{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T16:07:09Z","timestamp":1784131629342,"version":"3.55.0"},"reference-count":45,"publisher":"Institution of Engineering and Technology (IET)","issue":"1","license":[{"start":{"date-parts":[[2024,5,27]],"date-time":"2024-05-27T00:00:00Z","timestamp":1716768000000},"content-version":"am","delay-in-days":147,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"},{"start":{"date-parts":[[2024,5,27]],"date-time":"2024-05-27T00:00:00Z","timestamp":1716768000000},"content-version":"vor","delay-in-days":147,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IIS-2311969"],"award-info":[{"award-number":["IIS-2311969"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["IIS-2202395"],"award-info":[{"award-number":["IIS-2202395"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006754","name":"Army Research Laboratory","doi-asserted-by":"publisher","award":["W911NF2320179"],"award-info":[{"award-number":["W911NF2320179"]}],"id":[{"id":"10.13039\/100006754","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"publisher","award":["W911NF2110299"],"award-info":[{"award-number":["W911NF2110299"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-23-1-2850"],"award-info":[{"award-number":["N00014-23-1-2850"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["ietresearch.onlinelibrary.wiley.com"],"crossmark-restriction":true},"short-container-title":["IET Information Security"],"published-print":{"date-parts":[[2024,1]]},"abstract":"<jats:p>The increasing interconnectivity in our infrastructure poses a significant security challenge, with external threats having the potential to penetrate and propagate throughout the network. Bayesian attack graphs have proven to be effective in capturing the propagation of attacks in complex interconnected networks. However, most existing security approaches fail to systematically account for the limitation of resources and uncertainty arising from the complexity of attacks and possible undetected compromises. To address these challenges, this paper proposes a partially observable Markov decision process (POMDP) model for network security under uncertainty. The POMDP model accounts for uncertainty in monitoring and defense processes, as well as the probabilistic attack propagation. This paper develops two security policies based on the optimal stationary defense policy for the underlying POMDP state process (i.e., a network with known compromises): the estimation\u2010based policy that performs the defense actions corresponding to the optimal minimum mean square error state estimation and the distribution\u2010based policy that utilizes the posterior distribution of network compromises to make defense decisions. Optimal monitoring policies are designed to specifically support each of the defense policies, allowing dynamic allocation of monitoring resources to capture network vulnerabilities\/compromises. The performance of the proposed policies is examined in terms of robustness, accuracy, and uncertainty using various numerical experiments.<\/jats:p>","DOI":"10.1049\/2024\/7966713","type":"journal-article","created":{"date-parts":[[2024,5,27]],"date-time":"2024-05-27T23:35:10Z","timestamp":1716852910000},"update-policy":"https:\/\/doi.org\/10.1002\/crossmark_policy","source":"Crossref","is-referenced-by-count":17,"title":["Optimal Joint Defense and Monitoring for Networks Security under Uncertainty: A POMDP\u2010Based Approach"],"prefix":"10.1049","volume":"2024","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-8174-8507","authenticated-orcid":false,"given":"Armita","family":"Kazeminajafabadi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9570-9909","authenticated-orcid":false,"given":"Mahdi","family":"Imani","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"265","published-online":{"date-parts":[[2024,5,27]]},"reference":[{"key":"e_1_2_11_1_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSMCA.2010.2048028"},{"key":"e_1_2_11_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3314219"},{"key":"e_1_2_11_3_2","doi-asserted-by":"publisher","DOI":"10.3389\/fpace.2022.1036642"},{"key":"e_1_2_11_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2022.3190556"},{"key":"e_1_2_11_5_2","unstructured":"FrigaultM. Measuring network security using Bayesian network-based attack graphs 2010 Concordia University Ph.D. thesis."},{"key":"e_1_2_11_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSECP.2003.1236235"},{"key":"e_1_2_11_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/SURV.2013.101613.00077"},{"key":"e_1_2_11_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2023.3310072"},{"key":"e_1_2_11_9_2","doi-asserted-by":"crossref","unstructured":"Amala NikithaG. KathrineG. J. W. DuthieC. R. EbenezerV. andSilasS. Hybrid cryptographic algorithm to secure internet of things 2023 7th International Conference on Intelligent Computing and Control Systems (ICICCS) May 2023 Madurai India IEEE 1556\u20131562 https:\/\/doi.org\/10.1109\/ICICCS56967.2023.10142709.","DOI":"10.1109\/ICICCS56967.2023.10142709"},{"key":"e_1_2_11_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2821095"},{"key":"e_1_2_11_11_2","doi-asserted-by":"crossref","unstructured":"ColaceF. KhanM. LombardiM. andSantanielloD. A multigraph approach for supporting computer network monitoring systems 2 Proceedings of Fifth International Congress on Information and Communication Technology: ICICT 2020 October 2020 London Springer 470\u2013477 https:\/\/doi.org\/10.1007\/978\u2010981\u201015\u20105859\u20107_46.","DOI":"10.1007\/978-981-15-5859-7_46"},{"key":"e_1_2_11_12_2","doi-asserted-by":"crossref","unstructured":"AsadiN. HosseiniS. H. ImaniM. AldrichD. P. andGhoreishiS. F. Privacy-preserved federated reinforcement learning for autonomy in signalized intersections ASCE International Conference on Transportation and Development (ICTD) 2024 American Society of Civil Engineers.","DOI":"10.1061\/9780784485514.035"},{"key":"e_1_2_11_13_2","doi-asserted-by":"crossref","unstructured":"KazeminajafabadiA. GhoreishiS. F. andImaniM. Optimal detection for Bayesian attack graphs under uncertainty in monitoring and reimaging 2023 American Control Conference (ACC) 2024 IEEE.","DOI":"10.23919\/ACC60939.2024.10644873"},{"key":"e_1_2_11_14_2","unstructured":"LiJ. XieJ. andLiuK. Bayesian attack graphs: a new approach to network security 2019 IEEE International Conference on Big Data (Big Data) 2019 IEEE 5044\u20135053."},{"key":"e_1_2_11_15_2","article-title":"Bayesian attack graphs: security risk assessment via probabilistic modeling","volume":"20","author":"Wohlfart E.","year":"2017","journal-title":"ACM Transactions on Information and System Security (TISSEC)"},{"key":"e_1_2_11_16_2","unstructured":"WohlfartE. SchauerS. andHolzT. Bayesian attack graphs: an advanced probabilistic model for security risk assessments Proceedings of the 10th ACM Symposium on Information Computer and Communications Security 2015 ACM 783\u2013794."},{"key":"e_1_2_11_17_2","unstructured":"WohlfartE. SchauerS. andHolzT. Bayesian attack graphs: security risk assessment and probabilistic graphical models Proceedings of the 8th ACM SIGSAC Symposium on Information Computer and Communications Security 2013 ACM 621\u2013632."},{"key":"e_1_2_11_18_2","first-page":"386","article-title":"Bayesian attack graphs: a new approach for modeling security risks in computer networks","volume":"16","author":"Li K.","year":"2019","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"e_1_2_11_19_2","doi-asserted-by":"crossref","unstructured":"MiehlingE. RasouliM. andTeneketzisD. Optimal defense policies for partially observable spreading processes on Bayesian attack graphs Proceedings of the Second ACM Workshop on Moving Target Defense October 2015 Denver Colorado USA Association for Computing Machinery 67\u201376 https:\/\/doi.org\/10.1145\/2808475.2808482.","DOI":"10.1145\/2808475.2808482"},{"key":"e_1_2_11_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3269018"},{"key":"e_1_2_11_21_2","doi-asserted-by":"crossref","unstructured":"HuZ. ZhuM. andLiuP. Online algorithms for adaptive cyber defense on Bayesian attack graphs Proceedings of the 2017 Workshop on Moving Target Defense October 2017 Dallas Texas USA Association for Computing Machinery 99\u2013109 https:\/\/doi.org\/10.1145\/3140549.3140556 2-s2.0-85043363103.","DOI":"10.1145\/3140549.3140556"},{"key":"e_1_2_11_22_2","doi-asserted-by":"crossref","unstructured":"BehfarniaA.andEslamiA. Risk assessment of autonomous vehicles using Bayesian defense graphs 2018 IEEE 88th Vehicular Technology Conference (VTC-Fall) August 2018 Chicago IL USA IEEE 1\u20135 https:\/\/doi.org\/10.1109\/VTCFall.2018.8690732 2-s2.0-85064916481.","DOI":"10.1109\/VTCFall.2018.8690732"},{"key":"e_1_2_11_23_2","doi-asserted-by":"crossref","unstructured":"NguyenT. H. WrightM. WellmanM. P. andBavejaS. Multi-stage attack graph security games: heuristic strategies with empirical game-theoretic analysis Proceedings of the 2017 Workshop on Moving Target Defense October 2017 Dallas Texas USA Association for Computing Machinery 87\u201397 https:\/\/doi.org\/10.1145\/3140549.3140562 2-s2.0-85043358358.","DOI":"10.1145\/3140549.3140562"},{"key":"e_1_2_11_24_2","doi-asserted-by":"crossref","unstructured":"DoynikovaE.andKotenkoI. Enhancement of probabilistic attack graphs for accurate cyber security monitoring 2017 IEEE SmartWorld Ubiquitous Intelligence & Computing Advanced & Trusted Computed Scalable Computing & Communications Cloud & Big Data Computing Internet of People and Smart City Innovation (SmartWorld\/SCALCOM\/UIC\/ATC\/CBDCom\/IOP\/SCI) August 2017 San Francisco CA USA IEEE 1\u20136 https:\/\/doi.org\/10.1109\/UIC\u2010ATC.2017.8397618 2-s2.0-85050186050.","DOI":"10.1109\/UIC-ATC.2017.8397618"},{"key":"e_1_2_11_25_2","doi-asserted-by":"crossref","unstructured":"WuH. GuY. ChengG. andZhouY. Effectiveness evaluation method for cyber deception based on dynamic Bayesian attack graph Proceedings of the 3rd International Conference on Computer Science and Software Engineering May 2020 Beijing China Association for Computing Machinery 1\u20139 https:\/\/doi.org\/10.1145\/3403746.3403897.","DOI":"10.1145\/3403746.3403897"},{"key":"e_1_2_11_26_2","doi-asserted-by":"crossref","unstructured":"MatthewsI. SoudjaniS. andvan MoorselA. Stochastic simulation techniques for inference and sensitivity analysis of Bayesian attack graphs International Conference on Science of Cyber Security October 2021 Springer 171\u2013186.","DOI":"10.1007\/978-3-030-89137-4_12"},{"key":"e_1_2_11_27_2","doi-asserted-by":"publisher","DOI":"10.1186\/s42400\u2010023\u201000155\u2010y"},{"key":"e_1_2_11_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2017.2749508"},{"key":"e_1_2_11_29_2","doi-asserted-by":"crossref","unstructured":"RoopakM. TianG. Y. andChambersJ. Deep learning models for cyber security in IoT networks 2019 IEEE 9th Annual Computing and Communication Workshop and Conference (CCWC) January 2019 Las Vegas NV USA IEEE 452\u2013457 https:\/\/doi.org\/10.1109\/CCWC.2019.8666588 2-s2.0-85063885958.","DOI":"10.1109\/CCWC.2019.8666588"},{"key":"e_1_2_11_30_2","unstructured":"WangS. PeiK. WhitehouseJ. YangJ. andJanaS. Formal security analysis of neural networks using symbolic intervals Proceedings of the 27th USENIX Conference on Security Symposium August 2018 Baltimore MD USA USENIX Association 1599\u20131614."},{"key":"e_1_2_11_31_2","first-page":"1","article-title":"Adaptive cyber defense against multi-stage attacks using learning-based POMDP","volume":"24","author":"Hu Z.","year":"2020","journal-title":"ACM Transactions on Privacy and Security (TOPS)"},{"key":"e_1_2_11_32_2","first-page":"1","article-title":"A complete guide to the common vulnerability scoring system version 2.0","volume":"1","author":"Mell P.","year":"2007","journal-title":"FIRST-Forum of Incident Response and Security Teams"},{"key":"e_1_2_11_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2024.3358261"},{"key":"e_1_2_11_34_2","doi-asserted-by":"crossref","unstructured":"GhoreishiS. F.andImaniM. Bayesian optimization for efficient design of uncertain coupled multidisciplinary systems 2020 American Control Conference (ACC) July 2020 Denver CO USA IEEE 3412\u20133418 https:\/\/doi.org\/10.23919\/ACC45564.2020.9147526.","DOI":"10.23919\/ACC45564.2020.9147526"},{"key":"e_1_2_11_35_2","doi-asserted-by":"crossref","unstructured":"RavariA. GhoreishiS. F. andImaniM. Implicit human perception learning in complex and unknown environments American Control Conference (ACC) 2024 IEEE.","DOI":"10.23919\/ACC60939.2024.10644975"},{"key":"e_1_2_11_36_2","doi-asserted-by":"publisher","DOI":"10.1080\/21642583.2024.2329260"},{"key":"e_1_2_11_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/LCSYS.2022.3229054"},{"key":"e_1_2_11_38_2","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611974263"},{"key":"e_1_2_11_39_2","volume-title":"Reinforcement Learning: An Introduction","author":"Sutton R. S.","year":"2018"},{"key":"e_1_2_11_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2017.2743240"},{"key":"e_1_2_11_41_2","doi-asserted-by":"crossref","unstructured":"DuthieC. KathrineG. J. W. Amala NikithaG. XavierS. B. andJebaduraiI. J. Deep learning based malware analysis prediction and prevention 2023 4th International Conference on Electronics and Sustainable Communication Systems (ICESC) July 2023 Coimbatore India IEEE 469\u2013475 https:\/\/doi.org\/10.1109\/ICESC57686.2023.10193068.","DOI":"10.1109\/ICESC57686.2023.10193068"},{"key":"e_1_2_11_42_2","doi-asserted-by":"crossref","unstructured":"AlaliM.andImaniM. Kernel-based particle filtering for scalable inference in partially observed boolean dynamical systems IFAC-PapersOnLine 20th IFAC Symposium on System Identification (SYSID 2024) 2024 Elsevier.","DOI":"10.1016\/j.ifacol.2024.08.495"},{"key":"e_1_2_11_43_2","doi-asserted-by":"publisher","DOI":"10.1017\/9781108917407"},{"key":"e_1_2_11_44_2","doi-asserted-by":"crossref","unstructured":"AlaliM.andImaniM. Reinforcement learning data-acquiring for causal inference of regulatory networks American Control Conference (ACC) 2023 San Diego CA USA IEEE 3957\u20133964 https:\/\/doi.org\/10.23919\/ACC55779.2023.10155867.","DOI":"10.23919\/ACC55779.2023.10155867"},{"key":"e_1_2_11_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3069172"}],"container-title":["IET Information Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/downloads.hindawi.com\/journals\/ietis\/2024\/7966713.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/ietis\/2024\/7966713.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/pdf\/10.1049\/2024\/7966713","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/pdf\/10.1049\/2024\/7966713","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,5]],"date-time":"2025-11-05T08:56:48Z","timestamp":1762333008000},"score":1,"resource":{"primary":{"URL":"https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/10.1049\/2024\/7966713"}},"subtitle":[],"editor":[{"given":"Taimur","family":"Bakhshi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"editor"}]}],"short-title":[],"issued":{"date-parts":[[2024,1]]},"references-count":45,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2024,1]]}},"alternative-id":["10.1049\/2024\/7966713"],"URL":"https:\/\/doi.org\/10.1049\/2024\/7966713","archive":["Portico"],"relation":{},"ISSN":["1751-8709","1751-8717"],"issn-type":[{"value":"1751-8709","type":"print"},{"value":"1751-8717","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,1]]},"assertion":[{"value":"2023-12-25","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-04-20","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-05-27","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"7966713"}}