A Quantitative Risk Analysis Model and Simulation Of Enterprise Networks

A Quantitative Risk Analysis Model and Simulation Of Enterprise Networks
复制标题

企业网络的定量风险分析模型与仿真

DOI:
--
复制
发表时间:
2018
期刊:
IEEE Annual Information Technology, Electronics and Mobile Communication Conference
影响因子:
--
通讯作者:
S. Shetty
S. Shetty
中科院分区:
--
文献类型:
--
作者:
Prabin B. Lamichhane;Liang Hong;S. Shetty

文献摘要

被引文献

相似文献

在企业网络中,攻击者可以通过一步一步地利用位于它们之间的网络设备的漏洞来获得对关键资产的访问和特权。这个安全问题是网络安全管理人员严重关注的问题,以防止大量数据丢失和业务中断。在给定的网络拓扑结构和安全条件下,分析网络风险是保护企业网络的方法之一。风险分析有助于安全管理人员在薄弱节点上实施更多的安全性,或者在攻击者利用过渡设备上的漏洞并危害高度重要的主机之前将关键主机转移到安全的地方。本文提出了一种网络风险的定量计算方法。我们计算了网络风险作为总漏洞利用沿着路径和利用的影响的函数。包括拓扑脆弱性分析(TVA)的先前研究已经完成了通过攻击图生成来建模和分析攻击路径。他们只考虑漏洞,并提供保护关键主机的方法。然而,在本文中,我们分析了网络风险,同时考虑了漏洞利用和漏洞利用的影响(即,通过平衡可利用性和影响来计算总网络风险)。我们还对企业网络进行了模拟分析,并展示了总网络风险如何随漏洞利用分数和影响分数而变化。
In an enterprise network, an attacker can get access and privilege to the critical asset through step by step vulnerabilities exploitation of network devices that lie between them. This security problem is serious concerns for a network security manager to protect from great data loss and business interruption. One of the ways to protect an enterprise network is to analyze network risk at given network topology and security condition. The risk analysis helps the security manager to enforce more security on weak nodes, or shift critical hosts in a secure place before an attacker takes benefit of vulnerabilities on transition devices and compromise highly important hosts. In this paper, we proposed a quantitative risk calculation method to compute network risk. We computed network risk as a function of total vulnerabilities exploitation along path and Impact of exploitation. Previous research including Topological Vulnerability Analysis (TVA) has been done to model and analyze attacking pathway through attack graph generation. They considered only vulnerabilities, and provide ways for the protection of critical hosts. However, in this paper, we analyze the network risk considering both vulnerabilities exploitation and impact of exploits (i.e., compute the total network risk by balancing exploitability and impact). We also perform a simulation analysis on an enterprise network and show how total network risk varies with vulnerabilities exploitation scores and impact scores.