Graph entropy-based node exposure score for risk assessment in information systems
Abstract
This paper introduces the node exposure score (NES), a topology-based metric that quantifies node exposure in an information system by computing random trees, with a focus on risk identification. NES aligns node exposure with the average infection time if an infectionâthe period required for a replicable state to reach a node through topological diffusion dynamicsâstarted from any other node. A multi-stage benchmark across Gnutella P2P, ErdĆsâRĂ©nyi, and BarabĂĄsiâAlbert graphs analyzes parameter sensitivity, runtime complexity, epidemiological kinetics, and comparative ranking alignment against seven baseline node invariants using Spearman (SC) and Kendallâs tau (KT) correlations in small- to medium-sized graphs. Aggregated benchmarks demonstrate NESâs superior robustness, achieving global mean scores of \(0.98 \pm 0.03\) (SC) and \(0.92 \pm 0.06\) (KT). Its high runtime cost indicates that the computation benefits from parallel and high-performance computing (HPC) frameworks, particularly in real-time processing dynamic environments where networks constantly change.
Data availability
No datasets were generated or analyzed during the current study.
References
Evans D (2011) The Internet of Things: how the next evolution of the internet is changing everything. CISCO White Paper 1:1â11
Ray S, Jin Y, Raychowdhury A (2016) The changing computing paradigm with Internet of Things: a tutorial introduction. IEEE Des Test 33(2):76â96
Segurola-Gil L, Zola F, Echeberria-Barrio X, Orduna-Urrutia R (2021) Nbcoded: network attack classifiers based on encoder and Naive Bayes model for resource limited devices. In: Joint European Conference on Machine Learning and Knowledge Discovery in Databases, pp 55â70
Segurola-Gil L, Moreno-Moreno M, Irigoien I, Florez-Tapia AM (2024) Unsupervised anomaly detection approach for cyberattack identification. Int J Mach Learn Cybern 15:1â12
FernĂĄndez-Carrasco, J.Ă, Segurola-Gil, L, Zola, F, Orduna-Urrutia, R (2022) Security and 5G: attack mitigation using reinforcement learning in SDN networks. In: 2022 IEEE Future Networks World Forum (FNWF), pp 622â627
National Institute of Standards and Technology: framework for improving critical infrastructure cybersecurity. Technical Report Version 1.1, U.S. Department of Commerce (2018). https://doi.org/10.6028/NIST.IR.8204. https://nist.gov. Accessed on 27 Nov 2024
International Organization for Standardization: ISO 31000:2018ârisk managementâGuidelines Standard (2018). https://www.iso.org/standard/65694.html. Accessed on 27 Nov 2024
SĂĄnchez-GarcĂa ID, MejĂa J, Feliu Gilabert ST (2022) Cybersecurity risk assessment: a systematic mapping review, proposal, and validation. Appl Sci 13(1):395
International Organization for Standardization: ISO/IEC 27005:2018âInformation technologyâSecurity techniquesâInformation security risk management. Standard (2018). https://www.iso.org/standard/75658.html. Accessed on 27 Nov 2024
Shannon CE, Weaver W (1949) The Mathematical Theory of Communication. The University of Illinois Press, Urbana
Travençolo BAN, Costa LDF (2008) Accessibility in complex networks. Phys Lett A 373(1):89â95
Fan W, He Y, Han X, Feng Y (2021) A new model to identify node importance in complex networks based on DEMATEL method. Sci Rep 11(1):22829
Wissler C (1905) The Spearman correlation formula. Science 22(558):309â311
Kendall MG (1938) A new measure of rank correlation. Biometrika 30(1â2):81â93
Ganin AA, Quach P, Panwar M, Collier ZA, Keisler JM, Marchese D, Linkov I (2020) Multicriteria decision framework for cybersecurity risk assessment and management. Risk Anal 40(1):183â199
Kalinin M, Krundyshev V, Zegzhda P (2021) Cybersecurity risk assessment in smart city infrastructures. Machines 9(4):78
King ZM, Henshel DS, Flora L, Cains MG, Hoffman B, Sample C (2018) Characterizing and measuring maliciousness for cybersecurity risk assessment. Front Psychol 9:39
PudlĂĄk P, Rödl V, Savickỳ P (1988) Graph complexity. Acta Informatica 25:515â535
Jukna S (2006) On graph complexity. Comb Probab Comput 15(6):855â876
Mowshowitz A, Dehmer M (2012) Entropy and the complexity of graphs revisited. Entropy 14(3):559â570
Dehmer M, Mowshowitz A (2011) A history of graph entropy measures. Inf Sci 181(1):57â78
Zenil H, Kiani NA, Tegnér J (2018) A review of graph and network complexity from an algorithmic information perspective. Entropy 20(8):551
Chen Z, Dehmer M, Shi Y (2014) A note on distance-based graph entropies. Entropy 16(10):5416â5427
Viana MP, Batista JLB, Costa LDF (2012) Effective number of accessed nodes in complex networks. Phys Rev E 85(3):036105
Wang Z, Huang R, Yang D, Peng Y, Zhou B, Chen Z (2024) Identifying influential nodes based on the disassortative and community structure of complex network. Sci Rep 14(1):8453
Rashidi R, Boroujeni FZ, Soltanaghaei M, Farhadi H (2024) Prediction of influential nodes in social networks based on local communities and usersâ reaction information. Sci Rep 14(1):15815
Efrati S, Reich Y (2025) System flow centrality index for evaluating the influence of a given system element in a network graph. Expert Syst Appl 274:126869
Zola F, Segurola-Gil L, Bruse JL, Galar M, Orduna-Urrutia R (2022) Network traffic analysis through node behaviour classification: a graph-based approach with temporal dissection and data-level preprocessing. Comput Secur 115:102632
Medina JA, Gorricho M, Segurola L, Zola F, Orduna R, Graphaviour (2024) Bitcoin behaviour classification based on graph topological similarities. In: Proceedings of the Jornadas Nacionales de InvestigaciĂłn en Ciberseguridad (JNIC), pp 116â124
Su G, Hu E (2024) Research on coal mine safety risk evolution and key hidden dangers under the perspective of complex network. Sci Rep 14(1):20624
Rossi RA, Ahmed NK (2015) The network data repository with interactive graph analytics and visualization. In: Proceedings of the AAAI Conference on Artificial Intelligence, pp 4292â4293
ErdĆs P, RĂ©nyi A (1960) On the evolution of random graphs. Publ Math Inst Hungar Acad Sci 5(1):17â61
Newman M (2018) Networks. Oxford University Press, Oxford
BarabĂĄsi A-L, Albert R (1999) Emergence of scaling in random networks. Science 286(5439):509â512
Pastor-Satorras R, Vespignani A (2001) Epidemic spreading in scale-free networks. Phys Rev Lett 86(14):3200
Albert R, BarabĂĄsi A-L (2002) Statistical mechanics of complex networks. Rev Mod Phys 74(1):47
Freeman LC (1978) Centrality in social networks conceptual clarification. Soc Netw 1(3):215â239
Page, L, Brin, S, Motwani, R, Winograd T (1999) The PageRank citation ranking: bringing order to the web. Technical Report 1999-66, Stanford InfoLab. https://web.mit.edu/6.033/2004/wwwdocs/papers/page98pagerank.pdf. Accessed on 27 Nov 2024
Bonacich P (1987) Power and centrality: a family of measures. Am J Sociol 92(5):1170â1182
Kleinberg JM (1999) Authoritative sources in a hyperlinked environment. J ACM (JACM) 46(5):604â632
Acknowledgements
This work has been partially supported by the European Unionâs Horizon Europe framework program under the project ATLANTIS with grant agreement No.101073909
Author information
Authors and Affiliations
Contributions
S.L. contributed to conceptualization, methodology, software, validation, formal analysis, investigation, writingâoriginal draft, writingâreview and editing, and visualization. I.I. contributed to methodology, writingâreview and editing, supervision, and project administration. U.R. contributed to supervision and writingâreview and editing. F.A. contributed to supervision and writingâreview and editing. F.J. contributed to writingâreview and editing.
Corresponding author
Additional information
Publisher's Note
Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.
Rights and permissions
Springer Nature or its licensor (e.g. a society or other partner) holds exclusive rights to this article under a publishing agreement with the author(s) or other rightsholder(s); author self-archiving of the accepted manuscript version of this article is solely governed by the terms of such publishing agreement and applicable law.
About this article
Cite this article
Segurola-Gil, L., Irigoien, I., Orduna-Urrutia, R. et al. Graph entropy-based node exposure score for risk assessment in information systems. J Supercomput 82, 662 (2026). https://doi.org/10.1007/s11227-026-08806-w
Received:
Accepted:
Published:
Version of record:
DOI: https://doi.org/10.1007/s11227-026-08806-w
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.