Background: Predicting attacker’s behavior plays an important role in network security assessment. Attack graphs systematically classify the possible intrusion paths against a system. For our purpose, we assume the attack graph structure comprised of states and transitions between them. Each state represents an attack phase (or adversarial action) and each transition indicates a possible action of attacker. Keywords: Computer networks, information systems, security, quantitative evaluation, attack graph, workstations.