Big Data Analytics on Cyber Attack Graphs for Prioritizing Agile Security Requirements
Big Data Analytics on Cyber Attack Graphs for Prioritizing Agile Security Requirements
复制标题
网络攻击图大数据分析,优先考虑敏捷安全需求
DOI:
10.1109/re.2019.00042
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
Amin Hassanzadeh
中科院分区:
文献类型:
--
作者:
E. Hadar;Amin Hassanzadeh
In enterprise environments, the amount of managed assets and vulnerabilities that can be exploited is staggering. Hackers' lateral movements between such assets generate a complex big data graph, that contains potential hacking paths. In this vision paper, we enumerate risk-reduction security requirements in large scale environments, then present the Agile Security methodology and technologies for detection, modeling, and constant prioritization of security requirements, agile style. Agile Security models different types of security requirements into the context of an attack graph, containing business process targets and critical assets identification, configuration items, and possible impacts of cyber-attacks. By simulating and analyzing virtual adversary attack paths toward cardinal assets, Agile Security examines the business impact on business processes and prioritizes surgical requirements. Thus, handling these requirements backlog that are constantly evaluated as an outcome of employing Agile Security, gradually increases system hardening, reduces business risks and informs the IT service desk or Security Operation Center what remediation action to perform next. Once remediated, Agile Security constantly recomputes residual risk, assessing risk increase by threat intelligence or infrastructure changes versus defender's remediation actions in order to drive overall attack surface reduction.