A Scalable, Bidirectional-Based Search Strategy to Generate Attack Graphs

Junchun Ma, Yongjun Wang, Jiyin Sun, Xiaofeng Hu · 2010

Attack graphs can reveal the threat of sophisticated multi-step attacks by enumerating possible sequences of exploits leading to the compromise of given critical resources. In order to resolve the current emergence methods of generating attack graphs is difficult to apply to the large-scale complex network system; this paper presents a scalable, bidirectional-based search strategy to generate attack graphs. On the one hand, it models the target network in four levels: network service, host system, security system, the host's accessibility, at the same time, it puts forward a technology that can automatically acquire the parameters of the host's accessibility, which effectively supports us to model a large-scale target network automatically and reduces the algorithm's space complexity; on the other hand, it follows the assumption of monotonicity, using bidirectional-based search strategy to generate attack graphs, which achieves the overall analysis of network security, and also reduces the algorithm's time complexity.

Read the paper · More papers on PaperTik