POMDPs Make Better Hackers: Accounting for Uncertainty in Penetration Testing

POMDPs Make Better Hackers: Accounting for Uncertainty in Penetration Testing
复制标题

POMDP 造就更好的黑客:解释渗透测试中的不确定性

DOI:
--
复制
发表时间:
2012
期刊:
AAAI Conference on Artificial Intelligence
影响因子:
--
通讯作者:
J. Hoffmann
J. Hoffmann
中科院分区:
--
文献类型:
--
作者:
Carlos Sarraute;O. Buffet;J. Hoffmann

文献摘要

被引文献

相似文献

渗透测试是一种通过生成和执行可能的黑客攻击来评估网络安全的方法。这样做自动允许定期和系统的测试。一个关键问题是如何产生攻击。这自然被表述为不确定性下的规划,即,在不完全了解网络配置的情况下。以前的工作使用经典的规划,并需要昂贵的预处理减少这种不确定性的广泛应用的扫描方法。相比之下,我们在此模型的攻击规划问题的部分可观察马尔可夫决策过程(POMDP)。这允许对可用的知识进行推理,并智能地将扫描操作作为攻击的一部分。正如人们所预料的那样,这种精确的解决方案不具有可扩展性。我们设计了一种方法,依赖于POMDPs来找到对单个机器的良好攻击,然后将其组成对整个网络的攻击。这种分解尽可能地利用网络结构,(仅)在需要时进行有针对性的近似。评估这种方法在适当适应的工业测试套件,我们证明了它的有效性,在运行时和解决方案的质量。
Penetration Testing is a methodology for assessing network security, by generating and executing possible hacking attacks. Doing so automatically allows for regular and systematic testing. A key question is how to generate the attacks. This is naturally formulated as planning under uncertainty, i.e., under incomplete knowledge about the network configuration. Previous work uses classical planning, and requires costly pre-processes reducing this uncertainty by extensive application of scanning methods. By contrast, we herein model the attack planning problem in terms of partially observable Markov decision processes (POMDP). This allows to reason about the knowledge available, and to intelligently employ scanning actions as part of the attack. As one would expect, this accurate solution does not scale. We devise a method that relies on POMDPs to find good attacks on individual machines, which are then composed into an attack on the network as a whole. This decomposition exploits network structure to the extent possible, making targeted approximations (only) where needed. Evaluating this method on a suitably adapted industrial test suite, we demonstrate its effectiveness in both runtime and solution quality.