Modeling Interdependent Cybersecurity Threats Using Bayesian Networks: A Case Study on In-Vehicle Infotainment Systems
Sangita Sridar

TL;DR
This paper demonstrates how Bayesian Networks can model interdependent cybersecurity threats in automotive systems, enabling probabilistic reasoning, causal analysis, and vulnerability identification to improve risk assessment.
Contribution
It presents a novel approach of transforming attack trees into Bayesian Networks for dynamic cybersecurity risk modeling in in-vehicle systems.
Findings
Bayesian Networks effectively model threat dependencies and uncertainties.
The model supports probabilistic inference and causal analysis.
Insights into high-impact vulnerabilities guide mitigation strategies.
Abstract
Cybersecurity threats are increasingly marked by interdependence, uncertainty, and evolving complexity challenges that traditional assessment methods such as CVSS, STRIDE, and attack trees fail to adequately capture. This paper reviews the application of Bayesian Networks (BNs) in cybersecurity risk modeling, highlighting their capacity to represent probabilistic dependencies, integrate diverse threat indicators, and support reasoning under uncertainty. A structured case study is presented in which a STRIDE-based attack tree for an automotive In-Vehicle Infotainment (IVI) system is transformed into a Bayesian Network. Logical relationships are encoded using Conditional Probability Tables (CPTs), and threat likelihoods are derived from normalized DREAD scores. The model enables not only probabilistic inference of system compromise likelihood but also supports causal analysis using…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Information and Cyber Security · Vehicular Ad Hoc Networks (VANETs)
