A Minimum Cost of Network Hardening Model Based on Attack Graphs

Junchun Ma, WANG Yong-jun, Jiyin Sun, Shan Chen · Procedia Engineering · 2011

In order to improve network's security, a minimum cost of network hardening model (MCNHM) based on attack graphs is presented. Firstly, the bidirectional-based search strategy is used to search the network vulnerabilities’ relationship, which improves the generation efficiency of attack graphs, and reduces the system resource consumption; Secondly, this model gives the formal definition of minimum-cost of network hardening; Finally, it combines attack graphs and genetic algorithm, and transforms the problem of minimum cost of network hardening to a non-restraint optimization problem with penalty by establishing the corresponding mathematical model, which guarantees the network security with the least cost. This model is an important component of the National High-Tech Research and Development Plan of China, under Grant No.2009AA01Z432, a great of experimental results show that this model can find the minimum cost of target network, so it can help network security managers carry on safety protection in pertinence, and has important practical significance.

Read the paper · More papers on PaperTik