Pareto-Optimal Adversarial Defense of Enterprise Systems

Pareto-Optimal Adversarial Defense of Enterprise Systems
复制标题

企业系统的帕累托最优对抗防御

DOI:
--
复制
发表时间:
2015
期刊:
TSEC
影响因子:
--
通讯作者:
V. S. Subrahmanian
V. S. Subrahmanian
中科院分区:
--
文献类型:
--
作者:
Edoardo Serra;S. Jajodia;Andrea Pugliese;Antonino Rullo;V. S. Subrahmanian

文献摘要

被引文献

相似文献

由美国国家标准与技术研究所维护的国家漏洞数据库(NVD)提供了有关流行软件漏洞的宝贵信息,以及可用于解决这些漏洞的任何补丁。如今,大多数企业安全管理人员只是简单地修补最危险的漏洞,因此,对手可以通过使用不太重要的漏洞来渗透企业,从而轻松地危害企业。在本文中,我们将企业中的漏洞捕获为漏洞依赖图(Vulnerability Dependency Graph,VDG),并展示了攻击图可以在其中表达。我们首先提出这样一个问题:攻击者应该利用哪一组漏洞来最大化他的预期影响?我们表明,这个问题可以解决作为一个整数线性规划。防御者显然希望最大限度地减少攻击者发动的最坏情况攻击的影响,但防御者也有义务确保其企业内的高生产力。我们提出了一种算法,找到一个帕累托最优的解决方案的后卫,使他能够同时最大限度地提高生产力,并最大限度地降低成本的修补产品的企业网络。我们已经实现了这个框架,并表明我们的计算的运行时间都在可接受的时间范围内,即使是包含30K边缘的大型VDG,生产力和攻击的影响之间的平衡也是可以接受的。
The National Vulnerability Database (NVD) maintained by the US National Institute of Standards and Technology provides valuable information about vulnerabilities in popular software, as well as any patches available to address these vulnerabilities. Most enterprise security managers today simply patch the most dangerous vulnerabilities—an adversary can thus easily compromise an enterprise by using less important vulnerabilities to penetrate an enterprise. In this article, we capture the vulnerabilities in an enterprise as a Vulnerability Dependency Graph (VDG) and show that attacks graphs can be expressed in them. We first ask the question: What set of vulnerabilities should an attacker exploit in order to maximize his expected impact? We show that this problem can be solved as an integer linear program. The defender would obviously like to minimize the impact of the worst-case attack mounted by the attacker—but the defender also has an obligation to ensure a high productivity within his enterprise. We propose an algorithm that finds a Pareto-optimal solution for the defender that allows him to simultaneously maximize productivity and minimize the cost of patching products on the enterprise network. We have implemented this framework and show that runtimes of our computations are all within acceptable time bounds even for large VDGs containing 30K edges and that the balance between productivity and impact of attacks is also acceptable.