z-logo
open-access-imgOpen Access
A Proactive and Time-Sensitive Cyber Risk Assessment Model Integrating Markov Chains and Bayesian Networks
Author(s) -
Pavlos Cheimonidis,
Konstantinos Rantos
Publication year - 2025
Publication title -
ieee access
Language(s) - English
Resource type - Magazines
SCImago Journal Rank - 0.587
H-Index - 127
eISSN - 2169-3536
DOI - 10.1109/access.2025.3575070
Subject(s) - aerospace , bioengineering , communication, networking and broadcast technologies , components, circuits, devices and systems , computing and processing , engineered materials, dielectrics and plasmas , engineering profession , fields, waves and electromagnetics , general topics for engineers , geoscience , nuclear engineering , photonics and electrooptics , power, energy and industry applications , robotics and control systems , signal processing and analysis , transportation
As cyberattacks grow in complexity, they pose increasing threats to organizations reliant on networked infrastructures. Conventional risk assessment methodologies often fail to adapt to the evolving nature of these threats. This paper introduces a novel cyber risk assessment model that adopts a proactive, dynamic, and time-aware approach to evaluating security risks. The proposed model leverages the Exploit Prediction Scoring System (EPSS) to estimate the short-term likelihood of exploitation over a 30-day period. To improve accuracy, Bayesian networks are employed to capture both system vulnerabilities and asset interdependencies within the network. This information is integrated into an absorbing Markov chain along with the identified attack paths, which are explored using Depth-First Search (DFS). The model generates exploitation probability distributions over the predefined time window, which, when combined with asset impact, facilitates dynamic, proactive, and time-sensitive risk assessments. Additionally, it provides valuable insights into attack progression by estimating the time required for an adversary to compromise critical assets. To demonstrate the practical applicability of the model, a case study is presented, showcasing its effectiveness in assessing cyber risks within a SCADA environment.

The content you want is available to Zendy users.

Already have an account? Click here to sign in.
Having issues? You can contact us here
Empowering knowledge with every search

Address

John Eccles House
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom