<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMES</journal-id>
<journal-id journal-id-type="nlm-ta">CMES</journal-id>
<journal-id journal-id-type="publisher-id">CMES</journal-id>
<journal-title-group>
<journal-title>Computer Modeling in Engineering &#x0026; Sciences</journal-title>
</journal-title-group>
<issn pub-type="epub">1526-1506</issn>
<issn pub-type="ppub">1526-1492</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">72357</article-id>
<article-id pub-id-type="doi">10.32604/cmes.2025.072357</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>MITRE ATT&#x0026;CK-Driven Threat Analysis for Edge-IoT Environment and a Quantitative Risk Scoring Model</article-title>
<alt-title alt-title-type="left-running-head">MITRE ATT&#x0026;CK-Driven Threat Analysis for Edge-IoT Environment and a Quantitative Risk Scoring Model</alt-title>
<alt-title alt-title-type="right-running-head">MITRE ATT&#x0026;CK-Driven Threat Analysis for Edge-IoT Environment and a Quantitative Risk Scoring Model</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Yun</surname><given-names>Tae-hyeon</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Min</surname><given-names>Moohong</given-names></name><xref ref-type="aff" rid="aff-2">2</xref><xref rid="cor1" ref-type="corresp">&#x002A;</xref><email>iceo@skku.edu</email></contrib>
<aff id="aff-1"><label>1</label><institution>Department of Computer Education, Sungkyunkwan University</institution>, <addr-line>Seoul, 03063</addr-line>, <country>Republic of Korea</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Computer Education/Social Innovation Convergence Program, Sungkyunkwan University</institution>, <addr-line>Seoul, 03063</addr-line>, <country>Republic of Korea</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Moohong Min. Email: <email>iceo@skku.edu</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>26</day><month>11</month><year>2025</year>
</pub-date>
<volume>145</volume>
<issue>2</issue>
<fpage>2707</fpage>
<lpage>2731</lpage>
<history>
<date date-type="received">
<day>25</day>
<month>08</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>27</day>
<month>10</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Authors.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMES_72357.pdf"></self-uri>
<abstract>
<p>The dynamic, heterogeneous nature of Edge computing in the Internet of Things (Edge-IoT) and Industrial IoT (IIoT) networks brings unique and evolving cybersecurity challenges. This study maps cyber threats in Edge-IoT/IIoT environments to the Adversarial Tactics, Techniques, and Common Knowledge (ATT&#x0026;CK) framework by MITRE and introduces a lightweight, data-driven scoring model that enables rapid identification and prioritization of attacks. Inspired by the Factor Analysis of Information Risk model, our proposed scoring model integrates four key metrics: Common Vulnerability Scoring System (CVSS)-based severity scoring, Cyber Kill Chain&#x2013;based difficulty estimation, Deep Neural Networks-driven detection scoring, and frequency analysis based on dataset prevalence. By aggregating these indicators, the model generates comprehensive risk profiles, facilitating actionable prioritization of threats. Robustness and stability of the scoring model are validated through non-parametric correlation analysis using Spearman&#x2019;s and Kendall&#x2019;s rank correlation coefficients, demonstrating consistent performance across diverse scenarios. The approach culminates in a prioritized attack ranking that provides actionable guidance for risk mitigation and resource allocation in Edge-IoT/IIoT security operations. By leveraging real-world data to align MITRE ATT&#x0026;CK techniques with CVSS metrics, the framework offers a standardized and practically applicable solution for consistent threat assessment in operational settings. The proposed lightweight scoring model delivers rapid and reliable results under dynamic cyber conditions, facilitating timely identification of attack scenarios and prioritization of response strategies. Our systematic integration of established taxonomies with data-driven indicators strengthens practical risk management and supports strategic planning in next-generation IoT deployments. Ultimately, this work advances adaptive threat modeling for Edge/IIoT ecosystems and establishes a robust foundation for evidence-based prioritization in emerging cyber-physical infrastructures.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>MITRE ATT&#x0026;CK</kwd>
<kwd>edge environment</kwd>
<kwd>IoT</kwd>
<kwd>threat analysis</kwd>
<kwd>quantitative analysis</kwd>
<kwd>deep neural network</kwd>
<kwd>CVSS</kwd>
<kwd>risk assessment</kwd>
<kwd>scoring model</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>Ministry of Education (MOE) and the Seoul Metropolitan Government</funding-source>
<award-id>2025-RISE-01-018-05</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<sec id="s1_1">
<label>1.1</label>
<title>Cyber Threat in Edge-Computing Environment</title>
<p>Edge environment relocates processing and storage resources to distributed, resource-constrained nodes at the network periphery, dramatically expanding the attack surface and introducing new security challenges [<xref ref-type="bibr" rid="ref-1">1</xref>]. Unlike centralized cloud data centers with consolidated security controls, edge nodes often operate with minimal oversight and heterogeneous hardware/software stacks, increasing misconfiguration risk and credential exposure. Modern adversaries exploit these weaknesses to mount data poisoning attacks during model training&#x2014;manipulating Internet of Things (IoT) sensor streams to degrade inference accuracy&#x2014;and adversarial-example assaults at inference time, where imperceptible perturbations in input signals induce model misclassifications that compromise both confidentiality and integrity of on-device intelligence [<xref ref-type="bibr" rid="ref-1">1</xref>]. Moreover, model-extraction techniques enable attackers to reconstruct proprietary Machine Learning (ML) models by systematically querying edge interfaces, leading to intellectual property theft and downstream privacy breaches [<xref ref-type="bibr" rid="ref-2">2</xref>].</p>
<p>Simultaneously, edge-enabled industrial and cyber-physical systems face volumetric distributed denial-of-service (DDoS) campaigns that overwhelm constrained network links and micro&#x2014;data centers, effectively severing communication between edge devices and control services [<xref ref-type="bibr" rid="ref-3">3</xref>]. Ransomware has also expanded beyond enterprise servers into the edge domain, encrypting crucial control logic and data repositories to disrupt real-time processes and demand high remediation payments [<xref ref-type="bibr" rid="ref-4">4</xref>]. The physical accessibility of many edge deployments&#x2014;ranging from roadside units in intelligent transportation systems to on-site gateways in smart factories&#x2014;further increases exposure to tampering, hardware injection, and side-channel attacks. To realistically assess these multifaceted threats, this work conducts threat analysis on real-world Edge-IIoTset Cyber Security Dataset of IoT &#x0026; IIoT datasets collected from operational testbeds, ensuring that our evaluations reflect genuine attack patterns rather than synthetic benchmarks [<xref ref-type="bibr" rid="ref-5">5</xref>].</p>
</sec>
<sec id="s1_2">
<label>1.2</label>
<title>Quantitative Indicators for Threat Response</title>
<p>Effective defense in edge environments requires systematic prioritization of limited security resources to address the most consequential threats [<xref ref-type="bibr" rid="ref-6">6</xref>]. From the perspective of cyber resilience, the use of experimental methods and tools for quantitative measurement is indispensable; such an approach enables the systematic enhancement of an organization&#x2019;s resilience posture [<xref ref-type="bibr" rid="ref-7">7</xref>]. To this end, we develop a scoring framework comprising four quantitative indicators&#x2014;impact, detection, difficulty, and frequency&#x2014;that collectively inform risk-driven decision making under operational constraints. First, we map observed attack instances to Adversarial Tactics, Techniques, and Common Knowledge (ATT&#x0026;CK) techniques and tactics by MITRE, standardizing threat descriptions to enable consistent comparison across diverse scenarios. This normalization is critical for edge contexts, where disjointed logs and telemetry often obscure attack lineage.</p>
<p>Impact is quantified using the Common Vulnerability Scoring System (CVSS) v3.1, which synthesizes metrics for exploitability, impact, and environmental factors into a single severity score. By applying CVSS to mapped ATT&#x0026;CK techniques, we obtain a unified metric for technical and operational risk regardless of device type or deployment context. Detection performance is measured by training deep neural networks(DNN) classifiers on the same real-world datasets, producing empirical detection scores; training employs focal loss to handle class imbalance and hard examples, and task-appropriate data augmentation to improve generalization. This DNN model captures complex feature relationships in network and sensor data, yielding robust detection of both volumetric and subtle stealth attacks.</p>
<p>In this study, execution difficulties are computed across the seven phases of Lockheed Martin&#x2019;s Cyber Kill Chain by reflecting the characteristic behaviors of each attack type. Attack types that require a larger number of techniques expand both the offensive and defensive surfaces&#x2014;raising operational complexity and potential exposure&#x2014;and are therefore classified as higher risk [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-9">9</xref>]. Frequency is derived from the observed prevalence of each attack type in our datasets, the relative proportions of attack types are incorporated through normalization. By integrating these four indicators into a composite scoring model inspired by quantitative risk analysis principles, the practical ranking of attack types is derived as an explainable quantitative measure.</p>
<p>To ensure robustness, we validate the scoring model via non-parametric Spearman and Kendall rank-correlation analyses, demonstrating stability of rankings under perturbations in indicator weights and data sampling. The resulting evidence-based prioritization provides actionable guidance for practitioners to allocate detection, mitigation, and response efforts where they yield the greatest security impact.</p>
</sec>
</sec>
<sec id="s2">
<label>2</label>
<title>Background</title>
<sec id="s2_1">
<label>2.1</label>
<title>Linking MITRE ATT&#x0026;CK with Edge Environment</title>
<p>The MITRE ATT&#x0026;CK framework has emerged as a cornerstone of modern cybersecurity practice, serving as a globally recognized knowledge base that systematically categorizes adversary tactics, techniques, and procedures based on real-world observations [<xref ref-type="bibr" rid="ref-10">10</xref>]. Academic analysis demonstrates that ATT&#x0026;CK&#x2019;s structured approach to threat intelligence has fundamentally enhanced the systematic detection and analysis of cyber threats, particularly advanced persistent threats, across industries including healthcare, finance, and critical infrastructure [<xref ref-type="bibr" rid="ref-10">10</xref>]. Research shows that over 80% of large enterprises utilize the framework for threat protection, with 57% employing it to identify security gaps and 55% leveraging it for security policy implementation [<xref ref-type="bibr" rid="ref-11">11</xref>]. The framework&#x2019;s comprehensive documentation of attack behaviors enables security professionals to develop more effective defense strategies and improve incident response capabilities through standardized threat representation.</p>
<p>Edge environments introduce distinctive security challenges characterized by distributed architectures, resource constraints, and dynamic device topologies that significantly expand traditional attack surfaces. These environments face multifaceted threats including data tampering attacks where adversaries alter transmitted or stored data, denial-of-service campaigns targeting resource-constrained edge nodes, and service manipulation attacks where attackers gain control over edge data centers to misrepresent services [<xref ref-type="bibr" rid="ref-12">12</xref>]. Privacy leakage emerges as a critical concern due to the proximity of edge nodes to users and the substantial volumes of sensitive data they process [<xref ref-type="bibr" rid="ref-12">12</xref>]. Physical attacks represent another unique vulnerability, as distributed edge server deployments often operate with weaker physical protection compared to centralized data centers [<xref ref-type="bibr" rid="ref-12">12</xref>]. Research indicates that edge computing networks possess limited computational resources compared to cloud environments, preventing implementation of complex encryption algorithms and creating additional security vulnerabilities [<xref ref-type="bibr" rid="ref-12">12</xref>]. The dynamic nature of edge environments, where devices continuously join and leave networks, further complicates the establishment of consistent security policies and access controls [<xref ref-type="bibr" rid="ref-13">13</xref>].</p>
<p>The integration of MITRE ATT&#x0026;CK with edge environment security analysis enables systematic mapping of attack behaviors specific to distributed computing environments to standardized threat taxonomies. Academic research demonstrates that ATT&#x0026;CK&#x2019;s enterprise and mobile matrices can be effectively extended to address edge-specific attack patterns, including those targeting 5G networks and cellular communications [<xref ref-type="bibr" rid="ref-10">10</xref>]. Studies have successfully mapped cellular attack techniques and procedures to ATT&#x0026;CK tactics, creating structured frameworks for analyzing threats in mobile edge environments [<xref ref-type="bibr" rid="ref-14">14</xref>]. This integration proves particularly valuable for edge deployments where initial access may occur through compromised IoT devices or physical tampering, enabling defenders to track lateral movement and persistence techniques across distributed infrastructures. Research shows that attack graph methodologies combined with ATT&#x0026;CK mapping provide dynamic threat modeling capabilities essential for edge environments characterized by continuous topology changes, allowing security practitioners to assess evolving attack paths as devices join or leave networks [<xref ref-type="bibr" rid="ref-14">14</xref>]. The framework&#x2019;s emphasis on post-compromise behavior analysis addresses the unique characteristics of edge deployments, where traditional enterprise security models inadequately account for physical accessibility vulnerabilities and resource constraints.</p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>DNN for Cyber Threat Detection</title>
<p>ML techniques, particularly DNN, are increasingly adopted for cyber threat detection due to their capacity to model complex, non-linear patterns in high-dimensional data and to generalize to novel attack variants [<xref ref-type="bibr" rid="ref-15">15</xref>&#x2013;<xref ref-type="bibr" rid="ref-17">17</xref>]. DNN automatically learn hierarchical feature representations from raw network traffic and system logs, enabling superior detection accuracy and lower false positive rates compared to signature-based methods [<xref ref-type="bibr" rid="ref-18">18</xref>]. Furthermore, DNN architectures support real-time inference on streaming data, facilitating rapid identification of volumetric and stealth attacks even in resource-constrained environments such as edge and IoT deployments [<xref ref-type="bibr" rid="ref-18">18</xref>].</p>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>Scoring with CVSS Vector</title>
<p>The quantitative assessment of cyber threats demands a standardized method to compare vulnerabilities and adversary behaviors across diverse environments. CVSS provides a structured vector of base, temporal, and environmental metrics, translating technical details&#x2014;such as exploitability, impact, and required privileges&#x2014;into a unified severity score [<xref ref-type="bibr" rid="ref-19">19</xref>]. <xref ref-type="fig" rid="fig-1">Fig. 1</xref> presents the flow from individual evaluation metrics to the final severity rating bands. This allows organizations to prioritize remediation and allocate defensive resources based on objective, comparable risk ratings. Without such an approach, prioritization becomes subjective, and critical threats may be overlooked amidst a flood of alerts and vulnerabilities [<xref ref-type="bibr" rid="ref-19">19</xref>].</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Common Vulnerability Scoring System (CVSS) score calculation process</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_72357-fig-1.tif"/>
</fig>
<p>Building on the mapping between MITRE ATT&#x0026;CK techniques and Common Vulnerabilities and Exposures (CVE) identifiers, and leveraging the established correlation between CVEs and their corresponding CVSS vectors, we can quantitatively assess the risk posed by attack paths by synthesizing adversary techniques with documented vulnerability characteristics [<xref ref-type="bibr" rid="ref-20">20</xref>]. This integration enables security teams not only to catalogue threat behaviors but also to rank them by severity, sharpening risk assessments and focusing response on the most impactful attacks [<xref ref-type="bibr" rid="ref-19">19</xref>].</p>
</sec>
<sec id="s2_4">
<label>2.4</label>
<title>Cyber Kill Chain</title>
<p>The Cyber Kill Chain is a framework developed by Lockheed Martin that systematizes the cyber-attack lifecycle into seven distinct phases to support analysis and defense planning. The Cyber Kill Chain comprises seven stages&#x2014;reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives&#x2014;commonly used to structure analysis and response [<xref ref-type="bibr" rid="ref-21">21</xref>]. The attack execution difficulty increases nonlinearly with the number of Cyber Kill Chain stages traversed and this leads to the defensive surface expands, thereby raising defender-side difficulty [<xref ref-type="bibr" rid="ref-22">22</xref>,<xref ref-type="bibr" rid="ref-23">23</xref>].</p>
</sec>
<sec id="s2_5">
<label>2.5</label>
<title>FAIR-Based Evaluation Metrics</title>
<p>As IoT technologies continue to evolve, they have become increasingly intelligent and are delivering value to society in ever more diverse ways [<xref ref-type="bibr" rid="ref-24">24</xref>]. However, alongside these advances in network technology, new security challenges have emerged which must be addressed; accordingly, research into robust methodologies for assessing and prioritizing these risks is actively ongoing [<xref ref-type="bibr" rid="ref-24">24</xref>].</p>
<p>Among the various risk assessment models, we selected the Factor Analysis of Information Risk (FAIR) framework to establish the foundational structure for evaluating cyber threats. A close examination of the FAIR model reveals that it quantifies risk primarily through two core indicators: Loss Event Frequency and Loss Magnitude, treating these as equally significant determinants of overall risk exposure, as illustrated in <xref ref-type="fig" rid="fig-2">Fig. 2</xref> [<xref ref-type="bibr" rid="ref-25">25</xref>]. In this study, we extend the FAIR framework by introducing additional dimensions&#x2014;namely, attack difficulty and detection rate&#x2014;thereby developing a scalable yet robust risk scoring model that enhances the granularity and applicability of cyber threat assessments.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Risk determinants of Factor Analysis of Information Risk (FAIR) framework</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_72357-fig-2.tif"/>
</fig>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Cyber Threat Analysis with MITRE ATT&#x0026;CK</title>
<sec id="s3_1">
<label>3.1</label>
<title>Dataset Overview</title>
<p>The Edge-IIoTset Cyber Security Dataset of IoT &#x0026; IIoT comprises normal logs as well as attack-specific logs stratified by threat category, and provides separate CSV files tailored for ML and DNN workflows. As the raw data are not precurated, it is necessary to perform preprocessing to remove non-informative columns and extraneous records prior to analysis. The resulting curated dataset serves as the foundational corpus for all subsequent risk quantification procedures [<xref ref-type="bibr" rid="ref-26">26</xref>]. The distribution of log counts by attack category in the cleaned dataset is summarized in <xref ref-type="table" rid="table-1">Table 1</xref>.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Class distribution after preprocessing</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/> 
</colgroup>
<thead>
<tr>
<th>Attack_type</th>
<th>Rows</th>
</tr>
</thead>
<tbody>
<tr>
<td>Normal</td>
<td>1,380,858</td>
</tr>
<tr>
<td>DDoS_UDP</td>
<td>121,567</td>
</tr>
<tr>
<td>DDoS_ICMP</td>
<td>67,939</td>
</tr>
<tr>
<td>DDoS_TCP</td>
<td>50,062</td>
</tr>
<tr>
<td>DDoS_HTTP</td>
<td>49,203</td>
</tr>
<tr>
<td>SQL_injection</td>
<td>50,826</td>
</tr>
<tr>
<td>Vulnerability_scanner</td>
<td>50,026</td>
</tr>
<tr>
<td>Password</td>
<td>49,933</td>
</tr>
<tr>
<td>Uploading</td>
<td>36,915</td>
</tr>
<tr>
<td>Backdoor</td>
<td>24,026</td>
</tr>
<tr>
<td>Port_Scanning</td>
<td>19,983</td>
</tr>
<tr>
<td>XSS</td>
<td>15,066</td>
</tr>
<tr>
<td>Ransomware</td>
<td>9689</td>
</tr>
<tr>
<td>Fingerprinting</td>
<td>853</td>
</tr>
<tr>
<td>MITM</td>
<td>358</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>An examination of the preprocessed data reveals pronounced inter-class imbalance. In particular, the Man-in-the-Middle (MITM) category contains a substantial number of degenerate records that exhibit zero values across all features, further diminishing the already limited effective sample size for this class. Overall, Fingerprinting and MITM possess markedly fewer instances than the other attack types, indicating a need for targeted rebalancing where appropriate. In the section Detection in Noise Environment Using DNN, we detail our strategy to mitigate this imbalance via data augmentation and loss-function design tailored to skewed class distributions [<xref ref-type="bibr" rid="ref-27">27</xref>].</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Mapping with MITRE ATT&#x0026;CK</title>
<p>Following data preprocessing, enumeration of attack categories within the curated dataset yields a total of 15 distinct attack types, including a separate class for normal traffic. Excluding the normal class, 14 unique attack signatures are identified. Notably, the security threats observed in actual Edge-IoT &#x0026; Industrial IoT (IIoT) environments are sufficiently heterogeneous to map across multiple MITRE ATT&#x0026;CK matrix categories, including Industrial Control System (ICS), Enterprise, and Mobile [<xref ref-type="bibr" rid="ref-28">28</xref>,<xref ref-type="bibr" rid="ref-29">29</xref>]. Accordingly, the mapping process primarily emphasizes techniques rather than general tactics, with each attack signature analyzed for correspondence to specific ATT&#x0026;CK techniques. In the case of techniques, MITRE ATT&#x0026;CK assigns distinct identifiers depending on the operational context&#x2014;for example, Enterprise, Mobile, or ICS. In <xref ref-type="table" rid="table-2">Table 2</xref>, the mapping of techniques is performed by selectively referencing a subset of techniques from multiple operational matrices, prioritizing those most representative of the relevant environments. Notably, many techniques share nomenclature but have different unique identifiers across matrices, reflecting the inherent heterogeneity of edge environments discussed previously [<xref ref-type="bibr" rid="ref-28">28</xref>,<xref ref-type="bibr" rid="ref-29">29</xref>]. Certain attack types, such as DDoS, admit direct mapping to ATT&#x0026;CK technique identifiers, while others require careful examination of operational characteristics to assign the closest matching technique. This mapping framework further serves as the foundation for quantitative risk assessment when integrated with external vulnerability indices such as CVE and CVSS.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Mapping attack types with adversarial tactics, techniques, and common knowledge (ATT&#x0026;CK) framework by MITRE</title>
</caption>
<table>
<colgroup>
<col align="center" width="50mm"/>
<col align="center" width="50mm"/> </colgroup>
<thead>
<tr>
<th>Attack_type</th>
<th>Techniques (MITRE ATT&#x0026;CK)</th>
</tr>
</thead>
<tbody>
<tr>
<td>DDoS_UDP</td>
<td>T1498, T1499</td>
</tr>
<tr>
<td>DDoS_ICMP</td>
<td>T1498, T1499</td>
</tr>
<tr>
<td>DDoS_TCP</td>
<td>T1498, T1499</td>
</tr>
<tr>
<td>DDoS_HTTP</td>
<td>T1498, T1499</td>
</tr>
<tr>
<td>SQL_injection</td>
<td>T1190</td>
</tr>
<tr>
<td>Vulnerability_scanner</td>
<td>T1595</td>
</tr>
<tr>
<td>Password</td>
<td>T1110</td>
</tr>
<tr>
<td>Uploading</td>
<td>T1190, T1505</td>
</tr>
<tr>
<td>Backdoor</td>
<td>T1071, T1505</td>
</tr>
<tr>
<td>Port_Scanning</td>
<td>T1595</td>
</tr>
<tr>
<td>XSS</td>
<td>T1059</td>
</tr>
<tr>
<td>Ransomware</td>
<td>T1486</td>
</tr>
<tr>
<td>Fingerprinting</td>
<td>T1595</td>
</tr>
<tr>
<td>MITM</td>
<td>T1557</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>CVSS-Based Attack Severity Assessment</title>
<p>CVSS enables quantitative assessment of risk severity by assigning a computed score for each vulnerability based on its unique vector string. To generate the CVSS vector for each identified threat, the mitigation techniques were systematically mapped to corresponding CVE entries. This mapping was accomplished utilizing CVE data and attack pattern taxonomies provided by the MITRE group [<xref ref-type="bibr" rid="ref-30">30</xref>,<xref ref-type="bibr" rid="ref-31">31</xref>]. Moreover, leveraging dataset-provider descriptions of each attack type and their mapped ATT&#x0026;CK techniques, CVEs from the past four years were heuristically queried to derive practitioner-aligned associations [<xref ref-type="bibr" rid="ref-26">26</xref>]. Following mapping, each CVSS vector was validated, the associated score was determined, and the results were recorded. The integration of CVE identifiers with CVSS metrics constitutes the foundation of the National Vulnerability Database (NVD), which has emerged as a globally recognized standard for comprehensive vulnerability assessment [<xref ref-type="bibr" rid="ref-32">32</xref>]. The mapped CVEs and their corresponding CVSS values are summarized in <xref ref-type="table" rid="table-3">Table 3</xref>. CVSS v3.1 Base Scores are adopted, and the table records, among CVEs with an available CVSS score, the single CVE with the highest score as the representative entry. For candidate CVEs mapped to each attack type and the CVSS vectors underlying the tabulated scores, as detailed in <xref ref-type="app" rid="app-1">Appendix A</xref>.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Common vulnerabilities and exposures (CVE)-CVSS for each attack type</title>
</caption>
<table>
<colgroup>
<col align="center" width="33mm"/>
<col align="center" width="33mm"/>
<col align="center" width="33mm"/> </colgroup>
<thead>
<tr>
<th>Attack_type</th>
<th>CVE</th>
<th>CVSS Score</th>
</tr>
</thead>
<tbody>
<tr>
<td>DDoS_UDP</td>
<td>CVE-2024-47850</td>
<td>7.5</td>
</tr>
<tr>
<td>DDoS_ICMP</td>
<td>CVE-2024-47678</td>
<td>5.5</td>
</tr>
<tr>
<td>DDoS_TCP</td>
<td>CVE-2023-0881</td>
<td>7.5</td>
</tr>
<tr>
<td>DDoS_HTTP</td>
<td>CVE-2025-55163</td>
<td>7.5</td>
</tr>
<tr>
<td>SQL_injection</td>
<td>CVE-2024-8465</td>
<td>9.8</td>
</tr>
<tr>
<td>Vulnerability_scanner</td>
<td>CVE-2024-43405</td>
<td>7.8</td>
</tr>
<tr>
<td>Password</td>
<td>CVE-2024-48845</td>
<td>9.8</td>
</tr>
<tr>
<td>Uploading</td>
<td>CVE-2025-21624</td>
<td>9.8</td>
</tr>
<tr>
<td>Backdoor</td>
<td>CVE-2022-42044</td>
<td>9.8</td>
</tr>
<tr>
<td>Port_Scanning</td>
<td>CVE-2025-57437</td>
<td>9.8</td>
</tr>
<tr>
<td>XSS</td>
<td>CVE-2025-1076</td>
<td>4.8</td>
</tr>
<tr>
<td>Ransomware</td>
<td>CVE-2024-51378</td>
<td>10.0</td>
</tr>
<tr>
<td>Fingerprinting</td>
<td>CVE-2023-37213</td>
<td>9.8</td>
</tr>
<tr>
<td>MITM</td>
<td>CVE-2025-54792</td>
<td>6.8</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Detection in Noise Environment by Using DNN</title>
<sec id="s4_1">
<label>4.1</label>
<title>Noise Environment and Loss Function Settings</title>
<p>DNN have demonstrated state-of-the-art performance in modern security domains and have established themselves as essential tools for intrusion and anomaly detection [<xref ref-type="bibr" rid="ref-18">18</xref>]. Building upon the demonstrated efficacy of DNN in these contexts, the present study systematically evaluates detection rates across various experimental configurations, including the deliberate introduction of synthetic noise and data augmentation techniques to emulate real-world conditions, as well as the selection of appropriate loss functions [<xref ref-type="bibr" rid="ref-33">33</xref>]. These procedures represent a foundational methodology for establishing reliable detection baselines, distinct from the optimized architectures typically employed for achieving maximal detection performance. Specifically, this study employs a Gaussian &#x002B; Spike (Mixed) distribution as the noise profile.
<list list-type="bullet">
<list-item>
<p>Gaussian Noise: Following a Gaussian (normal) distribution, characterized by a bell-shaped curve centered at the mean. Gaussian noise is considered a fundamental model in signal processing and communication channel analysis, owing to its prevalence in both theoretical and empirical studies [<xref ref-type="bibr" rid="ref-34">34</xref>].</p></list-item>
<list-item>
<p>Spike Noise: Characterized by sharp, high-amplitude transients that occur sporadically at specific locations within the signal. It is commonly employed to model sudden disturbances or sporadic errors that may introduce intermittent interference in communication systems or signal processing pipelines [<xref ref-type="bibr" rid="ref-35">35</xref>].</p></list-item>
<list-item>
<p>Mixed (Gaussian &#x002B; Spike): Combining both Gaussian and spike noise components, thereby emulating practical scenarios in Edge-IoT environments where persistent interference and sporadic outliers may occur simultaneously. Such a model provides a closer approximation to the complex and heterogeneous noise conditions encountered in real-world deployments [<xref ref-type="bibr" rid="ref-36">36</xref>].</p></list-item>
</list></p>
<p>For the loss function, we employ the standard loss for multi-class classification tasks, sparse categorical focal loss(Focal), which is specifically designed to address class imbalance [<xref ref-type="bibr" rid="ref-37">37</xref>]. This selection is made to reflect the inherent characteristics of the dataset and, together with the chosen noise profile, supports a reliable evaluation of detection performance using Focal.
<list list-type="bullet">
<list-item>
<p>Sparse Categorical Focal Loss(Focal): Derived by introducing a weighting mechanism into cross-entropy. It dynamically adjusts the weights assigned to easy and difficult samples, thereby improving model performance in scenarios characterized by significant inter-class imbalance [<xref ref-type="bibr" rid="ref-37">37</xref>].</p></list-item>
</list></p>
</sec>
<sec id="s4_2">
<label>4.2</label>
<title>Detection Performance Using DNN</title>
<p>To train the DNN, data proportions were adjusted and noise was introduced during preprocessing. DDoS_UDP was disproportionately large among the attack types; for each training run, it was randomly downsampled by half, after which the Normal-to-Attack ratio was equalized, and Mixed noise was applied to double the sample count of each type. The severely imbalanced minority classes, Fingerprinting and MITM, were augmented tenfold to mitigate class imbalance as far as practicable. Dataset statistics after preprocessing and augmentation are reported in <xref ref-type="table" rid="table-4">Table 4</xref>. Please refer to <xref ref-type="app" rid="app-2">Appendix B</xref> for the DNN layer configuration, optimizer specifications, and other implementation details.</p>
<table-wrap id="table-4">
<label>Table 4</label>
<caption>
<title>Class distribution after preprocessing for Deep Neural Networks (DNN)</title>
</caption>
<table>
<colgroup>
<col align="center" width="50mm"/>
<col align="center" width="50mm"/> </colgroup>
<thead>
<tr>
<th>Attack_type</th>
<th>Rows</th>
</tr>
</thead>
<tbody>
<tr>
<td>Normal</td>
<td>971,326</td>
</tr>
<tr>
<td>DDoS_UDP</td>
<td>121,568</td>
</tr>
<tr>
<td>DDoS_ICMP</td>
<td>135,878</td>
</tr>
<tr>
<td>DDoS_TCP</td>
<td>100,124</td>
</tr>
<tr>
<td>DDoS_HTTP</td>
<td>98,406</td>
</tr>
<tr>
<td>SQL_injection</td>
<td>101,652</td>
</tr>
<tr>
<td>Vulnerability_scanner</td>
<td>100,052</td>
</tr>
<tr>
<td>Password</td>
<td>99,866</td>
</tr>
<tr>
<td>Uploading</td>
<td>73,830</td>
</tr>
<tr>
<td>Backdoor</td>
<td>48,052</td>
</tr>
<tr>
<td>Port_Scanning</td>
<td>39,966</td>
</tr>
<tr>
<td>XSS</td>
<td>30,132</td>
</tr>
<tr>
<td>Ransomware</td>
<td>19,378</td>
</tr>
<tr>
<td>Fingerprinting</td>
<td>8530</td>
</tr>
<tr>
<td>MITM</td>
<td>3580</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>In the context of security threat detection, undetected threats pose far more severe consequences&#x2014;including significant security breaches, data compromise, and system disruption&#x2014;than false positives or over-detection [<xref ref-type="bibr" rid="ref-38">38</xref>]. Consequently, quantitative evaluation of detection results is centered on Recall. Training was conducted with three random seeds in total. The noise-free setting is denoted as Clean, and the noise-added setting is denoted as Mixed.</p>
<p>Training was conducted with three random seeds in total. The noise-free setting is denoted as Clean, and the noise-added setting is denoted as Mixed. <xref ref-type="fig" rid="fig-3">Figs. 3</xref> and <xref ref-type="fig" rid="fig-4">4</xref> illustrate epoch-wise learning curve for the Clean and Mixed environments, with lines indicating the mean over random seeds and shading corresponding to the standard deviation across seeds.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Learning curve (Clean environment)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_72357-fig-3.tif"/>
</fig><fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Learning curve (Mixed environment)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_72357-fig-4.tif"/>
</fig>
<p>For the Clean and Mixed environments, the per&#x2013;attack-type training metrics are reported in <xref ref-type="table" rid="table-5">Tables 5</xref> and <xref ref-type="table" rid="table-6">6</xref>. Overall, results in the Clean environment are marginally superior, although certain attack types occasionally exhibit better performance in the Mixed environment.</p>
<table-wrap id="table-5">
<label>Table 5</label>
<caption>
<title>Comparison of precision, recall, and F1-score for each attack class (Clean)</title>
</caption>
<table>
<colgroup>
<col align="center" width="25mm"/>
<col align="center" width="25mm"/>
<col align="center" width="25mm"/>
<col align="center" width="25mm"/> </colgroup>
<thead>
<tr>
<th>Attack_type</th>
<th>Precision</th>
<th>Recall</th>
<th>F1-Score</th>
</tr>
</thead>
<tbody>
<tr>
<td>Normal</td>
<td>0.9999</td>
<td>1.0000</td>
<td>1.0000</td>
</tr>
<tr>
<td>DDoS_UDP</td>
<td>0.9995</td>
<td>0.9965</td>
<td>0.9980</td>
</tr>
<tr>
<td>DDoS_ICMP</td>
<td>1.0000</td>
<td>0.9997</td>
<td>0.9999</td>
</tr>
<tr>
<td>DDoS_TCP</td>
<td>0.9799</td>
<td>0.6996</td>
<td>0.8163</td>
</tr>
<tr>
<td>DDoS_HTTP</td>
<td>0.9825</td>
<td>0.7704</td>
<td>0.8624</td>
</tr>
<tr>
<td>SQL_injection</td>
<td>0.6913</td>
<td>0.3695</td>
<td>0.4192</td>
</tr>
<tr>
<td>Vulnerability_scanner</td>
<td>0.9803</td>
<td>0.8443</td>
<td>0.9072</td>
</tr>
<tr>
<td>Password</td>
<td>0.4848</td>
<td>0.7330</td>
<td>0.5649</td>
</tr>
<tr>
<td>Uploading</td>
<td>0.6840</td>
<td>0.5516</td>
<td>0.6107</td>
</tr>
<tr>
<td>Backdoor</td>
<td>1.0000</td>
<td>0.9481</td>
<td>0.9734</td>
</tr>
<tr>
<td>Port_Scanning</td>
<td>0.5324</td>
<td>0.8573</td>
<td>0.6569</td>
</tr>
<tr>
<td>XSS</td>
<td>0.4621</td>
<td>0.9226</td>
<td>0.6140</td>
</tr>
<tr>
<td>Ransomware</td>
<td>0.9971</td>
<td>0.9727</td>
<td>0.9847</td>
</tr>
<tr>
<td>Fingerprinting</td>
<td>0.5313</td>
<td>0.9943</td>
<td>0.6922</td>
</tr>
<tr>
<td>MITM</td>
<td>1.0000</td>
<td>1.0000</td>
<td>1.0000</td>
</tr>
</tbody>
</table>
</table-wrap><table-wrap id="table-6">
<label>Table 6</label>
<caption>
<title>Comparison of precision, recall, and F1-score for each attack class (Mixed)</title>
</caption>
<table>
<colgroup>
<col align="center" width="25mm"/>
<col align="center" width="25mm"/>
<col align="center" width="25mm"/>
<col align="center" width="25mm"/> </colgroup>
<thead>
<tr>
<th>Attack_type</th>
<th>Precision</th>
<th>Recall</th>
<th>F1-Score</th>
</tr>
</thead>
<tbody>
<tr>
<td>Normal</td>
<td>1.0000</td>
<td>1.0000</td>
<td>1.0000</td>
</tr>
<tr>
<td>DDoS_UDP</td>
<td>0.9991</td>
<td>0.9888</td>
<td>0.9939</td>
</tr>
<tr>
<td>DDoS_ICMP</td>
<td>0.9993</td>
<td>0.9993</td>
<td>0.9993</td>
</tr>
<tr>
<td>DDoS_TCP</td>
<td>0.9757</td>
<td>0.6886</td>
<td>0.8073</td>
</tr>
<tr>
<td>DDoS_HTTP</td>
<td>0.9651</td>
<td>0.7902</td>
<td>0.8680</td>
</tr>
<tr>
<td>SQL_injection</td>
<td>0.8571</td>
<td>0.2058</td>
<td>0.3316</td>
</tr>
<tr>
<td>Vulnerability_scanner</td>
<td>0.9865</td>
<td>0.8294</td>
<td>0.9011</td>
</tr>
<tr>
<td>Password</td>
<td>0.4594</td>
<td>0.8999</td>
<td>0.6083</td>
</tr>
<tr>
<td>Uploading</td>
<td>0.6860</td>
<td>0.5537</td>
<td>0.6127</td>
</tr>
<tr>
<td>Backdoor</td>
<td>0.9992</td>
<td>0.9461</td>
<td>0.9719</td>
</tr>
<tr>
<td>Port_Scanning</td>
<td>0.5340</td>
<td>0.9076</td>
<td>0.6724</td>
</tr>
<tr>
<td>XSS</td>
<td>0.4681</td>
<td>0.9193</td>
<td>0.6189</td>
</tr>
<tr>
<td>Ransomware</td>
<td>0.9850</td>
<td>0.9705</td>
<td>0.9776</td>
</tr>
<tr>
<td>Fingerprinting</td>
<td>0.5928</td>
<td>0.9793</td>
<td>0.7385</td>
</tr>
<tr>
<td>MITM</td>
<td>0.9995</td>
<td>0.9963</td>
<td>0.9976</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-5">Figs. 5</xref> and <xref ref-type="fig" rid="fig-6">6</xref> visualize recall across environments. Values are reported to two decimal places, and this visualization serves as input to the scoring model. Because operational settings typically contain mixed noise, the final metric selection adopts the Mixed environment.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Comparison of recall across environment (part 1)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_72357-fig-5.tif"/>
</fig><fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Comparison of recall across environment (part 2)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_72357-fig-6.tif"/>
</fig>
</sec>
</sec>
<sec id="s5">
<label>5</label>
<title>Risk Scoring Model</title>
<sec id="s5_1">
<label>5.1</label>
<title>Components and Weight</title>
<p>To enable the quantitative assessment of risk, our evaluation model adopts key concepts from the FAIR framework. While FAIR employs a multiplicative approach centered on the product of impact and frequency, the present study introduces a lightweight, additive model based on weighted linear combinations of four independently measured factors: the MITRE Impact Score (MIS), Frequency Score (FS), Detection Score (DS), and Difficulty Score (DifS) [<xref ref-type="bibr" rid="ref-25">25</xref>,<xref ref-type="bibr" rid="ref-39">39</xref>]. This revised structure facilitates independent evaluation and targeted feedback for each risk component [<xref ref-type="bibr" rid="ref-39">39</xref>].
<list list-type="bullet">
<list-item>
<p>MIS: The previously mapped CVSS risk scores, which range from 0.0 to 10.0, are normalized to a 0&#x2013;1 interval via division by 10 for incorporation into the risk scoring framework.</p></list-item>
<list-item>
<p>FS: Due to relative frequency shifts induced by differing class distributions, the raw metrics are not directly comparable and are therefore adjusted via normalization. Laplace smoothing assigns a minimal probability mass to extremely rare attack types, after which a log transform and 0&#x2013;1 rescaling are applied to obtain corrected values that are not unduly skewed [<xref ref-type="bibr" rid="ref-40">40</xref>,<xref ref-type="bibr" rid="ref-41">41</xref>].</p></list-item>
<list-item>
<p>DS: Grounded in the DNN-derived recall performance for each class, this metric is computed as 1&#x2013;recall, where values approaching 1 reflect greater risk due to undetected threats.</p></list-item>
<list-item>
<p>DifS: Modern cyberattacks are typically executed through multiple, sequential stages, each of which represents a critical axis for risk evaluation. As the number of attack phases increases, so does the associated risk score [<xref ref-type="bibr" rid="ref-42">42</xref>]. Based on the Cyber Kill Chain, the computation incorporates the distinctive characteristics of each attack type in a non-linear manner.</p></list-item>
</list></p>
<p>Based on the aforementioned factors, the risk scoring model is formulated as follows:
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mrow><mml:mtext mathvariant="italic">RiskScore</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mtext mathvariant="italic">MIS</mml:mtext></mml:mrow><mml:mo>&#x2217;</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>+</mml:mo><mml:mi>F</mml:mi><mml:mi>S</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>&#x03B2;</mml:mi><mml:mo>+</mml:mo><mml:mi>D</mml:mi><mml:mi>S</mml:mi><mml:mo>&#x2217;</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mo>+</mml:mo><mml:mrow><mml:mtext mathvariant="italic">DifS</mml:mtext></mml:mrow><mml:mo>&#x2217;</mml:mo><mml:mi>&#x03B4;</mml:mi></mml:math></disp-formula></p>
<p>The weights assigned to each factor are as follows: MIS (35%, <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> &#x003D; 0.35), FS (30%, <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mi>&#x03B2;</mml:mi></mml:math></inline-formula> &#x003D; 0.30), DS (25%, <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mi>&#x03B3;</mml:mi></mml:math></inline-formula> &#x003D; 0.25), and DifS (10%, <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mi>&#x03B4;</mml:mi></mml:math></inline-formula> &#x003D; 0.10). MIS and FS are regarded as the two most influential components within the risk scoring model; however, MIS is allocated a slightly greater weighting than FS due to its heightened impact on overall risk variation [<xref ref-type="bibr" rid="ref-25">25</xref>,<xref ref-type="bibr" rid="ref-39">39</xref>]. Following model formulation, real-world risk assessment is conducted, after which the robustness of the risk evaluation framework itself is systematically validated.</p>
<p>An additive scoring model enables meaningful evaluation of low-frequency yet high-impact attacks, while preserving the independent interpretability of each indicator and preventing the severe distortions that multiplicative aggregation can induce [<xref ref-type="bibr" rid="ref-43">43</xref>,<xref ref-type="bibr" rid="ref-44">44</xref>]. By managing multiple threat dimensions for cyber attack types as independent components and combining them additively via weights, the model maintains priority across indicators and captures multidimensional risk characteristics in a realistic and effective manner.</p>
<sec id="s5_1_1">
<label>5.1.1</label>
<title>FS via Laplace-Based Normalization</title>
<p>The Laplace smoothing formula is as follows.
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>n</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mi>&#x03B1;</mml:mi></mml:mrow><mml:mrow><mml:mi>N</mml:mi><mml:mo>+</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mi>K</mml:mi></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p>The parameters of the equation are as follows; <italic>N</italic> &#x003D; Total number of attack samples, <italic>K</italic> &#x003D; Number of attack types, <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>n</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> &#x003D; Count of attack type <italic>k</italic>, <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> &#x003D; 1 (corresponds to add-one smoothing), <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> &#x003D; Per-class smoothed probability prior. After applying Laplace smoothing, a logarithmic transformation is performed using below equation for numerical stability. The 0&#x2013;1 rescaling formula is as follows.
<disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:msub><mml:mi>l</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>+</mml:mo><mml:mi>c</mml:mi><mml:mo>,</mml:mo><mml:mi>c</mml:mi><mml:mo>=</mml:mo><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>6</mml:mn></mml:mrow></mml:msup></mml:math></disp-formula></p>
<p>The parameters of the equation are as follows; <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:msub><mml:mi>p</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> &#x003D; Per-class smoothed probability prior, <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:msub><mml:mi>l</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> &#x003D; Log-transformed value, <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mi>c</mml:mi></mml:math></inline-formula> &#x003D; Numerical stability constant. Finally, the values are mapped to the 0&#x2013;1 rescaling and applied to the scoring model. The 0&#x2013;1 rescaling formula is as follows.
<disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:msub><mml:mi>z</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:msub><mml:mi>l</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mi>l</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mi>m</mml:mi><mml:mi>a</mml:mi><mml:mi>x</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mi>l</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mi>l</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac></mml:math></disp-formula>
<disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:mi>s</mml:mi><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:msub><mml:mi>e</mml:mi><mml:mi>k</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mi>f</mml:mi><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mi>f</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mi>z</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></disp-formula></p>
<p>The parameters of the equation are as follows; <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:msub><mml:mi>l</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> &#x003D; Log-transformed value, <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mi>l</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:msub><mml:mi>l</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>&#x2026;</mml:mo><mml:msub><mml:mi>l</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:msub><mml:mi>z</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> &#x003D; min&#x2013;max normalized value, <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mi>f</mml:mi></mml:math></inline-formula> &#x003D; 0.050 (Floor value), <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:mi>s</mml:mi><mml:mi>c</mml:mi><mml:mi>o</mml:mi><mml:mi>r</mml:mi><mml:msub><mml:mi>e</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> &#x003D; Normalized FS. The final FS, corrected for severe inter-sample imbalance and the frequency loss of certain attack types via normalization, is presented in <xref ref-type="table" rid="table-7">Table 7</xref>.</p>
<table-wrap id="table-7">
<label>Table 7</label>
<caption>
<title>Frequency Score (FS) by attack type</title>
</caption>
<table>
<colgroup>
<col align="center" width="25mm"/>
<col align="center" width="25mm"/>
<col align="center" width="25mm"/>
<col align="center" width="25mm"/> </colgroup>
<thead>
<tr>
<th>Attack_type</th>
<th>Raw_Count</th>
<th>Raw_Frequency</th>
<th>FS (Normalized)</th>
</tr>
</thead>
<tbody>
<tr>
<td>DDoS_UDP</td>
<td>121,567</td>
<td>0.222</td>
<td>1.000</td>
</tr>
<tr>
<td>DDoS_ICMP</td>
<td>67,939</td>
<td>0.124</td>
<td>0.905</td>
</tr>
<tr>
<td>DDoS_TCP</td>
<td>50,062</td>
<td>0.092</td>
<td>0.855</td>
</tr>
<tr>
<td>DDoS_HTTP</td>
<td>49,203</td>
<td>0.090</td>
<td>0.852</td>
</tr>
<tr>
<td>SQL_injection</td>
<td>50,826</td>
<td>0.093</td>
<td>0.858</td>
</tr>
<tr>
<td>Vulnerability_scanner</td>
<td>50,026</td>
<td>0.092</td>
<td>0.855</td>
</tr>
<tr>
<td>Password</td>
<td>49,933</td>
<td>0.091</td>
<td>0.855</td>
</tr>
<tr>
<td>Uploading</td>
<td>36,915</td>
<td>0.068</td>
<td>0.806</td>
</tr>
<tr>
<td>Backdoor</td>
<td>24,026</td>
<td>0.044</td>
<td>0.736</td>
</tr>
<tr>
<td>Port_Scanning</td>
<td>19,983</td>
<td>0.037</td>
<td>0.705</td>
</tr>
<tr>
<td>XSS</td>
<td>15,066</td>
<td>0.028</td>
<td>0.659</td>
</tr>
<tr>
<td>Ransomware</td>
<td>9689</td>
<td>0.018</td>
<td>0.587</td>
</tr>
<tr>
<td>Fingerprinting</td>
<td>853</td>
<td>0.002</td>
<td>0.191</td>
</tr>
<tr>
<td>MITM</td>
<td>358</td>
<td>0.001</td>
<td>0.050</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s5_1_2">
<label>5.1.2</label>
<title>DifS via Cyber Kill Chain</title>
<p>DifS is mapped using the Cyber Kill Chain by leveraging the characteristics of each attack type, with risk increasing at later stages and scores designed to grow nonlinearly [<xref ref-type="bibr" rid="ref-22">22</xref>,<xref ref-type="bibr" rid="ref-23">23</xref>]. The equation for computing DifS based on the number of mapped stages is given as follows.
<disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:mrow><mml:mtext mathvariant="italic">DifS</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo>+</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2217;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mi>s</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>7</mml:mn><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow></mml:msup></mml:math></disp-formula></p>
<p>The parameters of the equation are as follows; <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mi>&#x03B1;</mml:mi></mml:math></inline-formula> &#x003D; 0.1 (Floor value), <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mi>&#x03B2;</mml:mi></mml:math></inline-formula> &#x003D; 1.5 (Nonlinearity adjustment coefficient), <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mi>s</mml:mi></mml:math></inline-formula> &#x003D; Mapped Cyber Kill Chain stages. The heuristic Cyber Kill Chain mapping&#x2014;derived from the dataset documentation&#x2019;s attack-type characteristics and keywords&#x2014;and the resulting DifS are presented in <xref ref-type="table" rid="table-8">Table 8</xref>. The seven stages of the Cyber Kill Chain, from Stage 1 to Stage 7, are as follows: Stage 1 &#x003D; Reconnaissance, Stage 2 &#x003D; Weaponization, Stage 3 &#x003D; Delivery, Stage 4 &#x003D; Exploitation, Stage 5 &#x003D; Installation, Stage 6 &#x003D; Command and Control, Stage 7 &#x003D; Actions on Objectives [<xref ref-type="bibr" rid="ref-26">26</xref>].</p>
<table-wrap id="table-8">
<label>Table 8</label>
<caption>
<title>Difficulty Score (DifS) by attack type</title>
</caption>
<table>
<colgroup>
<col align="center" width="33mm"/>
<col align="center" width="33mm"/>
<col align="center" width="33mm"/> </colgroup>
<thead>
<tr>
<th>Attack_type</th>
<th>Stages</th>
<th>DifS</th>
</tr>
</thead>
<tbody>
<tr>
<td>DDoS_UDP</td>
<td>Stage 2, 6, 7</td>
<td>0.35</td>
</tr>
<tr>
<td>DDoS_ICMP</td>
<td>Stage 2, 6, 7</td>
<td>0.35</td>
</tr>
<tr>
<td>DDoS_TCP</td>
<td>Stage 2, 6, 7</td>
<td>0.35</td>
</tr>
<tr>
<td>DDoS_HTTP</td>
<td>Stage 2, 6, 7</td>
<td>0.35</td>
</tr>
<tr>
<td>SQL_injection</td>
<td>Stage 1, 2, 3</td>
<td>0.35</td>
</tr>
<tr>
<td>Vulnerability_scanner</td>
<td>Stage 1</td>
<td>0.15</td>
</tr>
<tr>
<td>Password</td>
<td>Stage 1, 4</td>
<td>0.22</td>
</tr>
<tr>
<td>Uploading</td>
<td>Stage 2, 3, 4</td>
<td>0.35</td>
</tr>
<tr>
<td>Backdoor</td>
<td>Stage 2, 3, 4, 5</td>
<td>0.49</td>
</tr>
<tr>
<td>Port_Scanning</td>
<td>Stage 1</td>
<td>0.22</td>
</tr>
<tr>
<td>XSS</td>
<td>Stage 1, 2, 3</td>
<td>0.35</td>
</tr>
<tr>
<td>Ransomware</td>
<td>Stage 2, 3, 4, 5, 6, 7</td>
<td>0.80</td>
</tr>
<tr>
<td>Fingerprinting</td>
<td>Stage 1</td>
<td>0.15</td>
</tr>
<tr>
<td>MITM</td>
<td>Stage 4, 5, 6, 7</td>
<td>0.49</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s5_2">
<label>5.2</label>
<title>Risk Evaluation</title>
<p>The outcomes of the risk scoring model, incorporating all specified factors and their corresponding ground truth values, are summarized in <xref ref-type="table" rid="table-9">Table 9</xref>.</p>
<table-wrap id="table-9">
<label>Table 9</label>
<caption>
<title>Result of risk scoring model</title>
</caption>
<table>
<colgroup>
<col align="center" width="35mm"/>
<col align="center" width="10mm"/>
<col align="center" width="10mm"/>
<col align="center" width="10mm"/>
<col align="center" width="10mm"/>
<col align="center" width="13mm"/> </colgroup>
<thead>
<tr>
<th>Attack_type</th>
<th>MIS</th>
<th>FS</th>
<th>DS</th>
<th>DifS</th>
<th>Total</th>
</tr>
</thead>
<tbody>
<tr>
<td>DDoS_UDP</td>
<td>0.75</td>
<td>1.000</td>
<td>0.01</td>
<td>0.35</td>
<td>0.66150</td>
</tr>
<tr>
<td>DDoS_ICMP</td>
<td>0.55</td>
<td>0.905</td>
<td>0.00</td>
<td>0.35</td>
<td>0.53625</td>
</tr>
<tr>
<td>DDoS_TCP</td>
<td>0.75</td>
<td>0.855</td>
<td>0.31</td>
<td>0.35</td>
<td>0.67025</td>
</tr>
<tr>
<td>DDoS_HTTP</td>
<td>0.75</td>
<td>0.852</td>
<td>0.21</td>
<td>0.35</td>
<td>0.65450</td>
</tr>
<tr>
<td>SQL_injection</td>
<td>0.98</td>
<td>0.858</td>
<td>0.79</td>
<td>0.35</td>
<td>0.85800</td>
</tr>
<tr>
<td>Vulnerability_scanner</td>
<td>0.78</td>
<td>0.855</td>
<td>0.17</td>
<td>0.15</td>
<td>0.64425</td>
</tr>
<tr>
<td>Password</td>
<td>0.98</td>
<td>0.855</td>
<td>0.10</td>
<td>0.22</td>
<td>0.74075</td>
</tr>
<tr>
<td>Uploading</td>
<td>0.98</td>
<td>0.806</td>
<td>0.45</td>
<td>0.35</td>
<td>0.79400</td>
</tr>
<tr>
<td>Backdoor</td>
<td>0.98</td>
<td>0.736</td>
<td>0.05</td>
<td>0.49</td>
<td>0.73050</td>
</tr>
<tr>
<td>Port_Scanning</td>
<td>0.98</td>
<td>0.705</td>
<td>0.09</td>
<td>0.22</td>
<td>0.70175</td>
</tr>
<tr>
<td>XSS</td>
<td>0.48</td>
<td>0.659</td>
<td>0.08</td>
<td>0.35</td>
<td>0.45175</td>
</tr>
<tr>
<td>Ransomware</td>
<td>1.00</td>
<td>0.587</td>
<td>0.03</td>
<td>0.80</td>
<td>0.73125</td>
</tr>
<tr>
<td>Fingerprinting</td>
<td>0.98</td>
<td>0.191</td>
<td>0.04</td>
<td>0.15</td>
<td>0.55875</td>
</tr>
<tr>
<td>MITM</td>
<td>0.68</td>
<td>0.050</td>
<td>0.00</td>
<td>0.49</td>
<td>0.40150</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s5_3">
<label>5.3</label>
<title>Sensitivity Analysis of the Risk Model</title>
<p>Based on the proposed model, quantitative risk scores were generated for each attack type. The weights assigned to individual model components are subject to variation, and changes to these weights may significantly impact the resultant risk scores&#x2014;a phenomenon referred to as sensitivity [<xref ref-type="bibr" rid="ref-45">45</xref>]. A model exhibiting low sensitivity to such variations is considered robust, as its output remains stable despite perturbations in parameter weighting [<xref ref-type="bibr" rid="ref-45">45</xref>].</p>
<p>For model validation, statistical measures widely employed across diverse disciplines&#x2014;specifically, Spearman&#x2019;s and Kendall&#x2019;s rank correlation coefficients&#x2014;are utilized to assess agreement between model outputs and empirical observations [<xref ref-type="bibr" rid="ref-46">46</xref>].
<list list-type="bullet">
<list-item>
<p>Spearman&#x2019;s correlation coefficients: Spearman&#x2019;s correlation coefficients quantifies the linear association between ranked variables; a value <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:mi>&#x03B4;</mml:mi><mml:mo>&#x2265;</mml:mo><mml:mn>0.9</mml:mn></mml:math></inline-formula> is interpreted as indicative of a robust model [<xref ref-type="bibr" rid="ref-47">47</xref>].</p></list-item>
<list-item>
<p>Kendall&#x2019;s correlation coefficients: Kendall&#x2019;s correlation coefficients measures the directional concordance between paired rankings; a value <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mi>&#x03B4;</mml:mi><mml:mo>&#x2265;</mml:mo><mml:mn>0.8</mml:mn></mml:math></inline-formula> is interpreted as indicative of a robust model [<xref ref-type="bibr" rid="ref-48">48</xref>].</p></list-item>
</list></p>
<p>Each of the four model parameters was systematically perturbed by varying proportions (&#x2212;10%, &#x2212;5%, &#x002B;5%, &#x002B;10%), while the remaining components were adjusted proportionally to ensure the aggregate weighting remained normalized to 100%. This set of perturbations was applied to both correlation-based validation frameworks, and the resulting robustness profiles are presented in <xref ref-type="fig" rid="fig-7">Figs. 7</xref> and <xref ref-type="fig" rid="fig-8">8</xref>.</p>
<fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Sensitivity analysis (Spearman)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_72357-fig-7.tif"/>
</fig><fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>Sensitivity analysis (Kendall)</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_72357-fig-8.tif"/>
</fig>
<p>Spearman&#x2019;s and Kendall&#x2019;s rank correlation coefficients are nonparametric; accordingly, bootstrap resampling with replacement is used to obtain standard errors and confidence intervals, thereby strengthening the robustness of the scoring model [<xref ref-type="bibr" rid="ref-49">49</xref>]. After generating 2000 bootstrap samples for the results across 14 attack types, scores and ranks are computed by applying the respective indicator weights to each resample. Based on these, 95% confidence intervals are obtained as shown in <xref ref-type="table" rid="table-10">Table 10</xref>, demonstrating the stability of the ranks and the robustness of the model. When the DifS indicator is decreased by 10%, its weight effectively drops to 0%, causing substantial sensitivity shifts; excluding this condition, the results remain highly stable under nearly all perturbations [<xref ref-type="bibr" rid="ref-49">49</xref>].</p>
<table-wrap id="table-10">
<label>Table 10</label>
<caption>
<title>Bootstrap confidence intervals for Spearman&#x2019;s and Kendall&#x2019;s rank correlation coefficients</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/>
<col align="center" width="40mm"/>
<col align="center" width="40mm"/> </colgroup>
<thead>
<tr>
<th>Factor</th>
<th>Delta</th>
<th>Spearman (95% CI)</th>
<th>Kendall (95% CI)</th>
</tr>
</thead>
<tbody>
<tr>
<td>MIS</td>
<td>&#x002B;0.10</td>
<td>0.947 [0.751, 1.000]</td>
<td>0.868 [0.639, 1.000]</td>
</tr>
<tr>
<td>MIS</td>
<td>&#x002B;0.05</td>
<td>0.974 [0.852, 1.000]</td>
<td>0.912 [0.741, 1.000]</td>
</tr>
<tr>
<td>MIS</td>
<td>&#x2212;0.05</td>
<td>0.974 [0.865, 1.000]</td>
<td>0.890 [0.732, 1.000]</td>
</tr>
<tr>
<td>MIS</td>
<td>&#x2212;0.10</td>
<td>0.934 [0.711, 0.996]</td>
<td>0.824 [0.590, 0.976]</td>
</tr>
<tr>
<td>FS</td>
<td>&#x002B;0.10</td>
<td>0.930 [0.676, 1.000]</td>
<td>0.824 [0.529, 1.000]</td>
</tr>
<tr>
<td>FS</td>
<td>&#x002B;0.05</td>
<td>0.978 [0.853, 1.000]</td>
<td>0.912 [0.701, 1.000]</td>
</tr>
<tr>
<td>FS</td>
<td>&#x2212;0.05</td>
<td>0.982 [0.879, 1.000]</td>
<td>0.934 [0.786, 1.000]</td>
</tr>
<tr>
<td>FS</td>
<td>&#x2212;0.10</td>
<td>0.943 [0.762, 0.996]</td>
<td>0.824 [0.600, 0.976]</td>
</tr>
<tr>
<td>DS</td>
<td>&#x002B;0.10</td>
<td>0.960 [0.808, 0.996]</td>
<td>0.846 [0.658, 0.977]</td>
</tr>
<tr>
<td>DS</td>
<td>&#x002B;0.05</td>
<td>0.997 [0.929, 1.000]</td>
<td>0.956 [0.835, 1.000]</td>
</tr>
<tr>
<td>DS</td>
<td>&#x2212;0.05</td>
<td>0.982 [0.879, 1.000]</td>
<td>0.934 [0.780, 1.000]</td>
</tr>
<tr>
<td>DS</td>
<td>&#x2212;0.10</td>
<td>0.956 [0.772, 1.000]</td>
<td>0.890 [0.667, 1.000]</td>
</tr>
<tr>
<td>DifS</td>
<td>&#x002B;0.10</td>
<td>0.952 [0.762, 1.000]</td>
<td>0.846 [0.566, 1.000]</td>
</tr>
<tr>
<td>DifS</td>
<td>&#x002B;0.05</td>
<td>0.965 [0.810, 1.000]</td>
<td>0.890 [0.678, 1.000]</td>
</tr>
<tr>
<td>DifS</td>
<td>&#x2212;0.05</td>
<td>0.943 [0.691, 1.000]</td>
<td>0.868 [0.571, 1.000]</td>
</tr>
<tr>
<td>DifS</td>
<td>&#x2212;0.10</td>
<td>0.903 [0.590, 1.000]</td>
<td>0.802 [0.471, 1.000]</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Results and Discussion</title>
<sec id="s6_1">
<label>6.1</label>
<title>Ranked Prioritization of Attack Types</title>
<p>Based on our risk scoring model, we have quantified each component of the attack types to compute an aggregate risk score. Furthermore, we conducted a sensitivity analysis of the risk scoring model using Spearman&#x2019;s and Kendall&#x2019;s rank correlation coefficients. The results confirmed the model&#x2019;s robustness. <xref ref-type="table" rid="table-11">Table 11</xref> presents the risk scores in descending order, thereby establishing a ranked prioritization of the attack types.</p>
<table-wrap id="table-11">
<label>Table 11</label>
<caption>
<title>Attack type risk ranking</title>
</caption>
<table>
<colgroup>
<col align="center" width="33mm"/>
<col align="center" width="33mm"/>
<col align="center" width="33mm"/> </colgroup>
<thead>
<tr>
<th>Attack_type</th>
<th>Total</th>
<th>Rank</th>
</tr>
</thead>
<tbody>
<tr>
<td>SQL_injection</td>
<td>0.85800</td>
<td>1</td>
</tr>
<tr>
<td>Uploading</td>
<td>0.79400</td>
<td>2</td>
</tr>
<tr>
<td>Password</td>
<td>0.74075</td>
<td>3</td>
</tr>
<tr>
<td>Ransomware</td>
<td>0.73125</td>
<td>4</td>
</tr>
<tr>
<td>Backdoor</td>
<td>0.73050</td>
<td>5</td>
</tr>
<tr>
<td>Port_Scanning</td>
<td>0.70175</td>
<td>6</td>
</tr>
<tr>
<td>DDoS_TCP</td>
<td>0.67025</td>
<td>7</td>
</tr>
<tr>
<td>DDoS_UDP</td>
<td>0.66150</td>
<td>8</td>
</tr>
<tr>
<td>DDoS_HTTP</td>
<td>0.65450</td>
<td>9</td>
</tr>
<tr>
<td>Vulnerability_scanner</td>
<td>0.64425</td>
<td>10</td>
</tr>
<tr>
<td>Fingerprinting</td>
<td>0.55875</td>
<td>11</td>
</tr>
<tr>
<td>DDoS_ICMP</td>
<td>0.53625</td>
<td>12</td>
</tr>
<tr>
<td>XSS</td>
<td>0.45175</td>
<td>13</td>
</tr>
<tr>
<td>MITM</td>
<td>0.40150</td>
<td>14</td>
</tr>
</tbody>
</table>
</table-wrap>
<p><xref ref-type="fig" rid="fig-9">Fig. 9</xref> illustrates the influence of each evaluation factor on the risk scores and their resultant rankings. A histogram analysis reveals that for the majority of attack types, a higher MIS tends to correlate with a higher overall rank. Among the top-ranked categories, SQL_injection and Uploading stood out due to their relative difficulty of detection, distinguishing them from other high-ranking attack types. DDoS variants achieved high FS values; however, their inherently lower MIS led to mid-to-lower tier rankings overall.</p>
<fig id="fig-9">
<label>Figure 9</label>
<caption>
<title>Weighted contributions of result</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMES_72357-fig-9.tif"/>
</fig>
<p>SQL_injection was ranked overwhelmingly first, achieving exceptionally high scores across all evaluation metrics. This finding aligns with the real-world industrial assessment where SQL injection is consistently classified as one of the top-tier security risks [<xref ref-type="bibr" rid="ref-50">50</xref>]. The most conspicuous metric was its DS, which was the highest among all 14 attack types. The DNN model recorded a detection rate of less than 20%, which is consistent with research findings indicating that advanced and polymorphic SQL injection attacks are difficult to detect and thus pose a significant vulnerability [<xref ref-type="bibr" rid="ref-51">51</xref>].</p>
<p>Ransomware, while assigned very high MIS and DifS scores given its well-known destructive impact, ranked fourth because detection proved comparatively easier in our evaluation. Nevertheless, given its sustained destructive potential, it remains a key attack category that warrants constant vigilance. This inference is supported by other research, which warns that although the core behaviors of ransomware can be relatively straightforward to detect, a successful attack can lead to catastrophic financial and societal damage [<xref ref-type="bibr" rid="ref-52">52</xref>,<xref ref-type="bibr" rid="ref-53">53</xref>].</p>
</sec>
<sec id="s6_2">
<label>6.2</label>
<title>The Significance of Time-Series Datasets in Cybersecurity Research</title>
<p>While the Edge-IoT dataset utilized for our risk model contained a &#x2018;frame.time&#x2019; column, it was ultimately excluded during preprocessing due to significant data quality issues. The logged timestamps lacked a consistent format, and many entries were ambiguous, rendering the data unsuitable for rigorous time-series analysis. This is a notable limitation, as time-series data can serve as a critical indicator, enabling the modeling of various distributions and mass functions beyond simple frequency counts [<xref ref-type="bibr" rid="ref-54">54</xref>]. Consequently, the absence of reliable temporal data restricted our ability to model more sophisticated functions for the FS calculation in this study.</p>
<p>There is a notable scarcity of publicly available cybersecurity datasets, and even when such datasets exist, they often present significant analytical challenges. A fundamental problem is that many available datasets do not reflect the contemporary technological landscape, thus providing an inadequate basis for evaluating modern threats and validating new models [<xref ref-type="bibr" rid="ref-55">55</xref>]. This scarcity of relevant, high-quality data ultimately impedes the development of robust and timely security metrics [<xref ref-type="bibr" rid="ref-55">55</xref>].</p>
<p>While assessing aggregate, ecosystem-wide cyber risk is important, it is equally necessary to evaluate threats using site-specific datasets tailored to particular operational contexts. Although proprietary datasets are more constrained than aggregated benchmarks, they enable risk assessments that align with the realities of a given industry environment. Achieving this requires high-quality time-series telemetry and consistent log collection across heterogeneous edge devices, ensuring comparability and longitudinal reliability.</p>
</sec>
<sec id="s6_3">
<label>6.3</label>
<title>Lightweight Risk Assessment Model</title>
<p>Cyber-attacks are growing in sophistication and intelligence, leading to a commensurate surge in financial and societal damages [<xref ref-type="bibr" rid="ref-56">56</xref>]. The recent advent of generative AI has magnified this risk, yet new technologies are often adopted without adequate security assessment procedures, creating a reality where defensive capabilities lag behind the non-linear growth of threats [<xref ref-type="bibr" rid="ref-57">57</xref>].</p>
<p>In this context, our research introduces a lightweight model designed to provide quantitative risk metrics. While the threat landscape is evolving rapidly, the development of indicators and frameworks to accurately measure and evaluate these changes has not kept pace [<xref ref-type="bibr" rid="ref-55">55</xref>]. We contend that in such a dynamic environment, a lightweight model enabling at least a baseline security evaluation is a valuable and pragmatic approach, allowing organizations to maintain alignment with and respond to the rapidly changing threat environment.</p>
<p>While greater rigor in designing quantitative evaluation metrics generally improves reliability, it also increases complexity and slows updates. In this study, limitations arising from reliance on a single dataset, the constraints of DNN models, and skepticism toward alternative metrics are all acknowledged as valid concerns. Nevertheless, to deliver a highly portable, field-ready lightweight scoring model, deliberate trade-offs were made, enabling a challenging yet effective approach that culminated in actionable conclusions. The community should continue to debate which values to prioritize and at what point to reach consensus so that defensible, practically acceptable evaluation models can be developed.</p>
</sec>
</sec>
<sec id="s7">
<label>7</label>
<title>Conclusion</title>
<p>Cyber threats are increasing at an exponential rate, yet defensive innovations have not kept pace with the rapid evolution of threats. This discrepancy compels critical re-evaluation of strategies for confronting such rapid change. This study addresses this challenge by presenting a lightweight yet robust quantitative risk scoring model that integrates MITRE ATT&#x0026;CK, CVE, CVSS, and the Cyber Kill Chain into a unified assessment methodology. The key contribution lies in systematically mapping attack types observed in Edge-IoT/IIoT environments to standardized frameworks, enabling immediate reference to attack methods, severity through CVSS vectors, and manualized response procedures. By consolidating multiple cybersecurity frameworks into a single scoring model, we create an organically adaptable system where each component can be independently updated as new attack vectors emerge, ensuring sustained relevance in rapidly evolving threat landscapes.</p>
<p>A significant advancement of this work is the additive scoring structure that balances computational efficiency with analytical rigor. Unlike traditional risk assessment frameworks that demand extensive computational resources and hierarchical complexity&#x2014;thereby limiting portability to resource-constrained environments and hindering widespread adoption in real-world industrial settings&#x2014;this lightweight model facilitates rapid threat prioritization across diverse operational contexts, including mobile and edge deployments. The additive formulation, comprising Impact (MIS), Frequency (FS), Detection (DS), and Difficulty (DifS) components, preserves independent interpretability of each risk dimension while preventing the severe distortions that multiplicative aggregation can induce when prioritizing low-frequency yet high-impact attacks. This design choice ensures that critical threats are not obscured by conventional frequency-based approaches, enabling more nuanced and actionable risk assessments.</p>
<p>Robustness validation through non-parametric correlation analysis confirms the model&#x2019;s stability under operational variability. Spearman&#x2019;s and Kendall&#x2019;s rank correlation coefficients, combined with bootstrap confidence interval analysis, demonstrate that the model maintains consistent ranking performance across weight perturbations, establishing sufficient robustness for deployment in dynamic threat environments despite its lightweight design. This statistical validation underscores that analytical validity is not compromised by computational efficiency, a critical characteristic for adaptive deployment across heterogeneous edge infrastructures.</p>
<p>A key strength of this approach lies in its grounding in well-established, industry-validated frameworks such as MITRE ATT&#x0026;CK. By systematically incorporating such rigorously vetted knowledge bases into our risk model, we enable not only rapid threat identification and response but also establish standardized assessment criteria that extend naturally into complementary domains such as digital forensics and cyber resilience. This framework-driven methodology provides coherent strategic guidance across the entire threat management lifecycle&#x2014;from prevention through incident response to post-breach recovery. The standardized risk profiles generated through this methodology support evidence-based resource allocation, facilitate systematic incident investigation, and strengthen digital forensics capabilities by providing traceable threat attribution through CVE-CVSS linkages and MITRE ATT&#x0026;CK mappings. Such structured threat intelligence becomes indispensable as edge deployments proliferate and diversify, where maintaining defensive agility commensurate with environmental change demands systematic data collection paired with portable evaluation frameworks.</p>
<p>This study bridges the gap between defensive capabilities and offensive innovation by delivering a highly portable, field-deployable methodology that maintains analytical validity while ensuring practical applicability in real-world cybersecurity environments. Establishing such a foundation for adaptive threat modeling in next-generation cyber-physical infrastructures represents a critical step toward operational resilience in increasingly complex threat landscapes. Nevertheless, challenges remain regarding improvements in detection rates and inherent limitations in model rigor. Addressing these will require continued research focused on balancing methodological precision with computational efficiency. The development of practical, field-deployable guidelines and evaluation methodologies is essential to enable effective utilization of quantitative risk models across diverse industrial environments, ultimately advancing the state of operational cybersecurity practice.</p>
</sec>
</body>
<back>
<app-group>
<app id="app-1">
<title>Appendix A CVE and CVSS Vector</title>
<p>This appendix provides the complete mapping between attack types and CVEs, along with the corresponding CVSS vector values. CVSS vector prefixes encode the version; in this study, all vectors were compiled under CVSS v3.1.</p>
<table-wrap id="table-12">
<label>Table A1</label>
<caption>
<title>CVE-CVSS for each attack type with full version</title>
</caption>
<table>
<colgroup>
<col align="center" width="50mm"/>
<col align="center" width="50mm"/> </colgroup>
<thead>
<tr>
<th>Attack_type</th>
<th>CVE</th>
</tr>
</thead>
<tbody>
<tr>
<td>DDoS_UDP</td>
<td>CVE-2024-47850</td>
</tr>
<tr>
<td>DDoS_ICMP</td>
<td>CVE-2024-47678</td>
</tr>
<tr>
<td>DDoS_TCP</td>
<td>CVE-2023-0881, CVE-2025-38181</td>
</tr>
<tr>
<td>DDoS_HTTP</td>
<td>CVE-2025-55163, CVE-2024-23953</td>
</tr>
<tr>
<td>SQL_injection</td>
<td>CVE-2024-8465, CVE-2025-25181</td>
</tr>
<tr>
<td>Vulnerability_scanner</td>
<td>CVE-2024-43405, CVE-2024-41479, CVE-2024-27920</td>
</tr>
<tr>
<td>Password</td>
<td>CVE-2024-48845, CVE-2024-12604</td>
</tr>
<tr>
<td>Uploading</td>
<td>CVE-2025-21624, CVE-2024-48646</td>
</tr>
<tr>
<td>Backdoor</td>
<td>CVE-2022-42044, CVE-2022-41385</td>
</tr>
<tr>
<td>Port_Scanning</td>
<td>CVE-2025-57437</td>
</tr>
<tr>
<td>XSS</td>
<td>CVE-2025-1076, CVE-2025-29412</td>
</tr>
<tr>
<td>Ransomware</td>
<td>CVE-2024-51378</td>
</tr>
<tr>
<td>Fingerprinting</td>
<td>CVE-2023-37213</td>
</tr>
<tr>
<td>MITM</td>
<td>CVE-2025-54792, CVE-2025-0254, CVE-2025-9961</td>
</tr>
</tbody>
</table>
</table-wrap>
<table-wrap id="table-13">
<label>Table A2</label>
<caption>
<title>CVSS Vector for selected CVEs</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center" width="100mm"/> 
</colgroup>
<thead>
<tr>
<th>CVE</th>
<th>CVSS vector</th>
</tr>
</thead>
<tbody>
<tr>
<td>CVE-2024-47850</td>
<td>3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</td>
</tr>
<tr>
<td>CVE-2024-47678</td>
<td>3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</td>
</tr>
<tr>
<td>CVE-2023-0881</td>
<td>3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</td>
</tr>
<tr>
<td>CVE-2025-55163</td>
<td>3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</td>
</tr>
<tr>
<td>CVE-2024-8465</td>
<td>3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</td>
</tr>
<tr>
<td>CVE-2024-43405</td>
<td>3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</td>
</tr>
<tr>
<td>CVE-2024-48845</td>
<td>3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</td>
</tr>
<tr>
<td>CVE-2025-21624</td>
<td>3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</td>
</tr>
<tr>
<td>CVE-2022-42044</td>
<td>3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</td>
</tr>
<tr>
<td>CVE-2025-57437</td>
<td>3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</td>
</tr>
<tr>
<td>CVE-2025-1076</td>
<td>3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N</td>
</tr>
<tr>
<td>CVE-2024-51378</td>
<td>3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</td>
</tr>
<tr>
<td>CVE-2023-37213</td>
<td>3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</td>
</tr>
<tr>
<td>CVE-2025-54792</td>
<td>3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</td>
</tr>
</tbody>
</table>
</table-wrap>
</app>
<app id="app-2">
<title>Appendix B Structure of DNN Model</title>
<p>This appendix provides a detailed specification of the DNN architecture and hyperparameter settings, including layer configurations and optimizer parameters, to facilitate transparency and reproducibility.</p>
<table-wrap id="table-14">
<label>Table A3</label>
<caption>
<title>Layers and training hyperparameters of DNN model</title>
</caption>
<table>
<colgroup>
<col align="center"/>
<col align="center"/> 
</colgroup>
<thead>
<tr>
<th>Layers, parameters</th>
<th>Value</th>
</tr>
</thead>
<tbody>
<tr>
<td>Layers</td>
<td>#1 Dense (128, ReLU)</td>
</tr>
<tr>
<td></td>
<td>#2 Dropout (0.3)</td>
</tr>
<tr>
<td></td>
<td>#3 Dense (64, ReLU)</td>
</tr>
<tr>
<td></td>
<td>#4 Dropout (0.3)</td>
</tr>
<tr>
<td></td>
<td>#5 Dense (15, Softmax)</td>
</tr>
<tr>
<td>Input features</td>
<td>97</td>
</tr>
<tr>
<td>Learning rate</td>
<td>0.001</td>
</tr>
<tr>
<td>Loss function</td>
<td>Focal Loss</td>
</tr>
<tr>
<td>Optimizer</td>
<td>Adam</td>
</tr>
<tr>
<td>Gauss level</td>
<td>0.02</td>
</tr>
<tr>
<td>Spike ratio</td>
<td>0.01</td>
</tr>
<tr>
<td>Spike scale</td>
<td>3.0</td>
</tr>
<tr>
<td>Seeds</td>
<td>24, 42, 2025</td>
</tr>
</tbody>
</table>
</table-wrap>
</app>
</app-group>   
<ack>
<p>We extend our appreciation to the Sungkyunkwan University Software Laboratory (swlab) for providing the computational infrastructure for our experiments.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>This research was supported by the &#x201C;Regional Innovation System &#x0026; Education (RISE)&#x201D; through the Seoul RISE Center, funded by the Ministry of Education (MOE) and the Seoul Metropolitan Government (2025-RISE-01-018-05). And this research was supported by Quad Miners Corp.</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>The authors confirm contribution to the paper as follows: Conceptualization, Tae-hyeon Yun; methodology, Tae-hyeon Yun; software, Tae-hyeon Yun; validation, Tae-hyeon Yun; formal analysis, Tae-hyeon Yun; investigation, Tae-hyeon Yun; resources, Moohong Min; data curation, Tae-hyeon Yun; writing&#x2014;original draft preparation, Tae-hyeon Yun; writing&#x2014;review and editing, Moohong Min; visualization, Tae-hyeon Yun; supervision, Moohong Min; project administration, Moohong Min. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>The Edge-IoT/IIoT dataset that support the findings of this study is openly available in Kaggle at <ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/datasets/mohamedamineferrag/edgeiiotset-cyber-security-dataset-of-iot-iiot">https://www.kaggle.com/datasets/mohamedamineferrag/edgeiiotset-cyber-security-dataset-of-iot-iiot</ext-link> (accessed on 06 August 2025). CVE dataset from NVD is openly available in NVD data feeds page at <ext-link ext-link-type="uri" xlink:href="https://nvd.nist.gov/vuln/data-feeds">https://nvd.nist.gov/vuln/data-feeds</ext-link> (accessed on 14 August 2025).</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement">
<title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest to report regarding the present study.</p>
</sec> 
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shafee</surname> <given-names>A</given-names></string-name>, <string-name><surname>Hasan</surname> <given-names>S</given-names></string-name>, <string-name><surname>Awaad</surname> <given-names>TA</given-names></string-name></person-group>. <article-title>Privacy and security vulnerabilities in edge intelligence: an analysis and countermeasures</article-title>. <source>Comput Elect Eng</source>. <year>2025</year>;<volume>123</volume>(<issue>4</issue>):<fpage>110146</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.compeleceng.2025.110146</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Zhao</surname> <given-names>K</given-names></string-name>, <string-name><surname>Li</surname> <given-names>L</given-names></string-name>, <string-name><surname>Ding</surname> <given-names>K</given-names></string-name>, <string-name><surname>Gong</surname> <given-names>NZ</given-names></string-name>, <string-name><surname>Zhao</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Dong</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>A survey of model extraction attacks and defenses in distributed computing environments</article-title>. <comment>arXiv:2502.16065. 2025</comment>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kolias</surname> <given-names>C</given-names></string-name>, <string-name><surname>Kambourakis</surname> <given-names>G</given-names></string-name>, <string-name><surname>Stavrou</surname> <given-names>A</given-names></string-name>, <string-name><surname>Voas</surname> <given-names>J</given-names></string-name></person-group>. <article-title>DDoS in the IoT: mirai and other botnets</article-title>. <source>Computer</source>. <year>2017</year>;<volume>50</volume>(<issue>7</issue>):<fpage>80</fpage>&#x2013;<lpage>4</lpage>. doi:<pub-id pub-id-type="doi">10.1109/mc.2017.201</pub-id>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Benmalek</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Ransomware on cyber-physical systems: taxonomies, case studies, security gaps, and open challenges</article-title>. <source>Inter Things Cyber-Phys Syst</source>. <year>2024</year>;<volume>4</volume>(<issue>1</issue>):<fpage>186</fpage>&#x2013;<lpage>202</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.iotcps.2023.12.001</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shi</surname> <given-names>W</given-names></string-name>, <string-name><surname>Cao</surname> <given-names>J</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Edge computing: vision and challenges</article-title>. <source>IEEE Inter Things J</source>. <year>2016</year>;<volume>3</volume>(<issue>5</issue>):<fpage>637</fpage>&#x2013;<lpage>46</lpage>. doi:<pub-id pub-id-type="doi">10.1109/jiot.2016.2579198</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Quinn</surname> <given-names>S</given-names></string-name>, <string-name><surname>Ivy</surname> <given-names>N</given-names></string-name>, <string-name><surname>Barrett</surname> <given-names>M</given-names></string-name>, <string-name><surname>Witte</surname> <given-names>G</given-names></string-name>, <string-name><surname>Gardner</surname> <given-names>R</given-names></string-name></person-group>. <article-title>NISTIR 8286B: prioritizing cybersecurity risk for enterprise risk management. Technical report; Gaithersburg, MD, USA: NIST</article-title>; <year>2022</year>. doi:<pub-id pub-id-type="doi">10.6028/NIST.IR.8286B</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Weisman</surname> <given-names>MJ</given-names></string-name>, <string-name><surname>Kott</surname> <given-names>A</given-names></string-name>, <string-name><surname>Ellis</surname> <given-names>JE</given-names></string-name>, <string-name><surname>Murphy</surname> <given-names>BJ</given-names></string-name>, <string-name><surname>Parker</surname> <given-names>TW</given-names></string-name>, <string-name><surname>Smith</surname> <given-names>S</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Quantitative measurement of cyber resilience: modeling and experimentation</article-title>. <source>ACM Transact Cyber-Phys Syst</source>. <year>2025</year>;<volume>9</volume>(<issue>1</issue>):<fpage>1</fpage>&#x2013;<lpage>25</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3703159</pub-id>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Theisen</surname> <given-names>C</given-names></string-name>, <string-name><surname>Munaiah</surname> <given-names>N</given-names></string-name>, <string-name><surname>Al-Zyoud</surname> <given-names>M</given-names></string-name>, <string-name><surname>Carver</surname> <given-names>JC</given-names></string-name>, <string-name><surname>Meneely</surname> <given-names>A</given-names></string-name>, <string-name><surname>Williams</surname> <given-names>L</given-names></string-name></person-group>. <article-title>Attack surface definitions: a systematic literature review</article-title>. <source>Inform Softw Technol</source>. <year>2018</year>;<volume>104</volume>(<issue>6</issue>):<fpage>94</fpage>&#x2013;<lpage>103</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.infsof.2018.07.008</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xiong</surname> <given-names>W</given-names></string-name>, <string-name><surname>Legrand</surname> <given-names>E</given-names></string-name>, <string-name><surname>&#x00C5;berg</surname> <given-names>O</given-names></string-name>, <string-name><surname>Lagerstr&#x00F6;m</surname> <given-names>R</given-names></string-name></person-group>. <article-title>Cyber security threat modeling based on the MITRE Enterprise ATT&#x0026;CK Matrix</article-title>. <source>Softw Syst Model</source>. <year>2022</year>;<volume>21</volume>(<issue>1</issue>):<fpage>157</fpage>&#x2013;<lpage>77</lpage>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Jiang</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Meng</surname> <given-names>Q</given-names></string-name>, <string-name><surname>Shang</surname> <given-names>F</given-names></string-name>, <string-name><surname>Oo</surname> <given-names>N</given-names></string-name>, <string-name><surname>Minh</surname> <given-names>LTH</given-names></string-name>, <string-name><surname>Lim</surname> <given-names>HW</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>MITRE ATT&#x0026;CK applications in cybersecurity and the way forward</article-title>. <comment>arXiv:2502.10825. 2025</comment>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Georgiadou</surname> <given-names>A</given-names></string-name>, <string-name><surname>Mouzakitis</surname> <given-names>S</given-names></string-name>, <string-name><surname>Askounis</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Assessing mitre att&#x0026;ck risk using a cyber-security culture framework</article-title>. <source>Sensors</source>. <year>2021</year>;<volume>21</volume>(<issue>9</issue>):<fpage>3267</fpage>; <pub-id pub-id-type="pmid">34065086</pub-id></mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alwakeel</surname> <given-names>AM</given-names></string-name></person-group>. <article-title>An overview of fog computing and edge computing security and privacy issues</article-title>. <source>Sensors</source>. <year>2021</year>;<volume>21</volume>(<issue>24</issue>):<fpage>8226</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s21248226</pub-id>; <pub-id pub-id-type="pmid">34960320</pub-id></mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mazhar</surname> <given-names>T</given-names></string-name>, <string-name><surname>Talpur</surname> <given-names>DB</given-names></string-name>, <string-name><surname>Shloul</surname> <given-names>TA</given-names></string-name>, <string-name><surname>Ghadi</surname> <given-names>YY</given-names></string-name>, <string-name><surname>Haq</surname> <given-names>I</given-names></string-name>, <string-name><surname>Ullah</surname> <given-names>I</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Analysis of IoT security challenges and its solutions using artificial intelligence</article-title>. <source>Brain Sci</source>. <year>2023</year>;<volume>13</volume>(<issue>4</issue>):<fpage>683</fpage>. doi:<pub-id pub-id-type="doi">10.3390/brainsci13040683</pub-id>; <pub-id pub-id-type="pmid">37190648</pub-id></mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Salayma</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Threat modelling in Internet of Things (IoT) environments using dynamic attack graphs</article-title>. <source>Front Inter Things</source>. <year>2024</year>;<volume>3</volume>:<fpage>1306465</fpage>. doi:<pub-id pub-id-type="doi">10.3389/friot.2024.1306465</pub-id>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Abraham</surname> <given-names>JA</given-names></string-name>, <string-name><surname>Bindu</surname> <given-names>V</given-names></string-name></person-group>. <article-title>Intrusion detection and prevention in networks using machine learning and deep learning approaches: a review</article-title>. In: <conf-name>2021 International Conference on Advancements in Electrical, Electronics, Communication, Computing and Automation (ICAECA); 2021 Oct 8&#x2013;9</conf-name>; <publisher-loc>Coimbatore, India</publisher-loc>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Alsoufi</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Siraj</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Ghaleb</surname> <given-names>FA</given-names></string-name>, <string-name><surname>Al-Razgan</surname> <given-names>M</given-names></string-name>, <string-name><surname>Al-Asaly</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Alfakih</surname> <given-names>T</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Anomaly-based intrusion detection model using deep learning for IoT networks</article-title>. <source>Comput Model Eng Sci</source>. <year>2024</year>;<volume>141</volume>(<issue>1</issue>):<fpage>823</fpage>&#x2013;<lpage>45</lpage>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Li</surname> <given-names>S</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Xu</surname> <given-names>L</given-names></string-name></person-group>. <article-title>A review of hybrid cyber threats modelling and detection using artificial intelligence in IIoT</article-title>. <source>Comput Model Eng Sci</source>. <year>2024</year>;<volume>140</volume>(<issue>2</issue>):<fpage>1233</fpage>&#x2013;<lpage>61</lpage>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Zheng</surname> <given-names>X</given-names></string-name>, <string-name><surname>Wu</surname> <given-names>DD</given-names></string-name></person-group>. <article-title>Attacking DNN-based Intrusion Detection Models</article-title>. <source>IFAC-PapersOnLine</source>. <year>2020</year>;<volume>53</volume>(<issue>5</issue>):<fpage>415</fpage>&#x2013;<lpage>9</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.ifacol.2021.04.118</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>FIRST Org, Inc</collab></person-group>. <article-title>Common Vulnerability Scoring System version 3.1: specification Document</article-title>; <year>2021 [Internet]</year>. <comment>[cited 2025 Aug 6]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.first.org/cvss/v4-0/specification-document">https://www.first.org/cvss/v4-0/specification-document</ext-link>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Kuppa</surname> <given-names>A</given-names></string-name>, <string-name><surname>Aouad</surname> <given-names>L</given-names></string-name>, <string-name><surname>Le-Khac</surname> <given-names>NA</given-names></string-name></person-group>. <article-title>Linking cve&#x2019;s to mitre att&#x0026;ck techniques</article-title>. In: <conf-name>Proceedings of the 16th International Conference on Availability, Reliability and Security; 2021 Aug 17&#x2013;20</conf-name>; <publisher-loc>Vienna, Austria</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>12</lpage>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>LOCKHEED MARTIN, Corp</collab></person-group>. <article-title>Cyber Kill Chain [Internet]</article-title>. <comment>[cited 2025 Sep 23]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html">https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html</ext-link>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Nisioti</surname> <given-names>A</given-names></string-name>, <string-name><surname>Loukas</surname> <given-names>G</given-names></string-name>, <string-name><surname>Mylonas</surname> <given-names>A</given-names></string-name>, <string-name><surname>Panaousis</surname> <given-names>E</given-names></string-name></person-group>. <article-title>Forensics for multi-stage cyber incidents: survey and future directions</article-title>. <source>Forensic Sci Int: Digit Investigat</source>. <year>2023</year>;<volume>44</volume>(<issue>2</issue>):<fpage>301480</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.fsidi.2022.301480</pub-id>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Salim</surname> <given-names>DT</given-names></string-name>, <string-name><surname>Singh</surname> <given-names>MM</given-names></string-name>, <string-name><surname>Keikhosrokiani</surname> <given-names>P</given-names></string-name></person-group>. <article-title>A systematic literature review for APT detection and Effective Cyber Situational Awareness (ECSA) conceptual model</article-title>. <source>Heliyon</source>. <year>2023</year>;<volume>9</volume>(<issue>7</issue>):<fpage>e17156</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.heliyon.2023.e17156</pub-id>; <pub-id pub-id-type="pmid">37449192</pub-id></mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jayakumar</surname> <given-names>V</given-names></string-name>, <string-name><surname>Kannan</surname> <given-names>J</given-names></string-name>, <string-name><surname>Kausar</surname> <given-names>N</given-names></string-name>, <string-name><surname>Deveci</surname> <given-names>M</given-names></string-name>, <string-name><surname>Wen</surname> <given-names>X</given-names></string-name></person-group>. <article-title>Multicriteria group decision making for prioritizing IoT risk factors with linear diophantine fuzzy sets and MARCOS method</article-title>. <source>Granul Comput</source>. <year>2024</year>;<volume>9</volume>(<issue>3</issue>):<fpage>56</fpage>. doi:<pub-id pub-id-type="doi">10.1007/s41066-024-00480-8</pub-id>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Goyal</surname> <given-names>P</given-names></string-name>, <string-name><surname>Sanna</surname> <given-names>N</given-names></string-name>, <string-name><surname>Tucker</surname> <given-names>T</given-names></string-name></person-group>. <article-title>A FAIR framework for effective cyber risk management: leveraging the FAIR Model, FAIR-CAM, and FAIR-MAM to align cybersecurity efforts with business priorities and regulatory compliance</article-title>; <year>2025 [Internet]. [cited 2025 Aug 12]</year>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.fairinstitute.org/state-of-crm-2025">https://www.fairinstitute.org/state-of-crm-2025</ext-link>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Ferrag</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Friha</surname> <given-names>O</given-names></string-name>, <string-name><surname>Hamouda</surname> <given-names>D</given-names></string-name>, <string-name><surname>Maglaras</surname> <given-names>L</given-names></string-name>, <string-name><surname>Janicke</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Edge-IIoTset: a new comprehensive realistic cyber security dataset of IoT and IIoT applications for centralized and federated learning</article-title>. <source>IEEE Access</source>. <year>2022</year>;<volume>10</volume>:<fpage>40281</fpage>&#x2013;<lpage>306</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2022.3165809</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Dablain</surname> <given-names>DA</given-names></string-name>, <string-name><surname>Bellinger</surname> <given-names>C</given-names></string-name>, <string-name><surname>Krawczyk</surname> <given-names>B</given-names></string-name>, <string-name><surname>Chawla</surname> <given-names>NV</given-names></string-name></person-group>. <article-title>Efficient augmentation for imbalanced deep learning</article-title>. In: <conf-name>2023 IEEE 39th International Conference on Data Engineering (ICDE); 2023 Apr 3&#x2013;7</conf-name>; <publisher-loc>Anaheim, CA, USA</publisher-loc>. p. <fpage>1433</fpage>&#x2013;<lpage>46</lpage>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sha</surname> <given-names>K</given-names></string-name>, <string-name><surname>Yang</surname> <given-names>TA</given-names></string-name>, <string-name><surname>Wei</surname> <given-names>W</given-names></string-name>, <string-name><surname>Davari</surname> <given-names>S</given-names></string-name></person-group>. <article-title>A survey of edge computing-based designs for IoT security</article-title>. <source>Digital Communicat Netw</source>. <year>2020</year>;<volume>6</volume>(<issue>2</issue>):<fpage>195</fpage>&#x2013;<lpage>202</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.dcan.2019.08.006</pub-id>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xu</surname> <given-names>H</given-names></string-name>, <string-name><surname>Yu</surname> <given-names>W</given-names></string-name>, <string-name><surname>Griffith</surname> <given-names>D</given-names></string-name>, <string-name><surname>Golmie</surname> <given-names>N</given-names></string-name></person-group>. <article-title>A survey on industrial Internet of Things: a cyber-physical systems perspective</article-title>. <source>IEEE Access</source>. <year>2018</year>;<volume>6</volume>:<fpage>78238</fpage>&#x2013;<lpage>59</lpage>. doi:<pub-id pub-id-type="doi">10.1109/access.2018.2884906</pub-id>; <pub-id pub-id-type="pmid">35531371</pub-id></mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>ReliaQuest</collab></person-group>. <article-title>Mapping MITRE ATT&#x0026;CK to the microsoft exchange zero-day exploits</article-title>; <year>2021 [Internet]. [cited 2025 Aug 13]</year>. Available from: <ext-link ext-link-type="uri" xlink:href="https://reliaquest.com/blog/mapping-mitre-attack-to-microsoft-exchange-zero-day-exploits/">https://reliaquest.com/blog/mapping-mitre-attack-to-microsoft-exchange-zero-day-exploits/</ext-link>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>The MITRE Corporation</collab></person-group>. <article-title>CVE 25 YEARS; 2021 [Internet]</article-title>. <comment>[cited 2025 Aug 13]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.cve.org/">https://www.cve.org/</ext-link>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>X</given-names></string-name>, <string-name><surname>Moreschini</surname> <given-names>S</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Palomba</surname> <given-names>F</given-names></string-name>, <string-name><surname>Taibi</surname> <given-names>D</given-names></string-name></person-group>. <article-title>The anatomy of a vulnerability database: a systematic mapping study</article-title>. <source>J Syst Softw</source>. <year>2023</year>;<volume>201</volume>(<issue>1</issue>):<fpage>111679</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jss.2023.111679</pub-id>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gordienko</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Gordienko</surname> <given-names>N</given-names></string-name>, <string-name><surname>Taran</surname> <given-names>V</given-names></string-name>, <string-name><surname>Rojbi</surname> <given-names>A</given-names></string-name>, <string-name><surname>Telenyk</surname> <given-names>S</given-names></string-name>, <string-name><surname>Stirenko</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Effect of natural and synthetic noise data augmentation on physical action classification by brain-computer interface and deep learning</article-title>. <source>Front Neuroinformatics</source>. <year>2025</year>;<volume>19</volume>:<fpage>1521805</fpage>. doi:<pub-id pub-id-type="doi">10.3389/fninf.2025.1521805</pub-id>; <pub-id pub-id-type="pmid">40083893</pub-id></mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>GeeksforGeeks</collab></person-group>. <article-title>Gaussian Noise; 2025 [Internet]</article-title>. <comment>[cited 2025 Aug 7]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://www.geeksforgeeks.org/electronics-engineering/gaussian-noise/">https://www.geeksforgeeks.org/electronics-engineering/gaussian-noise/</ext-link>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Adegoke</surname> <given-names>OM</given-names></string-name>, <string-name><surname>Gbadamosi</surname> <given-names>SL</given-names></string-name>, <string-name><surname>Adejumobi</surname> <given-names>BS</given-names></string-name>, <string-name><surname>Owolabi</surname> <given-names>IE</given-names></string-name>, <string-name><surname>Oke</surname> <given-names>WA</given-names></string-name>, <string-name><surname>Nwulu</surname> <given-names>NI</given-names></string-name></person-group>. <article-title>Noise modelling and mitigation for broadband in-door power line communication systems</article-title>. <source>IET Communications</source>. <year>2024</year>;<volume>18</volume>(<issue>15</issue>):<fpage>869</fpage>&#x2013;<lpage>81</lpage>. doi:<pub-id pub-id-type="doi">10.1049/cmu2.12797</pub-id>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Mafi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Izquierdo</surname> <given-names>W</given-names></string-name>, <string-name><surname>Martin</surname> <given-names>H</given-names></string-name>, <string-name><surname>Cabrerizo</surname> <given-names>M</given-names></string-name>, <string-name><surname>Adjouadi</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Deep convolutional neural network for mixed random impulse and Gaussian noise reduction in digital images</article-title>. <source>IET Image Processing</source>. <year>2020</year>;<volume>14</volume>(<issue>15</issue>):<fpage>3791</fpage>&#x2013;<lpage>801</lpage>. doi:<pub-id pub-id-type="doi">10.1049/iet-ipr.2019.0931</pub-id>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Lin</surname> <given-names>TY</given-names></string-name>, <string-name><surname>Goyal</surname> <given-names>P</given-names></string-name>, <string-name><surname>Girshick</surname> <given-names>R</given-names></string-name>, <string-name><surname>He</surname> <given-names>K</given-names></string-name>, <string-name><surname>Doll&#x00E1;r</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Focal loss for dense object detection</article-title>. In: <conf-name>Proceedings of the 2017 IEEE International Conference on Computer Vision; 2017 Oct 22&#x2013;29</conf-name>; <publisher-loc>Venice, Italy</publisher-loc>. p. <fpage>2980</fpage>&#x2013;<lpage>8</lpage>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Donchev</surname> <given-names>D</given-names></string-name>, <string-name><surname>Vassilev</surname> <given-names>V</given-names></string-name>, <string-name><surname>Tonchev</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Impact of false positives and false negatives on security risks in transactions under threat</article-title>. In: <conf-name>International Conference on Trust and Privacy in Digital Business</conf-name>. <publisher-loc>Cham, Switzerland</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2021</year>. p. <fpage>50</fpage>&#x2013;<lpage>66</lpage>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>MacKenzie</surname> <given-names>CA</given-names></string-name></person-group>. <article-title>Summarizing risk using risk measures and risk indices</article-title>. <source>Risk Analysis</source>. <year>2014</year>;<volume>34</volume>(<issue>12</issue>):<fpage>2143</fpage>&#x2013;<lpage>62</lpage>. doi:<pub-id pub-id-type="doi">10.1111/risa.12220</pub-id>; <pub-id pub-id-type="pmid">24916468</pub-id></mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Le</surname> <given-names>VH</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Log-based anomaly detection with deep learning: how far are we?</article-title> In: <conf-name>Proceedings of the 44th International Conference on Software Engineering; 2022 May 25&#x2013;27</conf-name>; <publisher-loc>Pittsburgh, PA, USA</publisher-loc>. p. <fpage>1356</fpage>&#x2013;<lpage>67</lpage>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Ullah</surname> <given-names>I</given-names></string-name>, <string-name><surname>Mahmoud</surname> <given-names>QH</given-names></string-name></person-group>. <article-title>A scheme for generating a dataset for anomalous activity detection in IoT networks</article-title>. In: <conf-name>Canadian Conference On Artificial Intelligence</conf-name>. <publisher-loc>Cham, Switzerland</publisher-loc>: <publisher-name>Springer</publisher-name>; <year>2020</year>. p. <fpage>508</fpage>&#x2013;<lpage>20</lpage>.</mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Sen</surname> <given-names>&#x00D6;</given-names></string-name>, <string-name><surname>Ivanov</surname> <given-names>B</given-names></string-name>, <string-name><surname>Kloos</surname> <given-names>C</given-names></string-name>, <string-name><surname>Z&#x00F6;ll</surname> <given-names>C</given-names></string-name>, <string-name><surname>Lutat</surname> <given-names>P</given-names></string-name>, <string-name><surname>Henze</surname> <given-names>M</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>Simulation of multi-stage attack and defense mechanisms in smart grids</article-title>. <source>Int J Crit Infrastruct Prot</source>. <year>2025</year>;<volume>48</volume>:<fpage>100727</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.ijcip.2024.100727</pub-id>.</mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Diaz-Gallo</surname> <given-names>LM</given-names></string-name>, <string-name><surname>Brynedal</surname> <given-names>B</given-names></string-name>, <string-name><surname>Westerlind</surname> <given-names>H</given-names></string-name>, <string-name><surname>Sandberg</surname> <given-names>R</given-names></string-name>, <string-name><surname>Ramsk&#x00F6;ld</surname> <given-names>D</given-names></string-name></person-group>. <article-title>Understanding interactions between risk factors, and assessing the utility of the additive and multiplicative models through simulations</article-title>. <source>PLoS One</source>. <year>2021</year>;<volume>16</volume>(<issue>4</issue>):<fpage>e0250282</fpage>. doi:<pub-id pub-id-type="doi">10.1101/706234</pub-id>.</mixed-citation></ref>
<ref id="ref-44"><label>[44]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Manning</surname> <given-names>L</given-names></string-name>, <string-name><surname>Birchmore</surname> <given-names>I</given-names></string-name>, <string-name><surname>Morris</surname> <given-names>W</given-names></string-name></person-group>. <article-title>Swans and elephants: a typology to capture the challenges of food supply chain risk assessment</article-title>. <source>Trends Food Sci Technoly</source>. <year>2020</year>;<volume>106</volume>(<issue>1&#x2013;2</issue>):<fpage>288</fpage>&#x2013;<lpage>97</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.tifs.2020.10.007</pub-id>; <pub-id pub-id-type="pmid">33071459</pub-id></mixed-citation></ref>
<ref id="ref-45"><label>[45]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Tsanakas</surname> <given-names>A</given-names></string-name>, <string-name><surname>Millossovich</surname> <given-names>P</given-names></string-name></person-group>. <article-title>Sensitivity analysis using risk measures</article-title>. <source>Risk Analysis</source>. <year>2016</year>;<volume>36</volume>(<issue>1</issue>):<fpage>30</fpage>&#x2013;<lpage>48</lpage>. doi:<pub-id pub-id-type="doi">10.1111/risa.12434</pub-id>; <pub-id pub-id-type="pmid">26552862</pub-id></mixed-citation></ref>
<ref id="ref-46"><label>[46]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Puth</surname> <given-names>MT</given-names></string-name>, <string-name><surname>Neuh&#x00E4;user</surname> <given-names>M</given-names></string-name>, <string-name><surname>Ruxton</surname> <given-names>GD</given-names></string-name></person-group>. <article-title>Effective use of Spearman&#x2019;s and Kendall&#x2019;s correlation coefficients for association between two measured traits</article-title>. <source>Animal Behaviour</source>. <year>2015</year>;<volume>102</volume>:<fpage>77</fpage>&#x2013;<lpage>84</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.anbehav.2015.01.010</pub-id>.</mixed-citation></ref>
<ref id="ref-47"><label>[47]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Miot</surname> <given-names>HA</given-names></string-name></person-group>. <article-title>Correlation analysis in clinical and experimental studies</article-title>. <source>Jornal Vascular Brasileiro</source>. <year>2018</year>;<volume>17</volume>:<fpage>275</fpage>&#x2013;<lpage>9</lpage>; <pub-id pub-id-type="pmid">30787944</pub-id></mixed-citation></ref>
<ref id="ref-48"><label>[48]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Croux</surname> <given-names>C</given-names></string-name>, <string-name><surname>Dehon</surname> <given-names>C</given-names></string-name></person-group>. <article-title>Influence functions of the Spearman and Kendall correlation measures</article-title>. <source>Statist Meth Applicat</source>. <year>2010</year>;<volume>19</volume>(<issue>4</issue>):<fpage>497</fpage>&#x2013;<lpage>515</lpage>.</mixed-citation></ref>
<ref id="ref-49"><label>[49]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bishara</surname> <given-names>AJ</given-names></string-name>, <string-name><surname>Hittner</surname> <given-names>JB</given-names></string-name></person-group>. <article-title>Confidence intervals for correlations when data are not normal</article-title>. <source>Behav Res Meth</source>. <year>2017</year>;<volume>49</volume>(<issue>1</issue>):<fpage>294</fpage>&#x2013;<lpage>309</lpage>. doi:<pub-id pub-id-type="doi">10.3758/s13428-016-0702-8</pub-id>; <pub-id pub-id-type="pmid">26822671</pub-id></mixed-citation></ref>
<ref id="ref-50"><label>[50]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Paul</surname> <given-names>A</given-names></string-name>, <string-name><surname>Sharma</surname> <given-names>V</given-names></string-name>, <string-name><surname>Olukoya</surname> <given-names>O</given-names></string-name></person-group>. <article-title>SQL injection attack: detection, prioritization &#x0026; prevention</article-title>. <source>J Inf Secur Appl</source>. <year>2024</year>;<volume>85</volume>:<fpage>103871</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.jisa.2024.103871</pub-id>.</mixed-citation></ref>
<ref id="ref-51"><label>[51]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Floris</surname> <given-names>G</given-names></string-name>, <string-name><surname>Scano</surname> <given-names>C</given-names></string-name>, <string-name><surname>Montaruli</surname> <given-names>B</given-names></string-name>, <string-name><surname>Demetrio</surname> <given-names>L</given-names></string-name>, <string-name><surname>Valenza</surname> <given-names>A</given-names></string-name>, <string-name><surname>Compagna</surname> <given-names>L</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>ModSec-AdvLearn: countering adversarial SQL injections with robust machine learning</article-title>. <source>IEEE Trans Inf Forensics Secur</source>. <year>2025</year>;<volume>20</volume>:<fpage>6693</fpage>&#x2013;<lpage>705</lpage>. doi:<pub-id pub-id-type="doi">10.1109/tifs.2025.3583234</pub-id>.</mixed-citation></ref>
<ref id="ref-52"><label>[52]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Ispahany</surname> <given-names>J</given-names></string-name>, <string-name><surname>Islam</surname> <given-names>M</given-names></string-name>, <string-name><surname>Khan</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Islam</surname> <given-names>M</given-names></string-name></person-group>. <article-title>A sysmon incremental learning system for ransomware analysis and detection</article-title>. <comment>arXiv:2501.01089. 2025</comment>.</mixed-citation></ref>
<ref id="ref-53"><label>[53]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Dameff</surname> <given-names>C</given-names></string-name>, <string-name><surname>Tully</surname> <given-names>J</given-names></string-name>, <string-name><surname>Chan</surname> <given-names>TC</given-names></string-name>, <string-name><surname>Castillo</surname> <given-names>EM</given-names></string-name>, <string-name><surname>Savage</surname> <given-names>S</given-names></string-name>, <string-name><surname>Maysent</surname> <given-names>P</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Ransomware attack associated with disruptions at adjacent emergency departments in the US</article-title>. <source>JAMA Network Open</source>. <year>2023</year>;<volume>6</volume>(<issue>5</issue>):<fpage>e2312270</fpage>&#x2013;<lpage>0</lpage>. doi:<pub-id pub-id-type="doi">10.1001/jamanetworkopen.2023.12270</pub-id>; <pub-id pub-id-type="pmid">37155166</pub-id></mixed-citation></ref>
<ref id="ref-54"><label>[54]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Shapovalova</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Ba&#x015F;t&#x00FC;rk</surname> <given-names>N</given-names></string-name>, <string-name><surname>Eichler</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Multivariate count data models for time series forecasting</article-title>. <source>Entropy</source>. <year>2021</year>;<volume>23</volume>(<issue>6</issue>):<fpage>718</fpage>. doi:<pub-id pub-id-type="doi">10.3390/e23060718</pub-id>; <pub-id pub-id-type="pmid">34198726</pub-id></mixed-citation></ref>
<ref id="ref-55"><label>[55]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Cremer</surname> <given-names>F</given-names></string-name>, <string-name><surname>Sheehan</surname> <given-names>B</given-names></string-name>, <string-name><surname>Fortmann</surname> <given-names>M</given-names></string-name>, <string-name><surname>Kia</surname> <given-names>AN</given-names></string-name>, <string-name><surname>Mullins</surname> <given-names>M</given-names></string-name>, <string-name><surname>Murphy</surname> <given-names>F</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>Cyber risk and cybersecurity: a systematic review of data availability</article-title>. <source>Geneva Pap Risk Insur Issues Pract</source>. <year>2022</year>;<volume>47</volume>(<issue>3</issue>):<fpage>698</fpage>. doi:<pub-id pub-id-type="doi">10.1057/s41288-022-00266-6</pub-id>; <pub-id pub-id-type="pmid">35194352</pub-id></mixed-citation></ref>
<ref id="ref-56"><label>[56]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><surname>Eisenbach</surname> <given-names>TM</given-names></string-name>, <string-name><surname>Kovner</surname> <given-names>A</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>M</given-names></string-name></person-group>. <source>When it rains, it pours: Cyber risk and financial conditions</source>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>FRB of New York. Staff Report. 2022. No. 1022</publisher-name>.</mixed-citation></ref>
<ref id="ref-57"><label>[57]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><collab>World Economic Forum</collab></person-group>. <article-title>Global Cybersecurity Outlook 2025</article-title>; <year>2025 [Internet]</year>. <comment>[cited 2025 Aug 16]</comment>. Available from: <ext-link ext-link-type="uri" xlink:href="https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2025.pdf">https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2025.pdf</ext-link>.</mixed-citation></ref>
</ref-list>
</back></article>

