{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T01:50:11Z","timestamp":1783648211954,"version":"3.55.0"},"reference-count":32,"publisher":"National Library of Serbia","issue":"4","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["ComSIS","COMPUT SCI INF SYST","COMPUT SCI INFORM SY","COMPUTER SCI INFORM","COMSIS J"],"published-print":{"date-parts":[[2025]]},"abstract":"<jats:p>Cyber incident forecasting has several applications within the security field, such as attack projection, intention recognition, attack prediction, or situational awareness. One of the main challenges of these issues lies in analysing the proneness of an entity to be attacked by an adversary evaluating the relevance of different target features or behaviours. This paper presents a methodology that defines the Attractiveness concept to address this issue. Attractiveness is the possession of features or the exhibition of behaviours in entities that raise interest for potential adversaries. Thus, the more significant the Attractiveness value is, the greater the proneness of attacking could be considered. The concept is decomposed into three main branches: basal attractiveness (relevance of the entity in the world), online reputation (the opinion of the individuals and the reach of the entity), and potential victimisation (the interest that the entity arouses for potential attackers). Machine Learning (ML) methods in combination with Information Retrieval (IR) and text mining techniques have been proposed to gather relevant information and identify hidden patterns and relations in past security incidents. With this approach, potential targets could reduce their Attractiveness, focusing on those aspects that can be remedied. Alternatively, future risky situations could be predicted to better prepare for proactive protection, detection, and response. The proposal has been validated through several experiments.<\/jats:p>","DOI":"10.2298\/csis250131060g","type":"journal-article","created":{"date-parts":[[2025,8,26]],"date-time":"2025-08-26T09:47:23Z","timestamp":1756201643000},"page":"1533-1553","source":"Crossref","is-referenced-by-count":2,"title":["Defining the attractiveness concept for cyber incidents forecasting"],"prefix":"10.2298","volume":"22","author":[{"given":"Javier","family":"Garc\u00eda-Ochoa","sequence":"first","affiliation":[{"name":"Rey Juan Carlos University, Department of Computing, ETSII, C\/ Tulip\u00e1n, s\/n, M\u00f3stoles, Madrid (Spain)"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alberto","family":"Fern\u00e1ndez-Isabel","sequence":"additional","affiliation":[{"name":"Rey Juan Carlos University, Department of Computing, ETSII, C\/ Tulip\u00e1n, s\/n, M\u00f3stoles, Madrid (Spain)"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Clara","family":"Contreras","sequence":"additional","affiliation":[{"name":"Rey Juan Carlos University, Department of Computing, ETSII, C\/ Tulip\u00e1n, s\/n, M\u00f3stoles, Madrid (Spain)"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"suffix":"R.","given":"Rub\u00e9n","family":"Fern\u00e1ndez","sequence":"additional","affiliation":[{"name":"Rey Juan Carlos University, Department of Computing, ETSII, C\/ Tulip\u00e1n, s\/n, M\u00f3stoles, Madrid (Spain)"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"suffix":"Isaac","given":"Diego","family":"de","sequence":"additional","affiliation":[{"name":"Rey Juan Carlos University, Department of Computing, ETSII, C\/ Tulip\u00e1n, s\/n, M\u00f3stoles, Madrid (Spain)"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marta","family":"Beltr\u00e1n","sequence":"additional","affiliation":[{"name":"Rey Juan Carlos University, Department of Computing, ETSII, C\/ Tulip\u00e1n, s\/n, M\u00f3stoles, Madrid (Spain)"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1078","reference":[{"key":"ref1","doi-asserted-by":"crossref","unstructured":"Abdlhamed, M., Kifayat, K., Shi, Q., Hurst, W.: A system for intrusion prediction in cloud computing. In: Proceedings of the International Conference on Internet of Things and Cloud Computing. pp. 1-9 (2016)","DOI":"10.1145\/2896387.2896420"},{"key":"ref2","doi-asserted-by":"crossref","unstructured":"Ahmed, A.A., Mohammed, M.F.: Sairf: A similarity approach for attack intention recognition using fuzzy min-max neural network. Journal of Computational Science 25, 467-473 (2018)","DOI":"10.1016\/j.jocs.2017.09.007"},{"key":"ref3","unstructured":"Ardagna, C., Corbiaux, S., Van Impe, K., Sfakianakis, A.: ENISA ThreatLandscape 2022. European Agency for Cybersecurity (2022)"},{"key":"ref4","doi-asserted-by":"crossref","unstructured":"Argyrous, G., Argyrous, G.: The chi-square test for independence. Statistics for Social Research pp. 257-284 (1997)","DOI":"10.1007\/978-1-349-14777-9_16"},{"key":"ref5","doi-asserted-by":"crossref","unstructured":"Awan, M.S.K., Dahabiyeh, L.: Corporate attractiveness index: A measure for assessing the potential of a cyber attack. In: 2018 9th International Conference on Information and Communication Systems (ICICS). pp. 1-6. IEEE (2018)","DOI":"10.1109\/IACS.2018.8355432"},{"key":"ref6","doi-asserted-by":"crossref","unstructured":"Bakdash, J.Z., Hutchinson, S., Zaroukian, E.G., Marusich, L.R., Thirumuruganathan, S., Sample, C., Hoffman, B., Das, G.: Malware in the future? forecasting of analyst detection of cyber events. Journal of Cybersecurity 4(1), tyy007 (2018)","DOI":"10.1093\/cybsec\/tyy007"},{"key":"ref7","doi-asserted-by":"crossref","unstructured":"Bar, A., Shapira, B., Rokach, L., Unger, M.: Identifying attack propagation patterns in honeypots using markov chains modeling and complex networks analysis. In: 2016 IEEE international conference on software science, technology and engineering (SWSTE). pp. 28-36. IEEE (2016)","DOI":"10.1109\/SWSTE.2016.13"},{"key":"ref8","doi-asserted-by":"crossref","unstructured":"Ben Fredj, O., Mihoub, A., Krichen, M., Cheikhrouhou, O., Derhab, A.: Cybersecurity attack prediction: a deep learning approach. In: 13th international conference on security of information and networks. pp. 1-6 (2020)","DOI":"10.1145\/3433174.3433614"},{"key":"ref9","doi-asserted-by":"crossref","unstructured":"Cho, J., Eling, M., Jung, K.: Spatial cyber loss clusters at county level and socioeconomic determinants of cyber risks. North American Actuarial Journal 29(2), 345-389 (2025)","DOI":"10.1080\/10920277.2024.2408263"},{"key":"ref10","doi-asserted-by":"crossref","unstructured":"Cioppi, M., Curina, I., Forlani, F., Pencarelli, T.: Online presence, visibility and reputation: a systematic literature review in management studies. Journal of Research in Interactive Marketing 13(4), 547-577 (2019)","DOI":"10.1108\/JRIM-11-2018-0139"},{"key":"ref11","unstructured":"CrowdStrike Holdings Inc: 2023 Global Threat Report. https:\/\/www.crowdstrike.com\/globalthreat-report\/ (2023), online accessed: 2024-09-02"},{"key":"ref12","doi-asserted-by":"crossref","unstructured":"Dalal, S., Manoharan, P., Lilhore, U.K., Seth, B., Mohammed alsekait, D., Simaiya, S., Hamdi, M., Raahemifar, K.: Extremely boosted neural network for more accurate multi-stage cyber attack prediction in cloud computing environment. Journal of Cloud Computing 12(1), 14 (2023)","DOI":"10.1186\/s13677-022-00356-9"},{"key":"ref13","unstructured":"Determ d.o.o.: Determ - ai media monitoring and analytics software. https:\/\/www.determ.com\/ (2024), online accesssed: 2024-09-02"},{"key":"ref14","doi-asserted-by":"crossref","unstructured":"Divine, G., Norton, H.J., Hunt, R., Dienemann, J.: A review of analysis and sample size calculation considerations for wilcoxon tests. Anesthesia & Analgesia 117(3), 699-710 (2013)","DOI":"10.1213\/ANE.0b013e31827f53d7"},{"key":"ref15","doi-asserted-by":"crossref","unstructured":"Djajasinga, N.D., Fatmawati, E., Syamsuddin, S., Sukomardojo, T., Sulistyo, A.B.: Risk management in the digital era addressing cybersecurity challenges in business. Branding: Jurnal Manajemen dan Bisnis 2(2) (2023)","DOI":"10.15575\/jb.v2i2.31919"},{"key":"ref16","doi-asserted-by":"crossref","unstructured":"Fang, X., Xu, M., Xu, S., Zhao, P.: A deep learning framework for predicting cyber attacks rates. EURASIP Journal on Information security 2019, 1-11 (2019)","DOI":"10.1186\/s13635-019-0090-6"},{"key":"ref17","doi-asserted-by":"crossref","unstructured":"GhasemiGol, M., Ghaemi-Bafghi, A., Takabi, H.: A comprehensive approach for network attack forecasting. Computers & Security 58, 83-105 (2016)","DOI":"10.1016\/j.cose.2015.11.005"},{"key":"ref18","doi-asserted-by":"crossref","unstructured":"Han, J., Pei, J., Yin, Y., Mao, R.: Mining frequent patterns without candidate generation: A frequent-pattern tree approach. Data mining and knowledge discovery 8, 53-87 (2004)","DOI":"10.1023\/B:DAMI.0000005258.31418.83"},{"key":"ref19","doi-asserted-by":"crossref","unstructured":"Huang, K., Zhou, C., Tian, Y.C., Yang, S., Qin, Y.: Assessing the physical impact of cyberattacks on industrial cyber-physical systems. IEEE Transactions on Industrial Electronics 65(10), 8153-8162 (2018)","DOI":"10.1109\/TIE.2018.2798605"},{"key":"ref20","doi-asserted-by":"crossref","unstructured":"Hus\u00e1k, M., Ka\u0161par, J.: Towards predicting cyber attacks using information exchange and data mining. In: 2018 14th International Wireless Communications & Mobile Computing Conference (IWCMC). pp. 536-541. IEEE (2018)","DOI":"10.1109\/IWCMC.2018.8450512"},{"key":"ref21","doi-asserted-by":"crossref","unstructured":"Hus\u00e1k, M., Kom\u00e1rkov\u00e1, J., Bou-Harb, E., \u010celeda, P.: Survey of attack projection, prediction, and forecasting in cyber security. IEEE Communications Surveys & Tutorials 21(1), 640-660 (2018)","DOI":"10.1109\/COMST.2018.2871866"},{"key":"ref22","doi-asserted-by":"crossref","unstructured":"Jain, J.K.,Waoo, A.A.: An artificial neural network technique for prediction of cyber-attack using intrusion detection system. Journal of Artificial Intelligence, Machine Learning and Neural Network (JAIMLNN) ISSN pp. 2799-1172 (2023)","DOI":"10.55529\/jaimlnn.32.33.42"},{"key":"ref23","doi-asserted-by":"crossref","unstructured":"van der Kleij, R., Schraagen, J.M., Cadet, B., Young, H.: Developing decision support for cybersecurity threat and incident managers. Computers & Security 113, 102535 (2022)","DOI":"10.1016\/j.cose.2021.102535"},{"key":"ref24","doi-asserted-by":"crossref","unstructured":"Kuhn, M.: Building predictive models in r using the caret package. Journal of statistical software 28, 1-26 (2008)","DOI":"10.18637\/jss.v028.i05"},{"key":"ref25","unstructured":"Mandiant: M-trends 2023. https:\/\/www.mandiant.com\/m-trends\/ (2023), online accessed: 2024-09-02"},{"key":"ref26","doi-asserted-by":"crossref","unstructured":"Okutan, A., Werner, G., Yang, S.J., McConky, K.: Forecasting cyberattacks with incomplete, imbalanced, and insignificant data. Cybersecurity 1, 1-16 (2018)","DOI":"10.1186\/s42400-018-0016-5"},{"key":"ref27","doi-asserted-by":"crossref","unstructured":"Okutan, A., Yang, S.J., McConky, K., Werner, G.: Capture: cyberattack forecasting using nonstationary features with time lags. In: 2019 IEEE Conference on Communications and Network Security (CNS). pp. 205-213. IEEE (2019)","DOI":"10.1109\/CNS.2019.8802639"},{"key":"ref28","doi-asserted-by":"crossref","unstructured":"Panigrahi, R., Borah, S., Bhoi, A.K., Mallick, P.K.: Intrusion detection systems (ids)-an overview with a generalized framework. Cognitive Informatics and Soft Computing: Proceeding of CISC 2019 pp. 107-117 (2020)","DOI":"10.1007\/978-981-15-1451-7_11"},{"key":"ref29","doi-asserted-by":"crossref","unstructured":"Polatidis, N., Pimenidis, E., Pavlidis, M., Papastergiou, S., Mouratidis, H.: From product recommendation to cyber-attack prediction: Generating attack graphs and predicting future attacks. Evolving Systems 11, 479-490 (2020)","DOI":"10.1007\/s12530-018-9234-z"},{"key":"ref30","doi-asserted-by":"crossref","unstructured":"Subroto, A., Apriyana, A.: Cyber risk prediction through social media big data analytics and statistical machine learning. Journal of Big Data 6(1), 50 (2019)","DOI":"10.1186\/s40537-019-0216-1"},{"key":"ref31","doi-asserted-by":"crossref","unstructured":"Szymoniak, S., Foks, K.: Open source intelligence opportunities and challenges-a review. Advances in Science and Technology. Research Journal 18(3) (2024)","DOI":"10.12913\/22998624\/186036"},{"key":"ref32","doi-asserted-by":"crossref","unstructured":"Wang, K., Tang, L., Han, J., Liu, J.: Top down fp-growth for association rule mining. In: Advances in Knowledge Discovery and Data Mining: 6th Pacific-Asia Conference, PAKDD 2002 Taipei, Taiwan, May 6-8, 2002 Proceedings 6. pp. 334-340. Springer (2002)","DOI":"10.1007\/3-540-47887-6_34"}],"container-title":["Computer Science and Information Systems"],"original-title":[],"language":"en","deposited":{"date-parts":[[2025,11,24]],"date-time":"2025-11-24T12:34:08Z","timestamp":1763987648000},"score":1,"resource":{"primary":{"URL":"https:\/\/doiserbia.nb.rs\/Article.aspx?ID=1820-02142500060G"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":32,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2025]]}},"URL":"https:\/\/doi.org\/10.2298\/csis250131060g","relation":{},"ISSN":["1820-0214","2406-1018"],"issn-type":[{"value":"1820-0214","type":"print"},{"value":"2406-1018","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}