{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T03:51:06Z","timestamp":1782445866907,"version":"3.54.5"},"publisher-location":"Cham","reference-count":54,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319702896","type":"print"},{"value":"9783319702902","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-70290-2_7","type":"book-chapter","created":{"date-parts":[[2017,11,3]],"date-time":"2017-11-03T14:58:05Z","timestamp":1509721085000},"page":"105-122","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":42,"title":["Bayesian Network Models in Cyber Security: A Systematic Review"],"prefix":"10.1007","author":[{"given":"Sabarathinam","family":"Chockalingam","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wolter","family":"Pieters","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andr\u00e9","family":"Teixeira","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pieter","family":"van Gelder","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,11,4]]},"reference":[{"key":"7_CR1","unstructured":"WEF: Partnering for Cyber Resilience: Towards the Quantification of Cyber Threats (2015)"},{"key":"7_CR2","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1109\/MNET.2015.7340429","volume":"29","author":"S Yu","year":"2015","unstructured":"Yu, S., Wang, G., Zhou, W.: Modeling malicious activities in cyber space. IEEE Netw. 29, 83\u201387 (2015)","journal-title":"IEEE Netw."},{"key":"7_CR3","volume-title":"Bayesian Networks. Encyclopedia of Statistics in Quality and Reliability","author":"I Ben-Gal","year":"2008","unstructured":"Ben-Gal, I.: Bayesian Networks. Encyclopedia of Statistics in Quality and Reliability. Wiley, Hoboken (2008)"},{"key":"7_CR4","doi-asserted-by":"publisher","unstructured":"Darwiche, A.: Chapter 11 - Bayesian networks. In: Foundations of Artificial Intelligence, vol. 3, pp. 467\u2013509 (2008). doi:10.1016\/S1574-6526(07)03011-8","DOI":"10.1016\/S1574-6526(07)03011-8"},{"key":"7_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.envsoft.2013.03.011","volume":"46","author":"D Landuyt","year":"2013","unstructured":"Landuyt, D., et al.: A review of Bayesian belief networks in ecosystem service modelling. Environ. Model. Softw. 46, 1\u201311 (2013)","journal-title":"Environ. Model. Softw."},{"key":"7_CR6","doi-asserted-by":"publisher","first-page":"312","DOI":"10.1016\/j.ecolmodel.2006.11.033","volume":"203","author":"L Uusitalo","year":"2007","unstructured":"Uusitalo, L.: Advantages and challenges of Bayesian networks in environmental modelling. Ecol. Model. 203, 312\u2013318 (2007)","journal-title":"Ecol. Model."},{"issue":"4","key":"7_CR7","doi-asserted-by":"publisher","first-page":"509","DOI":"10.1109\/69.868904","volume":"12","author":"D Nikovski","year":"2000","unstructured":"Nikovski, D.: Constructing Bayesian networks for medical diagnosis from incomplete and partially correct statistics. IEEE Trans. Knowl. Data Eng. 12(4), 509\u2013516 (2000)","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"7_CR8","doi-asserted-by":"publisher","DOI":"10.1002\/9780470400777","volume-title":"Reasoning with Diagrams: Decision-Making and Problem-Solving with Diagrams","author":"RT Nakatsu","year":"2009","unstructured":"Nakatsu, R.T.: Reasoning with Diagrams: Decision-Making and Problem-Solving with Diagrams. Wiley, Hoboken (2009)"},{"key":"7_CR9","doi-asserted-by":"publisher","first-page":"98","DOI":"10.1016\/j.envsoft.2016.08.006","volume":"85","author":"TD Phan","year":"2016","unstructured":"Phan, T.D., et al.: Applications of Bayesian belief networks in water resource management: a systematic review. Environ. Model. Softw. 85, 98\u2013111 (2016)","journal-title":"Environ. Model. Softw."},{"key":"7_CR10","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cosrev.2014.07.001","volume":"13","author":"B Kordy","year":"2014","unstructured":"Kordy, B., Pi\u00e8tre-Cambac\u00e9d\u00e8s, L., Schweitzer, P.: DAG-based attack and defense modeling: don\u2019t miss the forest for the attack trees. Comput. Sci. Rev. 13, 1\u201338 (2014)","journal-title":"Comput. Sci. Rev."},{"key":"7_CR11","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1109\/TDSC.2011.34","volume":"9","author":"N Poolsappasit","year":"2012","unstructured":"Poolsappasit, N., Dewri, R., Ray, I.: Dynamic security risk management using bayesian attack graphs. IEEE Trans. Dependable Secure Comput. 9, 61\u201374 (2012)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"7_CR12","doi-asserted-by":"crossref","unstructured":"Frigault, M., Wang, L.: Measuring network security using Bayesian network-based attack graphs. IEEE (2008)","DOI":"10.1145\/1456362.1456368"},{"key":"7_CR13","doi-asserted-by":"crossref","unstructured":"Liu, Y., Man, H.: Network vulnerability assessment using Bayesian networks. In: Proceedings of the SPIE, pp. 61\u201371 (2005)","DOI":"10.1117\/12.604240"},{"key":"7_CR14","doi-asserted-by":"crossref","unstructured":"Kwan, M., Chow, K.-P., Law, F., Lai, P.: Reasoning about evidence using Bayesian networks. In: IFIP International Conference on Digital Forensics, pp. 275\u2013289 (2008)","DOI":"10.1007\/978-0-387-84927-0_22"},{"key":"7_CR15","doi-asserted-by":"crossref","unstructured":"Axelrad, E.T., Sticha, P.J., Brdiczka, O., Shen, J.: A Bayesian network model for predicting insider threats. In: Security and Privacy Workshops, pp. 82\u201389 (2013)","DOI":"10.1109\/SPW.2013.35"},{"key":"7_CR16","doi-asserted-by":"crossref","unstructured":"Greitzer, F.L., et al.: Identifying at-risk employees: modeling psychosocial precursors of potential insider threats. In: Hawaii International Conference on System Science (HICSS), pp. 2392\u20132401 (2012)","DOI":"10.1109\/HICSS.2012.309"},{"key":"7_CR17","doi-asserted-by":"crossref","unstructured":"Greitzer, F.L., et al.: Identifying at-risk employees: a behavioral model for predicting potential insider threats. Pacific Northwest National Laboratory (2010)","DOI":"10.2172\/1000159"},{"key":"7_CR18","doi-asserted-by":"crossref","unstructured":"Pecchia, A., et al.: Identifying compromised users in shared computing infrastructures: a data-driven bayesian network approach. In: 2011 30th IEEE Symposium on Reliable Distributed Systems (SRDS), pp. 127\u2013136. IEEE (2011)","DOI":"10.1109\/SRDS.2011.24"},{"key":"7_CR19","doi-asserted-by":"publisher","first-page":"208","DOI":"10.1016\/j.ress.2014.10.006","volume":"134","author":"J Shin","year":"2015","unstructured":"Shin, J., Son, H., Heo, G.: Development of a cyber security risk model using Bayesian networks. Reliab. Eng. Syst. Saf. 134, 208\u2013217 (2015)","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"7_CR20","doi-asserted-by":"crossref","unstructured":"Kornecki, A.J., Subramanian, N., Zalewski, J.: Studying interrelationships of safety and security for software assurance in cyber-physical systems: approach based on bayesian belief networks. In: 2013 Federated Conference on Computer Science and Information Systems (FedCSIS), pp. 1393\u20131399. IEEE (2013)","DOI":"10.1109\/SysCon.2013.6549949"},{"key":"7_CR21","doi-asserted-by":"crossref","unstructured":"Wang, J.A., Guo, M.: Vulnerability categorization using Bayesian networks. In: Proceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research, p. 29. ACM (2010)","DOI":"10.1145\/1852666.1852699"},{"key":"7_CR22","doi-asserted-by":"crossref","unstructured":"Mo, S.Y.K., Beling, P.A., Crowther, K.G.: Quantitative assessment of cyber security risk using Bayesian network-based model. In: 2009 Systems and Information Engineering Design Symposium, SIEDS 2009, pp. 183\u2013187. IEEE (2009)","DOI":"10.1109\/SIEDS.2009.5166177"},{"key":"7_CR23","doi-asserted-by":"publisher","first-page":"304","DOI":"10.1016\/j.infsof.2014.07.001","volume":"58","author":"H Holm","year":"2015","unstructured":"Holm, H., Korman, M., Ekstedt, M.: A bayesian network model for likelihood estimations of acquirement of critical software vulnerabilities and exploits. Inf. Softw. Technol. 58, 304\u2013318 (2015)","journal-title":"Inf. Softw. Technol."},{"key":"7_CR24","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"241","DOI":"10.1007\/978-3-642-04155-6_18","volume-title":"Advances in Digital Forensics V","author":"M Kwan","year":"2009","unstructured":"Kwan, M., Chow, K.-P., Lai, P., Law, F., Tse, H.: Analysis of the digital evidence presented in the Yahoo! case. In: Peterson, G., Shenoi, S. (eds.) DigitalForensics 2009. IAICT, vol. 306, pp. 241\u2013252. Springer, Heidelberg (2009). doi:10.1007\/978-3-642-04155-6_18"},{"key":"7_CR25","doi-asserted-by":"publisher","first-page":"125","DOI":"10.7906\/indecs.14.2.2","volume":"14","author":"S Ibrahimovi\u0107","year":"2016","unstructured":"Ibrahimovi\u0107, S., Bajgori\u0107, N.: Modeling information system availability by using Bayesian belief network approach. Interdisc. Description Complex Syst. 14, 125\u2013138 (2016)","journal-title":"Interdisc. Description Complex Syst."},{"key":"7_CR26","unstructured":"Wilde, L.: A Bayesian Network Model for predicting data breaches caused by insiders of a health care organization. University of Twente (2016)"},{"key":"7_CR27","doi-asserted-by":"publisher","first-page":"65","DOI":"10.13052\/jcsm2245-1439.424","volume":"4","author":"K Herland","year":"2016","unstructured":"Herland, K., Hammainen, H., Kekolahti, P.: Information security risk assessment of smartphones using Bayesian networks. J. Cyber Secur. Mobility 4, 65\u201385 (2016)","journal-title":"J. Cyber Secur. Mobility"},{"key":"7_CR28","doi-asserted-by":"crossref","unstructured":"Herland, K.: Information security risk assessment of smartphones using Bayesian networks. Aalto University, Finland (2015)","DOI":"10.13052\/2245-1439.424"},{"key":"7_CR29","volume-title":"Bayesian Network Modeling for Analysis of Data Breach in a Bank","author":"V Apukhtin","year":"2011","unstructured":"Apukhtin, V.: Bayesian Network Modeling for Analysis of Data Breach in a Bank. University of Stavanger, Norway (2011)"},{"key":"7_CR30","doi-asserted-by":"crossref","unstructured":"Khosravi-Farmad, M., Rezaee, R., Harati, A., Bafghi, A.G.: Network security risk mitigation using Bayesian decision networks. In: 4th International eConference on Computer and Knowledge Engineering (ICCKE), pp. 267\u2013272. IEEE (2014)","DOI":"10.1109\/ICCKE.2014.6993444"},{"key":"7_CR31","doi-asserted-by":"crossref","unstructured":"Pan, S., Morris, T.H., Adhikari, U., Madani, V.: Causal event graphs cyber-physical system intrusion detection system. In: Proceedings of the Eighth Annual Cyber Security and Information Intelligence Research Workshop, p. 40. ACM (2013)","DOI":"10.1145\/2459976.2460022"},{"key":"7_CR32","doi-asserted-by":"crossref","unstructured":"Frigault, M., et al.: Measuring network security using dynamic Bayesian network. In: Proceedings of the 4th ACM Workshop on Quality of Protection, pp. 23\u201330 (2008)","DOI":"10.1145\/1456362.1456368"},{"key":"7_CR33","first-page":"304","volume":"3","author":"R Sarala","year":"2014","unstructured":"Sarala, R., Kayalvizhi, M., Zayaraz, G.: Information security risk assessment under uncertainty using dynamic Bayesian networks. Int. J. Res. Eng. Technol. 3, 304\u2013309 (2014)","journal-title":"Int. J. Res. Eng. Technol."},{"key":"7_CR34","doi-asserted-by":"crossref","unstructured":"Tang, K., Zhou, M.-T., Wang, W.-Y.: Insider cyber threat situational awareness framwork using dynamic Bayesian networks. In: 2009 4th International Conference on Computer Science and Education, ICCSE 2009, pp. 1146\u20131150. IEEE (2009)","DOI":"10.1109\/ICCSE.2009.5228485"},{"key":"7_CR35","doi-asserted-by":"crossref","unstructured":"Sommestad, T., Ekstedt, M., Johnson, P.: Cyber security risks assessment with Bayesian defense graphs and architectural models. In: 2009 42nd Hawaii International Conference on System Sciences, HICSS 2009, pp. 1\u201310. IEEE (2009)","DOI":"10.1109\/HICSS.2009.141"},{"key":"7_CR36","doi-asserted-by":"crossref","unstructured":"Ekstedt, M., Sommestad, T.: Enterprise architecture models for cyber security analysis. In: Power Systems Conference and Exposition, pp. 1\u20136. IEEE (2009)","DOI":"10.1109\/PSCE.2009.4840267"},{"key":"7_CR37","unstructured":"Laskey, K., et al.: Detecting threatening behavior using Bayesian networks. In: Conference on Behavioral Representation in Modeling and Simulation, p. 33 (2006)"},{"key":"7_CR38","unstructured":"AlGhamdi, G., et al.: Modeling insider behavior using multi-entity Bayesian networks (2006)"},{"key":"7_CR39","doi-asserted-by":"crossref","unstructured":"Okoli, C., Schabram, K.: A guide to conducting a systematic literature review of information systems research. Sprouts: Working Papers on Information Systems, vol. 10 (2010)","DOI":"10.2139\/ssrn.1954824"},{"key":"7_CR40","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1088\/2058-7058\/20\/1\/33","volume":"20","author":"LI Meho","year":"2007","unstructured":"Meho, L.I.: The rise and rise of citation analysis. Phys. World 20, 32 (2007)","journal-title":"Phys. World"},{"key":"7_CR41","doi-asserted-by":"publisher","first-page":"3063","DOI":"10.1139\/x06-135","volume":"36","author":"BG Marcot","year":"2006","unstructured":"Marcot, B.G., Steventon, J.D., Sutherland, G.D., McCann, R.K.: Guidelines for developing and updating Bayesian belief networks applied to ecological modeling and conservation. Can. J. For. Res. 36, 3063\u20133074 (2006)","journal-title":"Can. J. For. Res."},{"key":"7_CR42","unstructured":"Alberts, C., Dorofee, A.: OCTAVESM Threat Profiles"},{"key":"7_CR43","unstructured":"Bureau, F.I.P.: Unintentional Insider Threats: A Foundational Study (2013)"},{"key":"7_CR44","unstructured":"Rehman, R.: CISO MindMap (2017). http:\/\/rafeeqrehman.com\/wp-content\/uploads\/2017\/07\/CISO_Job_MindMap_v9.png"},{"key":"7_CR45","doi-asserted-by":"publisher","DOI":"10.1201\/9780203501405","volume-title":"Surviving Security: How to Integrate People, Process, and Technology","author":"A Andress","year":"2003","unstructured":"Andress, A.: Surviving Security: How to Integrate People, Process, and Technology. CRC Press, Boca Raton (2003)"},{"key":"7_CR46","unstructured":"Cyber Security Intelligence Index. IBM Security (2016)"},{"key":"7_CR47","doi-asserted-by":"crossref","unstructured":"Greitzer, F.L., et al.: Unintentional insider threat: contributing factors, observables, and mitigation strategies. In: 2014 47th Hawaii International Conference on System Sciences (HICSS), pp. 2025\u20132034. IEEE (2014)","DOI":"10.1109\/HICSS.2014.256"},{"key":"7_CR48","unstructured":"Antonioli, D., et al.: Gamifying Education and Research on ICS Security: Design, Implementation and Results of S3. arXiv preprint arXiv:1702.03067 (2017)"},{"key":"7_CR49","unstructured":"Database, R.: German Steel Mill Cyber Attack (2017). http:\/\/www.risidata.com\/database\/detail\/german-steel-mill-cyber-attack"},{"key":"7_CR50","doi-asserted-by":"crossref","unstructured":"Lippmann, R.P., Ingols, K.W.: An annotated review of past papers on attack graphs. Massachusetts Institute of Technology Lincoln Laboratory, Lexington (2005)","DOI":"10.21236\/ADA431826"},{"key":"7_CR51","doi-asserted-by":"publisher","first-page":"249","DOI":"10.1016\/S0951-8320(00)00077-6","volume":"71","author":"A Bobbio","year":"2001","unstructured":"Bobbio, A., Portinale, L., Minichino, M., Ciancamerla, E.: Improving the analysis of dependable systems by mapping fault trees into Bayesian networks. Reliab. Eng. Syst. Saf. 71, 249\u2013260 (2001)","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"7_CR52","doi-asserted-by":"publisher","first-page":"925","DOI":"10.1016\/j.ress.2011.03.012","volume":"96","author":"N Khakzad","year":"2011","unstructured":"Khakzad, N., Khan, F., Amyotte, P.: Safety analysis in process facilities: comparison of fault tree and Bayesian network approaches. Reliab. Eng. Syst. Saf. 96, 925\u2013932 (2011)","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"7_CR53","doi-asserted-by":"crossref","unstructured":"Chockalingam, S., et al.: Integrated safety and security risk assessment methods: a survey of key characteristics and applications. In: International Conference on Critical Information Infrastructures Security (CRITIS), Paris (2016)","DOI":"10.1007\/978-3-319-71368-7_5"},{"key":"7_CR54","series-title":"Advances in Information Security","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-77322-3_5","volume-title":"Insider Attack and Cyber Security","author":"MB Salem","year":"2008","unstructured":"Salem, M.B., Hershkop, S., Stolfo, S.J.: A Survey of Insider Attack Detection Research. In: Stolfo, S.J., Bellovin, S.M., Keromytis, A.D., Hershkop, S., Smith, S.W., Sinclair, S. (eds.) Insider Attack and Cyber Security. Advances in Information Security, vol. 39. Springer, Boston (2008)"}],"container-title":["Lecture Notes in Computer Science","Secure IT Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-70290-2_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,26]],"date-time":"2025-06-26T21:16:13Z","timestamp":1750972573000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-70290-2_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319702896","9783319702902"],"references-count":54,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-70290-2_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]},"assertion":[{"value":"4 November 2017","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"NordSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Nordic Conference on Secure IT Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Tartu","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Estonia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2017","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 November 2017","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 November 2017","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"nordsec2017","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/nordsec2017.cs.ut.ee\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}