نهج هجين يجمع بين الشبكات البايزية والانحدار اللوجستي لتعزيز تقييم المخاطر
A hybrid approach combining Bayesian networks and logistic regression for enhancing risk assessment

شارك:
المجلة: Scientific Reports، المجلد: 15، العدد: 1
DOI: https://doi.org/10.1038/s41598-025-10291-9
PMID: https://pubmed.ncbi.nlm.nih.gov/40702020
تاريخ النشر: 2025-07-23
المؤلف: Zhenyun Du
الموضوع الرئيسي: تحليل المخاطر والسلامة

نظرة عامة

تقدم هذه الدراسة نهجًا جديدًا لتقييم مخاطر الأمن السيبراني من خلال دمج الشبكات البايزية (BN) مع الانحدار اللوجستي (LR)، باستخدام بيانات من كتالوج الثغرات المعروفة المستغلة من CISA. تقوم الأبحاث ببناء نموذج سببي احتمالي من خلال BN الذي يلتقط التداخلات بين خصائص الثغرات المختلفة، مثل درجة CVSS وتعقيد الاستغلال. يحسب النموذج الاحتمالات الشرطية للاستغلال، والتي تُستخدم بعد ذلك كميزات إدخال لمصنف LR. يحقق هذا النهج الهجين دقة تنبؤية تبلغ 97% وROC-AUC قدره 0.1 على مجموعة اختبار من 775 سجل ثغرة، متفوقًا بشكل كبير على نماذج BN وLR المستقلة. تشير تحليل الحساسية إلى أن درجة CVSS وتعقيد الاستغلال هما أكثر العوامل تأثيرًا في توقعات المخاطر، مما يمكّن فرق الأمن من تحديد أولويات جهود التخفيف بشكل فعال.

تختتم الدراسة بالاعتراف بحدود النموذج الحالي، بما في ذلك اعتماده على كتالوج ثغرات واحد والتحديات التي تطرحها البيانات النادرة لتقدير المعلمات. ستركز الأعمال المستقبلية على توسيع مصادر البيانات، وأتمتة تعلم جدول الاحتمالات الشرطية (CPT)، وتنفيذ الشبكات البايزية الديناميكية للتحليل الزمني، وتعزيز النشر التشغيلي من خلال هياكل قابلة للتوسع. تهدف هذه الجهود إلى تحسين الهجين BN-LR ليصبح أداة قوية وقابلة للتكيف مناسبة لمجموعة متنوعة من تطبيقات الأمن السيبراني، مما يحسن في النهاية إدارة الثغرات الأمنية ووضع الأمن في المؤسسات.

الطرق

تشمل المنهجية لتقييم مخاطر الأمن السيبراني المقدمة في هذه الدراسة تحليلًا شاملاً للثغرات في الأنظمة والشبكات. يقترح المؤلفون نهجًا هجينًا يدمج الشبكات البايزية (BN) مع الانحدار اللوجستي (LR) لتحسين دقة توقعات المخاطر. يتم تطوير هيكل BN باستخدام منهجية Bow-Tie (BT) المعدلة، مع اشتقاق المعلمات من كل من البيانات التجريبية وتقييمات الخبراء.

يتبع بناء الإطار عملية من ثلاث خطوات، كما هو موضح في الشكل 1. يهدف هذا النهج المنظم إلى تحديد وتقييم المخاطر بشكل منهجي، مما يعزز الفعالية العامة لتدابير الأمن السيبراني. يهدف الجمع بين BN وLR إلى الاستفادة من نقاط القوة في كلا الطريقتين، مما يسهل تقييمًا أكثر قوة للثغرات المحتملة.

المناقشة

يوفر قسم المناقشة في ورقة البحث نظرة شاملة على منهجيات مختلفة لتحليل التهديدات السيبرانية في الأمن السيبراني. يؤكد على أهمية فهم احتمال وشدة الهجمات السيبرانية المحتملة، بالإضافة إلى تحديد العوامل المساهمة واستراتيجيات التخفيف. يتم تصنيف المنهجيات إلى طرق نوعية وكمية. تعتمد الطرق النوعية، مثل طريقة OCTAVE، ونموذج STRIDE، وسلسلة قتل السيبرانية، على تقييمات الخبراء والبيانات التاريخية لتحديد العوامل الرئيسية التي تؤدي إلى خروقات الأمان. في المقابل، تستخدم الطرق الكمية تقنيات إحصائية، وخوارزميات تعلم الآلة، ونماذج احتمالية لحساب احتمال سيناريوهات الهجوم وعواقبها.

تسلط الورقة الضوء على دمج الشبكات البايزية (BN) مع الانحدار اللوجستي (LR) كنهج واعد لتعزيز تقييم مخاطر الأمن السيبراني. تعتبر الشبكات البايزية مفيدة بشكل خاص بسبب قدرتها على نمذجة الاعتماديات بين المتغيرات وتحديث الاحتمالات مع الأدلة الجديدة، مما يجعلها مناسبة لإدارة المخاطر الديناميكية. تستخدم الدراسة نموذج BN-LR المتكامل لتحليل مخاطر الأمن السيبراني باستخدام بيانات من كتالوج الثغرات المعروفة المستغلة من CISA. يلتقط هذا النموذج بشكل فعال التطور الديناميكي للتهديدات السيبرانية ويحسن تحليل المخاطر من خلال الاستفادة من نقاط القوة في كلا المنهجين. تشير النتائج إلى أن النهج المتكامل لا يعزز فقط الدقة التنبؤية ولكنه يوفر أيضًا رؤى قيمة للتطبيقات العملية في إدارة الأمن السيبراني.

Journal: Scientific Reports, Volume: 15, Issue: 1
DOI: https://doi.org/10.1038/s41598-025-10291-9
PMID: https://pubmed.ncbi.nlm.nih.gov/40702020
Publication Date: 2025-07-23
Author(s): Zhenyun Du
Primary Topic: Risk and Safety Analysis

Overview

This study presents a novel approach to cybersecurity risk assessment by integrating Bayesian Networks (BN) with Logistic Regression (LR), utilizing data from the CISA Known Exploited Vulnerabilities catalog. The research constructs a probabilistic causal model through a BN that captures the interdependencies among various vulnerability characteristics, such as CVSS score and exploit complexity. The model calculates conditional probabilities of exploitation, which are then used as input features for an LR classifier. This hybrid approach achieves a predictive accuracy of 97% and a ROC-AUC of 0.1 on a test set of 775 vulnerability records, significantly outperforming standalone BN and LR models. Sensitivity analysis indicates that CVSS score and exploit complexity are the most influential factors in risk predictions, thereby enabling security teams to prioritize remediation efforts effectively.

The study concludes by acknowledging the limitations of the current model, including its reliance on a single vulnerability catalog and the challenges posed by sparse data for parameter estimation. Future work will focus on expanding data sources, automating conditional probability table (CPT) learning, implementing Dynamic Bayesian Networks for temporal analysis, and enhancing operational deployment through scalable architectures. These efforts aim to refine the BN-LR hybrid into a robust, adaptive tool suitable for various cybersecurity applications, ultimately improving organizational vulnerability management and security posture.

Methods

The methodology for the cybersecurity risk assessment presented in this study involves a comprehensive analysis of vulnerabilities in systems and networks. The authors propose a hybrid approach that integrates Bayesian Networks (BN) with Logistic Regression (LR) to improve the accuracy of risk predictions. The BN structure is developed using a modified Bow-Tie (BT) methodology, with parameters derived from both empirical data and expert evaluations.

The framework construction follows a three-step process, as illustrated in Figure 1. This structured approach aims to systematically identify and evaluate risks, thereby enhancing the overall effectiveness of cybersecurity measures. The combination of BN and LR is intended to leverage the strengths of both methods, facilitating a more robust assessment of potential vulnerabilities.

Discussion

The discussion section of the research paper provides a comprehensive overview of various methodologies for cyber threat analysis in cybersecurity. It emphasizes the importance of understanding the likelihood and potential severity of cyber attacks, as well as identifying contributing factors and mitigation strategies. The methodologies are categorized into qualitative and quantitative approaches. Qualitative methods, such as the OCTAVE method, STRIDE model, and Cyber Kill Chain, rely on expert assessments and historical data to identify key factors leading to security breaches. In contrast, quantitative methods utilize statistical techniques, machine learning algorithms, and probabilistic models to compute the likelihood of attack scenarios and their consequences.

The paper highlights the integration of Bayesian Networks (BN) with Logistic Regression (LR) as a promising approach for enhancing cybersecurity risk assessment. Bayesian Networks are particularly advantageous due to their ability to model dependencies among variables and update probabilities with new evidence, making them suitable for dynamic risk management. The study employs an integrated BN-LR model to analyze cybersecurity risks using data from the CISA Known Exploited Vulnerabilities catalog. This model effectively captures the dynamic evolution of cyber threats and improves risk analysis by leveraging the strengths of both methodologies. The findings suggest that the integrated approach not only enhances predictive accuracy but also provides valuable insights for practical applications in cybersecurity management.

شارك: