An Attack Graph-Based Probabilistic Security Metric

An Attack Graph-Based Probabilistic Security Metric
复制标题

DOI:
10.1007/978-3-540-70567-3_22
复制
发表时间:
2008-07
期刊:
--
影响因子:
--
通讯作者:
Lingyu Wang;T. Islam;Tao Long;A. Singhal;S. Jajodia
Lingyu Wang;T. Islam;Tao Long;A. Singhal;S. Jajodia
中科院分区:
其他
文献类型:
--
作者:
Lingyu Wang;T. Islam;Tao Long;A. Singhal;S. Jajodia

文献摘要

被引文献

相似文献

为了保护当今网络环境中的关键资源,需要量化联合收割机多个漏洞的潜在多步攻击的可能性。由于漏洞之间的因果关系模型,即攻击图,这现在变得可行。提出了一种基于攻击图的网络安全概率度量方法,并研究了其有效计算方法。我们首先定义了基本的指标,并提供了一个直观的和有意义的解释的指标。然后,我们研究了更复杂的攻击图的定义与循环,并相应地扩展的定义。我们表明,直接从它的定义计算的度量是没有效率的,在许多情况下,并提出算法,以提高这种计算的效率。
To protect critical resources in today’s networked environments, it is desirable to quantify the likelihood of potential multi-step attacks that combine multiple vulnerabilities. This now becomes feasible due to a model of causal relationships between vulnerabilities, namely, attack graph. This paper proposes an attack graph-based probabilistic metric for network security and studies its efficient computation. We first define the basic metric and provide an intuitive and meaningful interpretation to the metric. We then study the definition in more complex attack graphs with cycles and extend the definition accordingly. We show that computing the metric directly from its definition is not efficient in many cases and propose heuristics to improve the efficiency of such computation.