Science of Cyber Security - Third International Conference, SciSec 2021, Virtual Event, August 13-15, 2021, Revised Selected Papers

Science of Cyber Security - Third International Conference, SciSec 2021, Virtual Event, August 13-15, 2021, Revised Selected Papers
复制标题

网络安全科学 - 第三届国际会议,SciSec 2021,虚拟活动,2021 年 8 月 13-15 日,修订后的精选论文

DOI:
10.1007/978-3-030-89137-4_12
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
Matthews I
Matthews I
中科院分区:
--
文献类型:
--
作者:
Matthews I

文献摘要

相似文献

结合计算机网络信息的漏洞扫描可以用来创建一个攻击图,一个网络元素如何在攻击中被用来达到网络中的特定状态或目标的模型。通过将这些图转化为贝叶斯攻击图(bag),可以从概率上理解这些图,从而可以定量分析大型网络的安全性。在攻击事件中,图上的概率根据发现的证据而变化(例如,通过入侵检测系统或对主机活动的了解)。由于这种情况很难通过直接计算来解决,我们讨论了三种基于证据动态更新概率的随机模拟技术,并比较了它们的速度和准确性。从我们的实验中我们得出结论,可能性加权对大多数用途是最有效的。我们还考虑了bag的敏感性分析,以识别保护网络的最关键节点,并解决节点先验分配的不确定性问题。由于灵敏度分析很容易变得计算昂贵,我们提出并展示了一种有效的灵敏度分析方法,该方法利用了与随机推理的定量关系。
A vulnerability scan combined with information about a computer network can be used to create an attack graph, a model of how the elements of a network could be used in an attack to reach specific states or goals in the network. These graphs can be understood probabilistically by turning them into Bayesian attack graphs (BAGs), making it possible to quantitatively analyse the security of large networks. In the event of an attack, probabilities on the graph change depending on the evidence discovered (e.g., by an intrusion detection system or knowledge of a host’s activity). Since such scenarios are difficult to solve through direct computation, we discuss three stochastic simulation techniques for updating the probabilities dynamically based on the evidence and compare their speed and accuracy. From our experiments we conclude that likelihood weighting is most efficient for most uses. We also consider sensitivity analysis of BAGs, to identify the most critical nodes for protection of the network and solve the uncertainty problem for the assignment of priors to nodes. Since sensitivity analysis can easily become computationally expensive, we present and demonstrate an efficient sensitivity analysis approach that exploits a quantitative relation with stochastic inference.