{"id":"https://openalex.org/W4403918685","doi":"https://doi.org/10.1109/tnsm.2024.3488011","title":"Security Control Grid for Optimized Cyber Defense Planning","display_name":"Security Control Grid for Optimized Cyber Defense Planning","publication_year":2024,"publication_date":"2024-10-30","ids":{"openalex":"https://openalex.org/W4403918685","doi":"https://doi.org/10.1109/tnsm.2024.3488011"},"language":"en","primary_location":{"id":"doi:10.1109/tnsm.2024.3488011","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnsm.2024.3488011","pdf_url":null,"source":{"id":"https://openalex.org/S173527311","display_name":"IEEE Transactions on Network and Service Management","issn_l":"1932-4537","issn":["1932-4537","2373-7379"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Network and Service Management","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5103347817","display_name":"Ashutosh Dutta","orcid":null},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Ashutosh Dutta","raw_affiliation_strings":["Independent Researcher, Carnegie Mellon University, USA"],"affiliations":[{"raw_affiliation_string":"Independent Researcher, Carnegie Mellon University, USA","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043893479","display_name":"Ehab Al\u2010Shaer","orcid":"https://orcid.org/0000-0002-7665-8293"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ehab Al-Shaer","raw_affiliation_strings":["School of Computer Science Department, Carnegie Mellon University, Pittsburgh, PA, USA","School of Computer Science Department, Carnegie Mellon University, USA"],"affiliations":[{"raw_affiliation_string":"School of Computer Science Department, Carnegie Mellon University, Pittsburgh, PA, USA","institution_ids":["https://openalex.org/I74973139"]},{"raw_affiliation_string":"School of Computer Science Department, Carnegie Mellon University, USA","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5018155820","display_name":"Ehsan Aghaei","orcid":null},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ehsan Aghaei","raw_affiliation_strings":["School of Computer Science Department, Carnegie Mellon University, Pittsburgh, PA, USA","School of Computer Science Department, Carnegie Mellon University, USA"],"affiliations":[{"raw_affiliation_string":"School of Computer Science Department, Carnegie Mellon University, Pittsburgh, PA, USA","institution_ids":["https://openalex.org/I74973139"]},{"raw_affiliation_string":"School of Computer Science Department, Carnegie Mellon University, USA","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101713020","display_name":"Qi Duan","orcid":"https://orcid.org/0000-0002-6168-5192"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Qi Duan","raw_affiliation_strings":["School of Computer Science Department, Carnegie Mellon University, Pittsburgh, PA, USA","School of Computer Science Department, Carnegie Mellon University, USA"],"affiliations":[{"raw_affiliation_string":"School of Computer Science Department, Carnegie Mellon University, Pittsburgh, PA, USA","institution_ids":["https://openalex.org/I74973139"]},{"raw_affiliation_string":"School of Computer Science Department, Carnegie Mellon University, USA","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5103116017","display_name":"Hasan Ya\u015far","orcid":"https://orcid.org/0009-0006-9274-1202"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]},{"id":"https://openalex.org/I114772536","display_name":"Software Engineering Institute","ror":"https://ror.org/01xqjjn94","country_code":"US","type":"facility","lineage":["https://openalex.org/I114772536","https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hasan Yasar","raw_affiliation_strings":["Software Engineering Institute, Carnegie Mellon University, Pittsburgh, PA, USA","Carnegie Mellon University, USA"],"affiliations":[{"raw_affiliation_string":"Software Engineering Institute, Carnegie Mellon University, Pittsburgh, PA, USA","institution_ids":["https://openalex.org/I114772536","https://openalex.org/I74973139"]},{"raw_affiliation_string":"Carnegie Mellon University, USA","institution_ids":["https://openalex.org/I74973139"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5103347817"],"corresponding_institution_ids":["https://openalex.org/I74973139"],"apc_list":null,"apc_paid":null,"fwci":0.8142,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.80567885,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":"22","issue":"1","first_page":"913","last_page":"929"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9587000012397766,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9587000012397766,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9251000285148621,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7911973595619202},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5741338729858398},{"id":"https://openalex.org/keywords/grid","display_name":"Grid","score":0.526203453540802},{"id":"https://openalex.org/keywords/control","display_name":"Control (management)","score":0.5055160522460938},{"id":"https://openalex.org/keywords/distributed-computing","display_name":"Distributed computing","score":0.39583253860473633},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.35679349303245544},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.10698625445365906}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7911973595619202},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5741338729858398},{"id":"https://openalex.org/C187691185","wikidata":"https://www.wikidata.org/wiki/Q2020720","display_name":"Grid","level":2,"score":0.526203453540802},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.5055160522460938},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.39583253860473633},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.35679349303245544},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.10698625445365906},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tnsm.2024.3488011","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tnsm.2024.3488011","pdf_url":null,"source":{"id":"https://openalex.org/S173527311","display_name":"IEEE Transactions on Network and Service Management","issn_l":"1932-4537","issn":["1932-4537","2373-7379"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Network and Service Management","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W1480909796","https://openalex.org/W1481397690","https://openalex.org/W1925725102","https://openalex.org/W2012336291","https://openalex.org/W2014071948","https://openalex.org/W2055083533","https://openalex.org/W2059209509","https://openalex.org/W2091673436","https://openalex.org/W2126756319","https://openalex.org/W2143174928","https://openalex.org/W2751179444","https://openalex.org/W2951708229","https://openalex.org/W2969335200","https://openalex.org/W3131988611","https://openalex.org/W3193361787","https://openalex.org/W4294343684","https://openalex.org/W4298870559","https://openalex.org/W4318603353","https://openalex.org/W4319079731","https://openalex.org/W4368232268","https://openalex.org/W6682933086","https://openalex.org/W6747271121","https://openalex.org/W6790367193","https://openalex.org/W6841097320"],"related_works":["https://openalex.org/W2111375262","https://openalex.org/W2317728013","https://openalex.org/W1991205173","https://openalex.org/W2109048960","https://openalex.org/W2741481635","https://openalex.org/W2338537463","https://openalex.org/W2183644707","https://openalex.org/W1993039745","https://openalex.org/W1581129489","https://openalex.org/W2369252416"],"abstract_inverted_index":{"Cybersecurity":[0],"controls":[1,16,53,80],"are":[2],"essential":[3],"for":[4,55,167],"ensuring":[5],"information":[6],"confidentiality,":[7],"integrity,":[8],"and":[9,38,47,63,90,98,138,153,162],"availability.":[10],"However,":[11],"selecting":[12],"the":[13,69,78,95,104,146],"most":[14],"effective":[15],"to":[17,50],"maximize":[18],"return":[19],"on":[20,82],"investment":[21],"(RoI)":[22],"in":[23,145],"cyber":[24,96],"defense":[25],"is":[26,143],"a":[27,114,128],"complex":[28],"task":[29],"involving":[30],"numerous":[31],"factors":[32],"such":[33],"as":[34,113],"vulnerabilities,":[35],"threat":[36],"prioritization,":[37],"budget":[39],"constraints.":[40],"This":[41,141],"paper":[42],"introduces":[43],"an":[44],"innovative":[45],"model":[46,131],"optimization":[48,116],"techniques":[49],"select":[51],"cybersecurity":[52,110,160],"(CSC)":[54],"optimal":[56],"risk":[57,166],"mitigation,":[58],"balancing":[59],"residual":[60,165],"risk,":[61],"budget,":[62],"resiliency":[64],"requirements.":[65],"Our":[66],"approach":[67,142],"features":[68],"Security":[70],"Control":[71],"Grid":[72],"(SCG)":[73],"model,":[74],"which":[75,150],"automatically":[76],"determines":[77],"necessary":[79],"based":[81],"their":[83],"security":[84],"functions":[85],"(Identify,":[86],"Protect,":[87],"Detect,":[88],"Respond,":[89],"Recover),":[91],"strategic":[92],"placement":[93],"within":[94],"environment,":[97],"effectiveness":[99],"at":[100],"different":[101],"stages":[102],"of":[103],"attack":[105],"kill":[106],"chain.":[107],"We":[108],"formulate":[109],"control":[111],"decision-making":[112],"multidimensional":[115],"problem,":[117],"solving":[118],"it":[119],"using":[120],"Satisfiability":[121],"Modulo":[122],"Theories":[123],"(SMT).":[124],"Additionally,":[125],"we":[126],"integrate":[127],"domain-specific":[129],"language":[130],"that":[132,158],"links":[133],"CSCs":[134],"with":[135],"Common":[136],"Vulnerabilities":[137],"Exposures":[139],"(CVEs).":[140],"implemented":[144],"SCG":[147],"solver":[148],"tool,":[149],"generates":[151],"scalable":[152],"robust":[154],"CSC":[155],"deployment":[156],"plans":[157],"optimize":[159],"RoI":[161],"maintain":[163],"acceptable":[164],"large-scale":[168],"enterprises.":[169]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2025-12-27T23:08:20.325037","created_date":"2025-10-10T00:00:00"}
