Measuring likelihood in cybersecurity

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Corona-Fraga, Pablo, Diaz-Rodriguez, Vanessa, Niebla-Zatarain, Jesus Manuel, Sanchez-Perez, Gabriel, Humphreys, Edward J.
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866915946036199424
author Corona-Fraga, Pablo
Diaz-Rodriguez, Vanessa
Niebla-Zatarain, Jesus Manuel
Sanchez-Perez, Gabriel
Humphreys, Edward J.
author_facet Corona-Fraga, Pablo
Diaz-Rodriguez, Vanessa
Niebla-Zatarain, Jesus Manuel
Sanchez-Perez, Gabriel
Humphreys, Edward J.
contents Cybersecurity risk is commonly expressed through impact and likelihood, yet likelihood remains difficult to estimate because cyber incidents are underreported, heterogeneous datasets are weakly comparable, and attacker behaviour changes faster than conventional probability baselines. This article proposes a pipeline for operationalizing likelihood through a cyber exposure profile that integrates external cyber knowledge and organization specific telemetry into a graph based representation. The contribution is a formally specified artifact chain, from unified data model through organization specific profiling, metric registry, likelihood scoring, and control prioritization, that operationalizes four constructs grounded in incident evidence: Exposure, Traceability, Motivation, and Systems Update. The pipeline provides a pathway from heterogeneous source evidence to a bounded likelihood indicator comparable across organizations and observation periods. An evaluation in 15 real organizations shows that those implementing the cyber exposure profile were associated with reduced incident frequency and faster detection and response times, providing preliminary empirical support for the framework directional claims.
format Preprint
id arxiv_https___arxiv_org_abs_2504_15395
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Measuring likelihood in cybersecurity
Corona-Fraga, Pablo
Diaz-Rodriguez, Vanessa
Niebla-Zatarain, Jesus Manuel
Sanchez-Perez, Gabriel
Humphreys, Edward J.
Cryptography and Security
Cybersecurity risk is commonly expressed through impact and likelihood, yet likelihood remains difficult to estimate because cyber incidents are underreported, heterogeneous datasets are weakly comparable, and attacker behaviour changes faster than conventional probability baselines. This article proposes a pipeline for operationalizing likelihood through a cyber exposure profile that integrates external cyber knowledge and organization specific telemetry into a graph based representation. The contribution is a formally specified artifact chain, from unified data model through organization specific profiling, metric registry, likelihood scoring, and control prioritization, that operationalizes four constructs grounded in incident evidence: Exposure, Traceability, Motivation, and Systems Update. The pipeline provides a pathway from heterogeneous source evidence to a bounded likelihood indicator comparable across organizations and observation periods. An evaluation in 15 real organizations shows that those implementing the cyber exposure profile were associated with reduced incident frequency and faster detection and response times, providing preliminary empirical support for the framework directional claims.
title Measuring likelihood in cybersecurity
topic Cryptography and Security
url https://arxiv.org/abs/2504.15395