Network risk management using attacker profiling

Network risk management using attacker profiling
复制标题

使用攻击者分析进行网络风险管理

DOI:
10.1002/sec.58
复制
发表时间:
2009
期刊:
Secur. Commun. Networks
影响因子:
--
通讯作者:
J. Cangussu
J. Cangussu
中科院分区:
--
文献类型:
--
作者:
R. Dantu;Prakash Kolan;J. Cangussu

文献摘要

被引文献

相似文献

风险管理是指做出决策的过程,最大限度地减少漏洞对网络主机的影响。在高漏洞利用概率和难以识别新漏洞利用和漏洞的情况下,这可能是一项艰巨的任务。多年来,安全工程师一直使用经济模型进行风险分析,以设计和操作具有风险倾向的技术系统。根据识别的攻击者类型,安全管理员可以为网络制定有效的风险管理策略。我们假设攻击者的网络行为序列取决于社交行为(例如,技能水平、韧性、财务能力)。我们对此进行了扩展,并制定了一种机制来估计可能基于攻击者行为受到损害的关键资源的风险级别。这种估计是使用基于行为的攻击图来完成的,这些攻击图表示所有关键资源的所有可能攻击路径。基于这些图计算风险级别,并将其用作资源脆弱性的度量,并形成系统管理员对网络配置执行适当更改的有效基础。版权所有© 2008约翰威利父子有限公司.
Risk management refers to the process of making decisions that minimize the effects of vulnerabilities on the network hosts. This can be a difficult task in the context of high-exploit probability and the difficult to identify new exploits and vulnerabilities. For many years, security engineers have performed risk analysis using economic models for the design and operation of risk-prone, technological systems using attack profiles. Based on the type of attacker identified, security administrators can formulate effective risk management policies for a network. We hypothesize that sequence of network actions by an attacker depends on the social behavior (e.g., skill level, tenacity, financial ability). We extended this and formulated a mechanism to estimate the risk level of critical resources that may be compromised based on attacker behavior. This estimation is accomplished using behavior based attack graphs representing all the possible attack paths to all the critical resources. The risk level is computed based on these graphs and are used as a measure of the vulnerability of the resource and forming an effective basis for a system administrator to perform suitable changes to network configuration. Copyright © 2008 John Wiley & Sons, Ltd.