{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T16:42:36Z","timestamp":1780332156109,"version":"3.54.1"},"reference-count":95,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2022,3,9]],"date-time":"2022-03-09T00:00:00Z","timestamp":1646784000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001872","name":"Centre for Industrial Technological Development","doi-asserted-by":"publisher","award":["CER-20191012"],"award-info":[{"award-number":["CER-20191012"]}],"id":[{"id":"10.13039\/501100001872","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The rapid evolution of industrial components, the paradigm of Industry 4.0, and the new connectivity features introduced by 5G technology all increase the likelihood of cybersecurity incidents. Such incidents are caused by the vulnerabilities present in these components. Designing a secure system is critical, but it is also complex, costly, and an extra factor to manage during the lifespan of the component. This paper presents a model to analyze the known vulnerabilities of industrial components over time. The proposed Extended Dependency Graph (EDG) model is based on two main elements: a directed graph representation of the internal structure of the component, and a set of quantitative metrics based on the Common Vulnerability Scoring System (CVSS). The EDG model can be applied throughout the entire lifespan of a device to track vulnerabilities, identify new requirements, root causes, and test cases. It also helps prioritize patching activities. The model was validated by application to the OpenPLC project. The results reveal that most of the vulnerabilities associated with OpenPLC were related to memory buffer operations and were concentrated in the libssl library. The model was able to determine new requirements and generate test cases from the analysis.<\/jats:p>","DOI":"10.3390\/s22062126","type":"journal-article","created":{"date-parts":[[2022,3,10]],"date-time":"2022-03-10T02:10:35Z","timestamp":1646878235000},"page":"2126","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":16,"title":["A Novel Model for Vulnerability Analysis through Enhanced Directed Graphs and Quantitative Metrics"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6085-820X","authenticated-orcid":false,"given":"\u00c1ngel","family":"Longueira-Romero","sequence":"first","affiliation":[{"name":"Ikerlan Technology Research Centre, Basque Research and Technology Alliance (BRTA), 20500 Arrasate, Spain"},{"name":"Department of Electronics and Computing, Mondragon Unibertsitatea, 20500 Mondrag\u00f3n, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1036-3035","authenticated-orcid":false,"given":"Rosa","family":"Iglesias","sequence":"additional","affiliation":[{"name":"Ikerlan Technology Research Centre, Basque Research and Technology Alliance (BRTA), 20500 Arrasate, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5555-9712","authenticated-orcid":false,"given":"Jose Luis","family":"Flores","sequence":"additional","affiliation":[{"name":"Ikerlan Technology Research Centre, Basque Research and Technology Alliance (BRTA), 20500 Arrasate, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0387-9167","authenticated-orcid":false,"given":"I\u00f1aki","family":"Garitano","sequence":"additional","affiliation":[{"name":"Department of Electronics and Computing, Mondragon Unibertsitatea, 20500 Mondrag\u00f3n, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,3,9]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Qingyu, O., Fang, L., and Kai, H. (2009, January 18\u201320). High-Security System Primitive for Embedded Systems. Proceedings of the 2009 International Conference on Multimedia Information Networking and Security, Wuhan, China.","DOI":"10.1109\/MINES.2009.48"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"91","DOI":"10.1109\/MC.2011.115","article-title":"Lessons from Stuxnet","volume":"44","author":"Chen","year":"2011","journal-title":"Computer"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Vai, M., Nahill, B., Kramer, J., Geis, M., Utin, D., Whelihan, D., and Khazan, R. (2015, January 15\u201317). Secure architecture for embedded systems. Proceedings of the 2015 IEEE High Performance Extreme Computing Conference (HPEC), Waltham, MA, USA.","DOI":"10.1109\/HPEC.2015.7322461"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"853","DOI":"10.1109\/TSMCA.2010.2048028","article-title":"Cybersecurity for Critical Infrastructures: Attack and Defense Modeling","volume":"40","author":"Ten","year":"2010","journal-title":"IEEE Trans. Syst. Man Cybern.-Part A Syst. Hum."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3430372","article-title":"Design Space Exploration for Secure IoT Devices and Cyber-Physical Systems","volume":"20","author":"Gressl","year":"2021","journal-title":"ACM Trans. Embed. Comput. Syst."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"34564","DOI":"10.1109\/ACCESS.2020.2975142","article-title":"Security and Privacy in Smart Farming: Challenges and Opportunities","volume":"8","author":"Gupta","year":"2020","journal-title":"IEEE Access"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"28","DOI":"10.1109\/MIE.2016.2618724","article-title":"Massive Internet of Things for Industrial Applications: Addressing Wireless IIoT Connectivity Challenges and Ecosystem Fragmentation","volume":"11","author":"Mumtaz","year":"2017","journal-title":"IEEE Ind. Electron. Mag."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"70528","DOI":"10.1109\/ACCESS.2018.2879615","article-title":"A Review of Low-End, Middle-End, and High-End Iot Devices","volume":"6","author":"Ojo","year":"2018","journal-title":"IEEE Access"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"23022","DOI":"10.1109\/ACCESS.2020.2970118","article-title":"Internet of Things (IoT) for Next-Generation Smart Systems: A Review of Current Challenges, Future Trends and Prospects for Emerging 5G-IoT Scenarios","volume":"8","author":"Shafique","year":"2020","journal-title":"IEEE Access"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"3175","DOI":"10.1007\/s10664-020-09830-x","article-title":"Detection, assessment and mitigation of vulnerabilities in open source dependencies","volume":"25","author":"Ponta","year":"2020","journal-title":"Empir. Softw. Eng."},{"key":"ref_11","unstructured":"Hejderup, J.I., Van Deursen, A., and Mesbah, A. (2015). In Dependencies We Trust: How Vulnerable are Dependencies in Software Modules?. [Ph.D. Thesis, Department of Software Technology, TU Delft]."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Pashchenko, I., Plate, H., Ponta, S.E., Sabetta, A., and Massacci, F. (2018, January 11\u201312). Vulnerable Open Source Dependencies: Counting Those That Matter. Proceedings of the 12th International Symposium on Empirical Software Engineering and Measurement (ESEM), Oulu, Finland.","DOI":"10.1145\/3239235.3268920"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"29775","DOI":"10.1109\/ACCESS.2021.3058403","article-title":"Cyber-Physical Energy Systems Security: Threat Modeling, Risk Assessment, Resources, Metrics, and Case Studies","volume":"9","author":"Zografopoulos","year":"2021","journal-title":"IEEE Access"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"1039","DOI":"10.1109\/JPROC.2015.2512235","article-title":"The Cybersecurity Landscape in Industrial Control Systems","volume":"104","author":"McLaughlin","year":"2016","journal-title":"Proc. IEEE"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Mathew, A. (2020, January 11\u201313). Network Slicing in 5G and the Security Concerns. Proceedings of the 2020 Fourth International Conference on Computing Methodologies and Communication (ICCMC), Erode, India.","DOI":"10.1109\/ICCMC48092.2020.ICCMC-00014"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"2292","DOI":"10.1109\/ACCESS.2016.2566339","article-title":"Blockchains and Smart Contracts for the Internet of Things","volume":"4","author":"Christidis","year":"2016","journal-title":"IEEE Access"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"82721","DOI":"10.1109\/ACCESS.2019.2924045","article-title":"A Survey on IoT Security: Application Areas, Security Threats, and Solution Architectures","volume":"7","author":"Hassija","year":"2019","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"129551","DOI":"10.1109\/ACCESS.2019.2932609","article-title":"Internet-of-Things (IoT)-Based Smart Agriculture: Toward Making the Fields Talk","volume":"7","author":"Ayaz","year":"2019","journal-title":"IEEE Access"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"108952","DOI":"10.1109\/ACCESS.2020.2998358","article-title":"Digital Twin: Enabling Technologies, Challenges and Open Research","volume":"8","author":"Fuller","year":"2020","journal-title":"IEEE Access"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"35365","DOI":"10.1109\/ACCESS.2018.2836950","article-title":"Machine Learning and Deep Learning Methods for Cybersecurity","volume":"6","author":"Xin","year":"2018","journal-title":"IEEE Access"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Benias, N., and Markopoulos, A.P. (2017, January 23\u201325). A review on the readiness level and cyber-security challenges in Industry 4.0. Proceedings of the 2017 South Eastern European Design Automation, Computer Engineering, Computer Networks and Social Media Conference (SEEDA-CECNSM), Kastoria, Greece.","DOI":"10.23919\/SEEDA-CECNSM.2017.8088234"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Matsuda, W., Fujimoto, M., Aoyama, T., and Mitsunaga, T. (2019, January 19\u201321). Cyber Security Risk Assessment on Industry 4.0 using ICS testbed with AI and Cloud. Proceedings of the 2019 IEEE Conference on Application, Information and Network Security (AINS), Pulau Pinang, Malaysia.","DOI":"10.1109\/AINS47559.2019.8968698"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1109\/EMR.2019.2927559","article-title":"Addressing Industry 4.0 Cybersecurity Challenges","volume":"47","author":"Culot","year":"2019","journal-title":"IEEE Eng. Manag. Rev."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"97","DOI":"10.1016\/j.compind.2018.09.004","article-title":"Cybersecurity for Industry 4.0 in the current literature: A reference framework","volume":"103","author":"Lezzi","year":"2018","journal-title":"Comput. Ind."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Ustundag, A., and Cevikcan, E. (2018). Industry 4.0: Managing The Digital Transformation, Springer International Publishing.","DOI":"10.1007\/978-3-319-57870-5"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Thames, L., and Schaefer, D. (2017). Cybersecurity for Industry 4.0, Springer International Publishing.","DOI":"10.1007\/978-3-319-50660-9"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Medeiros, N., Ivaki, N., Costa, P., and Vieira, M. (2017, January 23\u201326). Software Metrics as Indicators of Security Vulnerabilities. Proceedings of the 2017 IEEE 28th International Symposium on Software Reliability Engineering (ISSRE), Toulouse, France.","DOI":"10.1109\/ISSRE.2017.11"},{"key":"ref_28","first-page":"51","article-title":"On the Relationship between Software Complexity and Security","volume":"11","author":"Alenezi","year":"2020","journal-title":"Int. J. Softw. Eng. Appl."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1109\/MSP.2011.67","article-title":"Stuxnet: Dissecting a Cyberwarfare Weapon","volume":"9","author":"Langner","year":"2011","journal-title":"IEEE Secur. Priv."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"43586","DOI":"10.1109\/ACCESS.2018.2863244","article-title":"A Graph-Based Security Framework for Securing Industrial IoT Networks From Vulnerability Exploitations","volume":"6","author":"George","year":"2018","journal-title":"IEEE Access"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Papp, D., Ma, Z., and Buttyan, L. (2015, January 21\u201323). Embedded systems security: Threats, vulnerabilities, and attack taxonomy. Proceedings of the 2015 13th Annual Conference on Privacy, Security and Trust (PST), Izmir, Turkey.","DOI":"10.1109\/PST.2015.7232966"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Nielsen, B.B., Torp, M.T., and M\u00f8ller, A. (2021). Modular Call Graph Construction for Security Scanning of Node.Js Applications. Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis, Association for Computing Machinery.","DOI":"10.1145\/3460319.3464836"},{"key":"ref_33","unstructured":"Jajodia, S., and Lopez, J. (2008). Identifying Critical Attack Assets in Dependency Attack Graphs. Computer Security\u2014ESORICS 2008, Springer. Available online: https:\/\/link.springer.com\/chapter\/10.1007\/978-3-540-88313-5_2#citeas."},{"key":"ref_34","unstructured":"MITRE Corporation (2022, January 27). CVE\u2014Common Vulnerability and Exposures. Available online: https:\/\/cve.mitre.org\/index.html."},{"key":"ref_35","unstructured":"MITRE Corporation (2022, January 21). CVE\u2014Common Vulnerabilities and Exposures: Definitions. Available online: https:\/\/cve.mitre.org\/about\/terminology.html."},{"key":"ref_36","unstructured":"National Institute for Standards and Technology (NIST) (2022, January 27). National Vulnerability Database NVD\u2014Vulnerability List, Available online: https:\/\/nvd.nist.gov\/vuln\/full-listing."},{"key":"ref_37","unstructured":"FIRST\u2014global Forum of Incident Response and Security Teams (2022, January 27). Common Vulnerability Scoring System (CVSS). Available online: https:\/\/www.first.org\/cvss\/."},{"key":"ref_38","unstructured":"MITRE Corporation (2022, January 27). CWE\u2014Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/index.html."},{"key":"ref_39","unstructured":"MITRE Corporation (2022, January 27). CWE\u2014Common Weakness Enumeration: Definitions. Available online: https:\/\/cwe.mitre.org\/about\/faq.html."},{"key":"ref_40","unstructured":"Nadjm-Tehrani, S. (2020). Cyber-Physical Systems Security Based on a Cross-Linked and Correlated Vulnerability Database. Critical Information Infrastructures Security, Springer International Publishing. Available online: https:\/\/link.springer.com\/book\/10.1007\/978-3-030-37670-3."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Kleidermacher, D., and Kleidermacher, M. (2012). Practical Methods for Safe and Secure Software and Systems Development. Embedded Systems Security, Newnes.","DOI":"10.1016\/B978-0-12-386886-2.00001-1"},{"key":"ref_42","unstructured":"Andreeva, O., Gordeychik, S., Gritsai, G., Kochetova, O., Potseluevskaya, E., Sidorov, S., and Timorin, A. (2016). Industrial Control Systems Vulnerabilities Statistics, Karpersky. Technical Report."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1109\/MSP.2006.51","article-title":"Securing embedded systems","volume":"4","author":"Hwang","year":"2006","journal-title":"IEEE Secur. Priv."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"68","DOI":"10.1109\/MSP.2012.134","article-title":"The State of Embedded-Device Security (Spoiler Alert: It\u2019s Bad)","volume":"10","author":"Viega","year":"2012","journal-title":"IEEE Secur. Priv."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Marwedel, P. (2018). Embedded Systems Foundations of Cyber-Physical Systems, and the Internet of Things. Embedded System Design, Springer Nature.","DOI":"10.1007\/978-3-319-56045-8"},{"key":"ref_46","first-page":"1","article-title":"Reproducibility Enhancement by Optimized Power Analysis Attacks in Vulnerability Assessment of IoT Transducers","volume":"70","author":"Arpaia","year":"2021","journal-title":"IEEE Trans. Instrum. Meas."},{"key":"ref_47","unstructured":"(2010). Industrial Communication Networks\u2014Network and System Security (Standard No. IEC 62443)."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Mugarza, I., Flores, J.L., and Montero, J.L. (2020). Security Issues and Software Updates Management in the Industrial Internet of Things (IIoT) Era. Sensors, 20.","DOI":"10.3390\/s20247160"},{"key":"ref_49","unstructured":"(2018). Security for Industrial Automation and Control Systems\u2014Part 4-1: Secure Product Development Lifecycle Requirements (Standard No. IEC 62443)."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1109\/TDSC.2004.2","article-title":"Basic concepts and taxonomy of dependable and secure computing","volume":"1","author":"Avizienis","year":"2004","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"168201","DOI":"10.1109\/ACCESS.2019.2954092","article-title":"Unknown Vulnerability Risk Assessment Based on Directed Graph Models: A Survey","volume":"7","author":"He","year":"2019","journal-title":"IEEE Access"},{"key":"ref_52","unstructured":"(2019). Information Technology\u2014Security Techniques\u2014Vulnerability Handling Processes (Standard No. ISO\/IEC 30111:2019). Available online: https:\/\/www.iso.org\/standard\/69725.html."},{"key":"ref_53","unstructured":"Common Criteria (CC) (2022, January 27). The Common Criteria for Information Technology Security Evaluation\u2014Introduction and General Model. Available online: https:\/\/www.commoncriteriaportal.org\/files\/ccfiles\/CCPART1V3.1R5.pdf."},{"key":"ref_54","unstructured":"Common Criteria (CC) (2022, January 27). Part 3: Security Assurance Components. Available online: https:\/\/commoncriteriaportal.org\/files\/ccfiles\/CCPART3V3.1R5.pdf."},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Herrmann, D. (2002). Using the Common Criteria for IT Security Evaluation, Auerbach Publications.","DOI":"10.1201\/9781420031423"},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"66","DOI":"10.1109\/MSEC.2019.2904475","article-title":"Toward a Cybersecurity Certification Framework for the Internet of Things","volume":"17","author":"Matheu","year":"2019","journal-title":"IEEE Secur. Priv."},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"244","DOI":"10.1016\/j.csi.2006.04.002","article-title":"A common criteria based security requirements engineering process for the development of secure information systems","volume":"29","author":"Mellado","year":"2007","journal-title":"Comput. Stand. Interfaces"},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"Hohenegger, A., Krummeck, G., Ba\u00f1os, J., Ortega, A., Hager, M., Sterba, J., Kertis, T., Novobilsky, P., Prochazka, J., and Caracuel, B. (2021, January 10\u201312). Security certification experience for industrial cyberphysical systems using Common Criteria and IEC 62443 certifications in certMILS. Proceedings of the 2021 4th IEEE International Conference on Industrial Cyber-Physical Systems (ICPS), Victoria, BC, Canada.","DOI":"10.1109\/ICPS49255.2021.9468241"},{"key":"ref_59","unstructured":"Homer, J., Ou, X., and Schmidt, D. (2022, January 27). A Sound and Practical Approach to Quantifying Security Risk in Enterprise Networks. Available online: https:\/\/www.cse.usf.edu\/~xou\/publications\/tr_homer_0809.pdf."},{"key":"ref_60","unstructured":"Zhang, S., Ou, X., Singhal, A., and Homer, J. (2011). An Empirical Study of a Vulnerability Metric Aggregation Method, Kansas State University. Available online: https:\/\/www.cse.usf.edu\/~xou\/publications\/stmacip11.pdf."},{"key":"ref_61","doi-asserted-by":"crossref","first-page":"561","DOI":"10.3233\/JCS-130475","article-title":"Aggregating vulnerability metrics in enterprise networks using attack graphs","volume":"21","author":"Homer","year":"2013","journal-title":"J. Comput. Secur."},{"key":"ref_62","doi-asserted-by":"crossref","first-page":"8820413","DOI":"10.1155\/2021\/8820413","article-title":"Power Grid-Oriented Cascading Failure Vulnerability Identifying Method Based on Wireless Sensors","volume":"2021","author":"Li","year":"2021","journal-title":"J. Sens."},{"key":"ref_63","doi-asserted-by":"crossref","first-page":"1407","DOI":"10.1109\/ACCESS.2020.3047159","article-title":"Vulnerability Assessment of the Urban Rail Transit Network Based on Travel Behavior Analysis","volume":"9","author":"Liu","year":"2021","journal-title":"IEEE Access"},{"key":"ref_64","doi-asserted-by":"crossref","first-page":"61","DOI":"10.1109\/TDSC.2011.34","article-title":"Dynamic Security Risk Management Using Bayesian Attack Graphs","volume":"9","author":"Poolsappasit","year":"2012","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_65","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1109\/TDSC.2016.2627033","article-title":"Exact Inference Techniques for the Analysis of Bayesian Attack Graphs","volume":"16","author":"Sgandurra","year":"2019","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_66","doi-asserted-by":"crossref","first-page":"79523","DOI":"10.1109\/ACCESS.2019.2920763","article-title":"Secure Internet of Things (IoT)-Based Smart-World Critical Infrastructures: Survey, Case Study and Research Opportunities","volume":"7","author":"Liu","year":"2019","journal-title":"IEEE Access"},{"key":"ref_67","doi-asserted-by":"crossref","unstructured":"Pascale, F., Adinolfi, E.A., Coppola, S., and Santonicola, E. (2021). Cybersecurity in Automotive: An Intrusion Detection System in Connected Vehicles. Electronics, 10.","DOI":"10.3390\/electronics10151765"},{"key":"ref_68","doi-asserted-by":"crossref","first-page":"1431","DOI":"10.1109\/ACCESS.2019.2961997","article-title":"I-HMM-Based Multidimensional Network Security Risk Assessment","volume":"8","author":"Hu","year":"2020","journal-title":"IEEE Access"},{"key":"ref_69","doi-asserted-by":"crossref","first-page":"1794","DOI":"10.1007\/s10922-020-09558-5","article-title":"Bayesian Decision Network-Based Security Risk Management Framework","volume":"28","author":"Bafghi","year":"2020","journal-title":"J. Netw. Syst. Manag."},{"key":"ref_70","first-page":"1","article-title":"Why to adopt a security metric? A brief survey","volume":"23","author":"Atzeni","year":"2006","journal-title":"Adv. Inf. Secur."},{"key":"ref_71","doi-asserted-by":"crossref","first-page":"126","DOI":"10.1109\/CC.2018.8438279","article-title":"A quantitative security metric model for security controls: Secure virtual machine migration protocol as target of assessment","volume":"15","author":"Zeb","year":"2018","journal-title":"China Commun."},{"key":"ref_72","doi-asserted-by":"crossref","unstructured":"Longueira-Romero, A., Iglesias, R., Gonzalez, D., and Garitano, I.N. (2020, January 20\u201323). How to Quantify the Security Level of Embedded Systems? A Taxonomy of Security Metrics. Proceedings of the 2020 IEEE 18th International Conference on Industrial Informatics (INDIN), Warwick, UK.","DOI":"10.1109\/INDIN45582.2020.9442219"},{"key":"ref_73","doi-asserted-by":"crossref","unstructured":"Rudolph, M., and Schwarz, R. (2012, January 20\u201324). A Critical Survey of Security Indicator Approaches. Proceedings of the 2012 Seventh International Conference on Availability, Reliability and Security, Prague, Czech Republic.","DOI":"10.1109\/ARES.2012.10"},{"key":"ref_74","unstructured":"Sentilles, S., Papatheocharous, E., and Ciccozzi, F. (2022, January 27). What Do We Know about Software Security Evaluation? A Preliminary Study. Available online: http:\/\/ceur-ws.org\/Vol-2273\/QuASoQ-04.pdf."},{"key":"ref_75","unstructured":"Amutio, M.A., Candau, J., and Ma\u00f1as, J.A. (2014). MAGERIT V3.0. Methodology for Information Systems Risk Analysis and Management, Book I\u2014The Method; National Standard."},{"key":"ref_76","unstructured":"Dekker, M., and Karsberg, C. (2022, January 27). Guideline on Threats and Assets: Technical Guidance on Threats and Assets in Article 13a, Available online: https:\/\/www.enisa.europa.eu\/publications\/technical-guideline-on-threats-and-assets."},{"key":"ref_77","unstructured":"(2004). Information Technology\u2014Security Techniques\u2014Management of Information and Communications Technology Security\u2014Part 1: Concepts and Models for Information and Communications Technology Security Management (Standard No. ISO\/IEC 13335-1:2004)."},{"key":"ref_78","unstructured":"National Institute for Standards and Technology (NIST) (2022, January 27). CPE\u2014Common Platform Enumeration, Available online: https:\/\/nvd.nist.gov\/products\/cpe."},{"key":"ref_79","unstructured":"Cheikes, B.A., Waltermire, D., and Scarfone, K. (2022, January 27). NIST Interagency Report 7695\u2014Common Platform Enumeration: Naming Specification Version 2.3, Available online: https:\/\/tsapps.nist.gov\/publication\/get_pdf.cfm?pub_id=909010."},{"key":"ref_80","unstructured":"Parmelee, M.C., Booth, H., Waltermire, D., and Scarfone, K. (2022, January 27). NIST Interagency Report 7696\u2014Common Platform Enumeration: Name Matching Specification Version 2.3, Available online: https:\/\/tsapps.nist.gov\/publication\/get_pdf.cfm?pub_id=909008."},{"key":"ref_81","unstructured":"(2019). Data and time-Representation for Information Interchange\u2014Part 1: Basic Rules (Standard No. ISO 8601:2019)."},{"key":"ref_82","unstructured":"MITRE Corporation (2022, January 27). CAPEC\u2014Common Attack Pattern Enumeration and Classification. Available online: https:\/\/capec.mitre.org\/."},{"key":"ref_83","unstructured":"MITRE Corporation (2022, January 27). CAPEC\u2014Common Attack Pattern Enumeration and Classification: Glossary. Available online: https:\/\/capec.mitre.org\/about\/glossary.html."},{"key":"ref_84","unstructured":"NIST\u2014National Institute of Standards and Technology (2022, January 27). National Vulnerability database (NVD), Available online: https:\/\/nvd.nist.gov\/."},{"key":"ref_85","doi-asserted-by":"crossref","unstructured":"Dimitriadis, A., Flores, J.L., Kulvatunyou, B., Ivezic, N., and Mavridis, I. (2020). ARES: Automated Risk Estimation in Smart Sensor Environments. Sensors, 20.","DOI":"10.3390\/s20164617"},{"key":"ref_86","unstructured":"Alves, T. (2022, January 27). OpenPLC Project. Available online: https:\/\/www.openplcproject.com\/."},{"key":"ref_87","unstructured":"Alves, T. (2022, January 27). OpenPLC V1. Available online: https:\/\/github.com\/thiagoralves\/OpenPLC."},{"key":"ref_88","unstructured":"Alves, T. (2022, January 27). OpenPLC V2. Available online: https:\/\/github.com\/thiagoralves\/OpenPLC_v2."},{"key":"ref_89","unstructured":"Alves, T. (2022, January 27). OpenPLC V3. Available online: https:\/\/github.com\/thiagoralves\/OpenPLC_v3."},{"key":"ref_90","unstructured":"Alves, T.R., Buratto, M., de Souza, F.M., and Rodrigues, T.V. (2014, January 10\u201313). OpenPLC: An open source alternative to automation. Proceedings of the IEEE Global Humanitarian Technology Conference (GHTC 2014), San Jose, CA, USA."},{"key":"ref_91","doi-asserted-by":"crossref","first-page":"364","DOI":"10.1016\/j.cose.2018.07.007","article-title":"OpenPLC: An IEC 61,131\u20143 compliant open source industrial controller for cyber security research","volume":"78","author":"Alves","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_92","unstructured":"(2022, January 27). Ubuntu 14.04 and 16.04 Lifecycle Extended to Ten Years. Available online: https:\/\/ubuntu.com\/blog\/ubuntu-14-04-and-16-04-lifecycle-extended-to-ten-years."},{"key":"ref_93","unstructured":"(2022, January 27). libssl1.0.0: Trusty (14.04): Ubuntu. Available online: https:\/\/launchpad.net\/ubuntu\/trusty\/+package\/libssl1.0.0\/+index."},{"key":"ref_94","unstructured":"(2022, January 27). nodejs: Trusty (14.04): Ubuntu. Available online: https:\/\/launchpad.net\/ubuntu\/trusty\/+package\/nodejs\/+index."},{"key":"ref_95","unstructured":"(2019). Security for Industrial Automation and Control Systems\u2014Part 4-2: Technical Security Requirements for IACS Components (Standard No. IEC 62443). Available online: https:\/\/www.isa.org\/products\/ansi-isa-62443-4-1-2018-security-for-industrial-au."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/6\/2126\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:33:48Z","timestamp":1760135628000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/6\/2126"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,9]]},"references-count":95,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2022,3]]}},"alternative-id":["s22062126"],"URL":"https:\/\/doi.org\/10.3390\/s22062126","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,9]]}}}