A scalable approach to attack graph generation

A scalable approach to attack graph generation
复制标题

DOI:
10.1145/1180405.1180446
复制
发表时间:
2006-10
期刊:
--
影响因子:
--
通讯作者:
Xinming Ou;W. F. Boyer;M. McQueen
Xinming Ou;W. F. Boyer;M. McQueen
中科院分区:
其他
文献类型:
--
作者:
Xinming Ou;W. F. Boyer;M. McQueen

文献摘要

被引文献

相似文献

攻击图是分析企业网络安全漏洞的重要工具。以往对攻击图的研究没有考虑到攻击图生成过程的可扩展性,并且在表示攻击图时往往缺乏逻辑形式化,导致攻击图很难被人类使用和理解。Sheyner等人的开拓性工作。是第一个基于形式逻辑技术的攻击图工具,即模型检测。然而,当应用于中等规模的网络时,Sheyner的工具遇到了显著的指数爆炸问题。本文描述了一种表示和生成攻击图的新方法。我们提出了逻辑攻击图,它直接说明了攻击目标和配置信息之间的逻辑依赖关系。逻辑攻击图对于所分析的网络总是具有大小多项式。我们的攻击图生成工具建立在基于逻辑编程的网络安全分析器MulVAL的基础上。我们演示了如何在MulVAL逻辑编程引擎中生成派生轨迹,以及如何使用该轨迹在二次时间内生成逻辑攻击图。实验证明,我们的逻辑攻击图生成算法是非常有效的。我们已经为使用奔腾4 CPU和1 GB RAM的1000台机器的完全连接的网络生成了逻辑攻击图。
Attack graphs are important tools for analyzing security vulnerabilities in enterprise networks. Previous work on attack graphs has not provided an account of the scalability of the graph generating process, and there is often a lack of logical formalism in the representation of attack graphs, which results in the attack graph being difficult to use and understand by human beings. Pioneer work by Sheyner, et al. is the first attack-graph tool based on formal logical techniques, namely model-checking. However, when applied to moderate-sized networks, Sheyner's tool encountered a significant exponential explosion problem. This paper describes a new approach to represent and generate attack graphs. We propose logical attack graphs, which directly illustrate logical dependencies among attack goals and configuration information. A logical attack graph always has size polynomial to the network being analyzed. Our attack graph generation tool builds upon MulVAL, a network security analyzer based on logical programming. We demonstrate how to produce a derivation trace in the MulVAL logic-programming engine, and how to use the trace to generate a logical attack graph in quadratic time. We show experimental evidence that our logical attack graph generation algorithm is very efficient. We have generated logical attack graphs for fully connected networks of 1000 machines using a Pentium 4 CPU with 1GB of RAM.