{"id":"https://openalex.org/W1547152107","doi":"https://doi.org/10.3233/jcs-130475","title":"Aggregating vulnerability metrics in enterprise networks using attack graphs","display_name":"Aggregating vulnerability metrics in enterprise networks using attack graphs","publication_year":2013,"publication_date":"2013-09-20","ids":{"openalex":"https://openalex.org/W1547152107","doi":"https://doi.org/10.3233/jcs-130475","mag":"1547152107"},"language":"en","primary_location":{"id":"doi:10.3233/jcs-130475","is_oa":false,"landing_page_url":"https://doi.org/10.3233/jcs-130475","pdf_url":null,"source":{"id":"https://openalex.org/S106992369","display_name":"Journal of Computer Security","issn_l":"0926-227X","issn":["0926-227X","1875-8924"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310318577","host_organization_name":"IOS Press","host_organization_lineage":["https://openalex.org/P4310318577"],"host_organization_lineage_names":["IOS Press"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Computer Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://digitalcommons.acu.edu/info_tech_computing/2","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5079211489","display_name":"John Homer","orcid":"https://orcid.org/0009-0002-3454-9600"},"institutions":[{"id":"https://openalex.org/I60205797","display_name":"Abilene Christian University","ror":"https://ror.org/004srrf86","country_code":"US","type":"education","lineage":["https://openalex.org/I60205797"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"John Homer","raw_affiliation_strings":["Abilene Christian University, Abilene, TX, USA","Abilene Christian University , Abilene, TX, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Abilene Christian University, Abilene, TX, USA","institution_ids":["https://openalex.org/I60205797"]},{"raw_affiliation_string":"Abilene Christian University , Abilene, TX, USA","institution_ids":["https://openalex.org/I60205797"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101757162","display_name":"Su Zhang","orcid":"https://orcid.org/0000-0002-8172-7740"},"institutions":[{"id":"https://openalex.org/I189590672","display_name":"Kansas State University","ror":"https://ror.org/05p1j8758","country_code":"US","type":"education","lineage":["https://openalex.org/I189590672"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Su Zhang","raw_affiliation_strings":["Kansas State University, Manhattan, KS, USA","Kansas State University, Manhattan, KS, USA;"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Kansas State University, Manhattan, KS, USA","institution_ids":["https://openalex.org/I189590672"]},{"raw_affiliation_string":"Kansas State University, Manhattan, KS, USA;","institution_ids":["https://openalex.org/I189590672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113810433","display_name":"Xinming Ou","orcid":"https://orcid.org/0009-0007-2501-7991"},"institutions":[{"id":"https://openalex.org/I189590672","display_name":"Kansas State University","ror":"https://ror.org/05p1j8758","country_code":"US","type":"education","lineage":["https://openalex.org/I189590672"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xinming Ou","raw_affiliation_strings":["Kansas State University, Manhattan, KS, USA","Kansas State University, Manhattan, KS, USA;"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Kansas State University, Manhattan, KS, USA","institution_ids":["https://openalex.org/I189590672"]},{"raw_affiliation_string":"Kansas State University, Manhattan, KS, USA;","institution_ids":["https://openalex.org/I189590672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5020594899","display_name":"David Schmidt","orcid":"https://orcid.org/0000-0001-7728-2884"},"institutions":[{"id":"https://openalex.org/I189590672","display_name":"Kansas State University","ror":"https://ror.org/05p1j8758","country_code":"US","type":"education","lineage":["https://openalex.org/I189590672"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"David Schmidt","raw_affiliation_strings":["Kansas State University, Manhattan, KS, USA","Kansas State University, Manhattan, KS, USA;"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Kansas State University, Manhattan, KS, USA","institution_ids":["https://openalex.org/I189590672"]},{"raw_affiliation_string":"Kansas State University, Manhattan, KS, USA;","institution_ids":["https://openalex.org/I189590672"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101605564","display_name":"Yanhui Du","orcid":"https://orcid.org/0000-0003-1711-1156"},"institutions":[{"id":"https://openalex.org/I37448385","display_name":"China People's Public Security University","ror":"https://ror.org/05twya590","country_code":"CN","type":"education","lineage":["https://openalex.org/I37448385"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yanhui Du","raw_affiliation_strings":["Chinese People's Public Security University, Beijing, China","Chinese People's Public Security University, Beijing, China#TAB#"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Chinese People's Public Security University, Beijing, China","institution_ids":["https://openalex.org/I37448385"]},{"raw_affiliation_string":"Chinese People's Public Security University, Beijing, China#TAB#","institution_ids":["https://openalex.org/I37448385"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5108572482","display_name":"S. Raj Rajagopalan","orcid":null},"institutions":[{"id":"https://openalex.org/I82514191","display_name":"Honeywell (United States)","ror":"https://ror.org/02t71h845","country_code":"US","type":"company","lineage":["https://openalex.org/I82514191"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"S. Raj Rajagopalan","raw_affiliation_strings":["Honeywell ACS Labs, Phoenix, AZ, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Honeywell ACS Labs, Phoenix, AZ, USA","institution_ids":["https://openalex.org/I82514191"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5088206056","display_name":"Anoop Singhal","orcid":"https://orcid.org/0000-0002-2602-3927"},"institutions":[{"id":"https://openalex.org/I1321296531","display_name":"National Institute of Standards and Technology","ror":"https://ror.org/05xpvk416","country_code":"US","type":"funder","lineage":["https://openalex.org/I1321296531","https://openalex.org/I1343035065"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Anoop Singhal","raw_affiliation_strings":["National Institute of Standards and Technology, Gaithersburg, MD, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"National Institute of Standards and Technology, Gaithersburg, MD, USA","institution_ids":["https://openalex.org/I1321296531"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5079211489"],"corresponding_institution_ids":["https://openalex.org/I60205797"],"apc_list":null,"apc_paid":null,"fwci":20.9021,"has_fulltext":false,"cited_by_count":132,"citation_normalized_percentile":{"value":0.99137338,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":95,"max":100},"biblio":{"volume":"21","issue":"4","first_page":"561","last_page":"597"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9352999925613403,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9352999925613403,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.008700000122189522,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.005100000184029341,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8588284850120544},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.7149163484573364},{"id":"https://openalex.org/keywords/probabilistic-logic","display_name":"Probabilistic logic","score":0.6740404367446899},{"id":"https://openalex.org/keywords/aggregate","display_name":"Aggregate (composite)","score":0.6384551525115967},{"id":"https://openalex.org/keywords/metric","display_name":"Metric (unit)","score":0.5917572975158691},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5788750648498535},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.514712393283844},{"id":"https://openalex.org/keywords/semantics","display_name":"Semantics (computer science)","score":0.5023195743560791},{"id":"https://openalex.org/keywords/network-security","display_name":"Network security","score":0.4550545811653137},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.42120328545570374},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3879201412200928},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.33251887559890747},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.18261617422103882}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8588284850120544},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.7149163484573364},{"id":"https://openalex.org/C49937458","wikidata":"https://www.wikidata.org/wiki/Q2599292","display_name":"Probabilistic logic","level":2,"score":0.6740404367446899},{"id":"https://openalex.org/C4679612","wikidata":"https://www.wikidata.org/wiki/Q866298","display_name":"Aggregate (composite)","level":2,"score":0.6384551525115967},{"id":"https://openalex.org/C176217482","wikidata":"https://www.wikidata.org/wiki/Q860554","display_name":"Metric (unit)","level":2,"score":0.5917572975158691},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5788750648498535},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.514712393283844},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.5023195743560791},{"id":"https://openalex.org/C182590292","wikidata":"https://www.wikidata.org/wiki/Q989632","display_name":"Network security","level":2,"score":0.4550545811653137},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.42120328545570374},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3879201412200928},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.33251887559890747},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.18261617422103882},{"id":"https://openalex.org/C159985019","wikidata":"https://www.wikidata.org/wiki/Q181790","display_name":"Composite material","level":1,"score":0.0},{"id":"https://openalex.org/C187736073","wikidata":"https://www.wikidata.org/wiki/Q2920921","display_name":"Management","level":1,"score":0.0},{"id":"https://openalex.org/C192562407","wikidata":"https://www.wikidata.org/wiki/Q228736","display_name":"Materials science","level":0,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C21547014","wikidata":"https://www.wikidata.org/wiki/Q1423657","display_name":"Operations management","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.3233/jcs-130475","is_oa":false,"landing_page_url":"https://doi.org/10.3233/jcs-130475","pdf_url":null,"source":{"id":"https://openalex.org/S106992369","display_name":"Journal of Computer Security","issn_l":"0926-227X","issn":["0926-227X","1875-8924"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310318577","host_organization_name":"IOS Press","host_organization_lineage":["https://openalex.org/P4310318577"],"host_organization_lineage_names":["IOS Press"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Journal of Computer Security","raw_type":"journal-article"},{"id":"pmh:oai:digitalcommons.acu.edu:info_tech_computing-1001","is_oa":true,"landing_page_url":"https://digitalcommons.acu.edu/info_tech_computing/2","pdf_url":null,"source":{"id":"https://openalex.org/S4377196697","display_name":"Digital Commons - ACU (Abilene Christian University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I60205797","host_organization_name":"Abilene Christian University","host_organization_lineage":["https://openalex.org/I60205797"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"School of Information Technology and Computing","raw_type":"text"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.418.9112","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.418.9112","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://people.cis.ksu.edu/~zhangs84/papers/JCS.pdf","raw_type":"text"}],"best_oa_location":{"id":"pmh:oai:digitalcommons.acu.edu:info_tech_computing-1001","is_oa":true,"landing_page_url":"https://digitalcommons.acu.edu/info_tech_computing/2","pdf_url":null,"source":{"id":"https://openalex.org/S4377196697","display_name":"Digital Commons - ACU (Abilene Christian University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I60205797","host_organization_name":"Abilene Christian University","host_organization_lineage":["https://openalex.org/I60205797"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"School of Information Technology and Computing","raw_type":"text"},"sustainable_development_goals":[{"score":0.6399999856948853,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":46,"referenced_works":["https://openalex.org/W63046450","https://openalex.org/W82848659","https://openalex.org/W132732249","https://openalex.org/W135995917","https://openalex.org/W153010205","https://openalex.org/W164306009","https://openalex.org/W1508191694","https://openalex.org/W1515452738","https://openalex.org/W1590752147","https://openalex.org/W1755360231","https://openalex.org/W1971114459","https://openalex.org/W2009470162","https://openalex.org/W2017140356","https://openalex.org/W2030014066","https://openalex.org/W2030092670","https://openalex.org/W2052645878","https://openalex.org/W2054127354","https://openalex.org/W2069033598","https://openalex.org/W2073097601","https://openalex.org/W2076252092","https://openalex.org/W2083658929","https://openalex.org/W2085048397","https://openalex.org/W2091673436","https://openalex.org/W2099103357","https://openalex.org/W2100033648","https://openalex.org/W2110908300","https://openalex.org/W2117694832","https://openalex.org/W2118382442","https://openalex.org/W2121141821","https://openalex.org/W2121805588","https://openalex.org/W2129586531","https://openalex.org/W2130373165","https://openalex.org/W2132243817","https://openalex.org/W2141289698","https://openalex.org/W2143122640","https://openalex.org/W2143396794","https://openalex.org/W2147495040","https://openalex.org/W2150168063","https://openalex.org/W2151369956","https://openalex.org/W2159080219","https://openalex.org/W2165307808","https://openalex.org/W2171797753","https://openalex.org/W2207375515","https://openalex.org/W2234839255","https://openalex.org/W2620244897","https://openalex.org/W2748369307"],"related_works":["https://openalex.org/W17155033","https://openalex.org/W3207760230","https://openalex.org/W1496222301","https://openalex.org/W1590307681","https://openalex.org/W2536018345","https://openalex.org/W4312814274","https://openalex.org/W2906845177","https://openalex.org/W4200107511","https://openalex.org/W2891427086","https://openalex.org/W1968625315"],"abstract_inverted_index":{"Quantifying":[0],"security":[1,13,79],"risk":[2],"is":[3,23,70,164],"an":[4,45,71,95],"important":[5,72],"and":[6,89,101,146,174],"yet":[7],"difficult":[8],"task":[9],"in":[10,44,86,139,166],"enterprise":[11,46],"network":[12,61,78,191],"management.":[14],"While":[15],"metrics":[16,43,50],"exist":[17],"for":[18,67,148,162],"individual":[19],"software":[20],"vulnerabilities,":[21],"there":[22],"currently":[24],"no":[25],"standard":[26],"way":[27],"of":[28,190],"aggregating":[29],"such":[30],"metrics.":[31],"We":[32,82,104,120,134],"present":[33],"a":[34,59,76,113,158,188],"model":[35,66,143,161],"that":[36,51,97,106,126,157],"can":[37,56],"be":[38],"used":[39],"to":[40,93,144],"aggregate":[41],"vulnerability":[42],"network,":[47],"producing":[48],"quantitative":[49],"measure":[52],"the":[53,117,168,171],"likelihood":[54],"breaches":[55],"occur":[57],"within":[58],"given":[60],"configuration.":[62],"A":[63],"clear":[64,99,159],"semantic":[65,160],"this":[68],"aggregation":[69,96,163],"first":[73],"step":[74],"toward":[75],"comprehensive":[77],"metric":[80,172],"model.":[81],"utilize":[83],"existing":[84],"work":[85],"attack":[87,110],"graphs":[88],"apply":[90],"probabilistic":[91,141],"reasoning":[92],"produce":[94],"has":[98,183],"semantics":[100],"sound":[102],"computation.":[103],"ensure":[105],"shared":[107],"dependencies":[108],"between":[109],"paths":[111],"have":[112],"proportional":[114],"effect":[115],"on":[116],"final":[118],"calculation.":[119],"correctly":[121],"reason":[122],"over":[123],"cycles,":[124],"ensuring":[125],"privileges":[127],"are":[128],"evaluated":[129,186],"without":[130],"any":[131],"self-referencing":[132],"effect.":[133],"introduce":[135],"additional":[136],"modeling":[137],"artifacts":[138],"our":[140],"graphical":[142],"capture":[145],"account":[147],"hidden":[149],"correlations":[150],"among":[151],"exploit":[152],"steps.":[153],"The":[154],"paper":[155],"shows":[156],"critical":[165],"interpreting":[167],"results,":[169],"calibrating":[170],"model,":[173],"explaining":[175],"insights":[176],"gained":[177],"from":[178,197],"empirical":[179],"evaluation.":[180],"Our":[181],"approach":[182],"been":[184],"rigorously":[185],"using":[187],"number":[189],"models,":[192],"as":[193,195],"well":[194],"data":[196],"production":[198],"systems.":[199]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":7},{"year":2024,"cited_by_count":15},{"year":2023,"cited_by_count":8},{"year":2022,"cited_by_count":10},{"year":2021,"cited_by_count":15},{"year":2020,"cited_by_count":16},{"year":2019,"cited_by_count":6},{"year":2018,"cited_by_count":12},{"year":2017,"cited_by_count":17},{"year":2016,"cited_by_count":11},{"year":2015,"cited_by_count":8},{"year":2014,"cited_by_count":6}],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2025-10-10T00:00:00"}
