A Suite of Metrics for Network Attack Graph Analytics

A Suite of Metrics for Network Attack Graph Analytics
复制标题

网络攻击图分析的一套指标

DOI:
10.1007/978-3-319-66505-4_7
复制
发表时间:
2017
期刊:
2015 12th International Iranian Society of Cryptology Conference on Information Security and Cryptology (ISCISC)
影响因子:
--
通讯作者:
S. Jajodia
S. Jajodia
中科院分区:
--
文献类型:
--
作者:
S. Noel;S. Jajodia

文献摘要

被引文献

相似文献

本章介绍了一套基于多步攻击漏洞模型(攻击图)的衡量企业范围网络安全风险的指标。攻击图的计算通过拓扑脆弱性分析,它考虑了网络拓扑结构,防火墙的影响,和主机漏洞的相互作用。我们的指标是标准化的,因此指标值可以在企业之间进行有意义的比较。为了支持更高抽象级别的评估,我们定义了相关指标的家庭组,将个人得分组合为家庭得分,并将家庭得分组合为整体企业网络得分。受害指标系列衡量所有网络漏洞的固有风险(存在性、可利用性和影响)的关键属性。Size系列表示漏洞攻击图的相对大小。Containment系列通过最大限度地减少安全保护边界上的漏洞暴露来衡量风险。拓扑家族通过攻击图的图论属性(连通性、循环和深度)来衡量风险。我们在交互式可视化中显示这些指标(在个人,家庭和整体级别),显示多个指标随时间的趋势。
This chapter describes a suite of metrics for measuring enterprise-wide cybersecurity risk based on a model of multi-step attack vulnerability (attack graphs). The attack graphs are computed through topological vulnerability analysis, which considers the interactions of network topology, firewall effects, and host vulnerabilities. Our metrics are normalized so that metric values can be compared meaningfully across enterprises. To support evaluations at higher levels of abstraction, we define family groups of related metrics, combining individual scores into family scores, and combining family scores into an overall enterprise network score. The Victimization metrics family measures key attributes of inherent risk (existence, exploitability, and impact) over all network vulnerabilities. The Size family is an indication of the relative size of the vulnerability attack graph. The Containment family measures risk in terms of minimizing vulnerability exposure across security protection boundaries. The Topology family measures risk through graph theoretic properties (connectivity, cycles, and depth) of the attack graph. We display these metrics (at the individual, family, and overall levels) in interactive visualizations, showing multiple metrics trends over time.