{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,28]],"date-time":"2026-07-28T19:12:01Z","timestamp":1785265921648,"version":"3.55.0"},"reference-count":46,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,1,23]],"date-time":"2025-01-23T00:00:00Z","timestamp":1737590400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,1,23]],"date-time":"2025-01-23T00:00:00Z","timestamp":1737590400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100015688","name":"\u00d3buda University","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100015688","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"published-print":{"date-parts":[[2025,2]]},"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>In an era where cybersecurity threats are evolving at an unprecedented pace, this paper introduces a methodology for near real-time risk assessment of high-profile, high security infrastructures, where data security and operational continuity inherently limits observability. Our approach addresses the challenges of this limited observability and minimized disruption, offering a new perspective on processing and evaluating cybersecurity knowledge. We present an innovative method that leverages attack graphs and attacker behavior analysis to assess risks and vulnerabilities. Our research includes the development of an automated risk assessment mechanism, graphical security modeling, and a Markov chain-based model for attacker behavior. Our methodology utilizes a blend of direct and indirect event sources, incorporating an attacker behavioral model based on a random walk method akin to Google\u2019s PageRank. The proof-of-concept solution calculates potential risk according to the actual threat landscape, providing a more accurate and timely assessment.<\/jats:p>","DOI":"10.1007\/s10207-024-00971-4","type":"journal-article","created":{"date-parts":[[2025,1,23]],"date-time":"2025-01-23T03:31:49Z","timestamp":1737603109000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Low-impact, near real-time risk assessment for legacy IT infrastructures"],"prefix":"10.1007","volume":"24","author":[{"given":"Eszter","family":"Kail","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Annam\u00e1ria","family":"Riethn\u00e9 Nagy","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rita","family":"Fleiner","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anna","family":"B\u00e1n\u00e1ti","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ern\u0151","family":"Rig\u00f3","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,1,23]]},"reference":[{"key":"971_CR1","unstructured":"Archiveddocs. The STRIDE Threat Model. en-us. Nov. 2009. url: https:\/\/learn.microsoft.com\/en-us\/previous-versions\/commerce-server\/ee823878(v=cs.20)"},{"key":"971_CR2","unstructured":"Stolen, K. et al.: Model-based risk assessment\u2013the CORAS approach. In: iTrust Workshop. Citeseer. (2002)"},{"issue":"2","key":"971_CR3","doi-asserted-by":"publisher","first-page":"187","DOI":"10.1007\/s12652-013-0179-6","volume":"5","author":"B Solhaug","year":"2014","unstructured":"Solhaug, B., Seehusen, F.: Model-driven risk analysis of evolving critical infrastructures. J. Ambient Intell. Humaniz. Comput. 5(2), 187\u2013204 (2014). https:\/\/doi.org\/10.1007\/s12652-013-0179-6","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"key":"971_CR4","doi-asserted-by":"publisher","unstructured":"Keramati, M., Akbari, A.: An attack graph based metric for security evaluation of computer networks. In: 6th International Symposium on Telecommunications (IST). 6th International Symposium on Telecommunications (IST). (2012), pp.\u00a01094\u20131098. https:\/\/doi.org\/10.1007\/11909033_20","DOI":"10.1007\/11909033_20"},{"key":"971_CR5","doi-asserted-by":"publisher","unstructured":"Chen, Y., Boehm, B., Sheppard, L.: Value driven security threat modeling based on attack path analysis. In: 2007 40th Annual Hawaii International Conference on System Sciences (HICSS\u201907). Proceedings of the 40th Annual Hawaii International Conference on System Sciences. Waikoloa, HI: IEEE, Jan. (2007), 280a\u2013280a. isbn: 978-0-7695-2755-0.https:\/\/doi.org\/10.1109\/HICSS.2007.601 (Visited on 12\/03\/2024)","DOI":"10.1109\/HICSS.2007.601"},{"key":"971_CR6","doi-asserted-by":"publisher","unstructured":"Casola, V. et al.: Towards automated penetration testing for cloud applications. In: 2018 IEEE 27th International Conference on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE). 2018 IEEE 27th International Conference on Enabling Technologies: Infrastructure for Collaborative Enterprises (WETICE). Paris: IEEE, June (2018), pp.\u00a024\u201329. isbn: 978-1-5386-6916-7. https:\/\/doi.org\/10.1109\/WETICE.2018.00012","DOI":"10.1109\/WETICE.2018.00012"},{"key":"971_CR7","unstructured":"OWASP risk rating methodology. url: https:\/\/owasp.org\/www-community\/OWASP_Risk_Rating_Methodology (visited on 12\/03\/2024)"},{"key":"971_CR8","unstructured":"Alavizadeh, H. et al.: An automated security analysis framework and implementation for cloud. In: arXiv:1904.01758 [cs] (Dec.\u00a03, 2024)"},{"key":"971_CR9","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cosrev.2017.09.001","volume":"26","author":"JB Hong","year":"2017","unstructured":"Hong, J.B., et al.: A survey on the usability and practical applications of graphical security models. Comput. Sci. Rev. 26, 1\u201316 (2017). https:\/\/doi.org\/10.1016\/j.cosrev.2017.09.001","journal-title":"Comput. Sci. Rev."},{"key":"971_CR10","first-page":"21","volume":"24","author":"B Schneier","year":"1999","unstructured":"Schneier, B.: Attack trees. Dr. Dobb\u2019s J. 24, 21\u201329 (1999)","journal-title":"Dr. Dobb\u2019s J."},{"key":"971_CR11","unstructured":"Edge, K.S.: A framework for analyzing and mitigating the vulnerabilities of complex systems via attack and protection trees. Air Force Institute of Technology, (2007)"},{"key":"971_CR12","doi-asserted-by":"publisher","unstructured":"Roy, A., Kim, D.S., Trivedi, K.S.: Cyber security analysis using attack countermeasure trees. In: Proceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research - CSIIRW \u201910. the Sixth Annual Workshop. Oak Ridge, Tennessee: ACM Press, (2010), p.\u00a01. isbn: 978-1-4503-0017-9. https:\/\/doi.org\/10.1145\/1852666.1852698 (Visited on 12\/03\/2024)","DOI":"10.1145\/1852666.1852698"},{"key":"971_CR13","doi-asserted-by":"publisher","unstructured":"Roy, A., Kim, D.S., Trivedi, K.S.: Cyber security analysis using attack countermeasure trees. In: Proceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research - CSIIRW \u201910. the Sixth Annual Workshop. Oak Ridge, Tennessee: ACM Press, (2010), p.\u00a01. isbn: 978-1-4503-0017-9. https:\/\/doi.org\/10.1145\/1852666.1852698 (Visited on 12\/03\/2024)","DOI":"10.1145\/1852666.1852698"},{"key":"971_CR14","doi-asserted-by":"publisher","unstructured":"Jha, S., Sheyner, O., Wing, J.: Two formal analyses of attack graphs. In: Proceedings 15th IEEE Computer Security Foundations Workshop. CSFW-15. 15th IEEE Computer Security Foundations Workshop CSFW-15. Cape Breton, NS, Canada: IEEE Comput. Soc, 2002, pp.\u00a049\u201363. isbn: 978-0-7695-1689-9. https:\/\/doi.org\/10.1109\/CSFW.2002.1021806","DOI":"10.1109\/CSFW.2002.1021806"},{"key":"971_CR15","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1016\/j.jisa.2016.02.001","volume":"29","author":"K Kaynar","year":"2016","unstructured":"Kaynar, K.: A taxonomy for attack graph generation and usage in network security. J. Inf. Secur. Appl. 29, 27\u201356 (2016). https:\/\/doi.org\/10.1016\/j.jisa.2016.02.001","journal-title":"J. Inf. Secur. Appl."},{"key":"971_CR16","doi-asserted-by":"publisher","first-page":"264","DOI":"10.1049\/iet-ifs.2011.0103","volume":"6","author":"SK Ghosh","year":"2012","unstructured":"Ghosh, S.K., Bhattacharya, P.: Analytical framework for measuring network security using exploit dependency graph. IET Inf. Secur. 6, 264\u2013270 (2012). https:\/\/doi.org\/10.1049\/iet-ifs.2011.0103","journal-title":"IET Inf. Secur."},{"key":"971_CR17","doi-asserted-by":"publisher","unstructured":"Hong, J., Kim, D.-S.: HARMs: Hierarchical attack representation models for network security analysis. In: 10th Australian Information Security Management Conference (2012). https:\/\/doi.org\/10.4225\/75\/57B559A3CD8DA (Visited on 12\/03\/2024)","DOI":"10.4225\/75\/57B559A3CD8DA"},{"key":"971_CR18","doi-asserted-by":"crossref","unstructured":"Enoch, S.Y., Hong, J.B., Kim, D.S.: Time independent security analysis for dynamic networks using graphical security models. In: 2018 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications\/12th IEEE International Conference On Big Data Science And Engineering (TrustCom\/BigDataSE). IEEE. (2018), pp.\u00a0588\u2013595","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00089"},{"key":"971_CR19","unstructured":"Ou, X., Govindavajhala, S., Appel, A.W., et al.: MulVAL: A logic-based network security analyzer. USENIX security symposium 8, 113\u2013128 (2005)"},{"issue":"4","key":"971_CR20","doi-asserted-by":"publisher","first-page":"735","DOI":"10.15676\/ijeei.2015.7.4.15","volume":"7","author":"J Sembiring","year":"2015","unstructured":"Sembiring, J., Ramadhan, M., Gondokaryono, Y.S., Arman, A.A.: Network security risk analysis using improved MulVAL Bayesian attack graphs. Int. J. Electr. Eng. Inf. 7(4), 735 (2015). https:\/\/doi.org\/10.15676\/ijeei.2015.7.4.15","journal-title":"Int. J. Electr. Eng. Inf."},{"key":"971_CR21","doi-asserted-by":"crossref","unstructured":"Jing, J.T.W. et al.: Augmenting MulVAL with automated extraction of vulnerabilities descriptions. In: TENCON 2017 - 2017 IEEE Region 10 Conference. (2017), pp.\u00a0476\u2013481","DOI":"10.1109\/TENCON.2017.8227911"},{"key":"971_CR22","doi-asserted-by":"publisher","first-page":"27974","DOI":"10.1109\/ACCESS.2023.3257721","volume":"11","author":"D Tayouri","year":"2023","unstructured":"Tayouri, D., et al.: A survey of MulVAL extensions and their attack scenarios coverage. IEEE Access 11, 27974\u201327991 (2023)","journal-title":"IEEE Access"},{"key":"971_CR23","unstructured":"MITRE ATT &CK\u00ae. url: https:\/\/attack.mitre.org\/ (visited on 12\/03\/2024)"},{"key":"971_CR24","doi-asserted-by":"publisher","unstructured":"Lippmann, R. et al.: Validating and restoring defense in depth using attack graphs. MILCOM 2006. Washington, DC, USA: IEEE, Oct (2006), pp.\u00a01\u201310. https:\/\/doi.org\/10.1109\/MILCOM.2006.302434","DOI":"10.1109\/MILCOM.2006.302434"},{"key":"971_CR25","doi-asserted-by":"publisher","unstructured":"Yi, S. et al.: Overview on attack graph generation and visualization technology. In: 2013 International Conference on Anti-Counterfeiting, Security and Identification (ASID). 2013 International Conference on Anti-Counterfeiting, Security and Identification (ASID). Shanghai, China: IEEE, Oct. 2013, pp.\u00a01\u20136. isbn: 978-1-4799-1111-0. https:\/\/doi.org\/10.1109\/ICASID.2013.6825274 (Visited on 12\/03\/2024)","DOI":"10.1109\/ICASID.2013.6825274"},{"key":"971_CR26","doi-asserted-by":"crossref","unstructured":"Jajodia, S., Noel, S., O\u2019berry, B.: Topological analysis of network attack vulnerability. In: Managing Cyber Threats: Issues, Approaches, and Challenges (2005), pp.\u00a0247\u2013266","DOI":"10.1007\/0-387-24230-9_9"},{"key":"971_CR27","doi-asserted-by":"publisher","unstructured":"Xie, A. et al.: A probability-based approach to attack graphs generation. In: 2009 Second International Symposium on Electronic Commerce and Security. 2009 Second International Symposium on Electronic Commerce and Security. Nanchang City, China: IEEE, (2009), pp.\u00a0343\u2013347. isbn: 978-0-7695-3643-9. https:\/\/doi.org\/10.1109\/ISECS.2009.113","DOI":"10.1109\/ISECS.2009.113"},{"key":"971_CR28","doi-asserted-by":"publisher","unstructured":"Ma, J. et al.: A scalable, bidirectional-based search strategy to generate attack graphs. In: 2010 10th IEEE International Conference on Computer and Information Technology. 2010 IEEE 10th International Conference on Computer and Information Technology (CIT). Bradford, United Kingdom: IEEE, June (2010), pp.\u00a02976\u20132981. isbn: 978-1-4244-7547-6. https:\/\/doi.org\/10.1109\/CIT.2010.496. (Visited on 12\/03\/2024)","DOI":"10.1109\/CIT.2010.496"},{"key":"971_CR29","doi-asserted-by":"crossref","unstructured":"Zhang, S., Ou, X., Homer, J.: Effective network vulnerability assessment through model abstraction. In: Detection of Intrusions and Malware, and Vulnerability Assessment: 8th International Conference, DIMVA 2011, Amsterdam, The Netherlands, July 7-8, 2011. Proceedings 8. (2011), pp.\u00a017\u201334","DOI":"10.1007\/978-3-642-22424-9_2"},{"key":"971_CR30","doi-asserted-by":"crossref","unstructured":"Yousefi, M. et al.: A novel approach for analysis of attack graph. In: 2017 IEEE International Conference on Intelligence and Security Informatics (ISI). IEEE. (2017), pp.\u00a07\u201312","DOI":"10.1109\/ISI.2017.8004866"},{"key":"971_CR31","doi-asserted-by":"publisher","first-page":"168","DOI":"10.3390\/info11030168","volume":"11","author":"E Doynikova","year":"2020","unstructured":"Doynikova, E., Novikova, E., Kotenko, I.: Attacker behaviour forecasting using methods of intelligent data analysis: a comparative review and prospects. Information 11, 168 (2020)","journal-title":"Information"},{"key":"971_CR32","doi-asserted-by":"publisher","DOI":"10.1155\/2019\/2031063","author":"J Zeng","year":"2019","unstructured":"Zeng, J., et al.: Survey of attack graph analysis methods from the perspective of data and knowledge processing. Secur. Commun. Netw. (2019). https:\/\/doi.org\/10.1155\/2019\/2031063","journal-title":"Secur. Commun. Netw."},{"key":"971_CR33","doi-asserted-by":"crossref","unstructured":"Mehta, V. et al.: Ranking attack graphs. In: International Workshop on Recent Advances in Intrusion Detection. Springer, pp.\u00a0127\u2013144 (2006)","DOI":"10.1007\/11856214_7"},{"key":"971_CR34","doi-asserted-by":"publisher","unstructured":"Claise, B.: Cisco systems NetFlow services export version 9. Request for Comments RFC 3954. Num Pages: 33. Internet Engineering Task Force, (2004). https:\/\/doi.org\/10.17487\/RFC3954 (Visited on 12\/03\/2024)","DOI":"10.17487\/RFC3954"},{"key":"971_CR35","unstructured":"About sFlow Overview @ sFlow.org. url: https:\/\/sflow.org\/about\/index.php (visited on 12\/03\/2024)"},{"key":"971_CR36","unstructured":"OpenVAS - Open vulnerability assessment scanner. url: https:\/\/www.openvas.org\/ (visited on 12\/03\/2024)"},{"key":"971_CR37","unstructured":"Reddit\u2014dive into anything. Nov.\u00a028, 2023. url: https:\/\/www.reddit.com\/ (visited on 12\/03\/2024)"},{"key":"971_CR38","unstructured":"NVD\u2014Home. url: https:\/\/nvd.nist.gov\/ (visited on 12\/03\/2024)"},{"key":"971_CR39","unstructured":"NVD\u2014CVSS v3 Calculator. url: https:\/\/nvd.nist.gov\/vuln-metrics\/cvss\/v3-calculator (visited on 12\/03\/2024)"},{"key":"971_CR40","unstructured":"NVD\u2014CPE. url: https:\/\/nvd.nist.gov\/products\/cpe (visited on 11\/28\/2023)"},{"key":"971_CR41","unstructured":"Rig\u00f3, E.: Anonymized netflow and security scan data. Version\u00a0V1. 2024. DOI: 21.15109\/ARP\/FBIIOZ https:\/\/hdl.handle.net\/21.15109\/ARP\/FBIIOZ"},{"key":"971_CR42","unstructured":"Tan, R.: Automating cyber incident response. original-date: 2019-07-10T02:37:22Z. Jan.\u00a018, (2023). url: https:\/\/github.com\/rebstan97\/AttackGraphGeneration (visited on 12\/03\/2024)"},{"key":"971_CR43","doi-asserted-by":"publisher","unstructured":"Ingols, K., Lippmann, R., Piwowarski, K.: Practical attack graph generation for network defense. In: 2006 22nd Annual Computer Security Applications Conference (ACSAC\u201906). ISSN: 1063-9527. Miami Beach, FL, USA: IEEE, Dec. 2006, pp.\u00a0121\u2013130. isbn: 978-0-7695-2716-1. https:\/\/doi.org\/10.1109\/ACSAC.2006.39 (Visited on 12\/03\/2024)","DOI":"10.1109\/ACSAC.2006.39"},{"key":"971_CR44","unstructured":"Haveliwala, T., Kamvar, S., Jeh, G.: An analytical comparison of approaches to personalizing pagerank. Tech. rep, Stanford (2003)"},{"key":"971_CR45","unstructured":"Freedman, A.: Convergence theorem for finite Markov chains. In: Proc. Reu (2017)"},{"key":"971_CR46","doi-asserted-by":"publisher","unstructured":"H\u00e9der, M. et al.: The past, present and future of the ELKH Cloud. Inform\u00e1ci\u00f3s T\u00e1rsadalom (Information Society) XXII.2 (2022). issn: 1587-8694. https:\/\/doi.org\/10.22503\/inftars.XXII.2022.2.8","DOI":"10.22503\/inftars.XXII.2022.2.8"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-024-00971-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-024-00971-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-024-00971-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,12]],"date-time":"2025-02-12T05:20:05Z","timestamp":1739337605000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-024-00971-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,23]]},"references-count":46,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,2]]}},"alternative-id":["971"],"URL":"https:\/\/doi.org\/10.1007\/s10207-024-00971-4","relation":{},"ISSN":["1615-5262","1615-5270"],"issn-type":[{"value":"1615-5262","type":"print"},{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,23]]},"assertion":[{"value":"23 January 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"67"}}