Logo Goletty

A Scalable Approach to Analyzing Network Security using Compact Attack Graphs
Journal Title Journal of Networks
Journal Abbreviation jnw
Publisher Group Academy Publisher
Website http://ojs.academypublisher.com
PDF (376 kb)
   
Title A Scalable Approach to Analyzing Network Security using Compact Attack Graphs
Authors Su, Jinshu; Zhang, Yi; Liu, Dehui; Chen, Feng
Abstract The compact attack graphs implicitly reveal the threat of sophisticated multi-step attacks by enumerating possible sequences of exploits leading to the compromising given critical resources in enterprise networks with thousands of hosts. For security analysts, the challenge is how to analyze the complex attack graphs with possible ten thousands of nodes for defending the security of network. In the paper, we will essentially discuss three issues about it. The first is to compute non-loop attack paths with the distance less than the given number that the real attacker may take practically in realistic attack scenarios. The second is how to measure security risk of the given critical resources.  The third is to find the solution to removing vulnerabilities in such a way that given critical resources cannot be compromised while the cost for such removal incurs the least cost. We propose the scalable approach to solve the above three issues respectively. The approach is proved to have a polynomial time complexity and can scale to the attack graphs with ten thousands of nodes corresponding large enterprise networks.
Publisher ACADEMY PUBLISHER
Date 2010-05-01
Source Journal of Networks Vol 5, No 5 (2010)
Rights Copyright © ACADEMY PUBLISHER - All Rights Reserved.To request permission, please check out URL: http://www.academypublisher.com/copyrightpermission.html. 

 

See other article in the same Issue


Goletty © 2024