{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,9]],"date-time":"2025-04-09T00:52:03Z","timestamp":1744159923208,"version":"3.28.0"},"reference-count":20,"publisher":"IEEE","license":[{"start":{"date-parts":[[2020,12,1]],"date-time":"2020-12-01T00:00:00Z","timestamp":1606780800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,12,1]],"date-time":"2020-12-01T00:00:00Z","timestamp":1606780800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,12,1]],"date-time":"2020-12-01T00:00:00Z","timestamp":1606780800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100000038","name":"Natural Sciences and Engineering Research Council of Canada (NSERC)","doi-asserted-by":"publisher","award":["RGPIN-2019-06306"],"award-info":[{"award-number":["RGPIN-2019-06306"]}],"id":[{"id":"10.13039\/501100000038","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,12]]},"DOI":"10.1109\/trustcom50675.2020.00067","type":"proceedings-article","created":{"date-parts":[[2021,4,14]],"date-time":"2021-04-14T00:33:34Z","timestamp":1618360414000},"page":"442-449","source":"Crossref","is-referenced-by-count":3,"title":["Evaluating the Soundness of Security Metrics from Vulnerability Scoring Frameworks"],"prefix":"10.1109","author":[{"given":"Joe","family":"Samuel","sequence":"first","affiliation":[{"name":"Systems and Computer Engineering, Carleton University, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Khalil","family":"Aalab","sequence":"additional","affiliation":[{"name":"Systems and Computer Engineering, Carleton University, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jason","family":"Jaskolka","sequence":"additional","affiliation":[{"name":"Systems and Computer Engineering, Carleton University, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"journal-title":"Common vulnerability scoring system v3 1 Specification document","year":"2019","key":"ref10"},{"key":"ref11","first-page":"48","article-title":"Metrics for information security vulnerabilities","volume":"1","author":"wang","year":"2008","journal-title":"Journal of Applied Global Research"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/s11219-015-9274-6"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/MINES.2011.27"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ISTEL.2016.7881922"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.21236\/ADA470450"},{"journal-title":"Harmonized Threat and Risk Assessment (TRA) Methodology","year":"2007","key":"ref16"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2010.04.006"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.60"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/0-387-24006-3_8"},{"journal-title":"National Vulnerability Database","year":"2020","key":"ref4"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.4018\/IJSSSP.2019010101"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICSEA.2007.79"},{"key":"ref5","article-title":"SSE-CMM security metrics","author":"jelen","year":"0","journal-title":"NIST and CSSPAB Workshop"},{"journal-title":"A Guide to Security Metrics","year":"2006","author":"payne","key":"ref8"},{"key":"ref7","article-title":"Security metrology and the monty hall problem","author":"yee","year":"0","journal-title":"Workshop on Information Security System Rating and Ranking"},{"journal-title":"Security Metrics Replacing Fear Uncertainty and Doubt","year":"2007","author":"jaquith","key":"ref2"},{"key":"ref1","first-page":"511","article-title":"Recommendations for effective security assurance of software-dependent systems","author":"jaskolka","year":"2020","journal-title":"Intelligent Computing SAI 2020"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.IR.7435"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/HASE.2014.10"}],"event":{"name":"2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)","start":{"date-parts":[[2020,12,29]]},"location":"Guangzhou, China","end":{"date-parts":[[2021,1,1]]}},"container-title":["2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9342897\/9342964\/09343145.pdf?arnumber=9343145","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,30]],"date-time":"2022-06-30T11:18:53Z","timestamp":1656587933000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9343145\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,12]]},"references-count":20,"URL":"https:\/\/doi.org\/10.1109\/trustcom50675.2020.00067","relation":{},"subject":[],"published":{"date-parts":[[2020,12]]}}}