{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,3]],"date-time":"2025-12-03T17:53:17Z","timestamp":1764784397713,"version":"build-2065373602"},"reference-count":59,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2020,3,23]],"date-time":"2020-03-23T00:00:00Z","timestamp":1584921600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Early detection of the security incidents and correct forecasting of the attack development is the basis for the efficient and timely response to cyber threats. The development of the attack depends on future steps available to the attackers, their goals, and their motivation\u2014that is, the attacker \u201cprofile\u201d that defines the malefactor behaviour in the system. Usually, the \u201cattacker profile\u201d is a set of attacker\u2019s attributes\u2014both inner such as motives and skills, and external such as existing financial support and tools used. The definition of the attacker\u2019s profile allows determining the type of the malefactor and the complexity of the countermeasures, and may significantly simplify the attacker attribution process when investigating security incidents. The goal of the paper is to analyze existing techniques of the attacker\u2019s behaviour, the attacker\u2019 profile specifications, and their application for the forecasting of the attack future steps. The implemented analysis allowed outlining the main advantages and limitations of the approaches to attack forecasting and attacker\u2019s profile constructing, existing challenges, and prospects in the area. The approach for attack forecasting implementation is suggested that specifies further research steps and is the basis for the development of an attacker behaviour forecasting technique.<\/jats:p>","DOI":"10.3390\/info11030168","type":"journal-article","created":{"date-parts":[[2020,3,24]],"date-time":"2020-03-24T07:16:08Z","timestamp":1585034168000},"page":"168","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":26,"title":["Attacker Behaviour Forecasting Using Methods of Intelligent Data Analysis: A Comparative Review and Prospects"],"prefix":"10.3390","volume":"11","author":[{"given":"Elena","family":"Doynikova","sequence":"first","affiliation":[{"name":"St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences, St. Petersburg 199178, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2923-4954","authenticated-orcid":false,"given":"Evgenia","family":"Novikova","sequence":"additional","affiliation":[{"name":"St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences, St. Petersburg 199178, Russia"},{"name":"Saint Petersburg Electrotechnical University \u201cLETI\u201d, Department of computer science and technology, St. Petersburg 197022, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6859-7120","authenticated-orcid":false,"given":"Igor","family":"Kotenko","sequence":"additional","affiliation":[{"name":"St. Petersburg Institute for Informatics and Automation of the Russian Academy of Sciences, St. Petersburg 199178, Russia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2020,3,23]]},"reference":[{"key":"ref_1","unstructured":"Howard, J.D., and Longstaff, T.A. (1998). A Common Language for Computer Security Incidents, Sandia National Labs."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"65","DOI":"10.13052\/jcsm2245-1439.414","article-title":"Cyber security and the Internet of Things: Vulnerabilities, threats, intruders and attacks","volume":"4","author":"Abomhara","year":"2015","journal-title":"J. Cyber Secur. Mob."},{"key":"ref_3","unstructured":"Aliyev, V. (2010). Using Honeypots to Study Skill Level of Attackers Based on the Exploited Vulnerabilities in the Network. [Ph.D. Thesis, Chalmers University of technology]."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"6","DOI":"10.1186\/s41044-016-0006-0","article-title":"Detection and prediction of insider threats to cyber security: A systematic literature review and metaanalysis","volume":"1","author":"Gheyas","year":"2016","journal-title":"Big Data Anal."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"640","DOI":"10.1109\/COMST.2018.2871866","article-title":"Survey of Attack Projection, Prediction, and Forecasting in Cyber Security","volume":"21","year":"2019","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Yang, S.J., Du, H., Holsopple, J., and Sudit, M. (2014). Attack Projection. Cyber Defense and Situational Awareness, Springer.","DOI":"10.1007\/978-3-319-11391-3_12"},{"key":"ref_7","unstructured":"Ahmed, A.A., and Zaman, N.A.K. (2017). Attack intention recognition: A review. IJ Netw. Secur., 244\u2013250."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Abdlhamed, M., Kifayat, K., Shi, Q., and Hurst, W. (2017). Intrusion Prediction Systems. Information Fusion for Cyber-Security Analytics, Springer.","DOI":"10.1007\/978-3-319-44257-0_7"},{"key":"ref_9","unstructured":"Askoxylakis, I., Ioannidis, S., Katsikas, S., and Meadows, C. (2016). On Attacker Models and Profiles for Cyber-Physical Systems. Lecture Notes in Computer Science, Proceedings of the ESORICS, 2016, Springer."},{"key":"ref_10","unstructured":"Corman, J., and Etue, D. (2012, January 9\u201311). Adversary ROI: Evaluating Security from the Threat Actor\u2019s Perspective. Proceedings of the RSA Conference Europe 2012, San Francisco, CA, USA."},{"key":"ref_11","unstructured":"Heckman, R.M. (2020, January 22). Attacker Classification to Aid Targeting Critical Systems for Threat Modelling and Security Review. Available online: www.rockyh.net\/papers\/AttackerClassification.pdf."},{"key":"ref_12","unstructured":"Cardenas, A.A., Amin, S.M., Sinopoli, B., Giani, A., Perrig, A., and Sastry, S.S. (2009). Challenges for Securing Cyber Physical Systems, Workshop on Future Directions in Cyber-physical Systems Security."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"LeMay, E., Ford, M.D., Keefe, K., Sanders, W.H., and Muehrcke, C. (2011, January 5\u20138). Model-Based Security Metrics Using Adversary View Security Evaluation (ADVISE). Proceedings of the 2011 Eighth International Conference on Quantitative Evaluation of Systems, Aachen, Germany.","DOI":"10.1109\/QEST.2011.34"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"1434","DOI":"10.1016\/j.adhoc.2009.04.012","article-title":"Rethinking security properties, threat models, and the design space in sensor networks: A case study in SCADA systems","volume":"7","author":"Cardenas","year":"2009","journal-title":"Ad Hoc Netw."},{"key":"ref_15","first-page":"179","article-title":"Cyberterrorism: Postmodern state of chaos","volume":"17","author":"Matusitz","year":"2008","journal-title":"Inf. Secur. J."},{"key":"ref_16","first-page":"288","article-title":"Activism, hacktivism, and cyberterrorism: The internet as a tool for influencing foreign policy","volume":"239","author":"Denning","year":"2001","journal-title":"Netw. Netwars Future Terror Crime Militancy"},{"key":"ref_17","first-page":"12","article-title":"Attack Trees\u2014Modeling Security Threats","volume":"24","author":"Schneier","year":"1999","journal-title":"Dr. Dobb\u2019s J."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1109\/MSECP.2003.1236235","article-title":"Impact Analysis of Faults and Attacks in Large-Scale Networks","volume":"1","author":"Hariri","year":"2003","journal-title":"IEEE Secur. Priv."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Ingols, K., Chu, M., Lippmann, R., Webster, S., and Boyer, S. (2009, January 7\u201311). Modeling Modern Network Attacks and Countermeasures Using Attack Graphs. Proceedings of the 2009 Annual Computer Security Applications Conference (ACSAC\u201909), Honolulu, HI, USA.","DOI":"10.1109\/ACSAC.2009.21"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Kheir, N., Cuppens-Boulahia, N., Cuppens, F., and Debar, H. (2010, January 20\u201322). A Service Dependency Model for Cost-Sensitive Intrusion Response. Proceedings of the 15th European Symposium on Research in Computer Security (ESORICS), Athens, Greece.","DOI":"10.1007\/978-3-642-15497-3_38"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"216","DOI":"10.1007\/11909033_20","article-title":"Attack Graph based Evaluation of Network Security","volume":"4237","author":"Kotenko","year":"2006","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Kotenko, I., Stepashkin, M., and Doynikova, E. (2011, January 9\u201311). Security Analysis of Computer-aided Systems Taking into Account Social Engineering Attacks. Proceedings of the 19th Euromicro International Conference on Parallel, Distributed and Network-Based Processing (PDP 2011), Los Alamitos, CA, USA.","DOI":"10.1109\/PDP.2011.62"},{"key":"ref_23","unstructured":"Noel, S., Jajodia, S., O\u2019Berry, B., and Jacobs, M. (2003, January 8\u201312). Efficient minimum-cost network hardening via exploit dependency graphs. Proceedings of the 19th Annual Computer Security Applications Conference (ACSAC\u201903), Las Vegas, NV, USA."},{"key":"ref_24","unstructured":"Wang, L., Jajodia, S., Singhal, A., and Noel, S. k-Zero Day Safety: Measuring the Security Risk of Networks against Unknown Attacks. Proceedings of the 15th European Conference on Research in Computer Security."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1016\/j.cose.2015.11.005","article-title":"A comprehensive approach for network attack forecasting","volume":"58","author":"GhasemiGol","year":"2016","journal-title":"Comput. Secur."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Atluri, V. (2008). An Attack Graph-Based Probabilistic Security Metric. Lecture Notes in Computer Science 5094, Proceedings of the Data and Applications Security XXII (DBSec 2008), Springer.","DOI":"10.1007\/978-3-540-70567-3"},{"key":"ref_27","first-page":"211","article-title":"Improvement of attack graphs for cybersecurity monitoring: Handling of inaccuracies, processing of cycles, mapping of incidents and automatic countermeasure selection","volume":"57","author":"Kotenko","year":"2018","journal-title":"SPIIRAS Proc."},{"key":"ref_28","unstructured":"An, S., Eom, T., Park, J.S., Hong, J.B., Nhlabatsi, A., Fetais, N., Khan, K.M., and Kim, D.S. (2020, January 25). CloudSafe: A Tool for an Automated Security Analysis for Cloud Computing. Available online: https:\/\/arxiv.org\/abs\/1903.04271v1."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Rashid, T., Agrafiotis, I., and Nurse, J.R.C. (2016, January 28). A New Take on Detecting Insider Threats: Exploring the Use of Hidden Markov Mode. Proceedings of the 8th ACM CCS International Workshop on Managing Insider Security Threats, Vienna, Austria.","DOI":"10.1145\/2995959.2995964"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Bar, A., Shapira, B., Rokach, L., and Unger, M. (2016, January 23\u201324). Identifying Attack Propagation Patterns in Honeypots Using Markov Chains Modeling and Complex Networks Analysis. Proceedings of the IEEE International Conference on Software Science, Technology and Engineering (SWSTE), Beer Sheva, Israel.","DOI":"10.1109\/SWSTE.2016.13"},{"key":"ref_31","unstructured":"Deshmukh, S., Rade, R., and Kazi, F. (2020, January 25). Attacker Behaviour Profiling Using Stochastic Ensemble of Hidden Markov Models. Available online: https:\/\/arxiv.org\/abs\/1905.11824."},{"key":"ref_32","unstructured":"Oosterhof, G.M. (2020, January 25). Cowrie\u2014Medium-Interaction Honeypot. Available online: https:\/\/github.com\/micheloosterhof\/cowrie."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Barthe, G., Markatos, E., and Samarati, P. (2016). A Stochastic Framework for Quantitative Analysis of Attack-Defense Trees. Lecture Notes in Computer Science 9871, Proceedings of the Security and Trust Management (STM 2016), Springer.","DOI":"10.1007\/978-3-319-46598-2"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Katipally, R., Yang, L., and Liu, A. (2011, January 12\u201314). Attacker Behavior Analysis in Multi-stage Attack Detection System. Proceedings of the Cyber Security and Information Intelligence Research (CSIIRW\u201911), Oak Ridge, TN, USA. Available online: https:\/\/www.utc.edu\/center-academic-excellence-cyber-defense\/pdfs\/paper-csiirw-2011-attacker-behavior.pdf.","DOI":"10.1145\/2179298.2179369"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Pricop, E., and Mihalache, S.F. (2015, January 25\u201327). Fuzzy approach on modelling cyber attacks patterns on data transfer in industrial control systems. Proceedings of the 7th International Conference on Electronics, Computers and Artificial Intelligence (ECAI 2015), Bucharest, Romania.","DOI":"10.1109\/ECAI.2015.7301200"},{"key":"ref_36","first-page":"1567","article-title":"Real Time Attacker Behavior Pattern Discovery and Profiling Using Fuzzy Rules","volume":"19","author":"Mallikarjunan","year":"2018","journal-title":"J. Internet Technol."},{"key":"ref_37","first-page":"10","article-title":"Fuzzy approach for intrusion detection based on user\u2019s commands","volume":"20","author":"Porwik","year":"2016","journal-title":"Soft Comput."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1080\/01402390.2014.977382","article-title":"Attributing Cyber Attacks","volume":"38","author":"Rid","year":"2015","journal-title":"J. Strateg. Stud."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"430","DOI":"10.1108\/13685201211266015","article-title":"Characterising and Predicting Cyber Attacks Using the Cyber Attacker Model Profile (CAMP)","volume":"15","author":"Watters","year":"2012","journal-title":"J. Money Laund. Control"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"31","DOI":"10.22619\/IJCSA.2017.100113","article-title":"YAAS\u2014On the Attribution of Honeypot Data","volume":"2","author":"Fraunholz","year":"2017","journal-title":"Int. J. Cyber Situat. Aware."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Perry, I., Li, L., Sweet, C., Su, S.H., Cheng, F.-Y., Yang, S.J., and Okutan, A. (2018, January 10\u201313). Differentiating and Predicting Cyberattack Behaviors Using LSTM. Proceedings of the 2018 IEEE Conference on Dependable and Secure Computing (DSC), Kaohsiung, Taiwan.","DOI":"10.1109\/DESEC.2018.8625145"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"\u00c7ayirci, E., and Rong, C. (2009). Security in Wireless Ad Hoc and Sensor Networks, John Wiley & Sons.","DOI":"10.1002\/9780470516782"},{"key":"ref_43","unstructured":"Kdd Cup 1999 Data (2020, January 25). UCI KDD Archive. Available online: http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html."},{"key":"ref_44","unstructured":"(2020, January 25). The CAIDA DDoS Attack 2007 Dataset. Available online: http:\/\/www.caida.org\/data\/passive\/ddos-20070804_dataset.xml."},{"key":"ref_45","first-page":"1626","article-title":"Cloud Security: LKM and Optimal Fuzzy System for Intrusion Detection in Cloud Environment","volume":"29","author":"Shyla","year":"2019","journal-title":"J. Intell. Syst."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"6111","DOI":"10.1002\/sec.1761","article-title":"Predicting the behavior of attackers and the consequences of attacks against cyber-physical systems","volume":"9","author":"Orojloo","year":"2016","journal-title":"Secur. Commun. Netw."},{"key":"ref_47","unstructured":"MASSIF FP7 Project (2020, January 22). MASSIF Architecture. 2011\u20132013. Available online: https:\/\/rieke.link\/MASSIF_Architecture_document.pdf."},{"key":"ref_48","unstructured":"Casey, T. (2020, January 22). Threat Agent Library Helps Identify Information Security Risks. Available online: https:\/\/www.sbs.ox.ac.uk\/cybersecurity-capacity\/system\/files\/Intel%20-%20Threat%20Agent%20Library%20Helps%20Identify%20Information%20Security%20Risks.pdf."},{"key":"ref_49","unstructured":"Shanmugam, B., and Idris, N.B. (2020, January 22). Hybrid Intrusion Detection Systems (HIDS) Using Fuzzy Logic. Available online: https:\/\/www.intechopen.com\/books\/intrusion-detection-systems\/hybrid-intrusion-detection-systems-hids-using-fuzzy-logic."},{"key":"ref_50","unstructured":"Dickerson, J.E., and Dickerson, J.A. (2000, January 13\u201315). Fuzzy Network Profiling for Intrusion Detection. Proceedings of the 19th International Conference of the North American Fuzzy Information Processing Society\u2014NAFIPS (Cat. No.00TH8500), PeachFuzz 2000, Atlanta, GA, USA."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Shanmugam, B., and Idris, N.B. (2009, January 4\u20137). Improved Intrusion Detection System Using Fuzzy Logic for Detecting Anamoly and Misuse Type of Attacks. Proceedings of the 2009 International Conference of Soft Computing and Pattern Recognition, Malacca, Malaysia.","DOI":"10.1109\/SoCPaR.2009.51"},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/S0165-0114(97)00377-1","article-title":"Extensions of the TOPSIS for group decision-making under fuzzy environment","volume":"114","author":"Chen","year":"2000","journal-title":"Fuzzy Sets Syst."},{"key":"ref_53","unstructured":"(2020, January 25). Structured Threat Information eXpression (STIX\u2122) 1.x Archive Website. Available online: https:\/\/stixproject.github.io\/."},{"key":"ref_54","unstructured":"(2020, January 25). About STIX. Available online: https:\/\/stixproject.github.io\/about\/."},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Akoglu, L., Ferrara, E., Deivamani, M., Baeza-Yates, R., and Yogesh, P. (2019). Temporal and Stochastic Modelling of Attacker Behaviour. Advances in Data Science 941, Proceedings of the Communications in Computer and Information Science (ICIIT 2018), Springer.","DOI":"10.1007\/978-981-13-3582-2"},{"key":"ref_56","unstructured":"Singapore University of Technology and Design Official Web Site (2020, January 25). iTrust. Dataset Characteristics. Available online: https:\/\/itrust.sutd.edu.sg\/itrust-labs_datasets\/dataset_info\/."},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"012033","DOI":"10.1088\/1742-6596\/820\/1\/012033","article-title":"Generation of Source Data for Experiments with Network Attack Detection Software","volume":"820","author":"Kotenko","year":"2017","journal-title":"J. Phys. Conf. Ser."},{"key":"ref_58","first-page":"655","article-title":"An Ontology-based Hybrid Storage of Security Information","volume":"47","author":"Kotenko","year":"2018","journal-title":"Inf. Technol. Control"},{"key":"ref_59","doi-asserted-by":"crossref","unstructured":"Doynikova, E., and Kotenko, I. (2018). Approach for determination of cyber attack goals based on the ontology of security metrics. IOP Conference Series: Materials Science and Engineering (MSE) 450, Proceedings of the International Workshop \u201cAdvanced Technologies in Aerospace, Mechanical and Automation Engineering\u201d (MIST: Aerospace-2018), Krasnoyarsk, Russia, 20 October 2018, IOP Publishing.","DOI":"10.1088\/1757-899X\/450\/5\/052006"}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/11\/3\/168\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T09:10:42Z","timestamp":1760173842000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/11\/3\/168"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,3,23]]},"references-count":59,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2020,3]]}},"alternative-id":["info11030168"],"URL":"https:\/\/doi.org\/10.3390\/info11030168","relation":{},"ISSN":["2078-2489"],"issn-type":[{"type":"electronic","value":"2078-2489"}],"subject":[],"published":{"date-parts":[[2020,3,23]]}}}