{"id":"https://openalex.org/W4294308997","doi":"https://doi.org/10.1145/3547133","title":"Measuring security practices","display_name":"Measuring security practices","publication_year":2022,"publication_date":"2022-08-19","ids":{"openalex":"https://openalex.org/W4294308997","doi":"https://doi.org/10.1145/3547133"},"language":"en","primary_location":{"id":"doi:10.1145/3547133","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3547133","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3547133","source":{"id":"https://openalex.org/S103482838","display_name":"Communications of the ACM","issn_l":"0001-0782","issn":["0001-0782","1557-7317"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Communications of the ACM","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3547133","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5067103824","display_name":"Louis F. DeKoven","orcid":null},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Louis F. DeKoven","raw_affiliation_strings":["University of California, San Diego, CA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, CA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5045654500","display_name":"Audrey Randall","orcid":null},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Audrey Randall","raw_affiliation_strings":["University of California, San Diego, CA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, CA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5089337298","display_name":"Ariana Mirian","orcid":"https://orcid.org/0009-0006-7293-3290"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ariana Mirian","raw_affiliation_strings":["University of California, San Diego, CA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, CA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5085735887","display_name":"Gautam Akiwate","orcid":"https://orcid.org/0000-0002-1359-1722"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Gautam Akiwate","raw_affiliation_strings":["University of California, San Diego, CA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, CA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5044730627","display_name":"Ansel Blume","orcid":null},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ansel Blume","raw_affiliation_strings":["University of California, San Diego, CA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, CA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103354854","display_name":"Lawrence K. Saul","orcid":null},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Lawrence K. Saul","raw_affiliation_strings":["University of California, San Diego, CA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, CA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5054807714","display_name":"Aaron Schulman","orcid":"https://orcid.org/0000-0002-9280-8925"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Aaron Schulman","raw_affiliation_strings":["University of California, San Diego, CA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, CA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5081366293","display_name":"Geoffrey M. Voelker","orcid":"https://orcid.org/0000-0003-0865-7499"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Geoffrey M. Voelker","raw_affiliation_strings":["University of California, San Diego, CA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, CA","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5048394730","display_name":"Stefan Savage","orcid":"https://orcid.org/0000-0001-6617-8029"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California, San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Stefan Savage","raw_affiliation_strings":["University of California, San Diego, CA"],"affiliations":[{"raw_affiliation_string":"University of California, San Diego, CA","institution_ids":["https://openalex.org/I36258959"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":9,"corresponding_author_ids":["https://openalex.org/A5067103824"],"corresponding_institution_ids":["https://openalex.org/I36258959"],"apc_list":null,"apc_paid":null,"fwci":0.4467,"has_fulltext":true,"cited_by_count":3,"citation_normalized_percentile":{"value":0.58480654,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":94},"biblio":{"volume":"65","issue":"9","first_page":"93","last_page":"102"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9987999796867371,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9983000159263611,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6629032492637634},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6380863785743713},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.6168612241744995},{"id":"https://openalex.org/keywords/scale","display_name":"Scale (ratio)","score":0.5041199922561646},{"id":"https://openalex.org/keywords/software-security-assurance","display_name":"Software security assurance","score":0.4614805579185486},{"id":"https://openalex.org/keywords/security-information-and-event-management","display_name":"Security information and event management","score":0.4509144425392151},{"id":"https://openalex.org/keywords/best-practice","display_name":"Best practice","score":0.4478503167629242},{"id":"https://openalex.org/keywords/cloud-computing-security","display_name":"Cloud computing security","score":0.4445390999317169},{"id":"https://openalex.org/keywords/ranging","display_name":"Ranging","score":0.43244534730911255},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.37480252981185913},{"id":"https://openalex.org/keywords/security-service","display_name":"Security service","score":0.352092981338501},{"id":"https://openalex.org/keywords/risk-analysis","display_name":"Risk analysis (engineering)","score":0.34357118606567383},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.2926786243915558},{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.2848265767097473},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.15940669178962708},{"id":"https://openalex.org/keywords/telecommunications","display_name":"Telecommunications","score":0.08847397565841675},{"id":"https://openalex.org/keywords/geography","display_name":"Geography","score":0.06954580545425415},{"id":"https://openalex.org/keywords/political-science","display_name":"Political science","score":0.06742379069328308}],"concepts":[{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6629032492637634},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6380863785743713},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.6168612241744995},{"id":"https://openalex.org/C2778755073","wikidata":"https://www.wikidata.org/wiki/Q10858537","display_name":"Scale (ratio)","level":2,"score":0.5041199922561646},{"id":"https://openalex.org/C62913178","wikidata":"https://www.wikidata.org/wiki/Q7554361","display_name":"Software security assurance","level":4,"score":0.4614805579185486},{"id":"https://openalex.org/C103377522","wikidata":"https://www.wikidata.org/wiki/Q3493999","display_name":"Security information and event management","level":4,"score":0.4509144425392151},{"id":"https://openalex.org/C184356942","wikidata":"https://www.wikidata.org/wiki/Q830382","display_name":"Best practice","level":2,"score":0.4478503167629242},{"id":"https://openalex.org/C184842701","wikidata":"https://www.wikidata.org/wiki/Q370563","display_name":"Cloud computing security","level":3,"score":0.4445390999317169},{"id":"https://openalex.org/C115051666","wikidata":"https://www.wikidata.org/wiki/Q6522493","display_name":"Ranging","level":2,"score":0.43244534730911255},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.37480252981185913},{"id":"https://openalex.org/C29983905","wikidata":"https://www.wikidata.org/wiki/Q7445066","display_name":"Security service","level":3,"score":0.352092981338501},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.34357118606567383},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.2926786243915558},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.2848265767097473},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.15940669178962708},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.08847397565841675},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.06954580545425415},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.06742379069328308},{"id":"https://openalex.org/C58640448","wikidata":"https://www.wikidata.org/wiki/Q42515","display_name":"Cartography","level":1,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3547133","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3547133","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3547133","source":{"id":"https://openalex.org/S103482838","display_name":"Communications of the ACM","issn_l":"0001-0782","issn":["0001-0782","1557-7317"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Communications of the ACM","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1145/3547133","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3547133","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3547133","source":{"id":"https://openalex.org/S103482838","display_name":"Communications of the ACM","issn_l":"0001-0782","issn":["0001-0782","1557-7317"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Communications of the ACM","raw_type":"journal-article"},"sustainable_development_goals":[{"score":0.6299999952316284,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G2587357081","display_name":null,"funder_award_id":"CNS-1629973 and CNS-1705050","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G4473328690","display_name":null,"funder_award_id":"CNS-1629973,CNS-1705050","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G6295539132","display_name":null,"funder_award_id":"AFRL-FA8750-18-2-0087","funder_id":"https://openalex.org/F4320306110","funder_display_name":"U.S. Department of Homeland Security"},{"id":"https://openalex.org/G768852885","display_name":"II-New: A Dual-Purpose Data Analytics Laboratory","funder_award_id":"1629973","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G8440009107","display_name":"SaTC: CORE: Medium: Large-Scale Characterization of DNS Abuse","funder_award_id":"1705050","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G848032724","display_name":null,"funder_award_id":"Science","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320306110","display_name":"U.S. Department of Homeland Security","ror":"https://ror.org/00jyr0d86"},{"id":"https://openalex.org/F4320338294","display_name":"Air Force Research Laboratory","ror":"https://ror.org/02e2egq70"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4294308997.pdf","grobid_xml":"https://content.openalex.org/works/W4294308997.grobid-xml"},"referenced_works_count":12,"referenced_works":["https://openalex.org/W1480376833","https://openalex.org/W1966831243","https://openalex.org/W2045591401","https://openalex.org/W2127062979","https://openalex.org/W2552371696","https://openalex.org/W2610762919","https://openalex.org/W2610939075","https://openalex.org/W2624735790","https://openalex.org/W2767011015","https://openalex.org/W2891316582","https://openalex.org/W2931556662","https://openalex.org/W4299689471"],"related_works":["https://openalex.org/W2065250680","https://openalex.org/W2336014427","https://openalex.org/W2092708554","https://openalex.org/W2120086576","https://openalex.org/W2086178534","https://openalex.org/W2353177111","https://openalex.org/W2907868081","https://openalex.org/W2784006287","https://openalex.org/W2062411488","https://openalex.org/W2608550600"],"abstract_inverted_index":{"Users":[0],"are":[1],"encouraged":[2],"to":[3,12,31,68,93],"adopt":[4],"a":[5,55,81,106],"wide":[6],"array":[7],"of":[8,20,28,58,74,83,111],"technologies":[9],"and":[10,70],"behaviors":[11,99],"reduce":[13],"their":[14,41],"security":[15,45,76,98],"risk.":[16],"However,":[17],"the":[18,26,72,91,101],"adoption":[19],"these":[21,51],"\"best":[22],"practices,\"":[23],"ranging":[24],"from":[25],"use":[27,65],"antivirus":[29],"products":[30],"keeping":[32],"software":[33],"updated,":[34],"is":[35,40],"not":[36],"well":[37,47,79],"understood,":[38],"nor":[39],"practical":[42],"impact":[43,100],"on":[44],"risk":[46],"established.":[48],"To":[49],"explore":[50,90],"issues,":[52],"we":[53],"conducted":[54],"large-scale":[56],"measurement":[57],"15,000":[59],"computers":[60],"over":[61],"six":[62],"months.":[63],"We":[64,88],"passive":[66],"monitoring":[67],"infer":[69],"characterize":[71],"prevalence":[73],"various":[75],"practices":[77],"as":[78,80],"range":[82],"other":[84],"potentially":[85],"security-relevant":[86],"behaviors.":[87],"then":[89],"extent":[92],"which":[94],"differences":[95],"in":[96],"key":[97],"real-world":[102],"outcomes":[103],"(i.e.,":[104],"that":[105],"device":[107],"shows":[108],"clear":[109],"evidence":[110],"having":[112],"been":[113],"compromised).":[114]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":1},{"year":2022,"cited_by_count":1}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
