Topological analysis of network attack vulnerability

Topological analysis of network attack vulnerability
复制标题

DOI:
10.1145/1501434.1501437
复制
发表时间:
2006-10
期刊:
--
影响因子:
--
通讯作者:
S. Jajodia
S. Jajodia
中科院分区:
其他
文献类型:
--
作者:
S. Jajodia

文献摘要

被引文献

相似文献

这次演讲将讨论系统在恶意攻击下的生存性问题和方法。为了防止此类攻击,有必要采取措施防止攻击得逞。与此同时,必须认识到,并非所有攻击都能从一开始就避免;必须认识到,在某种程度上成功的攻击是不可避免的,并且需要为确定和应对攻击提供全面支持。在我的演讲中,我将描述攻击图的最新研究,这些攻击图表示攻击者可以用来渗透计算机网络的已知攻击序列。我将展示如何使用攻击图来计算确保给定关键资源安全的实际强化措施集。攻击图还可以同时用于关联收到的警报、假设丢失的警报和预测未来的警报。因此,它们为管理员提供了一种很有前途的解决方案,可以监控和预测入侵的进展,并及时采取适当的对策。
This talk will discuss issues and methods for survivability of systems under malicious attacks. To protect from such attacks, it is necessary to take steps to prevent attacks from succeeding. At the same time, it is important to recognize that not all attacks can be averted at the outset; attacks that are successful to some degree must be recognized as unavoidable and comprehensive support for identifying and responding to attacks is required. In my talk, I will describe the recent research on attack graphs that represent known attack sequences attackers can use to penetrate computer networks. I will show how attack graphs can be used to compute actual sets of hardening measures that guarantee the safety of given critical resources. Attack graphs can also be used to correlate received alerts, hypothesize missing alerts, and predict future alerts, all at the same time. Thus, they offer a promising solution for administrators to monitor and predict the progress of an intrusion, and take appropriate countermeasures in a timely manner.