Aggregating vulnerability metrics in enterprise networks using attack graphs

Aggregating vulnerability metrics in enterprise networks using attack graphs
复制标题

使用攻击图聚合企业网络中的漏洞指标

DOI:
--
复制
发表时间:
2013
期刊:
Journal of computing and security
影响因子:
--
通讯作者:
Abilene Christian University
Abilene Christian University
中科院分区:
--
文献类型:
--
作者:
J. Homer;Su Zhang;Xinming Ou;David A. Schmidt;Yanhui Du;S. R. Rajagopalan;A. Singhal;Abilene Christian University

文献摘要

被引文献

相似文献

安全风险量化是企业网络安全管理中的一项重要而又困难的工作。虽然存在针对单个软件漏洞的度量标准,但目前还没有将这些度量标准聚合起来的标准方法。我们提出了一个模型,该模型可用于聚合企业网络中的漏洞度量,生成量化度量,以度量在给定网络配置中发生违规的可能性。为这种聚合建立一个清晰的语义模型是迈向全面的网络安全度量模型的重要的第一步。我们利用攻击图中的现有工作,并应用概率推理来产生具有清晰语义和可靠计算的聚合。我们确保攻击路径之间的共享依赖关系对最终计算具有成比例的影响。我们正确地对循环进行推理,确保在没有任何自引用影响的情况下对特权进行评估。我们在概率图形模型中引入了额外的建模工件,以捕获和解释利用步骤之间隐藏的相关性。本文表明,一个清晰的聚合语义模型对于解释结果、校准度量模型和解释从实证评估中获得的见解至关重要。我们的方法已经使用了许多网络模型和生产系统的数据进行了严格的评估。
Quantifying security risk is an important and yet difficult task in enterprise network security management. While metrics exist for individual software vulnerabilities, there is currently no standard way of aggregating such metrics. We present a model that can be used to aggregate vulnerability metrics in an enterprise network, producing quantitative metrics that measure the likelihood breaches can occur within a given network configuration. A clear semantic model for this aggregation is an important first step toward a comprehensive network security metric model. We utilize existing work in attack graphs and apply probabilistic reasoning to produce an aggregation that has clear semantics and sound computation. We ensure that shared dependencies between attack paths have a proportional effect on the final calculation. We correctly reason over cycles, ensuring that privileges are evaluated without any self-referencing effect. We introduce additional modeling artifacts in our probabilistic graphical model to capture and account for hidden correlations among exploit steps. The paper shows that a clear semantic model for aggregation is critical in interpreting the results, calibrating the metric model, and explaining insights gained from empirical evaluation. Our approach has been rigorously evaluated using a number of network models, as well as data from production systems.