A theoretical framework and modelling approaches for vulnerability & risk assessment of critical infrastructures under malicious threats