PENET: A practical method and tool for integrated modeling of security attacks and countermeasures

PENET: A practical method and tool for integrated modeling of security attacks and countermeasures
复制标题

PENET:安全攻击与对策集成建模的实用方法和工具

DOI:
10.1016/j.cose.2009.05.007
复制
发表时间:
2009
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
Chen
Chen
中科院分区:
--
文献类型:
--
作者:
Srdjan Pudar;G. Manimaran;Chen

文献摘要

被引文献

相似文献

随着近年来网络攻击活动的兴起,这一领域的研究得到了极大的重视。其中一项研究是网络攻击和对策的建模。在这种背景下,已经开发了几种建模方法,例如基于攻击树和各种随机工具的方法。攻击树模型是最直观、应用最广泛的工具之一。尽管其简单的设计具有各种优势,但一些未解决的弱点,如不精确的分析、有限的建模能力和静态特性,使其无法发挥全部潜力。我们提出了一种新的建模方法,称为PENET,通过扩展攻击树与新的建模构造和分析方法。我们添加了用于建模系统动态行为的动态构造,基于成本建模攻击周期性的到达构造,以及用于建模不安全系统可修复性的防御构造。Petri网攻击建模(PENET)方法能够通过更精细的参数、动态结构、Petri网表示能力和直观的时域分析来转换和增强现有的攻击树。我们展示了如何在Petri网域对攻击树进行转换和分析。我们提供了PENET模型的时域分析算法,以及用于定量描述易受攻击系统的生存能力以及攻击者和受害者努力的有效性的性能指标。接下来,我们介绍PENET工具作为我们方法的实用软件实现。最后,我们提供了一个案例研究来说明PENET方法。安全性,可靠性评估,安全性评估,可执行性评估,随机建模。
With the rise of cyber attack activities in the recent years, research in this area has gained immense emphasis. One of such research efforts is modeling of cyber attacks and countermeasures. In this context, several modeling approaches have been developed, such as approaches based on attack trees and on various stochastic tools. Attack tree model is one of the most intuitive and widely used tool. Although its simple design possesses various strengths, some unaddressed weaknesses such as imprecise analysis, limited modeling capabilities, and static nature plague its full potential. We propose a new modeling approach, called PENET, by extending the attack trees with new modeling constructs and analysis approaches. We add dynamic constructs for modeling dynamic behavior of system, arrival constructs that model periodic nature of attacks based on their cost, and defense constructs that model reparability of an insecure system. Petri Net Attack Modeling (PENET) approach has ability to convert and enhance existing attack trees with finer parameters, dynamic constructs, Petri net representation power, and intuitive time-domain analysis. We show how attack trees can be converted and analyzed in Petri net domain. We provide algorithm for time-domain analysis of PENET model, and performance metrics that are used to quantitatively describe survivability of a vulnerable system and effectiveness of attacker and victim's efforts. Next, we introduce PENET Tool as a practical software implementation of our approach. Finally, we provide a case study that illustrates the PENET approach. Security, dependability evaluation, security evaluation, performability evaluation, stochastic modeling.