{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T06:49:55Z","timestamp":1784530195143,"version":"3.55.0"},"reference-count":57,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2020,8,3]],"date-time":"2020-08-03T00:00:00Z","timestamp":1596412800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,8,3]],"date-time":"2020-08-03T00:00:00Z","timestamp":1596412800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Netw Syst Manage"],"published-print":{"date-parts":[[2020,10]]},"DOI":"10.1007\/s10922-020-09558-5","type":"journal-article","created":{"date-parts":[[2020,8,3]],"date-time":"2020-08-03T06:04:48Z","timestamp":1596434688000},"page":"1794-1819","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":43,"title":["Bayesian Decision Network-Based Security Risk Management Framework"],"prefix":"10.1007","volume":"28","author":[{"given":"Masoud","family":"Khosravi-Farmad","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Abbas","family":"Ghaemi-Bafghi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2020,8,3]]},"reference":[{"key":"9558_CR1","volume-title":"Information security risk analysis","author":"PR Thomas","year":"2010","unstructured":"Thomas, PR.: Information security risk analysis, 3rd edition, Auerbach publications, Boco Raton (2010)","edition":"3"},{"key":"9558_CR2","unstructured":"Ross, R.S.: Guide for conducting risk assessments, Special Publication (NIST SP)-800-30 Rev. 1, (2012)"},{"key":"9558_CR3","volume-title":"Security risk management: building an information security risk management program from the Ground Up","author":"W Evan","year":"2011","unstructured":"Evan, W.: Security risk management: building an information security risk management program from the ground up, 1st edn. Elsevier, Burlington (2011)","edition":"1"},{"key":"9558_CR4","doi-asserted-by":"crossref","unstructured":"Mell, P., et al.: A complete guide to the common vulnerability scoring system version 2.0, Published by FIRST-Forum of Incident Response and Security Teams, vol. 1, (2007)","DOI":"10.1049\/iet-ifs:20060055"},{"key":"9558_CR5","doi-asserted-by":"crossref","unstructured":"Ammann, P., et al.: Scalable, graph-based network vulnerability analysis, Proceedings of the 9th ACM Conference on Computer and Communications Security, ACM (2002)","DOI":"10.1145\/586110.586140"},{"key":"9558_CR6","unstructured":"Sheyner, O., et al.: Automated generation and analysis of attack graphs, In Proceedings 2002 IEEE Symposium on Security and Privacy. IEEE, New York (2002)"},{"key":"9558_CR7","doi-asserted-by":"crossref","unstructured":"Gallon, L., Bascou, J. J.: Cvss attack graphs, In 2011 Seventh International Conference on Signal Image Technology & Internet-Based Systems, pp. 24\u201331. IEEE, New York (2011)","DOI":"10.1109\/SITIS.2011.24"},{"key":"9558_CR8","volume-title":"Network vulnerability assessment using Bayesian networks, In Data mining, intrusion detection, information assurance, and data networks security","author":"Y Liu","year":"2005","unstructured":"Liu, Y., Man, H.: Network vulnerability assessment using Bayesian networks, In Data mining, intrusion detection, information assurance, and data networks security, vol. 5812, pp. 61\u201371, International Society for Optics and Photonics, Bellingham (2005)"},{"issue":"1","key":"9558_CR9","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1109\/TDSC.2011.34","volume":"9","author":"N Poolsappasit","year":"2012","unstructured":"Poolsappasit, N., et al.: Dynamic security risk management using bayesian attack graphs. IEEE Trans. Dependable Secure Comput. 9(1), 61\u201374 (2012)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"9558_CR10","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.cosrev.2017.09.001","volume":"26","author":"JB Hong","year":"2017","unstructured":"Hong, J.B., et al.: A survey on the usability and practical applications of graphical security models. Comput. Sci. Rev. 26, 1\u201316 (2017)","journal-title":"Comput. Sci. Rev."},{"key":"9558_CR11","doi-asserted-by":"crossref","unstructured":"Lippmann, R.P., Ingols, K.W.: An annotated review of past papers on attack graphs, No. PR-IA-1, Massachusetts Inst of Tech Lexington Lincoln Lab (2005)","DOI":"10.21236\/ADA431826"},{"key":"9558_CR12","doi-asserted-by":"publisher","first-page":"349","DOI":"10.1016\/j.cose.2018.04.006","volume":"77","author":"U Garg","year":"2018","unstructured":"Garg, U., et al.: Empirical analysis of attack graphs for mitigating critical paths and vulnerabilities. Comput. Security 77, 349\u2013359 (2018)","journal-title":"Comput. Security"},{"key":"9558_CR13","first-page":"27","volume":"29","author":"K Kaynar","year":"2016","unstructured":"Kaynar, K.: A taxonomy for attack graph generation and usage in network security. J. Inform. Security Appl. 29, 27\u201356 (2016)","journal-title":"J Inform. Security Appl."},{"key":"9558_CR14","doi-asserted-by":"publisher","first-page":"168201","DOI":"10.1109\/ACCESS.2019.2954092","volume":"7","author":"W He","year":"2019","unstructured":"He, W., et al.: Unknown vulnerability risk assessment based on directed graph models: a survey. IEEE Access 7, 168201\u2013168225 (2019)","journal-title":"IEEE Access"},{"key":"9558_CR15","doi-asserted-by":"crossref","unstructured":"Cheng, P., et al.: Aggregating CVSS base scores for semantics-rich network security metrics, In 2012 IEEE 31st Symposium on Reliable Distributed Systems, IEEE, New York (2012)","DOI":"10.1109\/SRDS.2012.4"},{"key":"9558_CR16","doi-asserted-by":"crossref","unstructured":"Wang, C., et al.: A novel comprehensive network security assessment approach, In 2011 IEEE International Conference on Communications (ICC), IEEE, New York (2011)","DOI":"10.1109\/icc.2011.5963092"},{"key":"9558_CR17","doi-asserted-by":"publisher","first-page":"158","DOI":"10.1016\/j.cose.2012.09.013","volume":"32","author":"S Wang","year":"2013","unstructured":"Wang, S., et al.: Exploring attack graph for cost-benefit security hardening: a probabilistic approach. Comput. Security 32, 158\u2013169 (2013)","journal-title":"Comput. Security"},{"key":"9558_CR18","doi-asserted-by":"crossref","unstructured":"Wang, L., et al.: An attack graph-based probabilistic security metric, In IFIP Annual Conference on Data and Applications Security and Privacy, pp. 283\u2013296. Springer, Berlin, Heidelberg (2008)","DOI":"10.1007\/978-3-540-70567-3_22"},{"key":"9558_CR19","doi-asserted-by":"crossref","unstructured":"Ghosh, N., Ghosh, S.K.: An approach for security assessment of network configurations using attack graph, In 2009 First International Conference on Networks Communications, pp. 283\u2013288. IEEE, New York (2009)","DOI":"10.1109\/NetCoM.2009.83"},{"issue":"1","key":"9558_CR20","first-page":"135","volume":"1","author":"S Noel","year":"2010","unstructured":"Noel, S., et al.: Measuring security risk of networks using attack graphs. Int. J. Next Gen. Comput. 1(1), 135\u2013147 (2010)","journal-title":"Int. J. Next Gen. Comput."},{"key":"9558_CR21","doi-asserted-by":"crossref","unstructured":"Frigault, M., Wang, L.: Measuring network security using Bayesian network-based attack graphs, In 2008 32nd Annual IEEE International Computer Software and Applications Conference, pp. 698\u2013703. IEEE, New York (2008)","DOI":"10.1109\/COMPSAC.2008.88"},{"key":"9558_CR22","doi-asserted-by":"crossref","unstructured":"Kondakci, S.: Network security risk assessment using Bayesian belief networks, In 2010 IEEE Second International Conference on Social Computing, pp. 952\u2013960. IEEE, New York(2010)","DOI":"10.1109\/SocialCom.2010.141"},{"key":"9558_CR23","unstructured":"Xie, P., et al.: Using Bayesian networks for cyber security analysis, In 2010 IEEE\/IFIP International Conference on Dependable Systems & Networks (DSN), pp. 211\u2013220. IEEE, New York (2010)"},{"key":"9558_CR24","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1016\/j.ins.2013.02.036","volume":"256","author":"N Feng","year":"2014","unstructured":"Feng, N., et al.: A security risk analysis model for information systems: causal relationships of risk factors and vulnerability propagation analysis. Inform. Sci. 256, 57\u201373 (2014)","journal-title":"Inform. Sci."},{"issue":"5","key":"9558_CR25","doi-asserted-by":"publisher","first-page":"1713","DOI":"10.1007\/s11036-018-1047-6","volume":"24","author":"A Le","year":"2019","unstructured":"Le, A., et al.: Incorporating FAIR into bayesian network for numerical assessment of loss event frequencies of smart grid cyber threats. Mobile Networks Appl.24(5), 1713\u20131721 (2019)","journal-title":"Mobile Networks Appl."},{"key":"9558_CR26","doi-asserted-by":"crossref","unstructured":"Wang, J., et al.: A Bayesian network approach for cybersecurity risk assessment implementing and extending the FAIR model, Computers Security 89, 101659","DOI":"10.1016\/j.cose.2019.101659"},{"key":"9558_CR27","first-page":"1","volume-title":"Measuring the overall network security by combining cvss scores based on attack graphs and Bayesian networks, in Network Security Metrics","author":"M Frigault","year":"2017","unstructured":"Frigault, M., et al.: Measuring the overall network security by combining cvss scores based on attack graphs and Bayesian networks, in Network Security Metrics, pp. 1\u201323. Springer, Cham (2017)"},{"key":"9558_CR28","first-page":"141","volume-title":"A suite of metrics for network attack graph analytics, in network security metrics","author":"S Noel","year":"2017","unstructured":"Noel, S., Jajodia, S.: A suite of metrics for network attack graph analytics, in network security metrics, pp. 141\u2013176. Springer, Cham (2017)"},{"key":"9558_CR29","volume-title":"Risk analysis and security countermeasure selection","author":"TL Norman","year":"2015","unstructured":"Norman, T.L.: Risk analysis and security countermeasure selection, 2nd edn. CRC Press, Cleveland (2015)","edition":"2"},{"key":"9558_CR30","volume-title":"Security risk management: building an information security risk management program from the Ground Up","author":"E Wheeler","year":"2011","unstructured":"Wheeler, E.: Security risk management: building an information security risk management program from the Ground Up, 1st edn. Elsevier, Amsterdam (2011)","edition":"1"},{"key":"9558_CR31","volume-title":"Artificial intelligence: a modern approach","author":"SJ Russell","year":"2020","unstructured":"Russell, S.J., Norvig, P.: Artificial intelligence: a modern approach, 4th edn. Pearson Education Limited, Malaysia (2020)","edition":"4"},{"key":"9558_CR32","volume-title":"Probabilistic graphical models: principles and techniques","author":"D Koller","year":"2009","unstructured":"Koller, D., Friedman, N., Bach, F.: Probabilistic graphical models: principles and techniques, 1st edition, MIT press, Cambridge (2009)","edition":"1"},{"issue":"3","key":"9558_CR33","doi-asserted-by":"publisher","first-page":"343","DOI":"10.1007\/s10922-010-9177-6","volume":"19","author":"MS Ahmed","year":"2011","unstructured":"Ahmed, M.S., et al.: Objective risk evaluation for automated security management. J. Network Syst. Manag. 19(3), 343\u2013366 (2011)","journal-title":"J. Network Syst. Manag."},{"key":"9558_CR34","doi-asserted-by":"publisher","first-page":"323","DOI":"10.1016\/j.cose.2017.09.011","volume":"74","author":"M Alali","year":"2018","unstructured":"Alali, M., et al.: Improving risk assessment model of cyber security using fuzzy logic inference system. Comput. Security 74, 323\u2013339 (2018)","journal-title":"Comput. Security"},{"issue":"6","key":"9558_CR35","doi-asserted-by":"publisher","first-page":"344","DOI":"10.1049\/iet-ifs.2014.0272","volume":"9","author":"F Dai","year":"2015","unstructured":"Dai, F., et al.: Exploring risk flow attack graph for security risk assessment. IET Infor. Security 9(6), 344\u2013353 (2015)","journal-title":"IET Inform. Security"},{"issue":"6","key":"9558_CR36","doi-asserted-by":"publisher","first-page":"681","DOI":"10.1007\/s10207-017-0382-0","volume":"17","author":"G Wangen","year":"2018","unstructured":"Wangen, G., et al.: A framework for estimating information security risk assessment method completeness. Int. J. Inform. Security 17(6), 681\u2013699 (2018)","journal-title":"Int. J. Inform. Security"},{"issue":"3","key":"9558_CR37","doi-asserted-by":"publisher","first-page":"491","DOI":"10.1007\/s10922-016-9370-3","volume":"24","author":"K Rusek","year":"2016","unstructured":"Rusek, K., et al.: Effective risk assessment in resilient communication networks. J. Network Syst. Manag. 24(3), 491\u2013515 (2016)","journal-title":"J. Network Syst. Manag."},{"key":"9558_CR38","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1016\/j.cose.2015.11.003","volume":"57","author":"MSK Awan","year":"2016","unstructured":"Awan, M.S.K., et al.: Identifying cyber risk hotspots: a framework for measuring temporal variance in computer network risk. Comput. Security 57, 31\u201346 (2016)","journal-title":"Comput. Security"},{"issue":"2","key":"9558_CR39","doi-asserted-by":"publisher","first-page":"1361","DOI":"10.1109\/COMST.2017.2781126","volume":"20","author":"P Nespoli","year":"2018","unstructured":"Nespoli, P., et al.: Optimal countermeasures selection against cyber attacks: a comprehensive survey on reaction frameworks. IEEE Commun. Surveys Tutorials 20(2), 1361\u20131396 (2018)","journal-title":"IEEE Commun. Surveys Tutorials"},{"key":"9558_CR40","first-page":"296","volume-title":"Rheostat real time risk manag","author":"A Gehani","year":"2004","unstructured":"Gehani, A., Kedem, G.: Rheostat Real Time Risk Manag. In: international workshop on recent advances in intrusion detection, pp. 296\u2013314. Springer, Berlin, Heidelberg (2004)"},{"issue":"1","key":"9558_CR41","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/s10922-013-9282-4","volume":"23","author":"O Dabbebi","year":"2015","unstructured":"Dabbebi, O., et al.: An online risk management strategy for VoIP enterprise infrastructures. J. Network Syst. Manag. 23(1), 137\u2013162 (2015)","journal-title":"J. Network Syst. Manag."},{"key":"9558_CR42","unstructured":"Noel, S., et al.: Efficient minimum-cost network hardening via exploit dependency graphs. In 19th Annual Computer Security Applications Conference Proceedings, IEEE, New York. pp. 86\u201395 (2003)"},{"key":"9558_CR43","unstructured":"Jha, S., et al.: Two formal analyses of attack graphs. In Proceedings 15th IEEE Computer Security Foundations Workshop, CSFW-15, IEEE, New York. pp. 49\u201363 (2002)"},{"key":"9558_CR44","doi-asserted-by":"crossref","unstructured":"Dewri, R., et al.: Optimal security hardening using multi-objective optimization on attack tree models of networks, In Proceedings of the 14th ACM conference on computer and communications security, ACM. pp. 204\u2013213, (2007)","DOI":"10.1145\/1315245.1315272"},{"key":"9558_CR45","doi-asserted-by":"crossref","unstructured":"Khosravi-Farmad, M., et al.: Network security risk mitigation using Bayesian decision networks, In 2014 4th International Conference on Computer and Knowledge Engineering (ICCKE), IEEE. pp. 267\u2013272 (2014)","DOI":"10.1109\/ICCKE.2014.6993444"},{"key":"9558_CR46","doi-asserted-by":"crossref","unstructured":"Liu, S. C., Liu, Y.: Network security risk assessment method based on HMM and attack graph model, In 2016 17th IEEE\/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel\/Distributed Computing (SNPD), IEEE, New York. pp. 517\u2013522 (2016)","DOI":"10.1109\/SNPD.2016.7515951"},{"key":"9558_CR47","unstructured":"Nessus Vulnerability Scanner. http:\/\/www.tenable.com\/products\/nessus-vulnerability-scanner"},{"key":"9558_CR48","unstructured":"OpenVAS, Open Vulnerability Assessment System. http:\/\/www.openvas.org\/"},{"key":"9558_CR49","unstructured":"Retina Network Security Vulnerability Scanner. https:\/\/www.beyondtrust.com\/products\/retina-network-security-scanner\/"},{"key":"9558_CR50","unstructured":"NIST. US National vulnerability database (NVD). https:\/\/nvd.nist.gov\/"},{"key":"9558_CR51","unstructured":"Common Vulnerabilities and Exposures (CVE). https:\/\/cve.mitre.org\/"},{"key":"9558_CR52","unstructured":"Nmap, The Network Mapper. https:\/\/nmap.org\/"},{"key":"9558_CR53","unstructured":"Ou, X., et al., MulVAL: A Logic-based Network Security Analyzer, In USENIX Security Symposium, pp. 113\u2013128 2005"},{"key":"9558_CR54","doi-asserted-by":"crossref","unstructured":"Khosravi-Farmad, M., et al.: Considering temporal and environmental characteristics of vulnerabilities in network security risk assessment, In 2014 11th International ISC Conference on Information Security and Cryptology, IEEE. pp. 186\u2013191 (2014)","DOI":"10.1109\/ISCISC.2014.6994045"},{"key":"9558_CR55","unstructured":"GeNIe Modeler, BayesFusion, LLC. https:\/\/www.bayesfusion.com\/"},{"key":"9558_CR56","doi-asserted-by":"crossref","unstructured":"ben Othmane, L., et al.: Incorporating attacker capabilities in risk estimation and mitigation., Computers Security 51, pp. 41\u201361 (2015)","DOI":"10.1016\/j.cose.2015.03.001"},{"key":"9558_CR57","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1016\/j.cose.2015.04.012","volume":"53","author":"H Holm","year":"2015","unstructured":"Holm, H., et al.: An expert-based investigation of the common vulnerability scoring system. Comput. Security 53, 18\u201330 (2015)","journal-title":"Comput. Security"}],"container-title":["Journal of Network and Systems Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-020-09558-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10922-020-09558-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-020-09558-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,8,2]],"date-time":"2021-08-02T23:20:41Z","timestamp":1627946441000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10922-020-09558-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,8,3]]},"references-count":57,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2020,10]]}},"alternative-id":["9558"],"URL":"https:\/\/doi.org\/10.1007\/s10922-020-09558-5","relation":{},"ISSN":["1064-7570","1573-7705"],"issn-type":[{"value":"1064-7570","type":"print"},{"value":"1573-7705","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,8,3]]},"assertion":[{"value":"19 August 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 May 2020","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 July 2020","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 August 2020","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Compliance with Ethical Standards"}},{"value":"Authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of Interest"}},{"value":"This article does not contain any studies with animals performed by any of the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical Approval"}},{"value":"Informed consent was obtained from all individual participants included in the study.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Informed Consent"}}]}}