier coverage based on integer linear programming","volume":"13","author":"Zhang","year":"2016","journal-title":"China Commun."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1016\/j.ins.2016.12.030","article-title":"EPCBIR: An efficient and privacy-preserving content-based image retrieval scheme in cloud computing","volume":"387","author":"Xia","year":"2017","journal-title":"Inf. Sci."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"395","DOI":"10.1016\/j.ins.2014.10.040","article-title":"A rapid learning algorithm for vehicle classification","volume":"295","author":"Wen","year":"2015","journal-title":"Inf. Sci."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"557","DOI":"10.1016\/j.ins.2016.07.014","article-title":"Monitoring and assessing fruit freshness in IOT-based e-commerce delivery using scenario analysis and interval number approaches","volume":"373","author":"Ruan","year":"2016","journal-title":"Inf. Sci."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"4368","DOI":"10.1080\/00207543.2016.1174344","article-title":"Optimizing the intermodal transportation of emergency medical supplies using balanced fuzzy clustering","volume":"54","author":"Ruan","year":"2016","journal-title":"Int. J. Prod. Res."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"6178","DOI":"10.1166\/jctn.2015.4654","article-title":"A rational four-arithmetic PH scheme for line-of-business service","volume":"12","author":"Jing","year":"2015","journal-title":"J. Comput. Theor. Nanosci."},{"key":"ref_10","first-page":"37","article-title":"A protocol of encrypted data enquijoin sharing across private databases","volume":"46","author":"Jing","year":"2012","journal-title":"J. Xi\u2019an Jiaotong Univ."},{"key":"ref_11","first-page":"95","article-title":"A protocol of equijoin size sharing across encrypted relational database","volume":"46","author":"Jing","year":"2014","journal-title":"J. Sichuan Univ."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"247","DOI":"10.14257\/ijdta.2016.9.4.23","article-title":"Sharing attribute names based LSH across cloud relational database","volume":"9","author":"Tan","year":"2016","journal-title":"Int. J. Database Theory Appl."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1947","DOI":"10.1007\/s11042-014-2381-8","article-title":"Steganalysis of LSB matching using differences between nonadjacent pixels","volume":"75","author":"Xia","year":"2016","journal-title":"Multimedia Tools Appl."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"495","DOI":"10.1109\/JSAC.2009.090512","article-title":"Comparative analysis of quality of service and memory usage for adaptive failure detectors in healthcare systems","volume":"27","author":"Xiong","year":"2009","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_15","first-page":"1364","article-title":"Information security risk assessment survey","volume":"52","author":"Zhang","year":"2012","journal-title":"J. Tsinghua Univ."},{"key":"ref_16","unstructured":"Gary, S., Alice, Y.G., and Alexis, F. (2002). Risk Management Guide for Information Technology Systems."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Jing, X., Liu, Z.N., Li, S.Q., Qiao, B., and Tan, G.X. (2015). A cloud-user behavior assessment based dynamic access control model. Int. J. Syst. Assur. Eng. Manag.","DOI":"10.1007\/s13198-015-0411-1"},{"key":"ref_18","unstructured":"Jorin, P. (2006). Value at Rsik: The New Benchmark for Managing of Financial Risk, McGraw-Hill."},{"key":"ref_19","unstructured":"Snort Users Manual. Available online: http:\/\/manual-snort-org.s3-website-us-east-1.amazonaws.com\/."},{"key":"ref_20","first-page":"404","article-title":"Study on evaluation for security situation of networked systems","volume":"38","author":"Chen","year":"2004","journal-title":"J. Xi\u2019an Jiaotong Univ."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"218","DOI":"10.1016\/j.cose.2004.08.009","article-title":"Multiple behavior information fusion based quantitative threat evaluation","volume":"24","author":"Chen","year":"2005","journal-title":"Comput. Secur."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"379","DOI":"10.1002\/j.1538-7305.1948.tb01338.x","article-title":"A mathematical theory of communication","volume":"27","author":"Shannon","year":"1948","journal-title":"Bell Labs Tech. J."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"1254","DOI":"10.1109\/TPDS.2010.29","article-title":"A distributed efficient flow control scheme for multirate multicast networks","volume":"21","author":"Xiong","year":"2010","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"967","DOI":"10.1360\/jos180967","article-title":"Anomaly detection based on web users\u2019 browsing behaviors","volume":"18","author":"Xie","year":"2007","journal-title":"J. Softw."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Tian, L.Q., Lin, C., and Ni, Y. (2010, January 22\u201324). Evaluation of user behavior trust in cloud computing. Proceedings of the International Conference on Computer Application and System Modeling, Taiyuan, China.","DOI":"10.1109\/ICCASM.2010.5620636"},{"key":"ref_26","first-page":"1818","article-title":"Model and analysis of user behavior based on dynamic game theory in cloud computing","volume":"39","author":"Chen","year":"2011","journal-title":"Acta Electron. Sin."},{"key":"ref_27","unstructured":"Chen, S., Mahboobeh, G., Wang, Y.Z., Paul, B., and Massoud, P. (July, January 27). Trace-based analysis and prediction of cloud computing user behavior using the fractal modeling technique. Proceedings of the IEEE International Congress on Big Data, Anchorage, AK, USA."},{"key":"ref_28","first-page":"3895","article-title":"Web log based analysis of user\u2019s browsing behavior","volume":"3","author":"Ashwini","year":"2014","journal-title":"Int. J. Adv. Res. Comput. Eng. Technol."},{"key":"ref_29","first-page":"2165","article-title":"A trust-based dynamic access control model","volume":"7","author":"Ma","year":"2010","journal-title":"J. Inf. Comput. Sci."},{"key":"ref_30","unstructured":"Parikshit, N.M., Pravin, A.T., Neeli, R.P., Ramjee, P., and Jayawantrao, S. (2013, January 24\u201327). A fuzzy approach to trust based access control in internet of things. Proceedings of the 3rd International Conference on Wireless Communications, Vehicular Technology, Information Theory and Aerospace & Electronics Systems, Atlantic City, NJ, USA."},{"key":"ref_31","first-page":"341","article-title":"Fuzzy ART-based user behavior trust in cloud computing","volume":"324","author":"Jaiganesh","year":"2015","journal-title":"Artif. Intell. Evolut. Algorithms Eng. Syst. Ser. Adv. Intell. Syst. Comput."},{"key":"ref_32","unstructured":"Ghazinour, K., and Ghayoumi, M. (July, January 28). An autonomous model to enforce security policies based on user\u2019s behavior. Proceedings of the IEEE\/ACIS 14th International Conference on Computer and Information Science, Las Vegas, NV, USA."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"688","DOI":"10.3724\/SP.J.1016.2009.00688","article-title":"A trust model based on behaviors risk evaluation","volume":"32","author":"Zhang","year":"2009","journal-title":"Chin. J. Comput."},{"key":"ref_34","first-page":"72","article-title":"A risk evaluation model merging behaviors trust of entities","volume":"10","author":"Xu","year":"2010","journal-title":"J. Nanjing Norm. Univ."},{"key":"ref_35","first-page":"333","article-title":"Outline of a theory of statistical estimation based on the classical theory of probability","volume":"236","author":"Neyman","year":"1937","journal-title":"Philos. Trans. R. Soc. Lond. Ser. A Math. Phys. Sci."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Cox, D.R., and Hinkley, D.V. (1979). Theoretical Statistics, Chapman & Hall.","DOI":"10.1201\/b14832"},{"key":"ref_37","unstructured":"Stuart, A., Ord, J.K., and Arnold, S. (2009). Kendall\u2019s Advanced Theory of Statistics, Classical Inference and the Linear Model, John-Wiley."},{"key":"ref_38","unstructured":"Thomas, D.S. Information Theory Primer with an Appendix on Logarithms, Available online: https:\/\/schneider.ncifcrf.gov\/papers\/primer\/primer.pdf."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Borda, M. (2011). Fundamentals in Information Theory and Coding, Springer.","DOI":"10.1007\/978-3-642-20347-3"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Han, T.S., and Kobayashi, K. (2007). Mathematics of Information and Coding, American Mathematical Society.","DOI":"10.1090\/mmono\/203"},{"key":"ref_41","first-page":"620","article-title":"Information theory and statistical mechanics","volume":"106","author":"Jaynes","year":"1957","journal-title":"APS J. Arch."},{"key":"ref_42","first-page":"43","article-title":"Portfolio optimization with conditional value-at-risk objective and constraints","volume":"4","author":"Pavlo","year":"2002","journal-title":"J. Risk"},{"key":"ref_43","unstructured":"McNeil, A., Frey, R., and Embrechts, P. (2005). Quantitative Risk Management: Concepts Techniques and Tools, Princeton University Press."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1111\/1467-9965.00068","article-title":"Coherent measures of risk","volume":"9","author":"Philippe","year":"1999","journal-title":"Math. Financ."},{"key":"ref_45","unstructured":"Du, H.F., and Yang, Y.Y. (2011). Financial Risk Management, China Financial and Economic Publishing House."},{"key":"ref_46","unstructured":"Philipe, J. (2006). Value at Risk, McGraw-Hill. [3rd ed.]."},{"key":"ref_47","unstructured":"Kiran, L., William, Y., and Adam, J.L. (2004, January 25\u201329). NVisionIP: Netflow visualizations of system state for security situational awareness. Proceedings of the ACM Workshop on Visualization and Data Mining for Computer Security, Washington, DC, USA."},{"key":"ref_48","first-page":"353","article-title":"A network security situational awareness model based on information fusion","volume":"46","author":"Wei","year":"2009","journal-title":"J. Comput. Res. Dev."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"36","DOI":"10.1109\/MC.2011.67","article-title":"Everything as a service: Powering the new information economy","volume":"44","author":"Prith","year":"2011","journal-title":"Computer"},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"633","DOI":"10.1109\/32.815323","article-title":"Experimenting with quantitative evaluation tools for monitoring operational security","volume":"25","author":"Ortalo","year":"1999","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"211","DOI":"10.3233\/JCS-1993-22-308","article-title":"Towards operational measures of computer security","volume":"2","author":"Littlewood","year":"1993","journal-title":"J. Comput. Secur."},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"60","DOI":"10.1109\/CC.2016.7559076","article-title":"Fingerprint liveness detection based on multi-scale LPQ and PCA","volume":"13","author":"Yuan","year":"2016","journal-title":"China Commun."},{"key":"ref_53","first-page":"113","article-title":"Improved design of the scalable network security situation model","volume":"38","author":"Hu","year":"2009","journal-title":"J. Univ. Electron. Sci. Technol. China"},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"235","DOI":"10.1109\/32.588541","article-title":"A quantitative model of the security intrusion process based on attacker behavior","volume":"23","author":"Erland","year":"1997","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"698","DOI":"10.1080\/01621459.1960.10483368","article-title":"Bivariate exponential distributions","volume":"55","author":"Gumbel","year":"1960","journal-title":"J. Am. Stat. Assoc."},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"1365","DOI":"10.1109\/18.532878","article-title":"Efficient scalar quantization of exponential and laplacian random variables","volume":"42","author":"Gary","year":"1996","journal-title":"IEEE Trans. Inf. Theory"},{"key":"ref_57","unstructured":"Massachusetts Institute of Technology Lincoln Laboratory 1998 DARPA Intrusion Detection Evaluation Data Set. Available online: https:\/\/www.ll.mit.edu\/ideval\/data\/1998data.html."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/17\/3\/642\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T18:30:55Z","timestamp":1760207455000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/17\/3\/642"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,3,21]]},"references-count":57,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2017,3]]}},"alternative-id":["s17030642"],"URL":"https:\/\/doi.org\/10.3390\/s17030642","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2017,3,21]]}}}