Time-Aware Bayesian Attack Graphs for Dynamic Cyber Risk Assessment Incorporating Attacker Behavior and Cost–Benefit Analysis
Received: 09-02-2026
Revised: 30-04-2026
Accepted: 04-05-2026
Published in Issue 26-05-2026
Published Online: 08-05-2026
Copyright (c) 2025 Lotfollah Mohammadi Aghchekohul, Mohammad Reza Ebrahimi Dishabi, Mahmoud Maheri, Mohammad Abdollahi Azgomi (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.
Abstract
With the increasing complexity of organizational and cloud-based networks, effective cyber risk and vulnerability assessment has become a critical challenge in modern network security. Conventional vulnerability analysis and attack graph–based approaches often overlook attacker behavior, economic incentives, and dynamic system evolution, leading to limited decision-making capability. This paper proposes a novel behavioral and cost–benefit driven Bayesian attack graph (BAG) framework for dynamic risk assessment in complex networks. The proposed approach integrates Bayesian belief networks with attack graph structures while explicitly incorporating attacker behavioral characteristics, including skill level, attack capability, and persistence, together with a cost–benefit analysis of attack actions. A new probabilistic formulation is introduced to quantify atomic attack success by jointly considering vulnerability exploitability, attacker behavior, and economic motivation. In addition, a time-aware path scoring mechanism is developed to identify critical attack paths by combining attack reachability probability and expected attack duration. The framework supports dynamic Bayesian updating in the presence of new evidence, enabling adaptive risk assessment in evolving environments such as cloud infrastructures. Theoretical analysis confirms that the proposed model is bounded, continuous, and guarantees the existence of an optimal attack path follows from finiteness of the attack graph. Empirical results demonstrate that the proposed framework fundamentally alters attack path prioritization compared with classical BAG-based methods, revealing economically attractive and time-efficient attack paths that are overlooked by vulnerability-centric approaches. By integrating attacker behavior, cost–benefit reasoning, and temporal dynamics, the proposed model provides a more realistic, operationally meaningful, and decision-oriented basis for proactive cyber risk management.
Keywords
- Bayesian attack graphs,
- Attacker behavior,
- Cost–benefit analysis,
- Dynamic cyber risk assessment,
- Network vulnerability,
- Time-aware analysis
References
- Dong, C., Feng, Y., Shang, W. (2024). A new method of dynamic network security analysis based on dynamic uncertain causality graph. Journal of Cloud Computing, 13(1), Article 24. https://doi.org/10.1186/s13677-023-00568-7.
- Sharma, A., Gupta, B.B., Singh, A.K., Saraswat, V.K. (2023). A novel approach for detection of APT malware using multi-dimensional hybrid Bayesian belief network. International Journal of Information Security, 22(1), 119–135. https://doi.org/10.1007/s10207-022-00631-5.
- Kim, H., Hwang, E., Kim, D., Cho, J.H., Moore, T.J., Nelson, F.F., Lim, H. (2023). Time-Based Moving Target Defense Using Bayesian Attack Graph Analysis. IEEE Access, 11, 40511–40524. https://doi.org/10.1109/ACCESS.2023.3269018.
- Dang, F., Zhao, X., Yan, L., Wu, K., Li, S. (2023). Research on network intrusion response method based on Bayesian attack graph. In 2023 3rd International Conference on Consumer Electronics and Computer Engineering (ICCECE) (pp. 639–645). IEEE. https://doi.org/10.1109/ICCECE58074.2023.10135239.
- Zimba, A. (2022). A Bayesian Attack-Network Modeling Approach to Mitigating Malware-Based Banking Cyberattacks. International Journal of Computer Network & Information Security, 14(1), 25–39. https://doi.org/10.5815/ijcnis.2022.01.03.
- Liu, X. (2020). A network attack path prediction method using an attack graph. Journal of Ambient Intelligence and Humanized Computing. https://doi.org/10.1007/s12652-020-02206-5.
- Frigault, M., Wang, L., Singhal, A., Jajodia, S. (2008). Measuring network security using dynamic Bayesian network. In Proceedings of the 4th ACM workshop on Quality of protection (pp.23–30). https://doi.org/10.1145/1456362.1456368.
- Yan, G., Lee, R., Kent, A., Wolpert, D. (2012). Towards a Bayesian network game framework for evaluating DDoS attacks and defense. In Proceedings of the 2012 ACM conference on Computer and communications security (pp. 553–566). https://doi.org/10.1145/2382196.2382255.
- Chockalingam, S., Pieters, W., Teixeira, A., van Gelder, P. (2017). Bayesian network models in cyber security: a systematic review. In Secure IT Systems: 22nd Nordic Conference, NordSec 2017, Tartu, Estonia, November 8–10, 2017, Proceedings 22 (pp. 105–122). Springer International Publishing. https://doi.org/10.1007/978-3-319-70290-2_7.
- Zimba, A., Chen, H., Wang, Z. (2019). Bayesian network based weighted APT attack paths modeling in cloud computing. Future Generation Computer Systems, 96, 525–537. https://doi.org/10.1016/j.future.2019.02.045.
- Pappaterra, M.J., Flammini, F. (2019). A Review of Intelligent Cybersecurity with Bayesian Networks. In 2019 IEEE International Conference on Systems, Man, and Cybernetics (SMC) (pp. 445–452). https://doi.org/10.1109/SMC.2019.8913864.
- Yusof, M.H.M., Zin, A.M., Satar, N.S.M. (2022). Behavioral Intrusion Prediction Model on Bayesian Network over Healthcare Infrastructure. Computers, Materials & Continua, 72(2). https://doi.org/10.32604/cmc.2022.023571.
- Sembiring, J., Ramadhan, M., Gondokaryono, Y.S., Arman, A.A. (2015). Network security risk analysis using improved MulVAL Bayesian attack graphs. International Journal on Electrical Engineering and Informatics, 7(4), 735–753. https://doi.org/10.15676/ijeei.2015.7.4.15
- Jemili, F., Zaghdoud, M., Ahmed, M.B. (2007). A framework for an adaptive intrusion detection system using a Bayesian network. In 2007 IEEE Intelligence and Security Informatics (pp. 66–70).
- Muñoz-González, L., Lupu, E.C. (2017). Bayesian attack graphs for security risk assessment. In IST-153 Workshop on Cyber Resilience.
- Argenti, F., Landucci, G., Reniers, G., Cozzani, V. (2018). Vulnerability assessment of chemical facilities to intentional attacks based on Bayesian Network. Reliability Engineering & System Safety, 169, 515–530. https://doi.org/10.1016/j.ress.2017.09.023.
- Meng, W., Li, W., Jiang, L., Choo, K.-K.R., Su, C. (2019). Practical Bayesian Poisoning Attacks on challenge-based collaborative intrusion detection networks. In K. Sako, S. Schneider, P.Y.A. Ryan (Eds.), Computer Security – ESORICS 2019: 24th European Symposium on Research in Computer Security, Luxembourg, September 23–27, 2019, proceedings, part I (pp. 493–511). Springer. https://doi.org/10.1007/978-3-030-29959-0_24.
- Matthews, I., Soudjani, S., van Moorsel, A. (2021). Stochastic simulation techniques for inference and sensitivity analysis of Bayesian attack graphs. In International Conference on Science of Cyber Security (pp. 171–186). Cham: Springer International Publishing. https://doi.org/10.1007/978-3-030-89137-4_12.
- Yin, X., Fang, Y., Liu, Y. (2013). Real-Time Risk Assessment of Network Security based on Attack Graphs. In Proceedings of International Conference on Information Science and Computer Applications (ISCA 2013) (pp. 75–80). Atlantis Press. https://doi.org/10.2991/isca-13.2013.13.
- Gao, N., He, Y., Ling, B. (2018). Exploring Attack Graphs for Security Risk Assessment: A Probabilistic Approach. Wuhan University Journal of Natural Sciences, 23(2), 171–177. https://doi.org/10.1007/s11859-018-1307-0.
- Dantu, R., Kolan, P. (2005). Risk Management Using Behavior Based Bayesian Networks. In Intelligence and Security Informatics: IEEE International Conference on Intelligence and Security Informatics, ISI 2005, Atlanta, GA, USA, May 19-20, 2005. Proceedings 3 (pp. 115–126). Springer Berlin Heidelberg.
- Luo, Z., Xu, R., Wang, J., Zhu, W. (2022). A Dynamic Risk Assessment Method Based on Bayesian Attack Graph. International Journal of Network Security, 24(5), 787–796. https://doi.org/10.6633/IJNS.202209 24(5).02.
- Minz, R.L., Nagarmat, S.P., Rakesh, R., Isobe, Y. (2018). Cyber Security Using Bayesian Attack Path Analysis. In the Third International Conference on Cyber-Technologies and Cyber-Systems (CYBER 2018) (pp. 15–22).
- Wang, H., Zhu, C., Shen, Z., Lin, D., Liu, K., Zhao, M. (2021). A Network Security Risk Assessment Method Based on a B_NAG Model. Computer Systems Science and Engineering, 38(1), 103–117. https://doi.org/10.32604/csse.2021.014680.
- Semertzis, I., Rajkumar, V.S., Ştefanov, A., Fransen, F., Palensky, P. (2022). Quantitative Risk Assessment of Cyber Attacks on Cyber-Physical Systems using Attack Graphs. In 10th Workshop on Modelling and Simulation of Cyber-Physical Energy Systems (MSCPES) (pp. 1–6). IEEE. https://doi.org/10.1109/MSCPES55116.2022.9770140
- Zhang, S., Song, S. (2011). A Novel Attack Graph Posterior Inference Model Based on Bayesian Network. Journal of Information Security, 2(1), 8–27. https://doi.org/10.4236/jis.2011.21002
- Hui, W., Fuwang, C., Yunfeng, W. (2015). An Approach of Security Risk Evaluation Based on the Bayesian Attack Graph. The Open Cybernetics & Systemics Journal, 9, 953–960.https://doi.org/10.2174/1874110X01509010953.
- Alhomidi, M., Reed, M. (2014). Attack Graph-Based Risk Assessment and Optimization Approach. International Journal of Network Security & Its Applications, 6(3), 31–43. https://doi.org/10.20533/JITST.2046.3723.2014.0029.
- Ding, Y., Zhang, C., Tang, S., Yang, C., Liang, H. (2026). Bayesian-Adaptive Graph Neural Network for Anomaly Detection (BAGNN). In: Han, J., Xiang, Y., Cheng, G., Susilo, W., Chen, L. (eds) International Conference on Information and Communications Security (ICICS 2025) (pp. 482–500). Lecture Notes in Computer Science, vol 16218. Springer, Singapore. https://doi.org/10.1007/978-981-95-3543-9_26.
- Zhang, L., Tang, G., He, X., Qi, K., Su, G., Zhang, H. (2025). Automatic generation of industrial internet attack graphs with graph neural networks and Bayesian models. Computer Networks, 272, Article 111736. https://doi.org/10.1016/j.comnet.2025.111736.
- Wang, R., Yang, C., Deng, X., Zhou, Y., Liu, Y., Tian, Z. (2025). Turn the tables: Proactive deception defense decision-making based on Bayesian attack graphs and Stackelberg games. Neurocomputing, 638, Article 130139. https://doi.org/10.1016/j.neucom.2025.130139.
- Jafari, A., Özkan, C., Ergun, H., Hertem, D.V., Singelee, D. (2025). An advanced cybersecurity risk assessment framework: Integrating vulnerabilities and exploitation techniques for systematic attack path analysis in multilayered power system networks. Sustainable Energy, Grids and Networks, 43, Article 101876. https://doi.org/10.1016/j.segan.2025.101876.
- Sun, H., Shao, C., Zhang, J., Wang, K., Huang, W. (2025). Evolution Analysis of Network Attack and Defense Situation Based on Game Theory. Computers, Materials and Continua, 83(1), 1451–1470. https://doi.org/10.32604/cmc.2025.059724.
- Mell, P., Scarfone, K., Romanosky, S. (2007). A Complete Guide to the Common Vulnerability Scoring System Version 2.0 | NIST. https://api.semanticscholar.org/CorpusID:13910056.
- CVE-2021-45046. (2021) [Online] Available: https://nvd.nist.gov/vuln/detail/CVE-2021-45046.
- CVE-2016-8931. (2016) [Online] Available: https://nvd.nist.gov/vuln/detail/CVE-2016-8931.
- CVE-2015-3456. (2015) [Online] Available: https://nvd.nist.gov/vuln/detail/CVE-2015-3456.
- CVE-2023-34362. (2023) [Online] Available: https://nvd.nist.gov/vuln/detail/CVE-2023-34362.
- CVE-2022-22965. (2025) [Online] Available: https://nvd.nist.gov/vuln/detail/CVE-2022-22965.
- Ou, X., Govindavajhala, S., Appel, A.W. (2005). MulVAL: A Logic-based Network Security Analyzer. USENIX Security Symposium. https://api.semanticscholar.org/CorpusID:2679804.
- Zhang, Y., Malacaria, P. (2021). Bayesian Stackelberg games for cyber-security decision support. Decision Support Systems, 148, Article 113599. https://doi.org/10.1016/j.dss.2021.113599.
- Cremonini, M., Martini, P. (2005). Evaluating information security investments from attackers perspective: the Return-On-Attack (ROA). 4th Workshop on the Economics on Information Security (WEIS). https://doi.org/10.1145/1042091.1042094.
- Frigault, M., Wang, L. (2008). Measuring network security using Bayesian network-based attack graphs. Proceedings of the 32nd Annual IEEE International Conference on Computer Software and Applications, Turku, Finland, 698–703. https://doi.org/10.1109/COMPSAC.2008.88
- Anderson, R., Moore, T. (2006). The economics of information security. Science, 314(5799), 610–613. https://doi.org/10.1126/science.113099
- M. A. McQueen. 2006. Time-to-Compromise Model for Cyber Risk Reduction Estimation. Springer https://doi.org/10.1007/978-0-387-36584-8_5
10.57647/ijm2c.2027.1701.02
