{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,5]],"date-time":"2025-05-05T07:25:04Z","timestamp":1746429904641,"version":"3.40.4"},"reference-count":55,"publisher":"Wiley","issue":"4","license":[{"start":{"date-parts":[[2013,4,26]],"date-time":"2013-04-26T00:00:00Z","timestamp":1366934400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/doi.wiley.com\/10.1002\/tdm_license_1.1"},{"start":{"date-parts":[[2013,4,26]],"date-time":"2013-04-26T00:00:00Z","timestamp":1366934400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/onlinelibrary.wiley.com\/termsAndConditions#vor"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Security Comm. Networks"],"published-print":{"date-parts":[[2014,4]]},"DOI":"10.1002\/sec.774","type":"journal-article","created":{"date-parts":[[2013,4,26]],"date-time":"2013-04-26T07:39:03Z","timestamp":1366961943000},"page":"714-737","source":"Crossref","is-referenced-by-count":9,"title":["Attack modelling and security evaluation based on stochastic activity networks"],"prefix":"10.1002","volume":"7","author":[{"given":"Ali","family":"Sedaghatbaf","sequence":"first","affiliation":[{"name":"School of Computer Engineering; Iran University of Science and Technology; Tehran Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammad","family":"Abdollahi Azgomi","sequence":"additional","affiliation":[{"name":"School of Computer Engineering; Iran University of Science and Technology; Tehran Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","published-online":{"date-parts":[[2013,4,26]]},"reference":[{"issue":"4","key":"10.1002\/sec.774-BIB0001|sec774-cit-0001","doi-asserted-by":"crossref","first-page":"297","DOI":"10.3233\/HSN-2004-250","article-title":"Security modelling and quantification of intrusion tolerant systems using attack-response graph","volume":"13","author":"Madan","year":"2004","journal-title":"Journal of High-Speed Networks"},{"issue":"1","key":"10.1002\/sec.774-BIB0002|sec774-cit-0002","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/TDSC.2004.11","article-title":"Model-based evaluation: from dependability to security","volume":"1","author":"Nicol","year":"2004","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"issue":"1","key":"10.1002\/sec.774-BIB0003|sec774-cit-0003","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1109\/MSP.2006.27","article-title":"The simple economics of cybercrimes","volume":"4","author":"Kshetri","year":"2006","journal-title":"IEEE Security and Privacy"},{"key":"10.1002\/sec.774-BIB0004|sec774-cit-0004","doi-asserted-by":"crossref","unstructured":"Niitsoo M Optimal adversary behaviour for the serial model of financial attack trees Proceedings of International Workshop on Security 2010","DOI":"10.1007\/978-3-642-16825-3_24"},{"issue":"7","key":"10.1002\/sec.774-BIB0005|sec774-cit-0005","doi-asserted-by":"crossref","first-page":"7","DOI":"10.1016\/S1353-4858(00)80012-4","article-title":"Managing network security: attack and defense strategies","volume":"1999","author":"Cohen","year":"1999","journal-title":"Network Security"},{"issue":"1","key":"10.1002\/sec.774-BIB0006|sec774-cit-0006","doi-asserted-by":"crossref","first-page":"78","DOI":"10.1145\/1053283.1053288","article-title":"Incentive-based modelling and inference of attacker intent, objectives, and strategies","volume":"8","author":"Liu","year":"2005","journal-title":"ACM Transactions on Information and System Security"},{"key":"10.1002\/sec.774-BIB0007|sec774-cit-0007","doi-asserted-by":"crossref","unstructured":"Xie P Li JH Ou X Liuu P Levy R Using Bayesian networks for cyber security analysis Proceedings of the 2010 IEEE\/IFIP Conference on Dependable Systems and Networks (DSN) 2010 211 220","DOI":"10.1109\/DSN.2010.5544924"},{"key":"10.1002\/sec.774-BIB0008|sec774-cit-0008","unstructured":"Amenaza TL Fundamentals of capabilities-based attack tree analysis 2005"},{"key":"10.1002\/sec.774-BIB0009|sec774-cit-0009","doi-asserted-by":"crossref","unstructured":"Pi\u00e8tre-Cambac\u00e9d\u00e8s L Bouissou M Beyond attack trees: dynamic security modelling with Boolean logic driven Markov process Proceedings of the 2010 European Dependable Computing Conference (EDCC'10) 2010 199 208","DOI":"10.1109\/EDCC.2010.32"},{"key":"10.1002\/sec.774-BIB0010|sec774-cit-0010","unstructured":"Abdollahi Azgomi M High-level extensions for stochastic activity networks: theories, tools and applications 2005"},{"key":"10.1002\/sec.774-BIB0011|sec774-cit-0011","unstructured":"Aabdollahi Azgomi M Movaghar A Coloured stochastic activity networks: definitions and behaviour Proceedings of the 20th Annual UK Performance Engineering Workshop 2004 297 308"},{"key":"10.1002\/sec.774-BIB0012|sec774-cit-0012","doi-asserted-by":"crossref","unstructured":"Sanders WH Meyer JF Stochastic activity networks: formal definitions and concepts Lectures on Formal Methods and Performance Analysis 2001 315 343","DOI":"10.1007\/3-540-44667-2_9"},{"key":"10.1002\/sec.774-BIB0013|sec774-cit-0013","unstructured":"Movaghar A Meyer JF Performability modelling with stochastic activity networks Proceedings of the 1984 Real-time Systems Symposium 1984 215 224"},{"issue":"4","key":"10.1002\/sec.774-BIB0014|sec774-cit-0014","first-page":"303","article-title":"Stochastic activity networks: a new definition and some properties","volume":"8","author":"Movaghar","year":"2001","journal-title":"Scientia Iranica"},{"key":"10.1002\/sec.774-BIB0015|sec774-cit-0015","doi-asserted-by":"crossref","unstructured":"Buldas A Laud P Priisalu J Saarepera M Willemson J Rational choice of security measures via multi-parameter attack trees Proceedings of the First International Workshop on Critical Information Infrastructures Security (CRITIS'06) 2006 235 248","DOI":"10.1007\/11962977_19"},{"key":"10.1002\/sec.774-BIB0016|sec774-cit-0016","doi-asserted-by":"crossref","unstructured":"Phillips C Swiler LP A graph-based system for network-vulnerability analysis Proceedings of the 1998 Workshop on New Security Paradigms (NSPW'98) 1998 71 79","DOI":"10.1145\/310889.310919"},{"key":"10.1002\/sec.774-BIB0017|sec774-cit-0017","doi-asserted-by":"crossref","unstructured":"Lippmann RIK An annotated review of past papers on attack graphs 2005","DOI":"10.21236\/ADA431826"},{"issue":"5","key":"10.1002\/sec.774-BIB0018|sec774-cit-0018","doi-asserted-by":"crossref","first-page":"633","DOI":"10.1109\/32.815323","article-title":"Experimenting with quantitative evaluation tools for monitoring operational security","volume":"25","author":"Ortalo","year":"1999","journal-title":"IEEE Transactions on Software Engineering"},{"key":"10.1002\/sec.774-BIB0019|sec774-cit-0019","doi-asserted-by":"crossref","unstructured":"Dacier M Deswarte Y Ka\u00e2niche M Quantitative assessment of operational security: models and tools 1996","DOI":"10.1007\/978-1-5041-2919-0_15"},{"issue":"8","key":"10.1002\/sec.774-BIB0020|sec774-cit-0020","doi-asserted-by":"crossref","first-page":"754","DOI":"10.1016\/j.cose.2009.05.007","article-title":"PENET: a practical method and tool for integrated modelling of security attacks and countermeasures","volume":"28","author":"Pudar","year":"2009","journal-title":"Computers and Security"},{"key":"10.1002\/sec.774-BIB0021|sec774-cit-0021","doi-asserted-by":"crossref","unstructured":"Chinchani R Iyer A Ngo HQ Upadhyaya S Towards a theory of insider threat assessment Proceedings of the 2005 International Conference on Dependable Systems and Networks (DSN'05) 2005 108 117","DOI":"10.1109\/DSN.2005.94"},{"key":"10.1002\/sec.774-BIB0022|sec774-cit-0022","doi-asserted-by":"crossref","unstructured":"Kiviharju M Ven\u00e4l\u00e4inen T Kinnunen S Towards modelling information security with key-challenge Petri nets Proceedings of the 14th Nordic Conference on Secure IT Systems: Identity and Privacy in the Internet Age (NordSec '09) 2009 190 206","DOI":"10.1007\/978-3-642-04766-4_14"},{"key":"10.1002\/sec.774-BIB0023|sec774-cit-0023","doi-asserted-by":"crossref","unstructured":"McQueen MA Boyer WF Flym MA Beitel GA Quantitative cyber risk reduction estimation methodology for a small SCADA control system Proceedings of the 39th Hawaii International Conference on System Sciences (HICSS '06) 2006 226 236","DOI":"10.1109\/HICSS.2006.405"},{"key":"10.1002\/sec.774-BIB0024|sec774-cit-0024","doi-asserted-by":"crossref","unstructured":"Templeton SJ Levitt K A requires\/provides model for computer attacks Proceedings of the 2000 Workshop on New Security Paradigms (NSPW'00) 2000 31 38","DOI":"10.1145\/366173.366187"},{"key":"10.1002\/sec.774-BIB0025|sec774-cit-0025","doi-asserted-by":"crossref","unstructured":"Song S Lu Y Cheng W Yuan H Capability-centric attack model for network security analysis Proceedings of 2nd International Conference on Signal Processing Systems (ICSPS'10) 2010 372 376","DOI":"10.1109\/ICSPS.2010.5555265"},{"key":"10.1002\/sec.774-BIB0026|sec774-cit-0026","doi-asserted-by":"crossref","unstructured":"McDermot JP Attack net penetration testing Proceedings of the 2000 Workshop on New Security Paradigms (NSPW'00) 2000 15 21","DOI":"10.1145\/366173.366183"},{"key":"10.1002\/sec.774-BIB0027|sec774-cit-0027","doi-asserted-by":"crossref","unstructured":"Dahl OM Wolthusen SD Modelling and execution of complex attack scenarios using interval timed coloured Petri nets Proceedings of the Fourth IEEE International Workshop on Information Assurance (IWIA '06) 2006 157 168","DOI":"10.1109\/IWIA.2006.17"},{"key":"10.1002\/sec.774-BIB0028|sec774-cit-0028","doi-asserted-by":"crossref","first-page":"247","DOI":"10.1007\/0-387-24230-9_9","volume-title":"Managing Cyber Threats: Issues, Approaches and Challenges","author":"Jajodia","year":"2005"},{"key":"10.1002\/sec.774-BIB0029|sec774-cit-0029","doi-asserted-by":"crossref","unstructured":"Frigault M Wang L Measuring network security using Bayesian network-based attack graphs Proceedings of the Computer Software and Applications Conference (COMPSAC'08) 2008 698 803","DOI":"10.1109\/COMPSAC.2008.88"},{"issue":"2","key":"10.1002\/sec.774-BIB0030|sec774-cit-0030","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1016\/S0951-8320(03)00143-1","article-title":"A new formalism that combines advantages of fault-trees and Markov models: Boolean logic driven Markov processes","volume":"82","author":"Bouissou","year":"2003","journal-title":"Reliability Engineering and System Safety"},{"key":"10.1002\/sec.774-BIB0031|sec774-cit-0031","doi-asserted-by":"crossref","unstructured":"Wang D Madan BB Trivedi KS Security analysis of SITAR intrusion tolerance system Proceedings of the ACM Workshop on Survivable and Self-regenerative Systems 2003 23 32","DOI":"10.1145\/1036921.1036924"},{"key":"10.1002\/sec.774-BIB0032|sec774-cit-0032","doi-asserted-by":"crossref","first-page":"167","DOI":"10.1016\/j.peva.2003.07.008","article-title":"A method for modelling and quantifying the security attributes of intrusion tolerant systems","volume":"56","author":"Madan","year":"2004","journal-title":"Performance Evaluation"},{"key":"10.1002\/sec.774-BIB0033|sec774-cit-0033","doi-asserted-by":"crossref","unstructured":"Willemson J J\u00fcrgenson A Serial model for attack tree computations Proceedings of the International Conference on Information Security and Cryptology (ICISC'09) 2009 118 128","DOI":"10.1007\/978-3-642-14423-3_9"},{"key":"10.1002\/sec.774-BIB0034|sec774-cit-0034","doi-asserted-by":"crossref","unstructured":"J\u00fcrgenson A Willemson J Processing multi-parameter attack trees with estimated parameter values Proceedings of the 2nd International Workshop on Security (IWSEC'07) 2007","DOI":"10.1007\/978-3-540-75651-4_21"},{"key":"10.1002\/sec.774-BIB0035|sec774-cit-0035","doi-asserted-by":"crossref","unstructured":"Sallhammar K Knapskog SJ Helvik BE Using stochastic game theory to compute the expected behaviour of attackers Proceedings of the 2005 International Symposium on Applications and the Internet Workshop (SAINT'05) 2005 102 105","DOI":"10.1109\/SAINTW.2005.1619988"},{"key":"10.1002\/sec.774-BIB0036|sec774-cit-0036","unstructured":"Sallhammar K Helvik BE Knapskog SJ Incorporating attacker behaviour in stochastic models of security Proceedings of the 2005 International Conference on Security and Management (SAM'05) 2005 79 85"},{"key":"10.1002\/sec.774-BIB0037|sec774-cit-0037","doi-asserted-by":"crossref","unstructured":"Zhang Z Naiit-Abdesselam F Ho PH Boosting Markov reward models for probabilistic security evaluation by characterizing behaviours of attacker and defender Proceedings of the 3rd International Conference on Availability, Reliability and Security (ARES'08) 2008 352 359","DOI":"10.1109\/ARES.2008.75"},{"key":"10.1002\/sec.774-BIB0038|sec774-cit-0038","doi-asserted-by":"crossref","unstructured":"Zhang Z Na\u00eft-Abdesselam F Ho PH A model-based semi-quantitative approach for evaluating security of enterprise networks Proceedings of the 2008 ACM Symposium on Applied Computing (SAC'08) 2008 1069 1074","DOI":"10.1145\/1363686.1363934"},{"key":"10.1002\/sec.774-BIB0039|sec774-cit-0039","doi-asserted-by":"crossref","unstructured":"Goldman RP A stochastic model for intrusions Proceedings of the 5th International Conference on Recent Advances in Intrusion Detection (RAID'02) 2002 199 218","DOI":"10.1007\/3-540-36084-0_11"},{"issue":"12","key":"10.1002\/sec.774-BIB0040|sec774-cit-0040","first-page":"21","article-title":"Attack trees: modelling security threats","volume":"24","author":"Schneier","year":"1999","journal-title":"Dr. Dobb's Journal"},{"key":"10.1002\/sec.774-BIB0041|sec774-cit-0041","doi-asserted-by":"crossref","unstructured":"Dalton GC Colombi JM Analysing attack trees using generalized stochastic Petri nets Proceedings of the IEEE Workshop on Information Assurance 2006 116 123","DOI":"10.1109\/IAW.2006.1652085"},{"key":"10.1002\/sec.774-BIB0042|sec774-cit-0042","doi-asserted-by":"crossref","unstructured":"J\u00fcrgenson A Willemson J Computing exact outcomes of multi-parameter attack trees Proceedings of OTM 2008 Confederated International Conferences (ODBASE'08) 2008 1036 1051","DOI":"10.1007\/978-3-540-88873-4_8"},{"key":"10.1002\/sec.774-BIB0043|sec774-cit-0043","unstructured":"Malhis LM Development and application of an efficient method for the solution of stochastic activity networks with deterministic activities 1996"},{"volume-title":"Stochastic Processes","year":"1994","author":"Medhi","key":"10.1002\/sec.774-BIB0044|sec774-cit-0044"},{"key":"10.1002\/sec.774-BIB0045|sec774-cit-0045","volume-title":"Elements of stochastic processes","author":"Bhat","year":"1984","edition":"2"},{"key":"10.1002\/sec.774-BIB0046|sec774-cit-0046","volume-title":"Probability and Statistics with Reliability, Queuing, and Computer Science Applications","author":"Trivedi","year":"2001","edition":"2"},{"volume-title":"Lecture Notes on Stochastic Models in Operations Research","year":"1990","author":"Kulkarni","key":"10.1002\/sec.774-BIB0047|sec774-cit-0047"},{"key":"10.1002\/sec.774-BIB0048|sec774-cit-0048","doi-asserted-by":"crossref","unstructured":"Verendel V Quantified security is a weak hypothesis Proceedings of the 2009 New Security Paradigms Workshop 2009 37 50","DOI":"10.1145\/1719030.1719036"},{"key":"10.1002\/sec.774-BIB0049|sec774-cit-0049","doi-asserted-by":"crossref","unstructured":"Madan BB Gogeva-Popstojanova K Vaidyanathan K Trivedi KS Modelling and quantification of security attributes of software systems Proceedings of the International Conference on Dependable Systems and Networks (DSN'02) 2002 505 514","DOI":"10.1109\/DSN.2002.1028941"},{"issue":"6","key":"10.1002\/sec.774-BIB0050|sec774-cit-0050","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1109\/MSP.2004.109","article-title":"Risk-based systems security engineering: stopping attacks with intention","volume":"2","author":"Evans","year":"2004","journal-title":"IEEE Security and Privacy"},{"key":"10.1002\/sec.774-BIB0051|sec774-cit-0051","unstructured":"Buldas A M\u00e4gi T Practical security analysis of e-voting systems Proceedings of the 2nd International Conference on Advances in Information and Computer Security 2007"},{"key":"10.1002\/sec.774-BIB0052|sec774-cit-0052","unstructured":"E-voting system: overview 2005 https:\/\/2.zoppoz.workers.dev:443\/http\/www.vvk.ee\/elektr\/docs\/Yldkirjeldus-eng.pdf"},{"key":"10.1002\/sec.774-BIB0053|sec774-cit-0053","unstructured":"Jefferson D Rubin AD Simons B Wagner D A security analysis of the Secure Electronic Registration and Voting Experiment (SERVE) 2004"},{"key":"10.1002\/sec.774-BIB0054|sec774-cit-0054","unstructured":"HCSAM Tool Web Page https:\/\/2.zoppoz.workers.dev:443\/http\/pdel.iust.ac.ir\/projects\/hcsamtool.html"},{"key":"10.1002\/sec.774-BIB0055|sec774-cit-0055","doi-asserted-by":"crossref","unstructured":"Braynov S Jadliwala M Representation and analysis of coordinated attacks Proceedings of the 2003 ACM Workshop on Formal Methods in Security Engineering 2003 43 51","DOI":"10.1145\/1035429.1035434"}],"container-title":["Security and Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fsec.774","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.wiley.com\/onlinelibrary\/tdm\/v1\/articles\/10.1002%2Fsec.774","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/onlinelibrary.wiley.com\/wol1\/doi\/10.1002\/sec.774\/fullpdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,30]],"date-time":"2025-04-30T06:38:59Z","timestamp":1745995139000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/onlinelibrary.wiley.com\/doi\/10.1002\/sec.774"}},"subtitle":["Attack modelling and security evaluation based on SANs"],"short-title":[],"issued":{"date-parts":[[2013,4,26]]},"references-count":55,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2014,4]]}},"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1002\/sec.774","archive":["Portico"],"relation":{},"ISSN":["1939-0114"],"issn-type":[{"type":"print","value":"1939-0114"}],"subject":[],"published":{"date-parts":[[2013,4,26]]}}}