{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T23:27:22Z","timestamp":1782170842327,"version":"3.54.5"},"reference-count":61,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2021,9,1]],"date-time":"2021-09-01T00:00:00Z","timestamp":1630454400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,9,1]],"date-time":"2021-09-01T00:00:00Z","timestamp":1630454400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100003246","name":"Nederlandse Organisatie voor Wetenschappelijk Onderzoek","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003246","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"published-print":{"date-parts":[[2021,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Water management infrastructures such as floodgates are critical and increasingly operated by Industrial Control Systems (ICS). These systems are becoming more connected to the internet, either directly or through the corporate networks. This makes them vulnerable to cyber-attacks. Abnormal behaviour in floodgates operated by ICS could be caused by both (intentional) attacks and (accidental) technical failures. When operators notice abnormal behaviour, they should be able to distinguish between those two causes to take appropriate measures, because for example replacing a sensor in case of intentional incorrect sensor measurements would be ineffective and would not block corresponding the attack vector. In the previous work, we developed the attack-failure distinguisher framework for constructing Bayesian Network (BN) models to enable operators to distinguish between those two causes, including the knowledge elicitation method to construct the directed acyclic graph and conditional probability tables of BN models. As a full case study of the attack-failure distinguisher framework, this paper presents a BN model constructed to distinguish between attacks and technical failures for the problem of incorrect sensor measurements in floodgates, addressing the problem of floodgate operators. We utilised experts who associate themselves with the safety and\/or security community to construct the BN model and validate the qualitative part of constructed BN model. The constructed BN model is usable in water management infrastructures to distinguish between intentional attacks and accidental technical failures in case of incorrect sensor measurements. This could help to decide on appropriate response strategies and avoid further complications in case of incorrect sensor measurements.<\/jats:p>","DOI":"10.1186\/s42400-021-00086-6","type":"journal-article","created":{"date-parts":[[2021,9,1]],"date-time":"2021-09-01T00:09:11Z","timestamp":1630454951000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":15,"title":["Bayesian network model to distinguish between intentional attacks and accidental technical failures: a case study of floodgates"],"prefix":"10.1186","volume":"4","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6003-2360","authenticated-orcid":false,"given":"Sabarathinam","family":"Chockalingam","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wolter","family":"Pieters","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andr\u00e9","family":"Teixeira","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pieter","family":"van Gelder","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,9,1]]},"reference":[{"key":"86_CR1","volume-title":"Revisiting anomaly detection in ICS: aimed at segregation of attacks and faults","author":"CM Ahmed","year":"2020","unstructured":"Ahmed, C. M., Prakash, J., & Zhou, J. (2020). Revisiting anomaly detection in ICS: aimed at segregation of attacks and faults. arXiv preprint arXiv:2005.00325"},{"key":"86_CR2","unstructured":"Alile OS (2018) Predicting multi-stage attack with normal IP addresses on a computer network using Bayesian belief network. University of Benin, Benin"},{"key":"86_CR3","volume-title":"Proceedings of the Workshop on Cyber-Physical Systems Security and Privacy","author":"D Antonioli","year":"2017","unstructured":"Antonioli D, Ghaeini HR, Adepu S, Ochoa M, Tippenhauer NO (2017) Gamifying ICS security training and research: design, implementation, and results of S3. In: Proceedings of the Workshop on Cyber-Physical Systems Security and Privacy"},{"key":"86_CR4","volume-title":"Proceedings of the 24th ACM International on Conference on Information and Knowledge Management","author":"A Anwar","year":"2015","unstructured":"Anwar A, Mahmood AN, Shah Z (2015) A data-driven approach to distinguish cyber-attacks from physical faults in a smart grid. In: Proceedings of the 24th ACM International on Conference on Information and Knowledge Management"},{"key":"86_CR5","volume-title":"Bayesian network modeling for analysis of data breach in a bank","author":"V Apukhtin","year":"2011","unstructured":"Apukhtin V (2011) Bayesian network modeling for analysis of data breach in a bank. University of Stavanger, Norway"},{"key":"86_CR6","volume-title":"2013 IEEE security and privacy workshops","author":"ET Axelrad","year":"2013","unstructured":"Axelrad ET, Sticha PJ, Brdiczka O, Shen J (2013) A Bayesian network model for predicting insider threats. In: 2013 IEEE security and privacy workshops"},{"issue":"1","key":"86_CR7","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1016\/j.jsp.2009.10.001","volume":"48","author":"AN Baraldi","year":"2010","unstructured":"Baraldi AN, Enders CK (2010) An introduction to modern missing data analyses. J Sch Psychol 48(1):5\u201337. https:\/\/doi.org\/10.1016\/j.jsp.2009.10.001","journal-title":"J Sch Psychol"},{"key":"86_CR8","unstructured":"Brewer J, Hunter A (1989) Multimethod research: a synthesis of styles. Sage library of social research (vol. 175). Sage Publications, Inc"},{"key":"86_CR9","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.apenergy.2013.09.043","volume":"114","author":"B Cai","year":"2014","unstructured":"Cai B, Liu Y, Fan Q, Zhang Y, Liu Z, Yu S, Ji R (2014) Multi-source information fusion based fault diagnosis of ground-source heat pump using Bayesian network. Appl Energy 114:1\u20139. https:\/\/doi.org\/10.1016\/j.apenergy.2013.09.043","journal-title":"Appl Energy"},{"key":"86_CR10","unstructured":"Castellon N, Frinking E (2015) Securing critical infrastructures in the Netherlands: towards a National Testbed. The Hague Centre for Strategic Studies. Retrieved from https:\/\/www.thehaguesecuritydelta.com\/media\/com_hsd\/report\/53\/document\/Securing-Critical-Infrastructures-in-the-Netherlands.pdf"},{"key":"86_CR11","volume-title":"2019 IEEE Conference on Information and Communication Technology (CICT)","author":"S Chockalingam","year":"2019","unstructured":"Chockalingam S, Katta V (2019) Developing a bayesian network framework for root cause analysis of observable problems in cyber-physical systems. In: 2019 IEEE Conference on Information and Communication Technology (CICT)"},{"key":"86_CR12","doi-asserted-by":"publisher","unstructured":"Chockalingam S, Pieters W, Teixeira A, Khakzad N, van Gelder P (2019) Combining Bayesian networks and fishbone diagrams to distinguish between intentional attacks and accidental technical failures. Graphical Models Secur (GramSec). https:\/\/doi.org\/10.1007\/978-3-030-15465-3_3","DOI":"10.1007\/978-3-030-15465-3_3"},{"key":"86_CR13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70290-2_7","volume-title":"Nordic Conference on Secure IT Systems (NordSec)","author":"S Chockalingam","year":"2017","unstructured":"Chockalingam S, Pieters W, Teixeira A, van Gelder P (2017) Bayesian network models in cyber security: a systematic review. In: Nordic Conference on Secure IT Systems (NordSec). https:\/\/doi.org\/10.1007\/978-3-319-70290-2_7"},{"key":"86_CR14","doi-asserted-by":"publisher","unstructured":"Chockalingam S (2020) Distinguishing attacks and failures in industrial control systems: knowledge-based design of Bayesian networks for Water Management Infrastructures \u2013 Chapter 5 (Doctoral Thesis, Delft University of Technology, Delft, The Netherlands). Retrieved from https:\/\/doi.org\/10.4233\/uuid:17da1df4-3295-45d3-9119-9f92a547e7c6","DOI":"10.4233\/uuid:17da1df4-3295-45d3-9119-9f92a547e7c6"},{"key":"86_CR15","volume-title":"Proceedings of the ITI 2009 31st International Conference on Information Technology Interfaces","author":"D-I Curiac","year":"2009","unstructured":"Curiac D-I, Vasile G, Banias O, Volosencu C, Albu A (2009) Bayesian network model for diagnosis of psychiatric diseases. In: Proceedings of the ITI 2009 31st International Conference on Information Technology Interfaces"},{"key":"86_CR16","doi-asserted-by":"publisher","first-page":"467","DOI":"10.1016\/S1574-6526(07)03011-8","volume":"3","author":"A Darwiche","year":"2008","unstructured":"Darwiche A (2008) Bayesian networks. Foundations Artif Intell 3:467\u2013509. https:\/\/doi.org\/10.1016\/S1574-6526(07)03011-8","journal-title":"Foundations Artif Intell"},{"key":"86_CR17","volume-title":"SPE Middle East Intelligent Oil and Gas Conference and Exhibition","author":"A Effendi","year":"2015","unstructured":"Effendi A, Davis R (2015) ICS and IT: managing cyber security across the enterprise. In: SPE Middle East Intelligent Oil and Gas Conference and Exhibition"},{"key":"86_CR18","doi-asserted-by":"publisher","first-page":"101908","DOI":"10.1016\/j.cose.2020.101908","volume":"96","author":"N Elmrabit","year":"2020","unstructured":"Elmrabit N, Yang S-H, Yang L, Zhou H (2020) Insider threat risk prediction based on Bayesian network. Comput Secur 96:101908. https:\/\/doi.org\/10.1016\/j.cose.2020.101908","journal-title":"Comput Secur"},{"key":"86_CR19","volume-title":"Fault detection, supervision and safety of technical processes","author":"G Fallet-Fidry","year":"2012","unstructured":"Fallet-Fidry G, Weber P, Simon C, Iung B, Duval C (2012) Evidential network-based extension of leaky Noisy-OR structure for supporting risks analyses. In: Fault detection, supervision and safety of technical processes"},{"issue":"3","key":"86_CR20","doi-asserted-by":"publisher","first-page":"209","DOI":"10.3390\/e20030209","volume":"20","author":"C Farr","year":"2018","unstructured":"Farr C, Ruggeri F, Mengersen K (2018) Prior and posterior linear pooling for combining expert opinions: uses and impact on Bayesian networks \u2014 the case of the wayfinding model. Entropy 20(3):209. https:\/\/doi.org\/10.3390\/e20030209","journal-title":"Entropy"},{"key":"86_CR21","doi-asserted-by":"crossref","unstructured":"Greitzer FL, Kangas LJ, Noonan CF, Dalton AC (2010) Identifying at-risk employees: a behavioral model for predicting potential insider threats. Pacific Northwest National Lab (PNNL), Richland. Retrieved from https:\/\/www.pnnl.gov\/main\/publications\/external\/technical_reports\/PNNL-19665.pdf","DOI":"10.2172\/1000159"},{"key":"86_CR22","volume-title":"2012 45th Hawaii International Conference on System Sciences","author":"FL Greitzer","year":"2012","unstructured":"Greitzer FL, Kangas LJ, Noonan CF, Dalton AC, Hohimer RE (2012) Identifying at-risk employees: modeling psychosocial precursors of potential insider threats. In: 2012 45th Hawaii International Conference on System Sciences"},{"issue":"1","key":"86_CR23","first-page":"19","volume":"228","author":"M H\u00e4nninen","year":"2014","unstructured":"H\u00e4nninen M, Mazaheri A, Kujala P, Montewka J, Laaksonen P, Salmiovirta M, Klang M (2014) Expert elicitation of a navigation service implementation effects on ship groundings and collisions in the Gulf of Finland. Proc Inst Mech Eng, Part O: J Risk Reliability 228(1):19\u201328","journal-title":"Proc Inst Mech Eng, Part O: J Risk Reliability"},{"issue":"3","key":"86_CR24","doi-asserted-by":"publisher","first-page":"65","DOI":"10.13052\/jcsm2245-1439.424","volume":"4","author":"K Herland","year":"2016","unstructured":"Herland K, H\u00e4mm\u00e4inen H, Kekolahti P (2016) Information security risk assessment of smartphones using Bayesian networks. J Cyber Secur Mobility 4(3):65\u201386. https:\/\/doi.org\/10.13052\/jcsm2245-1439.424","journal-title":"J Cyber Secur Mobility"},{"key":"86_CR25","doi-asserted-by":"publisher","first-page":"304","DOI":"10.1016\/j.infsof.2014.07.001","volume":"58","author":"H Holm","year":"2015","unstructured":"Holm H, Korman M, Ekstedt M (2015) A Bayesian network model for likelihood estimations of acquirement of critical software vulnerabilities and exploits. Inf Softw Technol 58:304\u2013318. https:\/\/doi.org\/10.1016\/j.infsof.2014.07.001","journal-title":"Inf Softw Technol"},{"key":"86_CR26","volume-title":"22nd International Conference and Exhibition on Electricity Distribution (CIRED 2013)","author":"H Holm","year":"2013","unstructured":"Holm H, Sommestad T, Ekstedt M, Nordstr\u00f6M L (2013) CySeMoL: a tool for cyber security analysis of enterprises. In: 22nd International Conference and Exhibition on Electricity Distribution (CIRED 2013)"},{"issue":"3","key":"86_CR27","doi-asserted-by":"publisher","first-page":"301","DOI":"10.1007\/s10845-008-0083-7","volume":"19","author":"Y Huang","year":"2008","unstructured":"Huang Y, McMurran R, Dhadyalla G, Jones RP (2008) Probability based vehicle fault diagnosis: Bayesian network method. J Intell Manuf 19(3):301\u2013311. https:\/\/doi.org\/10.1007\/s10845-008-0083-7","journal-title":"J Intell Manuf"},{"issue":"1","key":"86_CR28","doi-asserted-by":"publisher","first-page":"640","DOI":"10.1109\/COMST.2018.2871866","volume":"21","author":"M Hus\u00e1k","year":"2018","unstructured":"Hus\u00e1k M, Kom\u00e1rkov\u00e1 J, Bou-Harb E, \u010celeda P (2018) Survey of attack projection, prediction, and forecasting in cyber security. IEEE Commun Surveys Tutorials 21(1):640\u2013660","journal-title":"IEEE Commun Surveys Tutorials"},{"issue":"2","key":"86_CR29","doi-asserted-by":"publisher","first-page":"125","DOI":"10.7906\/indecs.14.2.2","volume":"14","author":"S Ibrahimovi\u0107","year":"2016","unstructured":"Ibrahimovi\u0107 S, Bajgori\u0107 N (2016) Modeling information system availability by using Bayesian belief network approach. Interdiscip Description Complex Syst: INDECS 14(2):125\u2013138. https:\/\/doi.org\/10.7906\/indecs.14.2.2","journal-title":"Interdiscip Description Complex Syst: INDECS"},{"key":"86_CR30","unstructured":"Jacobs F (2018) Safety through machine learning applications: a safety case analysis (Master thesis, Delft University of Technology, Delft). Retrieved from http:\/\/resolver.tudelft.nl\/uuid:ce5c73ef-8ad0-426f-926e-7d7ef3e197c3"},{"issue":"1","key":"86_CR31","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1007\/BF03190296","volume":"14","author":"CE Kahn","year":"2001","unstructured":"Kahn CE, Laur JJ, Carrera G (2001) A Bayesian network for diagnosis of primary bone tumors. J Digit Imaging 14(1):56\u201357. https:\/\/doi.org\/10.1007\/BF03190296","journal-title":"J Digit Imaging"},{"issue":"1","key":"86_CR32","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1016\/S0010-4825(96)00039-X","volume":"27","author":"CE Kahn Jr","year":"1997","unstructured":"Kahn CE Jr, Roberts LM, Shaffer KA, Haddawy P (1997) Construction of a Bayesian network for mammographic diagnosis of breast cancer. Comput Biol Med 27(1):19\u201329. https:\/\/doi.org\/10.1016\/S0010-4825(96)00039-X","journal-title":"Comput Biol Med"},{"key":"86_CR33","doi-asserted-by":"publisher","first-page":"52","DOI":"10.1016\/j.ijcip.2015.02.002","volume":"9","author":"W Knowles","year":"2015","unstructured":"Knowles W, Prince D, Hutchison D, Disso JFP, Jones K (2015) A survey of cyber security management in industrial control systems. Int J Crit Infrastruct Prot 9:52\u201380. https:\/\/doi.org\/10.1016\/j.ijcip.2015.02.002","journal-title":"Int J Crit Infrastruct Prot"},{"key":"86_CR34","volume-title":"2013 Federated Conference on Computer Science and Information Systems","author":"AJ Kornecki","year":"2013","unstructured":"Kornecki AJ, Subramanian N, Zalewski J (2013) Studying interrelationships of safety and security for software assurance in cyber-physical systems: approach based on Bayesian belief networks. In: 2013 Federated Conference on Computer Science and Information Systems"},{"key":"86_CR35","volume-title":"16th International Workshop on Principle Diagnosis","author":"P Kraaijeveld","year":"2005","unstructured":"Kraaijeveld P (2005) Genierate: an interactive generator of diagnostic Bayesian network models. In: 16th International Workshop on Principle Diagnosis"},{"key":"86_CR36","volume-title":"IFIP International Conference on Digital Forensics","author":"M Kwan","year":"2009","unstructured":"Kwan M, Chow K-P, Lai P, Law F, Tse H (2009) Analysis of the digital evidence presented in the yahoo! Case. In: IFIP International Conference on Digital Forensics"},{"key":"86_CR37","volume-title":"IFIP International Conference on Digital Forensics","author":"M Kwan","year":"2008","unstructured":"Kwan M, Chow K-P, Law F, Lai P (2008) Reasoning about evidence using Bayesian networks. In: IFIP International Conference on Digital Forensics"},{"issue":"4","key":"86_CR38","doi-asserted-by":"publisher","first-page":"698","DOI":"10.1046\/j.1538-7836.2003.00139.x","volume":"1","author":"D Luciani","year":"2003","unstructured":"Luciani D, Marchesi M, Bertolini G (2003) The role of Bayesian networks in the diagnosis of pulmonary embolism. J Thromb Haemost 1(4):698\u2013707. https:\/\/doi.org\/10.1046\/j.1538-7836.2003.00139.x","journal-title":"J Thromb Haemost"},{"key":"86_CR39","volume-title":"4th European workshop on probabilistic graphical models","author":"PP Maaskant","year":"2008","unstructured":"Maaskant PP, Druzdzel MJ (2008) An Independence of Causal Interactions Model for Opposing Influences. In: 4th European workshop on probabilistic graphical models"},{"issue":"1","key":"86_CR40","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1111\/j.1523-1739.2011.01806.x","volume":"26","author":"TG Martin","year":"2012","unstructured":"Martin TG, Burgman MA, Fidler F, Kuhnert PM, Low-Choy S, McBride M, Mengersen K (2012) Eliciting expert knowledge in conservation science. Conserv Biol 26(1):29\u201338. https:\/\/doi.org\/10.1111\/j.1523-1739.2011.01806.x","journal-title":"Conserv Biol"},{"key":"86_CR41","doi-asserted-by":"publisher","unstructured":"Milho I, Fred A (2001) A user-friendly development tool for medical diagnosis based on Bayesian networks. In: Sharp B, Filipe J, Cordeiro J (eds) Enterprise Information Systems II. Springer, Dordrecht, pp 113\u2013118. https:\/\/doi.org\/10.1007\/978-94-017-1427-3_16","DOI":"10.1007\/978-94-017-1427-3_16"},{"key":"86_CR42","volume-title":"2009 Systems and Information Engineering Design Symposium","author":"SYK Mo","year":"2009","unstructured":"Mo SYK, Beling PA, Crowther KG (2009) Quantitative assessment of cyber security risk using Bayesian network-based Model. In: 2009 Systems and Information Engineering Design Symposium"},{"key":"86_CR43","doi-asserted-by":"publisher","unstructured":"Nakatsu RT (2009) Diagrammatic Reasoning in AI. Wiley, Hoboken. https:\/\/doi.org\/10.1002\/9780470400777","DOI":"10.1002\/9780470400777"},{"key":"86_CR44","unstructured":"Nogueira HIS, Walraven M (2018) Overview storm surge barriers. Rijskwaterstaat, Deltares. Retrieved from http:\/\/www.masterpiece.dk\/UploadetFiles\/10852\/25\/Deltares_2018_Overview_storm_surge_barriers_komprimeret.pdf"},{"key":"86_CR45","volume-title":"Proceedings of the Eleventh Conference on Biocybernetics and Biomedical Engineering","author":"A Onisko","year":"1999","unstructured":"Onisko A, Druzdzel MJ, Wasyluk H (1999) A Bayesian network model for diagnosis of liver disorders. In: Proceedings of the Eleventh Conference on Biocybernetics and Biomedical Engineering"},{"key":"86_CR46","volume-title":"A literature review on the use of expert opinion in probabilistic risk analysis. World Bank Policy Research Working Paper 3201","author":"F Ouchi","year":"2004","unstructured":"Ouchi F (2004) A literature review on the use of expert opinion in probabilistic risk analysis. World Bank Policy Research Working Paper 3201"},{"key":"86_CR47","doi-asserted-by":"publisher","unstructured":"Pappaterra MJ, Flammini F (2021) Bayesian networks for online cybersecurity threat detection. In: Machine intelligence and big data analytics for cybersecurity applications (pp. 129-159). Springer, Cham. https:\/\/doi.org\/10.1007\/978-3-030-57024-8_6","DOI":"10.1007\/978-3-030-57024-8_6"},{"key":"86_CR48","volume-title":"Proceedings of the ACM\/IEEE Sixth International Conference on Cyber-Physical Systems","author":"J Park","year":"2015","unstructured":"Park J, Ivanov R, Weimer J, Pajic M, Lee I (2015) Sensor attack detection in the presence of transient faults. In: Proceedings of the ACM\/IEEE Sixth International Conference on Cyber-Physical Systems"},{"key":"86_CR49","volume-title":"2011 IEEE 30th International Symposium on Reliable Distributed Systems","author":"A Pecchia","year":"2011","unstructured":"Pecchia A, Sharma A, Kalbarczyk Z, Cotroneo D, Iyer RK (2011) Identifying compromised users in shared computing infrastructures: a data-driven Bayesian network approach. In: 2011 IEEE 30th International Symposium on Reliable Distributed Systems"},{"key":"86_CR50","volume-title":"German steel mill cyber attack","author":"RISI","year":"2014","unstructured":"RISI. (2014). German steel mill cyber attack. Retrieved from http:\/\/www.risidata.com\/database\/detail\/german-steelmill-cyber-attack."},{"issue":"4","key":"86_CR51","doi-asserted-by":"publisher","first-page":"789","DOI":"10.1109\/TCST.2007.903109","volume":"16","author":"PA Samara","year":"2008","unstructured":"Samara PA, Fouskitakis GN, Sakellariou JS, Fassois SD (2008) A statistical method for the detection of sensor abrupt faults in aircraft control systems. IEEE Trans Control Syst Technol 16(4):789\u2013798. https:\/\/doi.org\/10.1109\/TCST.2007.903109","journal-title":"IEEE Trans Control Syst Technol"},{"key":"86_CR52","doi-asserted-by":"publisher","first-page":"208","DOI":"10.1016\/j.ress.2014.10.006","volume":"134","author":"J Shin","year":"2015","unstructured":"Shin J, Son H, Heo G (2015) Development of a cyber security risk model using Bayesian networks. Reliability Eng Syst Saf 134:208\u2013217. https:\/\/doi.org\/10.1016\/j.ress.2014.10.006","journal-title":"Reliability Eng Syst Saf"},{"key":"86_CR53","doi-asserted-by":"publisher","unstructured":"Skopik F, Smith PD (eds) (2015) Smart grid security: innovative solutions for a modernized grid. Syngress, Boston. https:\/\/doi.org\/10.1016\/C2014-0-01356-1","DOI":"10.1016\/C2014-0-01356-1"},{"issue":"5","key":"86_CR54","doi-asserted-by":"publisher","first-page":"373","DOI":"10.1080\/08839510902872223","volume":"23","author":"B Twala","year":"2009","unstructured":"Twala B (2009) An empirical comparison of techniques for handling incomplete data using decision trees. Appl Artif Intell 23(5):373\u2013405. https:\/\/doi.org\/10.1080\/08839510902872223","journal-title":"Appl Artif Intell"},{"issue":"2","key":"86_CR55","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1016\/S0933-3657(02)00012-X","volume":"25","author":"LC Van der Gaag","year":"2002","unstructured":"Van der Gaag LC, Renooij S, Witteman CL, Aleman BM, Taal BG (2002) Probabilities for a probabilistic network: a case study in Oesophageal cancer. Artif Intell Med 25(2):123\u2013148. https:\/\/doi.org\/10.1016\/S0933-3657(02)00012-X","journal-title":"Artif Intell Med"},{"key":"86_CR56","volume-title":"Proceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research","author":"JA Wang","year":"2010","unstructured":"Wang JA, Guo M (2010) Vulnerability categorization using Bayesian networks. In: Proceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research"},{"key":"86_CR57","unstructured":"Zagorecki A (2010) Local probability distributions in Bayesian networks: knowledge elicitation and inference (Doctoral Dissertation, University of Pittsburgh, Pittsburgh). Retrieved from http:\/\/d-scholarship.pitt.edu\/6542\/1\/Zagorecki_April_21_2010.pdf"},{"key":"86_CR58","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1016\/j.ssci.2016.03.019","volume":"87","author":"G Zhang","year":"2016","unstructured":"Zhang G, Thai VV (2016) Expert elicitation and Bayesian network modeling for shipping accidents: a literature review. Saf Sci 87:53\u201362. https:\/\/doi.org\/10.1016\/j.ssci.2016.03.019","journal-title":"Saf Sci"},{"key":"86_CR59","doi-asserted-by":"publisher","first-page":"278","DOI":"10.1016\/j.enbuild.2012.11.007","volume":"57","author":"Y Zhao","year":"2013","unstructured":"Zhao Y, Xiao F, Wang S (2013) An intelligent chiller fault detection and diagnosis methodology using Bayesian belief network. Energy Build 57:278\u2013288. https:\/\/doi.org\/10.1016\/j.enbuild.2012.11.007","journal-title":"Energy Build"},{"issue":"2","key":"86_CR60","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1109\/MSP.2009.56","volume":"7","author":"M Zhivich","year":"2009","unstructured":"Zhivich M, Cunningham RK (2009) The real cost of software errors. IEEE Secur Privacy 7(2):87\u201390. https:\/\/doi.org\/10.1109\/MSP.2009.56","journal-title":"IEEE Secur Privacy"},{"key":"86_CR61","volume-title":"2018 IEEE International Conference on Systems, Man, and Cybernetics (SMC)","author":"Y Zhou","year":"2018","unstructured":"Zhou Y, Zhu C, Tang L, Zhang W, Wang P (2018) Cyber security inference based on a two-level Bayesian network framework. In: 2018 IEEE International Conference on Systems, Man, and Cybernetics (SMC)"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00086-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-021-00086-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00086-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,9,1]],"date-time":"2021-09-01T00:12:07Z","timestamp":1630455127000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-021-00086-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,1]]},"references-count":61,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,12]]}},"alternative-id":["86"],"URL":"https:\/\/doi.org\/10.1186\/s42400-021-00086-6","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,9,1]]},"assertion":[{"value":"12 August 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 April 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 September 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declaration"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"29"}}