Evaluating and Strengthening Enterprise Network Security Using Attack Graphs

Evaluating and Strengthening Enterprise Network Security Using Attack Graphs
复制标题

使用攻击图评估和加强企业网络安全

DOI:
--
复制
发表时间:
2005
期刊:
影响因子:
--
通讯作者:
R. Cunningham
R. Cunningham
中科院分区:
--
文献类型:
--
作者:
R. Lippmann;K. Ingols;Chris Scott;K. Piwowarski;K. Kratkiewicz;M. Artz;R. Cunningham

文献摘要

被引文献

相似文献

翻译后摘要:评估大型企业网络的安全性是复杂的,劳动密集型。当前的安全分析工具通常只单独检查单个防火墙、路由器或主机,而不能全面分析整体网络安全。作者提出了一种新的方法,使用防火墙上的配置信息和所有网络设备上的漏洞信息来构建攻击图,显示内部和外部攻击者可以通过连续危害暴露和易受攻击的主机在网络中前进多远。此外,攻击图会自动分析,以产生一个小的优先级建议,以提高网络安全性。在多达3,400台主机的网络上进行的现场试验表明,能够准确识别少数需要打补丁以抵御外部攻击者的关键垫脚石主机。对超过40,000台主机的复杂网络的模拟研究表明了良好的扩展性。此分析可用于多种目的,包括识别需要修补或使用防火墙保护的关键垫脚石主机,比较替代网络设计的安全性,确定防火墙规则或新漏洞的拟议更改所导致的安全风险,以及在宣布新漏洞时识别需要修补的最关键主机。这项工作的独特之处是新的攻击图生成算法,可扩展到具有数千台主机的企业网络,确定大型网络中其他主机和端口可从每个主机访问的有效方法,从网络漏洞扫描器和防火墙自动导入数据,以及自动攻击图分析以生成建议。
Abstract : Assessing the security of large enterprise networks is complex and labor intensive. Current security analysis tools typically examine only individual firewalls, routers, or hosts separately and do not comprehensively analyze overall network security. The authors present a new approach that uses configuration information on firewalls and vulnerability information on all network devices to build attack graphs that show how far inside and outside attackers can progress through a network by successively compromising exposed and vulnerable hosts. In addition, attack graphs are automatically analyzed to produce a small set of prioritized recommendations to enhance network security. Field trials on networks with up to 3,400 hosts demonstrate the ability to accurately identify a small number of critical stepping-stone hosts that need to be patched to protect against external attackers. Simulation studies on complex networks with more than 40,000 hosts demonstrate good scaling. This analysis can be used for many purposes, including identifying critical stepping-stone hosts to patch or protect with a firewall, comparing the security of alternative network designs, determining the security risk caused by proposed changes in firewall rules or new vulnerabilities, and identifying the most critical hosts to patch when a new vulnerability is announced. Unique aspects of this work are new attack graph generation algorithms that scale to enterprise networks with thousands of hosts, efficient approaches to determine what other hosts and ports in large networks are reachable from each individual host, automatic data importation from network vulnerability scanners and firewalls, and automatic attack graph analyses to generate recommendations.