• DocumentCode
    1394472
  • Title

    Analytical framework for measuring network security using exploit dependency graph

  • Author

    Bhattacharya, Pallab ; Ghosh, Soumya K.

  • Author_Institution
    Dept. of Comput. Sci. & Eng., Indian Inst. of Technol., Kharagpur, Kharagpur, India
  • Volume
    6
  • Issue
    4
  • fYear
    2012
  • Firstpage
    264
  • Lastpage
    270
  • Abstract
    Attack graph is a popular tool for modelling multi-staged, correlated attacks on computer networks. Attack graphs have been widely used for measuring network security risks. Majority of the works on attack graph use host-based or state-based approaches. These attack graph models are either too restrictive or too resource consuming. Also, a significant portion of these works have used `probability of successfully exploiting a network` as the metric. This approach requires that the `probability of successfully exploiting individual vulnerabilities` be known a priori. Finding such probabilities is inherently difficult. This present study uses exploit dependency graph, which is a space efficient and expressive attack graph model. It also associates an additive cost with executing individual exploits, and defines a security metric in terms of the `minimum cost required to successfully exploit the network`. The problem of calculating the said metric is proved to be NP-complete. A modified depth first branch and bound algorithm has been described for calculating it. This study also formulates, a linear-time computable, security metric in terms of the `expected cost required to successfully exploit the network` assuming a random attacker model and an uncorrelated attack graph.
  • Keywords
    computational complexity; computer network security; graph theory; probability; tree searching; NP-complete problem; analytical framework; attack graph; computer network; depth first branch and bound algorithm; exploit dependency graph; host-based approach; network security measurement; network security risk; probability-of-successfully-exploiting-a-network metric; probability-of-successfully-exploiting-individual-vulnerabilities; random attacker model; state-based approach;
  • fLanguage
    English
  • Journal_Title
    Information Security, IET
  • Publisher
    iet
  • ISSN
    1751-8709
  • Type

    jour

  • DOI
    10.1049/iet-ifs.2011.0103
  • Filename
    6404334