{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,20]],"date-time":"2026-08-20T18:01:14Z","timestamp":1787248874735,"version":"build-2736575974"},"reference-count":43,"publisher":"Elsevier BV","issue":"10","content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Networks"],"published-print":{"date-parts":[[2013,7]]},"DOI":"10.1016\/j.comnet.2013.03.011","type":"journal-article","created":{"date-parts":[[2013,4,9]],"date-time":"2013-04-09T03:30:46Z","timestamp":1365478246000},"page":"2159-2180","update-policy":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":34,"title":["A stochastic model of attack process for the evaluation of security metrics"],"prefix":"10.1016","volume":"57","author":[{"given":"Jaafar","family":"Almasizadeh","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohammad Abdollahi","family":"Azgomi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"1","key":"10.1016\/j.comnet.2013.03.011_b0005","doi-asserted-by":"crossref","first-page":"48","DOI":"10.1109\/TDSC.2004.11","article-title":"Model-based evaluation: from dependability to security","volume":"1","author":"Nicol","year":"2004","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"issue":"1-4","key":"10.1016\/j.comnet.2013.03.011_b0010","doi-asserted-by":"crossref","first-page":"167","DOI":"10.1016\/j.peva.2003.07.008","article-title":"A method for modeling and quantifying the security attributes of intrusion tolerant systems","volume":"56","author":"Madan","year":"2004","journal-title":"Performance Evaluation Journal"},{"key":"10.1016\/j.comnet.2013.03.011_b0015","doi-asserted-by":"crossref","unstructured":"D.J. Leversage, E. James, Estimating a System\u2019s Mean Time-to-Compromise, Security & Privacy, IEEE March 16\u201319, IEEE CS Press, 2008, pp. 52\u201360.","DOI":"10.1109\/MSP.2008.9"},{"key":"10.1016\/j.comnet.2013.03.011_b0020","doi-asserted-by":"crossref","unstructured":"E. LeMay, M.D. Ford, K. Keefe, W.H. Sanders, C. Muehrcke, Model-based security metrics using ADversary View security evaluation (ADVISE), in: Proceedings of the 8th International Conference on Quantitative Evaluation of SysTems (QEST 2011), Aachen, Germany, September 5\u20138, 2011.","DOI":"10.1109\/QEST.2011.34"},{"key":"10.1016\/j.comnet.2013.03.011_b0025","series-title":"Cryptography and Network Security: Principles and Practice","author":"Stallings","year":"2011"},{"key":"10.1016\/j.comnet.2013.03.011_b0030","doi-asserted-by":"crossref","unstructured":"D. Wang, B. Madan, K.S. Trivedi, Security analysis of SITAR intrusion-tolerant system, in: Proc. ACM Workshop on Survivable and Self-Regenerative Systems, 2003, pp. 23\u201332.","DOI":"10.1145\/1036921.1036924"},{"issue":"5","key":"10.1016\/j.comnet.2013.03.011_b0035","doi-asserted-by":"crossref","DOI":"10.4304\/jnw.1.5.31-42","article-title":"On stochastic modeling for integrated security and dependability evaluation","volume":"1","author":"Sallhammar","year":"2006","journal-title":"Journal of Networks"},{"key":"10.1016\/j.comnet.2013.03.011_b0040","doi-asserted-by":"crossref","unstructured":"F. Stevens, T. Courtney, S. Singh, A. Agbaria, J.F. Meyer, W.H. Sanders, P. Pal, Model-based validation of an intrusion-tolerant information system, in: Proceedings of the 23rd Symposium on Reliable Distributed Systems (SRDS 2004), Florianpolis, Brazil, October 2004.","DOI":"10.1109\/RELDIS.2004.1353019"},{"key":"10.1016\/j.comnet.2013.03.011_b0045","series-title":"First Workshop on Quality of Protection","article-title":"Time-to-compromise model for cyber risk reduction estimation","author":"McQueen","year":"2005"},{"key":"10.1016\/j.comnet.2013.03.011_b0050","doi-asserted-by":"crossref","first-page":"211","DOI":"10.3233\/JCS-1993-22-308","article-title":"Towards operational measures of computer security","volume":"2","author":"Littlewood","year":"1993","journal-title":"Journal of Computer Security"},{"issue":"4","key":"10.1016\/j.comnet.2013.03.011_b0055","doi-asserted-by":"crossref","first-page":"235","DOI":"10.1109\/32.588541","article-title":"A quantitative model of the security intrusion process based on attacker behavior","volume":"23","author":"Jonsson","year":"1997","journal-title":"IEEE Transactions on Software Engineering"},{"issue":"5","key":"10.1016\/j.comnet.2013.03.011_b0060","doi-asserted-by":"crossref","first-page":"635","DOI":"10.1109\/32.815323","article-title":"Experiments with quantitative evaluation tools for monitoring operational security","volume":"25","author":"Ortalo","year":"1999","journal-title":"IEEE Transactions on Software Engineering"},{"key":"10.1016\/j.comnet.2013.03.011_b0065","unstructured":"S. Singh, M. Cukier, W. Sanders, Probabilistic validation of an intrusion-tolerant replication system, in: Int\u2019l Conf. on Dependable Systems and Networks (DSN\u201803), 2001."},{"key":"10.1016\/j.comnet.2013.03.011_b0070","doi-asserted-by":"crossref","unstructured":"K. Goseva-Popstojanova, F. Wang, R. Wang, F. Gong, K. Vaidyanathan, K.S. Trivedi, B. Muthusamy, Characterizing intrusion tolerant systems using a state transition model, in: DARPA Information Survivability Conference and Exposition (DISCEX II), vol. 2, 2001, pp. 211\u2013221.","DOI":"10.1109\/DISCEX.2001.932173"},{"key":"10.1016\/j.comnet.2013.03.011_b0075","unstructured":"M. Ka\u00e2niche, E. Alata, V. Nicomette, Y. Deswarte, M. Dacier, Empirical analysis and statistical modelling of attack processes based on honeypots, in: Proc. of WEEDS 2006-Workshop on Empirical Evaluation of Dependability and Security, Philadelphia (USA), June 25\u201328, 2006."},{"key":"10.1016\/j.comnet.2013.03.011_b0080","doi-asserted-by":"crossref","unstructured":"N. Paulauskas, E. Garsva, Attacker skill level distribution estimation in the system mean time-to-compromise, in: Proceedings of 1st International Conference on Information Technology, Gdanks, 19\u201321 May, 2008, 463\u2013466. ISBN 978-1-4244-2244-9.","DOI":"10.1109\/INFTECH.2008.4621683"},{"issue":"3","key":"10.1016\/j.comnet.2013.03.011_b0085","doi-asserted-by":"crossref","first-page":"288","DOI":"10.1080\/15427951.2012.654480","article-title":"A extended stochastic model for quantitative security analyses of networked systems","volume":"8","author":"Xu","year":"2012","journal-title":"Internet Mathematics"},{"key":"10.1016\/j.comnet.2013.03.011_b0090","doi-asserted-by":"crossref","first-page":"450","DOI":"10.1016\/j.cose.2009.01.002","article-title":"Probabilistic model checking for the quantification of DoS security threats","volume":"28","author":"Basagiannis","year":"2009","journal-title":"Computers & Security"},{"key":"10.1016\/j.comnet.2013.03.011_b0095","series-title":"Proc. of the 2nd International Workshop on Security Issues with Petri Nets and other Computational Models (WISP\u201904)","first-page":"65","article-title":"A quantitative study of two attacks","volume":"vol. 121","author":"Bodei","year":"2005"},{"key":"10.1016\/j.comnet.2013.03.011_b0100","series-title":"INFOCOM 2008","first-page":"1957","article-title":"A novel quantitative approach for measuring network security","author":"Ahmed","year":"2008"},{"key":"10.1016\/j.comnet.2013.03.011_b0105","unstructured":"I. Cervesato, Towards a notion of quantitative security analysis, in: Proc. 1st Workshop on Quality of Protection, pages 12\u201326, 2005."},{"key":"10.1016\/j.comnet.2013.03.011_b0110","doi-asserted-by":"crossref","unstructured":"A. Hecker, M. Riguidel, On the operational security assurance evaluation of networked IT systems, NEW2AN, September 2009, St Petersburg, Russia.","DOI":"10.1007\/978-3-642-04190-7_24"},{"issue":"4","key":"10.1016\/j.comnet.2013.03.011_b0115","article-title":"Security metrics for e-healthcare information systems: a domain specific metrics approach","volume":"1","author":"Jafari","year":"2010","journal-title":"International Journal of Digital Society (IJDS)"},{"key":"10.1016\/j.comnet.2013.03.011_b0120","first-page":"3","article-title":"Ideal based cyber security technical metrics for control systems","volume":"7","author":"Boyer","year":"2007","journal-title":"CRITIS"},{"key":"10.1016\/j.comnet.2013.03.011_b0125","doi-asserted-by":"crossref","unstructured":"R. Lippmann, J. Riordan, T. Yu, K. Watson, Continuous Security Metrics for Prevalent Network Threats: Introduction and First Four Metrics, Project Report IA-3, MIT Lincoln Laboratory, Lexington, MA, 22 May 2012.","DOI":"10.21236\/ADA565825"},{"key":"10.1016\/j.comnet.2013.03.011_b0130","series-title":"Proc. 22nd Annual IFIP WG 11.3 Working Conference on Data and Applications Security (DBSEC 2008)","first-page":"283","article-title":"An attack graph-based probabilistic security metric","volume":"vol. 5094","author":"Wang","year":"2008"},{"key":"10.1016\/j.comnet.2013.03.011_b0135","article-title":"A method for estimation of the success probability of an intrusion process by considering the temporal aspects of the attacker behavior","volume":"vol. 4","author":"Almasizadeh","year":"2009"},{"key":"10.1016\/j.comnet.2013.03.011_b0140","doi-asserted-by":"crossref","unstructured":"J. Almasizadeh, M. Abdollahi Azgomi, Intrusion process modeling for security quantification, in: Proc. of the 4th International Conference on Availability, Reliability and Security (ARES\u201909), March 16\u201319, Fukuoka Institute of Technology (FIT), Fukuoka, Japan, IEEE CS Press, 2009, pp. 114\u2013121.","DOI":"10.1109\/ARES.2009.142"},{"key":"10.1016\/j.comnet.2013.03.011_b0145","series-title":"The Hackers Handbook: The Strategy Behind Breaking into and Defending Networks","author":"Young","year":"2004"},{"key":"10.1016\/j.comnet.2013.03.011_b0150","series-title":"Probability and Statistics with Reliability, Queuing, and Computer Science Applications","author":"Trivedi","year":"2001"},{"issue":"2","key":"10.1016\/j.comnet.2013.03.011_b0155","doi-asserted-by":"crossref","first-page":"193","DOI":"10.1109\/TR.2002.1011525","article-title":"System availability with non-exponentially distributed outages","volume":"51","author":"Cao","year":"2002","journal-title":"IEEE Transactions on Reliability"},{"key":"10.1016\/j.comnet.2013.03.011_b0160","doi-asserted-by":"crossref","unstructured":"S. Malhotra, S. Bhattacharya, S.K. Ghosh, A vulnerability and exploit independent approach for attack path prediction, in: Proc. of the 2008 IEEE 8th International Conference on Computer and Information Technology Workshops, July 08\u201311, 2008.","DOI":"10.1109\/CIT.2008.Workshops.73"},{"key":"10.1016\/j.comnet.2013.03.011_b0165","doi-asserted-by":"crossref","unstructured":"E. Jonsson, Towards an integrated conceptual model of security and dependability, in: Proc. of the First Int\u2019l. Conf.on Availability, Reliability and Security (AReS), 2006.","DOI":"10.1109\/ARES.2006.138"},{"key":"10.1016\/j.comnet.2013.03.011_b0170","doi-asserted-by":"crossref","unstructured":"Y. Chen, B. Boehm, L. Sheppard, Value driven security threat modeling based on attack path analysis, in: 40th Hawaii International Conference on Systems Sciences, Big Island, Hawaii, January 2007.","DOI":"10.1109\/HICSS.2007.601"},{"key":"10.1016\/j.comnet.2013.03.011_b0175","doi-asserted-by":"crossref","unstructured":"P. Liu, W. Zang, Incentive-based modeling and inference of attacker intent, objectives, and strategies, in: Proceedings of the 10th ACM Conference on Computer and Communication Security, 2003, pp. 179\u2013189.","DOI":"10.1145\/948109.948135"},{"key":"10.1016\/j.comnet.2013.03.011_b0180","unstructured":"X. Qin, W. Lee, Attack plan recognition and prediction using causal networks, in: Proc. of the 20th Annual Conference on Computer Security Applications, 2004, pp. 370\u2013379."},{"key":"10.1016\/j.comnet.2013.03.011_b0185","doi-asserted-by":"crossref","unstructured":"O. Sheyner, J. Wing, Tools for generating and analyzing attack graphs, In Proceedings of International Symposium on Formal Methods for Components and Objects, Lecture Notes in Computer Science 3188, 2004, pp. 344\u2013371.","DOI":"10.1007\/978-3-540-30101-1_17"},{"key":"10.1016\/j.comnet.2013.03.011_b0190","doi-asserted-by":"crossref","unstructured":"J. Steven, K.L. Templeton, A requires\/provides model for computer attacks, in: Proc. of the 2000 Workshop on New Security Paradigms, Ballycotton, County Cork, Ireland, 2001, pp. 31\u201338.","DOI":"10.1145\/366173.366187"},{"key":"10.1016\/j.comnet.2013.03.011_b0195","doi-asserted-by":"crossref","unstructured":"P. Maggi, D. Pozza, R. Sisto, Vulnerability modelling for the analysis of network attacks, Third International Conference on Dependability of Computer Systems DepCoS-RELCOMEX 2008.","DOI":"10.1109\/DepCoS-RELCOMEX.2008.49"},{"key":"10.1016\/j.comnet.2013.03.011_b0200","doi-asserted-by":"crossref","unstructured":"I. Kotenko, M. Stepashkin, Attack graph based evaluation of network security, CMS 2006, LNCS 4237, 2006, pp. 216\u2013227.","DOI":"10.1007\/11909033_20"},{"key":"10.1016\/j.comnet.2013.03.011_b0205","unstructured":"R.P. Lippmann, K.W. Ingols, C. Scott, K. Piwowarski, K.J. Kratkiewicz, M. Artz, R.K. Cunningham, Evaluating and strengthening enterprise network security using attack graphs, Technical report, MIT Lincoln Laboratory, Lexington, MA, 2005. ESC-TR-2005-064."},{"key":"10.1016\/j.comnet.2013.03.011_b0210","doi-asserted-by":"crossref","unstructured":"P. Manadhata, J.M. Wing, An attack surface metric, Technical report, CMU-CS-05-155, School of Computer Science, Carnegie Mellon University, July 2005.","DOI":"10.21236\/ADA457096"},{"key":"10.1016\/j.comnet.2013.03.011_b0215","doi-asserted-by":"crossref","first-page":"3691","DOI":"10.1016\/j.comcom.2008.07.001","article-title":"Risk assessment in practice: a real case study","volume":"31","author":"Benini","year":"2008","journal-title":"Computer Communications"}],"container-title":["Computer Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.elsevier.com\/content\/article\/PII:S1389128613000856?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/api.elsevier.com\/content\/article\/PII:S1389128613000856?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,4,30]],"date-time":"2025-04-30T03:42:02Z","timestamp":1745984522000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/linkinghub.elsevier.com\/retrieve\/pii\/S1389128613000856"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,7]]},"references-count":43,"journal-issue":{"issue":"10","published-print":{"date-parts":[[2013,7]]}},"alternative-id":["S1389128613000856"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/j.comnet.2013.03.011","relation":{},"ISSN":["1389-1286"],"issn-type":[{"value":"1389-1286","type":"print"}],"subject":[],"published":{"date-parts":[[2013,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"A stochastic model of attack process for the evaluation of security metrics","name":"articletitle","label":"Article Title"},{"value":"Computer Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1016\/j.comnet.2013.03.011","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"Copyright \u00a9 2013 Elsevier B.V. All rights reserved.","name":"copyright","label":"Copyright"}]}}