{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T10:52:38Z","timestamp":1778755958256,"version":"3.51.4"},"reference-count":51,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2023,9,1]],"date-time":"2023-09-01T00:00:00Z","timestamp":1693526400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,9,1]],"date-time":"2023-09-01T00:00:00Z","timestamp":1693526400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100000145","name":"Division of Information and Intelligent Systems","doi-asserted-by":"publisher","award":["2202395"],"award-info":[{"award-number":["2202395"]}],"id":[{"id":"10.13039\/100000145","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100004682","name":"Oracle","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100004682","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100016461","name":"Life Sciences Division, Army Research Office","doi-asserted-by":"publisher","award":["W911NF2110299"],"award-info":[{"award-number":["W911NF2110299"]}],"id":[{"id":"10.13039\/100016461","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Early attack detection is essential to ensure the security of complex networks, especially those in critical infrastructures. This is particularly crucial in networks with multi-stage attacks, where multiple nodes are connected to external sources, through which attacks could enter and quickly spread to other network elements. Bayesian attack graphs (BAGs) are powerful models for security risk assessment and mitigation in complex networks, which provide the probabilistic model of attackers\u2019 behavior and attack progression in the network. Most attack detection techniques developed for BAGs rely on the assumption that network compromises will be detected through routine monitoring, which is unrealistic given the ever-growing complexity of threats. This paper derives the optimal minimum mean square error (MMSE) attack detection and monitoring policy for the most general form of BAGs. By exploiting the structure of BAGs and their partial and imperfect monitoring capacity, the proposed detection policy achieves the MMSE optimality possible only for linear-Gaussian state space models using Kalman filtering. An adaptive resource monitoring policy is also introduced for monitoring nodes if the expected predictive error exceeds a user-defined value. Exact and efficient matrix-form computations of the proposed policies are provided, and their high performance is demonstrated in terms of the accuracy of attack detection and the most efficient use of available resources using synthetic Bayesian attack graphs with different topologies.<\/jats:p>","DOI":"10.1186\/s42400-023-00155-y","type":"journal-article","created":{"date-parts":[[2023,9,1]],"date-time":"2023-09-01T01:01:53Z","timestamp":1693530113000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":32,"title":["Optimal monitoring and attack detection of networks modeled by Bayesian attack graphs"],"prefix":"10.1186","volume":"6","author":[{"given":"Armita","family":"Kazeminajafabadi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mahdi","family":"Imani","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,9,1]]},"reference":[{"key":"155_CR1","doi-asserted-by":"crossref","unstructured":"Agmon N, Shabtai A, Puzis R (2019) Deployment optimization of IoT devices through attack graph analysis. In: Proceedings of the 12th conference on security and privacy in wireless and mobile networks, pp 192\u2013202","DOI":"10.1145\/3317549.3323411"},{"issue":"10","key":"155_CR2","doi-asserted-by":"publisher","first-page":"3488","DOI":"10.1109\/TSMC.2019.2915940","volume":"50","author":"AT Al Ghazo","year":"2019","unstructured":"Al Ghazo AT, Ibrahim M, Ren H, Kumar R (2019) A2G2V: automatic attack graph generation and visualization and its applications to computer and SCADA networks. IEEE Trans Syst Man Cybern: Syst 50(10):3488\u20133498","journal-title":"IEEE Trans Syst Man Cybern: Syst"},{"issue":"3","key":"155_CR3","doi-asserted-by":"publisher","first-page":"313","DOI":"10.33640\/2405-609X.3235","volume":"8","author":"Z Al-Araji","year":"2022","unstructured":"Al-Araji Z, Syed Ahmad SS, Abdullah RS et al (2022) Attack prediction to enhance attack path discovery using improved attack graph. Karbala Int J Mod Sci 8(3):313\u2013329","journal-title":"Karbala Int J Mod Sci"},{"key":"155_CR4","doi-asserted-by":"crossref","unstructured":"Albanese M, Jajodia S, Noel S (2012) Time-efficient and cost-effective network hardening using attack graphs. In: IEEE\/IFIP international conference on dependable systems and networks (DSN 2012). IEEE, pp 1\u201312","DOI":"10.1109\/DSN.2012.6263942"},{"key":"155_CR5","doi-asserted-by":"crossref","unstructured":"Alhomidi M, Reed M (2013) Risk assessment and analysis through population-based attack graph modelling. In: World Congress on Internet Security (WorldCIS-2013). IEEE, pp 19\u201324","DOI":"10.1109\/WorldCIS.2013.6751011"},{"issue":"12","key":"155_CR6","doi-asserted-by":"publisher","first-page":"6641","DOI":"10.1109\/TAC.2017.2714903","volume":"62","author":"C-Z Bai","year":"2017","unstructured":"Bai C-Z, Gupta V, Pasqualetti F (2017) On Kalman filtering with compromised sensors: Attack stealthiness and performance bounds. IEEE Trans Autom Control 62(12):6641\u20136648","journal-title":"IEEE Trans Autom Control"},{"key":"155_CR7","doi-asserted-by":"crossref","unstructured":"Capobianco F, George R, Huang K, Jaeger T, Krishnamurthy S, Qian Z, Payer M, Yu P (2019) Employing attack graphs for intrusion detection. In: Proceedings of the new security paradigms workshop, pp 16\u201330","DOI":"10.1145\/3368860.3368862"},{"key":"155_CR8","doi-asserted-by":"publisher","first-page":"636","DOI":"10.1016\/j.future.2020.03.014","volume":"108","author":"T Chadza","year":"2020","unstructured":"Chadza T, Kyriakopoulos KG, Lambotharan S (2020) Analysis of hidden Markov model learning algorithms for the detection and prediction of multi-stage network attacks. Futur Gener Comput Syst 108:636\u2013649","journal-title":"Futur Gener Comput Syst"},{"issue":"3","key":"155_CR9","doi-asserted-by":"publisher","first-page":"4511","DOI":"10.3233\/JIFS-189711","volume":"41","author":"YY Chen","year":"2021","unstructured":"Chen YY, Xu B, Long J (2021) Information security assessment of wireless sensor networks based on Bayesian attack graphs. J Intell Fuzzy Syst 41(3):4511\u20134517","journal-title":"J Intell Fuzzy Syst"},{"key":"155_CR10","doi-asserted-by":"crossref","unstructured":"Chockalingam S, Pieters W, Teixeira A, Gelder Pv (2017) Bayesian network models in cyber security: a systematic review. In: Nordic conference on secure IT systems. Springer, pp 105\u2013122","DOI":"10.1007\/978-3-319-70290-2_7"},{"key":"155_CR11","doi-asserted-by":"crossref","unstructured":"Dantu R, Loper K, Kolan P (2004) Risk management using behavior based attack graphs. In: International Conference on Information Technology: Coding and Computing, 2004. Proceedings. ITCC 2004., 1:445\u2013449. IEEE","DOI":"10.1109\/ITCC.2004.1286496"},{"key":"155_CR12","doi-asserted-by":"crossref","unstructured":"Frigault M, Wang L (2008) Measuring network security using Bayesian network-based attack graphs. In: 2008 32nd Annual IEEE International Computer Software and Applications Conference, pp. 698\u2013703. IEEE","DOI":"10.1109\/COMPSAC.2008.88"},{"key":"155_CR13","doi-asserted-by":"crossref","unstructured":"Frigault M, Wang L, Jajodia S, Singhal A (2017) Measuring the overall network security by combining CVSS scores based on attack graphs and Bayesian networks 1\u201323","DOI":"10.1007\/978-3-319-66505-4_1"},{"issue":"1","key":"155_CR14","doi-asserted-by":"publisher","first-page":"134","DOI":"10.1109\/TDSC.2017.2751478","volume":"17","author":"P Holgado","year":"2017","unstructured":"Holgado P, Villagr\u00e1 VA, Vazquez L (2017) Real-time multistep attack prediction based on hidden Markov models. IEEE Trans Dependable Secure Comput 17(1):134\u2013147","journal-title":"IEEE Trans Dependable Secure Comput"},{"issue":"4","key":"155_CR15","doi-asserted-by":"publisher","first-page":"561","DOI":"10.3233\/JCS-130475","volume":"21","author":"J Homer","year":"2013","unstructured":"Homer J, Zhang S, Ou X, Schmidt D, Du Y, Rajagopalan SR, Singhal A (2013) Aggregating vulnerability metrics in enterprise networks using attack graphs. J Comput Secur 21(4):561\u2013597","journal-title":"J Comput Secur"},{"issue":"1","key":"155_CR16","first-page":"1","volume":"24","author":"Z Hu","year":"2020","unstructured":"Hu Z, Zhu M, Liu P (2020) Adaptive cyber defense against multi-stage attacks using learning-based POMDP. ACM Transactions on Privacy and Security (TOPS) 24(1):1\u201325","journal-title":"ACM Transactions on Privacy and Security (TOPS)"},{"issue":"1","key":"155_CR17","doi-asserted-by":"publisher","first-page":"640","DOI":"10.1109\/COMST.2018.2871866","volume":"21","author":"M Hus\u00e1k","year":"2018","unstructured":"Hus\u00e1k M, Kom\u00e1rkov\u00e1 J, Bou-Harb E, \u010celeda P (2018) Survey of attack projection, prediction, and forecasting in cyber security. IEEE Commun Surv Tutor 21(1):640\u2013660","journal-title":"IEEE Commun Surv Tutor"},{"key":"155_CR18","doi-asserted-by":"crossref","unstructured":"Hu Z, Zhu M, Liu P (2017) Online algorithms for adaptive cyber defense on Bayesian attack graphs. In: Proceedings of the 2017 workshop on moving target defense, pp 99\u2013109","DOI":"10.1145\/3140549.3140556"},{"key":"155_CR19","doi-asserted-by":"crossref","unstructured":"Krisper M, Dobaj J, Macher G, Schmittner C (2019) Riskee: a risk-tree based method for assessing risk in cyber security. In: Systems, Software and Services Process Improvement: 26th European Conference, EuroSPI 2019, Edinburgh, UK, September 18\u201320, 2019, Proceedings 26, pp. 45\u201356. Springer","DOI":"10.1007\/978-3-030-28005-5_4"},{"key":"155_CR20","doi-asserted-by":"crossref","unstructured":"Kumar PR, Varaiya P (2015) Stochastic systems: Estimation, identification, and adaptive control. SIAM","DOI":"10.1137\/1.9781611974263"},{"key":"155_CR21","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2019.100219","volume":"35","author":"HS Lallie","year":"2020","unstructured":"Lallie HS, Debattista K, Bal J (2020) A review of attack graph and attack tree visual syntax in cyber security. Comput Sci Rev 35:100219","journal-title":"Comput Sci Rev"},{"key":"155_CR22","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101974","volume":"97","author":"T Li","year":"2020","unstructured":"Li T, Liu Y, Liu Y, Xiao Y, Nguyen NA (2020) Attack plan recognition using hidden Markov and probabilistic inference. Comput Secur 97:101974","journal-title":"Comput Secur"},{"key":"155_CR23","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1016\/j.inffus.2018.04.002","volume":"46","author":"C Liang","year":"2019","unstructured":"Liang C, Wen F, Wang Z (2019) Trust-based distributed Kalman filtering for target tracking under malicious cyber attacks. Information Fusion 46:44\u201350","journal-title":"Information Fusion"},{"key":"155_CR24","doi-asserted-by":"crossref","unstructured":"Liu S-c, Liu Y (2016) Network security risk assessment method based on HMM and attack graph model. In: 2016 17th IEEE\/ACIS International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel\/distributed Computing (SNPD), pp. 517\u2013522. IEEE","DOI":"10.1109\/SNPD.2016.7515951"},{"key":"155_CR25","doi-asserted-by":"crossref","unstructured":"Liu J, Liu B, Zhang R, Wang C (2019) Multi-step attack scenarios mining based on neural network and Bayesian network attack graph. In: International conference on artificial intelligence and security. Springer, pp 62\u201374","DOI":"10.1007\/978-3-030-24265-7_6"},{"issue":"5","key":"155_CR26","doi-asserted-by":"publisher","first-page":"155013292210978","DOI":"10.1177\/15501329221097817","volume":"18","author":"Y Ma","year":"2022","unstructured":"Ma Y, Wu Y, Yu D, Ding L, Chen Y (2022) Vulnerability association evaluation of internet of thing devices based on attack graph. Int J Distrib Sens Netw 18(5):15501329221097816","journal-title":"Int J Distrib Sens Netw"},{"key":"155_CR27","doi-asserted-by":"crossref","unstructured":"Malzahn D, Birnbaum Z, Wright-Hamor C (2020) Automated vulnerability testing via executable attack graphs. In: 2020 international conference on cyber security and protection of digital services (Cyber Security). IEEE, pp 1\u201310","DOI":"10.1109\/CyberSecurity49315.2020.9138852"},{"key":"155_CR28","doi-asserted-by":"crossref","unstructured":"Matthews I, Mace J, Soudjani S, van Moorsel A (2020) Cyclic Bayesian attack graphs: a systematic computational approach. In: 2020 IEEE 19th international conference on trust, security and privacy in computing and communications (TrustCom). IEEE, pp 129\u2013136","DOI":"10.1109\/TrustCom50675.2020.00030"},{"key":"155_CR29","doi-asserted-by":"crossref","unstructured":"Miehling E, Rasouli M, Teneketzis D (2015) Optimal defense policies for partially observable spreading processes on Bayesian attack graphs. In: Proceedings of the second ACM workshop on moving target defense, pp 67\u201376","DOI":"10.1145\/2808475.2808482"},{"key":"155_CR30","unstructured":"Munoz\u00a0Gonzalez L, Lupu E (2016) Bayesian attack graphs for security risk assessment. IST-153 Workshop on Cyber Resilience"},{"issue":"2","key":"155_CR31","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1109\/TDSC.2016.2627033","volume":"16","author":"L Mu\u00f1oz-Gonz\u00e1lez","year":"2017","unstructured":"Mu\u00f1oz-Gonz\u00e1lez L, Sgandurra D, Barr\u00e8re M, Lupu EC (2017) Exact inference techniques for the analysis of Bayesian attack graphs. IEEE Trans Dependable Secure Comput 16(2):231\u2013244","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"155_CR32","doi-asserted-by":"crossref","unstructured":"Nguyen HH, Palani K, Nicol DM (2017) An approach to incorporating uncertainty in network security analysis. In: Proceedings of the hot topics in science of security: symposium and bootcamp, pp 74\u201384","DOI":"10.1145\/3055305.3055308"},{"key":"155_CR33","unstructured":"Nipkow T et al (2012) Advances in probabilistic model checking. Software Safety and Security: Tools for Analysis and Verification 33(126)"},{"key":"155_CR34","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1007\/s10922-008-9109-x","volume":"16","author":"S Noel","year":"2008","unstructured":"Noel S, Jajodia S (2008) Optimal ids sensor placement and alert prioritization using attack graphs. J Netw Syst Manage 16:259\u2013275","journal-title":"J Netw Syst Manage"},{"key":"155_CR35","doi-asserted-by":"crossref","unstructured":"Noel S, Jajodia S (2014) Metrics suite for network attack graph analytics. In: Proceedings of the 9th Annual Cyber and Information Security Research Conference, pp 5\u20138","DOI":"10.1145\/2602087.2602117"},{"key":"155_CR36","doi-asserted-by":"crossref","unstructured":"Noel S, Jajodia S (2017) A suite of metrics for network attack graph analytics. Network Security Metrics 141\u2013176","DOI":"10.1007\/978-3-319-66505-4_7"},{"key":"155_CR37","doi-asserted-by":"crossref","unstructured":"Ou X, Boyer WF, McQueen MA (2006) A scalable approach to attack graph generation. In: Proceedings of the 13th ACM Conference on Computer and Communications Security, pp 336\u2013345","DOI":"10.1145\/1180405.1180446"},{"issue":"1","key":"155_CR38","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1109\/TDSC.2011.34","volume":"9","author":"N Poolsappasit","year":"2011","unstructured":"Poolsappasit N, Dewri R, Ray I (2011) Dynamic security risk management using Bayesian attack graphs. IEEE Trans Dependable Secure Comput 9(1):61\u201374","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"155_CR39","unstructured":"Radack SM et al (2007) The Common Vulnerability Scoring System (CVSS)"},{"key":"155_CR40","doi-asserted-by":"crossref","unstructured":"Ramaki AA, Khosravi-Farmad M, Bafghi AG (2015) Real time alert correlation and prediction using Bayesian networks. In: 2015 12th International Iranian Society of Cryptology Conference on Information Security and Cryptology (ISCISC), pp 98\u2013103. IEEE","DOI":"10.1109\/ISCISC.2015.7387905"},{"key":"155_CR41","doi-asserted-by":"crossref","unstructured":"Sahu A, Davis K (2021) Structural learning techniques for Bayesian attack graphs in cyber physical power systems. In: 2021 IEEE Texas power and energy conference (TPEC). IEEE, pp 1\u20136","DOI":"10.1109\/TPEC51183.2021.9384933"},{"key":"155_CR42","doi-asserted-by":"crossref","unstructured":"S\u00e4rkk\u00e4 S (2013) Bayesian filtering and smoothing. Cambridge university press (3)","DOI":"10.1017\/CBO9781139344203"},{"issue":"4","key":"155_CR43","first-page":"735","volume":"7","author":"J Sembiring","year":"2015","unstructured":"Sembiring J, Ramadhan M, Gondokaryono YS, Arman AA (2015) Network security risk analysis using improved MulVAL Bayesian attack graphs. Int J Electr Eng Inform 7(4):735","journal-title":"Int J Electr Eng Inform"},{"key":"155_CR44","doi-asserted-by":"crossref","unstructured":"Singhal A, Ou X (2017) Security risk analysis of enterprise networks using probabilistic attack graphs. Network Security Metrics 53\u201373","DOI":"10.1007\/978-3-319-66505-4_3"},{"key":"155_CR45","unstructured":"Stan O, Bitton R, Ezrets M, Dadon M, Inokuchi M, Yoshinobu O, Tomohiko Y, Elovici Y, Shabtai A (2020) Extending attack graphs to represent cyber-attacks in communication protocols and modern it networks. IEEE Trans Depend Secure Comput"},{"issue":"10","key":"155_CR46","doi-asserted-by":"publisher","first-page":"2506","DOI":"10.1109\/TIFS.2018.2821095","volume":"13","author":"X Sun","year":"2018","unstructured":"Sun X, Dai J, Liu P, Singhal A, Yen J (2018) Using Bayesian networks for probabilistic identification of zero-day attack paths. IEEE Trans Inf Forensics Secur 13(10):2506\u20132521","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"155_CR47","unstructured":"Thanthrige USK, Samarabandu J, Wang X (2016) Intrusion alert prediction using a hidden Markov model. arXiv:1610.07276"},{"key":"155_CR48","unstructured":"Wang X, Cheng M, Eaton J, Hsieh C-J, Wu F (2018) Attack graph convolutional networks by adding fake nodes. arXiv:1810.10751"},{"key":"155_CR49","doi-asserted-by":"crossref","unstructured":"Wang S, Zhang Z, Kadobayashi Y (2013) Exploring attack graph for cost-benefit security hardening: a probabilistic approach. Comput Secur 32:158\u2013169","DOI":"10.1016\/j.cose.2012.09.013"},{"key":"155_CR50","unstructured":"Welch G, Bishop G et al (1995) An introduction to the Kalman filter"},{"key":"155_CR51","doi-asserted-by":"crossref","unstructured":"Yu T, Sekar V, Seshan S, Agarwal Y, Xu C (2015) Handling a trillion (unfixable) flaws on a billion devices: Rethinking network security for the internet-of-things. In: Proceedings of the 14th ACM workshop on hot topics in networks, pp 1\u20137","DOI":"10.1145\/2834050.2834095"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-023-00155-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-023-00155-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-023-00155-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,1]],"date-time":"2023-09-01T01:03:16Z","timestamp":1693530196000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-023-00155-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,9,1]]},"references-count":51,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["155"],"URL":"https:\/\/doi.org\/10.1186\/s42400-023-00155-y","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,9,1]]},"assertion":[{"value":"18 January 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 March 2023","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 September 2023","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"22"}}