A2G2V: Automated Attack Graph Generator and Visualizer

A2G2V: Automated Attack Graph Generator and Visualizer
复制标题

A2G2V:自动攻击图生成器和可视化工具

DOI:
--
复制
发表时间:
2018
期刊:
Proceedings of the 1st ACM MobiHoc Workshop on Mobile IoT Sensing, Security, and Privacy
影响因子:
--
通讯作者:
Ratnesh Kumar
Ratnesh Kumar
中科院分区:
--
文献类型:
--
作者:
Alaa T. Al Ghazo;M. Ibrahim;Hao Ren;Ratnesh Kumar

文献摘要

被引文献

相似文献

物联网(IoT)和网络物理系统(CPS)技术增加了系统的复杂性,也使它们暴露在额外的漏洞中。攻击图是图形表示,提供了一个完整的视图,原子漏洞之间的相互依赖性如何可能被对手利用缝合在一起的攻击,可以危及系统。它们的手动构造是乏味的、容易出错的并且耗时的。本文提出了一个基于模型的攻击图自动生成器和可视化工具(A2G2V)。给定网络系统描述(其组件、连接性、其支持的服务、其漏洞和保护),攻击图列出了所有可能的序列集,其中原子级漏洞可以被利用来损害特定的系统级安全性。拟议的A2G2V工具扩展了现有的形式化方法工具(模型检查器),它集成了一个架构描述工具,我们自己的代码(解析反例,编码规范放松,迭代,直到所有攻击序列被揭示),也是一个图形可视化工具。
The Internet of Things (IoT) and Cyber-Physical Systems (CPS) technologies have increased the complexity of systems and also exposed them to additional vulnerabilities. Attack-graphs are graphical representations that provide a complete view of how inter-dependencies among atomic vulnerabilities may be exploited by an adversary to stitch together an attack that can compromise the system. Their manual construction is tedious, error-prone, and time consuming. This paper presents a model-based Automated Attack-Graph Generator and Visualizer (A2G2V). Given the networked system description (its components, connectivity, services it supports, their vulnerabilities and protections), the attack graph enlists set of all possible sequences in which atomic-level vulnerabilities can be exploited to compromise a certain system-level security. The proposed A2G2V tool extends an existing formal methods tool (a model-checker) by integrating with it an architecture description tool, our own code (for parsing counterexamples, encoding those for specification relaxation, iterating till all attack sequences are revealed), and also a graph visualization tool.