Practical Attack Graph Generation for Network Defense

Miami Beach, FL(2006)

引用 585|浏览1
暂无评分
摘要
Attack graphs are a valuable tool to network defenders, illustrating paths an attacker can use to gain access to a targeted network. Defenders can then focus their efforts on patching the vulnerabilities and configuration errors that allow the attackers the greatest amount of access. We have created a new type of attack graph, the multiple-prerequisite graph, that scales nearly linearly as the size of a typical network increases. We have built a prototype system using this graph type. The prototype uses readily available source data to automatically compute network reachability, classify vulnerabilities, build the graph, and recommend actions to improve network security. We have tested the prototype on an operational network with over 250 hosts, where it helped to discover a previously unknown configuration error. It has processed complex simulated networks with over 50,000 hosts in under four minutes.
更多
查看译文
关键词
operational network,network reachability,network defense,network defender,multiple-prerequisite graph,graph type,complex simulated network,targeted network,network security,attack graph,typical network increase,practical attack graph generation,computer networks,computer network,graph theory
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要