Measuring likelihood in cybersecurity

📅 2025-04-21
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Current cybersecurity risk assessments lack objective, consistent, and quantifiable likelihood estimates due to scarce historical incident data, limited public threat intelligence, and heterogeneous data formats. Method: This paper proposes a novel network exposure profiling data model grounded in adversary Tactics, Techniques, and Procedures (TTPs), Indicators of Compromise (IOCs), and defensive controls. It establishes the first operationally oriented, dynamically updatable likelihood quantification framework—introducing a paradigm that integrates heterogeneous multi-source threat elements without reliance on historical attack records. Likelihood is estimated indirectly yet quantifiably via synergistic modeling of threat intelligence, exposure data, and control effectiveness. Contribution/Results: The framework yields a deployable set of risk metrics and an automated update mechanism, significantly enhancing the objectivity, consistency, and operational utility of likelihood assessment in cyber risk management.

Technology Category

Application Category

📝 Abstract
In cybersecurity risk is commonly measured by impact and probability, the former is objectively measured based on the consequences from the use of technology to obtain business gains, or by achieving business objectives. The latter has been measured, in sectors such as financial or insurance, based on historical data because there is vast information, and many other fields have applied the same approach. Although in cybersecurity, as a new discipline, there is not always historical data to support an objective measure of probability, the data available is not public and there is no consistent formatting to store and share it, so a new approach is required to measure cybersecurity events incidence. Through a comprehensive analysis of the state of the art, including current methodologies, frameworks, and incident data, considering tactics, techniques, and procedures (TTP) used by attackers, indicators of compromise (IOC), and defence controls, this work proposes a data model that describes a cyber exposure profile that provides an indirect but objective measure for likelihood, including different sources and metrics to update the model if needed. We further propose a set of practical, quantifiable metrics for risk assessment, enabling cybersecurity practitioners to measure likelihood without relying solely on historical incident data. By combining these metrics with our data model, organizations gain an actionable framework for continuously refining their cybersecurity strategies.
Problem

Research questions and friction points this paper is trying to address.

Measuring cybersecurity likelihood without historical data
Developing objective metrics for risk assessment
Creating a data model for cyber exposure profiles
Innovation

Methods, ideas, or system contributions that make the work stand out.

Proposes a cyber exposure profile data model
Uses TTP, IOC, and defense controls
Provides quantifiable metrics for risk assessment
💼 Related Jobs
No related jobs found.
P
Pablo Corona-Fraga
INFOTEC Center for Research and Innovation in Information and Communication Technologies, México
V
Vanessa Diaz-Rodriguez
Legal Research Officer at the National Supreme Court of Justice, Mexico
J
Jesus Manuel Niebla-Zatarain
Professor and researcher at the Faculty of Law of Mazatlan of the Autonomous University of Sinaloa, Mexico
G
Gabriel Sanchez-Perez
Instituto Politecnico Nacional, ESIME Culhuacan, Mexico City 04440, Mexico