Application of Bayesian network in risk assessment for website deployment scenarios


  • Vu Thi Huong Giang HUST
  • Nguyen Manh Tuan Hanoi University of Science and Technology



deployment scenario, risk assessment, CVE, Bayesian network, scenario-based risk assessment

Tóm tắt

Abstract— The rapid development of web-based systems in the digital transformation era has led to a dramatic increase in the number and the severity of cyber-attacks. Current attack prevention solutions such as system monitoring, security testing and assessment are installed after the system has been deployed, thus requiring more cost and manpower. In that context, the need to assess cyber security risks before the deployment of web-based systems becomes increasingly urgent. This paper introduces a cyber security risk assessment mechanism for web-based systems before deployment. We use the Bayesian network to analyze and quantify the cyber security risks posed by threats to the deployment components of a website. First, the deployment components of potential website deployment scenarios are considered assets, so that their properties are mapped to specific vulnerabilities or threats. Next, the vulnerabilities or threats of each deployment component will be assessed according to the considered risk criteria in specific steps of a deployment process. The risk assessment results for deployment components are aggregated into the risk assessment results for their composed deployment scenario. Based on these results, administrators can compare and choose the least risky deployment scenario.


How to Cite

Giang, V. T. H. ., & Tuan, N. M. (2022). Application of Bayesian network in risk assessment for website deployment scenarios . Journal of Science and Technology on Information Security, 2(14), 3-17.