Houjun Liu

Ruth 2025

(Ruth et al., n.d.)

One-Liner

Governments’ security guidance lack overall consensus in both formatting as well as actual practice; we find this out using treeeeees.

Novelty

  • new tree similarity mechanism similar to edit distance
  • first hand-labeled ontological dataset for security guidance

Notable Methods

  1. download security guidance
  2. label guidance into multi-level controls
  3. tree distance metric for similarity
Ruth, Kimberly, Raymond Buernor Obu, Ifeoluwa Shode, Gavin Li, Carrie Gates, Grant Ho, and Zakir Durumeric. n.d. “A First Look at Governments’ Enterprise Security Guidance.” In USENIX Security Symposium.