Dynamic Risk Assessment by Bayesian Attack Graphs and Process Mining

πŸ“… 2026-04-20
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF

career value

203K/year
πŸ€– AI Summary
Traditional attack graphs struggle to dynamically assess the likelihood of known vulnerabilities being exploited and the risk of compromise at critical nodes. This work proposes a novel approach that integrates Bayesian attack graphs with process mining to enable real-time monitoring of network behavior for malicious traffic detection and dynamic updating of conditional probabilities associated with vulnerability exploitation. By incorporating process mining into the Bayesian attack graph framework for the first time, the method overcomes the limitations of static analysis. Evaluated in a test environment containing multiple CVE-listed vulnerabilities, the approach effectively identifies exploitation activities and significantly improves both the accuracy and timeliness of estimating the probability of system compromise.

Technology Category

Application Category

πŸ“ Abstract
While attack graphs are useful for identifying major cybersecurity threats affecting a system, they do not provide operational support for determining the likelihood of having a known vulnerability exploited, or that critical system nodes are likely to be compromised. In this paper, we perform dynamic risk assessment by combining Bayesian Attack Graphs (BAGs) and online monitoring of system behavior through process mining. Specifically, the proposed approach applies process mining techniques to characterize malicious network traffic and derive evidence regarding the probability of having a vulnerability actively exploited. This evidence is then provided to a BAG, which updates its conditional probability tables accordingly, enabling dynamic assessment of vulnerability exploitation. We apply our method to a cybersecurity testbed instantiating several machines deployed on different subnets and affected by several CVE vulnerabilities. The testbed is stimulated with both benign traffic and malicious behavior, which simulates network attack patterns aimed at exploiting the CVE vulnerabilities. The results indicate that our proposal effectively detects whether vulnerabilities are being actively exploited, allowing for an updated assessment of the probability of system compromise.
Problem

Research questions and friction points this paper is trying to address.

Dynamic Risk Assessment
Bayesian Attack Graphs
Process Mining
Vulnerability Exploitation
Cybersecurity
Innovation

Methods, ideas, or system contributions that make the work stand out.

Bayesian Attack Graphs
Process Mining
Dynamic Risk Assessment
Vulnerability Exploitation
Cybersecurity Monitoring
πŸ”Ž Similar Papers
No similar papers found.