A Logic-Based Attack Graph for Analyzing Network Security Risk Against Potential Attack

Feng Yi, Huang Yi Cai, Fu Zheng Xin

2018 IEEE International Conference on Networking, Architecture and Storage (NAS)(2018)

引用 1|浏览6
暂无评分
摘要
In this paper, we present LAPA, a framework for automatically analyzing network security risk and generating attack graph for potential attack. The key novelty in our work is that we represent the properties of networks and zero day vulnerabilities, and use logical reasoning algorithm to generate potential attack path to determine if the attacker can exploit these vulnerabilities. In order to demonstrate the efficacy, we have implemented the LAPA framework and compared with three previous network vulnerability analysis methods. Our analysis results have a low rate of false negatives and less cost of processing time due to the worst case assumption and logical property specification and reasoning. We have also conducted a detailed study of the efficiency for generation attack graph with different value of attack path number, attack path depth and network size, which affect the processing time mostly. We estimate that LAPA can produce high quality results for a large portion of networks.
更多
查看译文
关键词
network risk,vulnerability,potential attack,attack graph,logical language
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要