arrow
Return

Quantifying cyber threat using Bayesian statistical analysis

delete2026-02-05
delete0
delete
OA
AI
S
Sajeev Thevaratnam
Z
Zeinab Rezaeifar *
DOI:10.1007/s10207-026-01220-6delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Modern organisations face a cyber threat landscape that evolves faster than traditional qualitative risk scoring can adapt. It is important for organisations to keep pace with adversaries' tactics and react accordingly. This paper develops a quantitative cyber risk assessment framework that integrates Bayesian statistical analysis with system specific hazard mapping. Drawing on the Cyber Security Body of Knowledge (CyBOK) Risk Management and NIST guidance, the study maps unacceptable and acceptable losses to hazards, links hazards to MITRE ATT&CK tactics and onto broader threat categories; and Bayes' Theorem is applied to update threat probabilities as new cyber threat intelligence (CTI) is ingested. A proof of concept spreadsheet tool was developed - it ingests CTI pulses from publicly available feeds and recalculates hazard probabilities for each system, producing dynamic risk scores and dashboards. Evaluation using a simulated vulnerability set shows that the tool reprioritises hazards based on current exploitation activity: vulnerabilities with recent CTI evidence receive higher posterior probabilities than those with similar CVSS (Common Vulnerability Scoring System) scores but no active threats. The tool's transparency and its value in bridging technical risk data with organisational decision making, while noting the manual effort hazard mapping process as a candidate for future automation are the key observations. The study concludes that simple Bayesian updating, when combined with system context, provides an accessible yet rigorous approach to threat quantification and lays the foundation for future automation and dependency modelling.
Keywords:
Cyber-risk assessment
Bayesian statistical analysis
Cyber Security Body of Knowledge (CyBOK)
MITRE ATT& CK Framework
Cyber Threat Intelligence

Journal

I
International Journal of Information Security
IF:
3.2
Papers:
136
Citations:
1.8K

Organization

U
University of West England
Scholars:
3.2K
Papers: 3.5K
Citations: 5
Cited Papers

Cited Papers

Bayesian network model to distinguish between intentional attacks and accidental technical failures: a case study of floodgates
err2021-09-01
err12
errOAAI
errChockalingam, Sabarathinam; Pieters, Wolter; Teixeira, Andre; van Gelder, Pieter
errShare
errSave
FAIR: Cyber Security Risk Quantification In Logistics Sector
err2024-01-01
err0
errOAAI
errElias Seid; Soujanya Satheesh; Oliver Popov; Fredrik Blix
errShare
errSave
Alert correlation for intelligent threat detection and response
err2025-11-01
err1
PREAI
errLanigan, Bronagh; Rezaeifar, Zeinab; Cruciani, Federico; Milliken, Michael; Vincent, Jordan; Moore, Samuel; Aaqib, Muhammad; Mills, Alan; Chouhan, Pushpinder K.; Beard, Alfie; Nugent, Chris D.; Chen, Luke; Healing, Alex
errShare
errSave
A Bayesian Framework for the Analysis and Optimal Mitigation of Cyber Threats to Cyber-Physical Systems
err2022-03-01
err13
errOAAI
errZebrowski, Piotr; Couce-Vieira, Aitor; Mancuso, Alessandro
errShare
errSave
Aleatory or epistemic? Does it matter?
err2009-03-01
err1.8K
PREAI
errKiureghian, Armen Der; Didevsen, Ove
errShare
errSave
researcher View more