Security Risk Assessment Using Bayesian Attack Graphs and Complex Probabilities for Large Scale IoT Applications
Victorine Clotilde Wakam Younang, Amartya Kumar Sen · IEEE Transactions on Dependable and Secure Computing · 2025
The Internet of Things (IoT) infrastructure is a network of interconnected devices and systems, with applications ranging from remote healthcare to large-scale industrial applications. Securing such a resource-constrained infrastructure requires effective and efficient security measures, starting with a comprehensive security risk assessment. In traditional IT infrastructure, Bayesian Attack Graphs (BAGs) are commonly used for security risk assessment. The BAGs illustrate and quantify logical dependencies among vulnerabilities using real probabilities to depict potential attack paths, with their likelihood and impact. However, applying traditional BAGs to IoT infrastructure is challenging. First, purely additive nature of real probabilities makes it difficult to quantify exploits launched in tandem from the same or varying sources that may collectively exploit a given vulnerability or cancel out each other’s degenerative consequences on the network. Second, cycles may arise in BAGs, especially when attackers backtrack to a previously compromised state, a problem challenging to quantify using traditional BAGs. To address these challenges, this research proposes a risk assessment framework using complex probabilities for large-scale IoT applications. The framework effectively quantifies unpredictable attacker behavior, particularly when cycles occur due to attacker backtracking. A use case in the Connected and Autonomous Vehicles (CAVs) network demonstrates the framework’s effectiveness and validation.