Big Data Analytics on Cyber Attack Graphs for Prioritizing Agile Security Requirements

Big Data Analytics on Cyber Attack Graphs for Prioritizing Agile Security Requirements
复制标题

网络攻击图大数据分析,优先考虑敏捷安全需求

DOI:
10.1109/re.2019.00042
复制
发表时间:
2019
期刊:
2019 IEEE 27th International Requirements Engineering Conference (RE)
影响因子:
--
通讯作者:
Amin Hassanzadeh
Amin Hassanzadeh
中科院分区:
--
文献类型:
--
作者:
E. Hadar;Amin Hassanzadeh

文献摘要

被引文献

相似文献

在企业环境中,可利用的托管资产和漏洞的数量是惊人的。黑客在此类资产之间的横向移动会生成复杂的大数据图,其中包含潜在的黑客路径。在这篇愿景论文中,我们列举了大规模环境中降低风险的安全需求,然后介绍了用于检测、建模和安全需求的持续优先级排序的敏捷安全方法和技术,以及敏捷风格。敏捷安全将不同类型的安全需求建模到攻击图的上下文中,其中包含业务流程目标和关键资产识别、配置项以及网络攻击的可能影响。通过模拟和分析虚拟对手对主要资产的攻击路径,Agile Security 检查业务对业务流程的影响,并确定外科手术需求的优先级。因此,处理这些积压的需求(这些需求积压是采用敏捷安全的结果,不断进行评估),逐渐增强系统强化,降低业务风险,并通知 IT 服务台或安全运营中心下一步要执行哪些补救措施。修复后,Agile Security 会不断重新计算残余风险,评估威胁情报或基础设施变化导致的风险增加与防御者的修复操作,以推动整体攻击面减少。
In enterprise environments, the amount of managed assets and vulnerabilities that can be exploited is staggering. Hackers' lateral movements between such assets generate a complex big data graph, that contains potential hacking paths. In this vision paper, we enumerate risk-reduction security requirements in large scale environments, then present the Agile Security methodology and technologies for detection, modeling, and constant prioritization of security requirements, agile style. Agile Security models different types of security requirements into the context of an attack graph, containing business process targets and critical assets identification, configuration items, and possible impacts of cyber-attacks. By simulating and analyzing virtual adversary attack paths toward cardinal assets, Agile Security examines the business impact on business processes and prioritizes surgical requirements. Thus, handling these requirements backlog that are constantly evaluated as an outcome of employing Agile Security, gradually increases system hardening, reduces business risks and informs the IT service desk or Security Operation Center what remediation action to perform next. Once remediated, Agile Security constantly recomputes residual risk, assessing risk increase by threat intelligence or infrastructure changes versus defender's remediation actions in order to drive overall attack surface reduction.