This paper presents a description of a Markov model of cyberattacks by which two security metrics are constructed. An algorithm is given for estimating the input parameters of the model based on a limited number of empirical data. An example that illustrates the use of the proposed security metrics is considered.