Cyber Defense Effectiveness Evaluation for ICS Under Uncertainty: A Dynamic Bayesian Network Approach with Information Entropy
Abstract
1. Introduction
- 1.
- Neglect of defender perspective limitation. Most frameworks assume complete information, failing to model the discrepancy between observed and true system states—i.e., epistemic uncertainty. This yields overly optimistic evaluations disconnected from the defender’s actual environment.
- 2.
- Lack of joint dual-uncertainty modeling. Existing methods address epistemic or aleatoric uncertainty in isolation, without a framework that jointly models both within a single temporal probabilistic model. This fragmented treatment prevents defenders from simultaneously accounting for what they do not know about the current system state and what they cannot predict about its future evolution—a gap that directly motivates the need for a joint dual-uncertainty representation.
- 3.
- Absence of an encoding-independent companion metric for prediction uncertainty. Current approaches rely on expected values or variance to characterize effectiveness outcomes. Yet these metrics are tied to the numerical encoding of system states and do not provide a consistent, encoding-independent measure of prediction uncertainty. While information entropy offers such a measure, its integration with dynamic probabilistic models for pre-engagement defense evaluation remains an open gap.
- 1.
- Joint DBN-based framework for dual-uncertainty representation. We develop a DBN framework that simultaneously (i) embeds the defender’s partial observability and incomplete knowledge of attacker strategies (epistemic uncertainty), and (ii) models dynamic state evolution and inter-device dependency propagation (aleatoric uncertainty). By conditioning strategy evaluation on the defender’s actual observations rather than on an idealized global viewpoint, this framework provides a probabilistic representation that integrates both uncertainty types within a single temporal model.
- 2.
- Dual-metric methodology with entropy as a companion metric. Leveraging the DBN’s capacity to infer the full joint distribution of successive states, we couple the expected effectiveness differential with the information entropy of its predictive distribution. Operating in the probability domain rather than the numerical domain of variance, this entropy metric provides an encoding-independent measure of prediction uncertainty that captures the shape of the effectiveness distribution. Together, the two metrics jointly quantify anticipated performance and its associated unpredictability, offering a principled basis for risk-aware pre-engagement decisions.
2. Methods
2.1. Uncertainty from Perspective Bias
2.1.1. Uncertainty in Observed State
2.1.2. Uncertainty in Adversary Strategy
2.2. Uncertainty in State Evolution
2.2.1. State Evolution Uncertainty Triggered by Attack–Defense Actions
2.2.2. State Evolution Uncertainty Induced by Dependency Relationships
2.3. Attack–Defense Model Based on DBN
2.3.1. DBN Formulation
2.3.2. DBN Modeling Choices
2.4. Metrics of Attack–Defense Effectiveness
2.5. Computation of Attack–Defense Effectiveness
2.5.1. Theoretical Computational Procedure
- ()
- : the prior distribution of .
- ()
- : the likelihood probability of the observed state given the true state in the state observation model.
- ()
- : the decision strategy of the attacker.
- ()
- : the state transition probability triggered by attack–defense actions.
- , whose base CPT characterizes the structural dependency influence from other devices in the network;
- , whose base CPT characterizes the state transition driven by the device’s own current state and the attack–defense actions.
2.5.2. Practical Implementation
2.6. Summary of Notation
3. Results
3.1. Network Scenario Design
3.1.1. Network Isolation Layer
3.1.2. Dispatch and Control Layer
3.1.3. Substation Layer
3.1.4. Field Device Layer
3.2. Parameter Settings
3.2.1. State Vectors and Dependency Relationships
- 1.
- The firewall, located at the outermost security boundary of the system, has its policies independently configured and actively enforces access control. It does not depend on the operational state of any other network or functional node.
- 2.
- The IDS depends on the firewall. This is because the firewall determines the scope and security policy of allowed traffic. Its configuration or failure directly affects the volume and content of network traffic received by the IDS, thereby influencing its detection load and analysis results.
- 3.
- The operation of the SCADA Server depends on the firewall, IDS, gateway, and Station Switch. The Firewall and IDS together form the outer protective boundary of the SCADA Server’s network. Abnormal operation of either the firewall or IDS may expose the SCADA Server to security threats, affecting its normal operation. The gateway handles cross-domain communication and protocol conversion, while the Station Switch provides the fundamental communication channel for the SCADA Server to interact with station devices (e.g., protection devices). Malfunctions in either the gateway or the switch would interrupt the SCADA Server’s data acquisition and control command transmission.
- 4.
- The Communication Gateway depends on the Station Switch. The Station Switch provides the gateway with the intra-station data forwarding path and uplink channel. If the switch fails, the gateway will be unable to communicate with other devices, causing its protocol conversion and data relay functions to fail.
- 5.
- The Station Switch, as the core communication device within the substation, has fewer upstream dependencies and primarily provides basic connectivity functions.
- 6.
- Various protection devices collectively depend on the SCADA Server, Communication Gateway, and Station Switch. The switch and gateway provide them with communication and relay capabilities, while the SCADA Server issues operational parameters and control commands to manage them. Failures or anomalies in the switch, gateway, or SCADA Server will constrain the monitoring, control, or configuration functions of the protection devices, thereby affecting their protective actions and logic judgments.
3.2.2. Observation Vectors
3.2.3. Attack–Defense Strategies and State Transition Model
- : The attacker modifies firewall policies through credential leakage or vulnerability exploitation, relaxing access control and opening sensitive ports, allowing unauthorized traffic into the internal network.
- : The defender prevents unauthorized firewall modification through the principle of least-privilege and two-factor authentication.
- : The attacker evades IDS detection using packet fragmentation, encrypted tunnels, or signature mutation, allowing malicious traffic to go undetected.
- : The defender employs a combined rule-based and behavioral detection mechanism, regularly updating signature libraries to improve the identification rate of evasive traffic.
- : The attacker injects malicious code exploiting system vulnerabilities to tamper with monitoring data or execute incorrect control commands, causing SCADA functional anomalies or misoperations.
- : The defender prevents malicious code injection through system hardening, timely patching, and application signature verification, restoring normal SCADA logic.
- : The attacker exhausts switch resources by sending a large volume of spoofed broadcast or abnormal packets, causing LAN congestion or outage.
- : The defender mitigates flooding and abnormal traffic attacks by enabling MAC address binding, port security, and QoS rate limiting.
- : The attacker intercepts and tampers with control or measurement data in the inter-station communication channel, compromising protocol integrity and communication trust.
- : The defender prevents man-in-the-middle tampering of communications by enabling encrypted channels (TLS/IEC 62351) and message authentication codes.
- 1.
- Both attackers and defenders dynamically adjust the usage probability of their strategies based on the applicable scenarios and device states.
- 2.
- The attacker tends towards low-risk probing for normal devices and high-gain attacks for degraded devices.
- 3.
- The defender prioritizes deploying targeted measures for abnormal devices and reduces ineffective protection for failed devices.
- 1.
- When neither the attack nor the corresponding defense behavior is present, the device’s next state is always consistent with its current state:
- 2.
- When only the attack exists without the corresponding defense, the device’s state cannot improve, only worsen:
- 3.
- When only the defense exists without the corresponding attack, the device’s state cannot degrade, only improve:
3.2.4. Complete DBN
3.3. Effectiveness Function Definition
3.4. Experiments and Analysis
3.4.1. Defense Strategy Evaluation and Ablation Study
- (1)
- Experimental Settings
- , denoted , indicating the defender observes the system in an entirely normal state.
- , denoted , indicating the defender observes a minor anomaly in the firewall.
- , denoted , indicating the defender observes a severe anomaly in the SCADA Server.
- The defender takes no action, i.e., . This strategy set is denoted , serving as the baseline.
- The defender individually enables defense strategies targeting the firewall, IDS, SCADA Server, switch, and Communication Gateway, resulting in five strategy sets. These are denoted (), where for strategy , the corresponding has ().
- The defender simultaneously protects the firewall and SCADA Server, i.e., , denoted .
- The defender simultaneously protects the IDS and Communication Gateway, i.e., , denoted .
- Unknown Attack (): The defender has no knowledge of which attack strategies will be employed. The effectiveness distribution is computed by marginalizing over all possible attack strategy combinations according to . This condition retains full attacker strategy uncertainty.
- No Attack (): The attacker is known to employ no attack strategies (). This eliminates attacker strategy uncertainty entirely.
- Full-Scale Attack (): The attacker is known to employ all five attack strategies simultaneously (). This also eliminates attacker strategy uncertainty, but under a worst-case assumption.
- : The observation model is replaced by an identity mapping (), eliminating partial observability. This variant is functionally equivalent to a standard DBN evaluation that assumes the defender has full knowledge of the true system state—the common assumption in existing DBN-based risk assessment methods.
- : Inter-device dependency propagation is removed by making the state of each device conditionally independent of others. This variant represents the device-independent modeling adopted by most existing frameworks, which do not capture ICS-specific functional dependencies.
- (2)
- Strategy Evaluation with the Full Framework
- (3)
- Ablation Study: Contribution of Uncertainty Sources
- Attacker strategy uncertainty is examined through the –– contrast, which varies the defender’s knowledge of which attacks will be launched while keeping the full DBN model unchanged.
- Observation uncertainty is isolated by comparing the full model against under , where the observation noise is replaced by perfect state knowledge.
- Dependency propagation is assessed by comparing the full model against under , where inter-device dependencies are removed.
- Entropy vs. variance is examined in light of the preceding comparisons, to evaluate whether the entropy metric provides information distinct from traditional variance-based measures.
- Global elevation of prediction uncertainty. The expected loss and entropy increase across all strategies. In the full model, the posterior correctly reflects the defender’s cognitive limitations: the observation noise mixes a dominant fault branch () with a low-probability false-alarm branch (), the latter carrying substantially lower downstream uncertainty because a healthy firewall implies weaker attack incentives and reduced dependency propagation. Removing observation uncertainty () collapses the posterior onto the fault branch, assigning full weight to the high-uncertainty configuration. This systematically elevates the predicted uncertainty and expected cost for every strategy. For the baseline , the expected loss drops from to and the entropy rises from to bits; the same pattern holds for – and .
- Uneven impact across strategies. This elevation is not uniform. Strategies that directly protect the anomalous device ( and ) largely restore to normal, thereby switching the downstream uncertainty back to the low-uncertainty regime and insulating themselves from the global shift (, bits). Strategies that do not target the anomaly (–) absorb the full impact, widening the apparent performance gap between relevant and irrelevant options. The result is a distortion of the relative strategy ranking that is absent in the full model, where the false-alarm branch narrows these differences.
3.4.2. CPT Noise Robustness Analysis
- (1)
- Experimental Settings
- The entry with the largest probability value is selected as the anchor;
- A target relative change is drawn uniformly from the specified interval;
- The anchor entry is adjusted to , with the sign chosen randomly;
- The difference is redistributed among the remaining entries in proportion to their original values, ensuring that the sum of all probabilities remains exactly 1.0 and that no entry falls outside .
- (2)
- Results and Analysis
3.5. Computational Performance
3.5.1. Offline Precomputation Scaling
3.5.2. Online Evaluation Efficiency
4. Discussion
4.1. Comparison with Prior Work
4.2. The Value of Dual-Uncertainty Modeling
4.3. On the Choice of Entropy as a Companion Metric
4.4. Feasibility of Parameter Acquisition
- : Utilizing long-term operational data combined with Bayesian network structure learning and parameter learning methods [21,27,28] to automatically infer the dependency topology between device states and estimate their conditional probability distributions from historical data. This approach has mature theoretical support in the field of probabilistic graphical models.
- : Based on alerts and audit logs from monitoring systems (e.g., SIEM), this precisely quantifies the mapping relationship between the true state and the observed state (e.g., false positive rate, false negative rate).
- : This parameter represents the defender’s belief about “which strategies the attacker tends to adopt under specific system states.” Although the defender cannot directly know the attacker’s strategy distribution, this is essentially a threat behavior modeling problem and can be constructed in two ways: (1) Prior modeling based on authoritative knowledge bases and attack frameworks: defenders can leverage public, standardized cybersecurity knowledge bases, such as the MITRE ATT&CK ICS framework [29], to map the attack techniques in the framework to the attack strategy set in this model. Then, based on the preconditions for attack techniques described in the framework (e.g., required privileges, dependencies on system states) and combined with analyses of system vulnerabilities from guides like NIST SP 800-82 [20], they can qualitatively estimate under which system states a particular attack technique is more likely to be triggered. (2) Data-driven correction based on historical security events and threat intelligence: defenders can analyze internal historical security logs and external threat intelligence reports, using log mining and correlation analysis techniques [30,31] to count the frequency of different attack tactics and techniques occurring under specific system states, thereby using data to calibrate and enrich the prior model based on knowledge bases.
- : This parameter quantifies the likelihood of system state transitions under specific attack–defense strategy combinations, fusing attack effectiveness and defense effectiveness. Defenders can leverage public vulnerability databases (e.g., CVE/NVD), using CVSS exploitability scores as proxy variables for estimating attack success probability; alternatively, by repeatedly executing specific attack–defense actions in highly realistic ICS testbeds [32,33], the frequency of state transitions can be statistically obtained to estimate their probability.
4.5. Practical Deployment Workflow
- DBN construction and maintenance. The defender constructs the complete DBN—including true state variables , observation variables , attacker strategy variables , and defender strategy variables —from system architecture documentation, control logic specifications, network topology diagrams, and the deployed monitoring infrastructure. The DBN structure should be reviewed and refined after major system upgrades or topology changes.
- CPT specification. The four types of CPTs are populated through the pathways discussed in Section 4.4: prior distributions from operational data or device reliability statistics, observation likelihoods from SIEM false positive and false negative rates, attacker strategy models from the MITRE ATT&CK for ICS framework and threat intelligence, and state transition probabilities from vulnerability databases or testbed experiments.
- Effectiveness function and offline precomputation. The defender defines the state variables contributing to system effectiveness, assigns the device weights and single-device effectiveness functions according to organizational priorities, and precomputes the single-time-step effectiveness table for all single-time-step state configurations. This table is reused across all subsequent online evaluations (Section 2.5).
- Online evaluation. During pre-engagement planning, the defender supplies the current observation vector and a candidate defense strategy. The DBN inference engine computes the posterior joint distribution, and the effectiveness evaluation module outputs and as described in Section 2.5.
- Periodic model maintenance. The DBN structure and CPTs should be reviewed and updated after major system reconfigurations, significant threat landscape changes, or monitoring tool upgrades. The observation model merits particular attention, as changes in sensor deployment or IDS rule sets can shift false positive and false negative rates. The perturbation analysis (Section 3.4.2) demonstrates that the framework tolerates up to parameter drift, so continuous fine-tuning is unnecessary.
4.6. Defender-Attacker Duality
4.7. Limitations and Future Work
5. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
Abbreviations
| ICS | Industrial Control Systems |
| DBN | Dynamic Bayesian Network |
| CPT | Conditional Probability Table |
| SCADA | Supervisory Control and Data Acquisition |
| IDS | Intrusion Detection System |
References
- Langner, R. Stuxnet: Dissecting a cyberwarfare weapon. IEEE Secur. Priv. 2011, 9, 49–51. [Google Scholar] [CrossRef] [Scilit]
- Lee, R.M.; Assante, M.; Conway, T. Analysis of the Cyber Attack on the Ukrainian Power Grid: Defense Use Case; Technical Report; Electricity Information Sharing and Analysis Center (EISAC): Washington, DC, USA, 2016. [Google Scholar]
- Asghar, M.R.; Hu, Q.; Zeadally, S. Cybersecurity in industrial control systems: Issues, technologies, and challenges. Comput. Netw. 2019, 165, 106946. [Google Scholar] [CrossRef] [Scilit]
- Duo, W.; Zhou, M.; Abusorrah, A. A Survey of Cyber Attacks on Cyber Physical Systems: Recent Advances and Challenges. IEEE/CAA J. Autom. Sin. 2022, 9, 784–800. [Google Scholar] [CrossRef] [Scilit]
- Morozov, A.; Fabarisov, T.; Vock, S.; Siedel, G.; Bolbot, V.; Voß, S. Risk and Reliability Evaluation of Future Industrial Automation Systems: A Systematic Literature Review and Research Agenda. ASCE-ASME J. Risk Uncertain. Eng. Syst. Part B Mech. Eng. 2026, 12, 020801. [Google Scholar] [CrossRef] [Scilit]
- Bhosale, P.; Kastner, W.; Sauter, T. AutomationML Meets Bayesian Networks: A Comprehensive Safety-Security Risk Assessment in Industrial Control Systems. IEEE Open J. Ind. Electron. Soc. 2024, 5, 823–835. [Google Scholar] [CrossRef] [Scilit]
- Maradova, K.; Blecha, P.; Samelova, V.; Marada, T.; Zuth, D. Bayesian Networks for Cybersecurity Decision Support: Enhancing Human-Machine Interaction in Technical Systems. Appl. Sci. 2026, 16, 3053. [Google Scholar] [CrossRef] [Scilit]
- Cheimonidis, P.; Rantos, K. A novel proactive and dynamic cyber risk assessment methodology. Comput. Secur. 2025, 154, 104439. [Google Scholar] [CrossRef] [Scilit]
- Yang, W.; Hou, F.; Jia, Z.; Wang, H.; Yao, Y.; Yin, P.; Xu, X.; Liu, S. A Dynamic Risk Assessment Method for Industrial Control Network Security Based on Bayesian Attack Graph. In Proceedings of the 2025 5th International Conference on Computer, Control and Robotics, Hangzhou, China, 16–18 May 2025. [Google Scholar]
- Ren, J.; Liu, J.; Dong, Y.; Li, Z.; Li, W. An Attacker–Defender Game Model with Constrained Strategies. Entropy 2024, 26, 624. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Yao, P.; Wang, X.; Zhang, Z.; Yan, B.; Yang, Q.; Wang, W. Statistical Knowledge and Game-Theoretic Integrated Model for Cross-Layer Impact Assessment in Industrial Cyber-Physical Systems. Adv. Eng. Inform. 2024, 59, 102338. [Google Scholar] [CrossRef] [Scilit]
- Aftabi, N.; Li, D.; Sharkey, T. An Optimization Framework for Cyber-Physical Vulnerability Analysis in Industrial Cyber-Physical Systems. In Proceedings of IISE Annual Conference and Expo; IISE: Norcross, Georgia, 2023. [Google Scholar]
- Kim, Y.; Lee, I.; Kwon, H.; Lee, K.; Yoon, J. BAN: Predicting APT Attack Based on Bayesian Network with MITRE ATT&CK Framework. IEEE Access 2023, 11, 91949–91968. [Google Scholar] [CrossRef] [Scilit]
- Kazeminajafabadi, A.; Ghoreishi, S.F.; Imani, M. Optimal Detection for Bayesian Attack Graphs under Uncertainty in Monitoring and Reimaging. In Proceedings of the 2024 American Control Conference (ACC), Toronto, ON, Canada, 10–12 July 2024. [Google Scholar]
- Zhou, Y.; Zhang, Z.; Fan, K.; Wang, M.; Cheng, K.; Zhang, Z.; Zhang, H. A Novel Quantitative Risk Assessment Model for Industrial Control Systems Integrating the Cyber–Physical Domain. IEEE Trans. Ind. Inform. 2025, 21, 6433–6442. [Google Scholar] [CrossRef] [Scilit]
- Chockalingam, S.; Pieters, W.; Teixeira, A.M.; van Gelder, P. Probability Elicitation for Bayesian Networks to Distinguish Between Intentional Attacks and Accidental Technical Failures. J. Inf. Secur. Appl. 2023, 75, 103497. [Google Scholar] [CrossRef] [Scilit]
- Zhou, M.; Han, L.; Che, X. Strengthening Edge Defense: A Differential Game-Based Edge Intelligence Strategy Against APT Attacks. Comput. Secur. 2025, 157, 104580. [Google Scholar] [CrossRef] [Scilit]
- Caetano, H.O.; N., L.D.; Fogliatto, M.S.; Maciel, C.D. Resilience Assessment of Critical Infrastructures Using Dynamic Bayesian Networks and Evidence Propagation. Reliab. Eng. Syst. Saf. 2024, 241, 109691. [Google Scholar] [CrossRef] [Scilit]
- Alevizos, C.; Ta, V.-T. Threat-Informed Cyber Resilience Index: A Probabilistic Quantitative Approach to Measure Defence Effectiveness Against Cyber Attacks. arXiv 2024, arXiv:2406.19374. [Google Scholar] [CrossRef] [Scilit]
- Stouffer, K.; Falco, J.; Scarfone, K. Guide to Industrial Control Systems (ICS) Security; NIST Special Publication 800-82; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2011.
- Koller, D.; Friedman, N. Probabilistic Graphical Models: Principles and Techniques; MIT Press: Cambridge, MA, USA, 2009. [Google Scholar]
- pgmpy Package. Available online: https://pgmpy.org (accessed on 19 May 2025).
- IEC 60870-5-104; Telecontrol Equipment and Systems – Part 5-104: Transmission Protocols – Network Access for IEC 60870-5-101 Using Standard Transport Profiles. IEC: Geneva, Switzerland, 2016.
- IEC 62351; Power Systems Management and Associated Information Exchange—Data and Communications Security. IEC: Geneva, Switzerland, 2012.
- [Dataset] Simulation Data. Available online: https://github.com/engutou/ICS-Effectiveness (accessed on 9 April 2026).
- Janani, K. Cybersecurity through Entropy Injection: A Paradigm Shift from Reactive Defense to Proactive Uncertainty. arXiv 2025, arXiv:2504.11661. [Google Scholar] [CrossRef] [Scilit]
- Tsamardinos, I.; Brown, L.E.; Aliferis, C.F. The max-min hill-climbing Bayesian network structure learning algorithm. Mach. Learn. 2006, 65, 31–78. [Google Scholar] [CrossRef] [Scilit]
- Pradhan, S.; Singh, R.; Kachru, K.; Narasimhamurthy, S. A Bayesian network based approach for root cause analysis in industrial processes. In Proceedings of the 2007 International Conference on Computational Intelligence and Security (CIS 2007); IEEE: Piscataway, NJ, USA, 2007. [Google Scholar]
- MITRE Corporation. MITRE ATT&CK for Industrial Control Systems. Available online: https://attack.mitre.org/versions/v12/matrices/ics (accessed on 9 April 2026).
- Alam, M.T.; Bhusal, D.; Park, Y.; Rastogi, N. Looking Beyond IoCs: Automatically Extracting Attack Patterns from External CTI. In Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2023), Hong Kong, China, 16–18 October 2023; pp. 92–108. [Google Scholar]
- Arafune, M.; Rajalakshmi, S.; Jaldon, L.; Jadidi, Z.; Pal, S.; Foo, E. Design and Development of Automated Threat Hunting in Industrial Control Systems. In Proceedings of the 2022 IEEE International Conference on Pervasive Computing and Communications Workshops (PerCom Workshops); IEEE: Piscataway, NJ, USA, 2022. [Google Scholar]
- Formby, D.; Rad, M.; Beyah, R. Lowering the Barriers to Industrial Control System Security with GRFICS. In Proceedings of the 2018 USENIX Workshop on Advances in Security Education (ASE); USENIX Association: Berkeley, CA, USA, 2018. [Google Scholar]
- Goh, J.; Adepu, S.; Junejo, K.N.; Mathur, A. A Dataset to Support Research in the Design of Secure Water Treatment Systems. In Critical Information Infrastructures Security; Springer: Cham, Switzerland, 2016. [Google Scholar]


















| Symbol | Description |
|---|---|
| System State & Observations | |
| / | True system state vector (general/at time t) |
| / | Defender’s observation vector |
| / | Attacker’s observation vector |
| / | State of device i (scalar component of ) |
| A specific realization (value) of | |
| Sample space of the true system state | |
| Strategy & Actions | |
| Attacker’s strategy vector at time t | |
| Defender’s strategy vector at time t | |
| Binary indicators for specific attack/defense strategies | |
| Probabilistic Dependencies | |
| Defender’s posterior belief about the true state given observations | |
| Attacker’s posterior belief about the true state given observations | |
| Defender’s belief about the attacker’s strategy given the true state | |
| Effectiveness Metrics | |
| System effectiveness function | |
| Effectiveness differential: | |
| Expected effectiveness differential | |
| Information entropy of the effectiveness differential | |
| Bayesian Network Notation | |
| Set of parent nodes of random variable v | |
| Union of parent node sets for all | |
| Strategy | ||||
|---|---|---|---|---|
| Gain | Gain | |||
| — | — | |||
| (sum) | — | — | ||
| I | Time (s) | Memory (KB) | |
|---|---|---|---|
| 7 | 16,384 | 0.04 | 64 |
| 8 | 65,536 | 0.15 | 256 |
| 9 | 262,144 | 0.65 | 1024 |
| 10 | 1,048,576 | 4.08 | 4096 |
| 11 | 4,194,304 | 16.18 | 16,384 |
| 12 | 16,777,216 | 51.49 | 65,536 |
| Non-Zero Entries | Time (s) |
|---|---|
| 100,000 | 1.26 |
| 1,000,000 | 1.35 |
| 5,000,000 | 3.21 |
| 10,000,000 | 5.08 |
| Method Category | PO | DE | DP | EU | AU | Entropy |
|---|---|---|---|---|---|---|
| Static BN [6,7] | × | × | ✓ | × | ✓ | × |
| Dynamic Assessment [8,9,18] | × | ✓ | ✓ | × | ✓ | × |
| Game-theoretic/Optimization [10,11,12] | × | ✓ | × (Ltd.) | × | ✓ | × (Part.) |
| Attack Prediction and Detection [13,14] | ✓ (Part.) | ✓ | ✓ | ✓ (Part.) | ✓ | × |
| POMDP-based Resilience [19] | ✓ | ✓ | × | ✓ | ✓ | × |
| Uncertainty Quantification [15,16,17] | ✓ (Part.) | × (Ltd.) | × | ✓ (Part.) | ✓ (Part.) | × (Part.) |
| This Work (DBN + Entropy) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Kang, R.; Zhang, Z.; Zhang, X.; Chen, J.; Xu, R.; Zhang, Y.; Rao, Z. Cyber Defense Effectiveness Evaluation for ICS Under Uncertainty: A Dynamic Bayesian Network Approach with Information Entropy. Entropy 2026, 28, 635. https://doi.org/10.3390/e28060635
Kang R, Zhang Z, Zhang X, Chen J, Xu R, Zhang Y, Rao Z. Cyber Defense Effectiveness Evaluation for ICS Under Uncertainty: A Dynamic Bayesian Network Approach with Information Entropy. Entropy. 2026; 28(6):635. https://doi.org/10.3390/e28060635
Chicago/Turabian StyleKang, Rongbao, Zhiyong Zhang, Xiao Zhang, Jianfeng Chen, Ruoyu Xu, Yongdong Zhang, and Zhihong Rao. 2026. "Cyber Defense Effectiveness Evaluation for ICS Under Uncertainty: A Dynamic Bayesian Network Approach with Information Entropy" Entropy 28, no. 6: 635. https://doi.org/10.3390/e28060635
APA StyleKang, R., Zhang, Z., Zhang, X., Chen, J., Xu, R., Zhang, Y., & Rao, Z. (2026). Cyber Defense Effectiveness Evaluation for ICS Under Uncertainty: A Dynamic Bayesian Network Approach with Information Entropy. Entropy, 28(6), 635. https://doi.org/10.3390/e28060635

