New insights into approaches to evaluating intention and path for network multistep attacks (Q1720907)

From MaRDI portal





scientific article; zbMATH DE number 7018953
Language Label Description Also known as
default for all languages
No label defined
    English
    New insights into approaches to evaluating intention and path for network multistep attacks
    scientific article; zbMATH DE number 7018953

      Statements

      New insights into approaches to evaluating intention and path for network multistep attacks (English)
      0 references
      0 references
      8 February 2019
      0 references
      Summary: The attack graph (AG) is an abstraction technique that reveals the ways an attacker can use to leverage vulnerabilities in a given network to violate security policies. The analyses developed to extract security-relevant properties are referred to as AG-based security evaluations. In recent years, many evaluation approaches have been explored. However, they are generally limited to the attacker's ``monotonicity'' assumption, which needs further improvements to overcome the limitation. To address this issue, the stochastic mathematical model called absorbing Markov chain (AMC) is applied over the AG to give some new insights, namely, the expected success probability of attack intention (EAIP) and the expected attack path length (EAPL). Our evaluations provide the preferred mitigating target hosts and the vulnerabilities patching prioritization of middle hosts. Tests on the public datasets DARPA2000 and Defcon's CTF23 both verify that our evaluations are available and reliable.
      0 references
      0 references
      0 references
      0 references

      Identifiers

      0 references
      0 references
      0 references
      0 references
      0 references
      0 references