arXiv:2604.18080cs.CRcs.LG2026-04中稿 · the 2026 IEEE Inte…

结合过程挖掘与贝叶斯攻击图,动态评估漏洞是否被利用。

Dynamic Risk Assessment by Bayesian Attack Graphs and Process Mining

论文配图:Dynamic Risk Assessment by Bayesian Attack Graphs and Process Mining
图 1 · 摘自论文原文
  • 用过程挖掘分析网络流量,识别恶意行为证据
  • 实测显示能准确检测漏洞是否正在被利用
  • 适合安全监控系统实时风险评估场景

攻击图虽能识别系统主要安全威胁,但难以判断已知漏洞是否被利用,或关键节点是否可能被攻陷。本文提出将贝叶斯攻击图(BAGs)与过程挖掘相结合,实现动态风险评估。通过过程挖掘在线分析系统行为,提取恶意网络流量特征,生成漏洞被主动利用的概率证据,并输入至BAG中更新条件概率表,从而动态推断漏洞被利用的可能性。实验在包含多台主机、部署于不同子网并存在多个CVE漏洞的测试平台上进行,使用正常流量与模拟攻击流量混合刺激。结果表明,该方法能有效识别漏洞是否处于被利用状态,实现对系统被攻陷概率的持续更新评估。

原文摘要 · Abstract (English)

While attack graphs are useful for identifying major cybersecurity threats affecting a system, they do not provide operational support for determining the likelihood of having a known vulnerability exploited, or that critical system nodes are likely to be compromised. In this paper, we perform dynamic risk assessment by combining Bayesian Attack Graphs (BAGs) and online monitoring of system behavior through process mining. Specifically, the proposed approach applies process mining techniques to characterize malicious network traffic and derive evidence regarding the probability of having a vulnerability actively exploited. This evidence is then provided to a BAG, which updates its conditional probability tables accordingly, enabling dynamic assessment of vulnerability exploitation. We apply our method to a cybersecurity testbed instantiating several machines deployed on different subnets and affected by several CVE vulnerabilities. The testbed is stimulated with both benign traffic and malicious behavior, which simulates network attack patterns aimed at exploiting the CVE vulnerabilities. The results indicate that our proposal effectively detects whether vulnerabilities are being actively exploited, allowing for an updated assessment of the probability of system compromise.

安全评估贝叶斯网络过程挖掘

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。