<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>University of Isfahan &amp; Iranian Society of Cryptology</PublisherName>
				<JournalTitle>Journal of Computing and Security</JournalTitle>
				<Issn>2322-4460</Issn>
				<Volume>7</Volume>
				<Issue>1</Issue>
				<PubDate PubStatus="epublish">
					<Year>2020</Year>
					<Month>01</Month>
					<Day>01</Day>
				</PubDate>
			</Journal>
<ArticleTitle>A Risk Estimation Framework for Security Threats in Computer Networks</ArticleTitle>
<VernacularTitle></VernacularTitle>
			<FirstPage>19</FirstPage>
			<LastPage>33</LastPage>
			<ELocationID EIdType="pii">24611</ELocationID>
			
<ELocationID EIdType="doi">10.22108/jcs.2020.120412.1038</ELocationID>
			
			<Language>EN</Language>
<AuthorList>
<Author>
					<FirstName>Razieh</FirstName>
					<LastName>Rezaee</LastName>
<Affiliation>Data and Communication Security Lab., Computer Dept., Ferdowsi University of Mashhad, Iran.</Affiliation>

</Author>
<Author>
					<FirstName>Abbas</FirstName>
					<LastName>Ghaemi Bafghi</LastName>
<Affiliation>Data and Communication Security Lab., Computer Dept., Ferdowsi University of Mashhad, Iran.</Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2020</Year>
					<Month>01</Month>
					<Day>04</Day>
				</PubDate>
			</History>
		<Abstract>In security risk management of computer networks, some challenges are more serious in large networks. Specifying and estimating risks is largely dependent on the knowledge of security experts. In this paper, a framework for security risk estimation is proposed to address this issue. It represents the security knowledge required for security risk estimation and utilizes current security metrics and vulnerability databases. This framework is a major step towards automating the process of security risk estimation so that a network administrator can estimate the risk of the network with less expertise and effort. As a case study, the proposed framework is applied to a sample network to show its applicability and usability in operational environments. The comparison of results with two existing methods showed the validity of the estimations given by the proposed framework.</Abstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">Security Threat</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">analysis model</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Computer Networks</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Risk Estimation</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">attack graph</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Bayesian network</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://jcomsec.ui.ac.ir/article_24611_ab7b840ce97ed1c990bfa82dcf61c6ab.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
