<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
<PublisherName>OICC Press</PublisherName>
<JournalTitle>International Journal of Mathematical Modelling &amp; Computations</JournalTitle>
<Issn>2228-6233</Issn>
<Volume></Volume>
<Issue></Issue>
<PubDate PubStatus="epublish">
<Year>2026</Year>
<Month>05</Month>
<Day>26</Day>
</PubDate>
</Journal>
<ArticleTitle>Time-Aware Bayesian Attack Graphs for Dynamic Cyber Risk Assessment Incorporating Attacker Behavior and Cost–Benefit Analysis</ArticleTitle>
<VernacularTitle></VernacularTitle>
<FirstPage></FirstPage>
<LastPage></LastPage>
<ELocationID EIdType="doi">10.57647/ijm2c.2027.1701.02</ELocationID>
<Language>EN</Language>
<AuthorList>
<Author>
<FirstName>Lotfollah</FirstName>
<LastName>Mohammadi Aghchekohul</LastName>
<Affiliation>Department of Computer Engineering, Mi.C., Islamic Azad University, Miyaneh, Iran</Affiliation>
<Identifier Source="ORCID">https://orcid.org/0009-0001-9439-704X</Identifier>
</Author>
<Author>
<FirstName>Mohammad Reza</FirstName>
<LastName>Ebrahimi Dishabi</LastName>
<Affiliation>Department of Computer Engineering, Mi.C., Islamic Azad University, Miyaneh, Iran</Affiliation>
<Identifier Source="ORCID"></Identifier>
</Author>
<Author>
<FirstName>Mahmoud</FirstName>
<LastName>Maheri</LastName>
<Affiliation>Department of Computer Engineering, Mi.C., Islamic Azad University, Miyaneh, Iran</Affiliation>
<Identifier Source="ORCID"></Identifier>
</Author>
<Author>
<FirstName>Mohammad</FirstName>
<LastName>Abdollahi Azgomi</LastName>
<Affiliation>School of Computer Engineering, Iran University of Science and Technology, Tehran, Iran</Affiliation>
<Identifier Source="ORCID"></Identifier>
</Author>
</AuthorList>
<PublicationType>Journal Article</PublicationType>
<History>
<PubDate PubStatus="received">
<Year>2026</Year>
<Month>05</Month>
<Day>26</Day>
</PubDate>
</History>
<Abstract>With the increasing complexity of organizational and cloud-based networks, effective cyber risk and vulnerability assessment has become a critical challenge in modern network security. Conventional vulnerability analysis and attack graph–based approaches often overlook attacker behavior, economic incentives, and dynamic system evolution, leading to limited decision-making capability. This paper proposes a novel behavioral and cost–benefit driven Bayesian attack graph (BAG) framework for dynamic risk assessment in complex networks. The proposed approach integrates Bayesian belief networks with attack graph structures while explicitly incorporating attacker behavioral characteristics, including skill level, attack capability, and persistence, together with a cost–benefit analysis of attack actions. A new probabilistic formulation is introduced to quantify atomic attack success by jointly considering vulnerability exploitability, attacker behavior, and economic motivation. In addition, a time-aware path scoring mechanism is developed to identify critical attack paths by combining attack reachability probability and expected attack duration. The framework supports dynamic Bayesian updating in the presence of new evidence, enabling adaptive risk assessment in evolving environments such as cloud infrastructures. Theoretical analysis confirms that the proposed model is bounded, continuous, and guarantees the existence of an optimal attack path follows from finiteness of the attack graph. Empirical results demonstrate that the proposed framework fundamentally alters attack path prioritization compared with classical BAG-based methods, revealing economically attractive and time-efficient attack paths that are overlooked by vulnerability-centric approaches. By integrating attacker behavior, cost–benefit reasoning, and temporal dynamics, the proposed model provides a more realistic, operationally meaningful, and decision-oriented basis for proactive cyber risk management.</Abstract>
<ObjectList>
<Object Type="keyword">
<Param Name="value">Bayesian attack graphs</Param>
</Object>
<Object Type="keyword">
<Param Name="value">Attacker behavior</Param>
</Object>
<Object Type="keyword">
<Param Name="value">Cost–benefit analysis</Param>
</Object>
<Object Type="keyword">
<Param Name="value">Dynamic cyber risk assessment</Param>
</Object>
<Object Type="keyword">
<Param Name="value">Network vulnerability</Param>
</Object>
<Object Type="keyword">
<Param Name="value">Time-aware analysis</Param>
</Object>
</ObjectList>
</Article>
</ArticleSet>