Automatic Extraction of Vulnerability Information for Attack Graphs

Robert Schuppenies, Cheng Feng · 2009

As computer networks are emerging in everyday life, network security has become an important issue. At the same time, attacks turned more sophisticated, making the defense of computer networks increasingly difficult. In order to model and assess the security of complex networks, attack graphs are used. These graphs provide a formal model to describe network security and allow to identify paths which lead an attacker to the attack goal. By means of attack graphs, unsuspicious system properties can be correlated into imminent threats, intrusion detection systems can be deployed more efficiently, and new network configurations can be tested conveniently. To construct attack graphs system information as well as vulnerability information are required. System information contains gathered data of the network to be analyzed, whereas vulnerability information describes what is required for a vulnerability to be exploited and what are the effects of such an exploitation. The automatic extraction of vulnerability information to make them usable for attack graphs remains an open issue. This Master’s Thesis addresses the challenge to automatically extract vulnerability information from existing vulnerability databases and transform them into a formal and unified format, thus making them available to attack graph modeling. At first, the technical foundations are described, highlighting fundamental aspects of vulnerabilities and the workflow of attack graph construction. Then, related work on vulnerability representation and extraction as well as attack graph construction, analysis, and tools is presented. Next, a data structure is proposed which is able to represent vulnerability information and important properties of systems under attack. Based on previous works, an unrestrictive, predicate-based structure is recommended, which will address the requirements of attack graph modeling. Afterwards, the current state of vulnerability databases is examined, with an emphasis on information extraction of data significant for attack graph construction. A special focus is put on the information extraction from textual vulnerability descriptions which have been neglected as a valuable source in previous research. Finally, a proof of concept implementation is presented which utilizes an attack graph tool as well as transformed vulnerability information to build attack graphs. The contribution is fourfold. First of all, information stored in vulnerability databases is analyzed and its usefulness for attack graph generation is evaluated. Second of all, a data structure is proposed which allows to unify vulnerability information in an integrated model. Third of all, transformations are realized that extract vulnerability information from existing databases and transform them to the proposed model, hence making them available to attack graph applications. Finally, a prototype is implemented which uses both, the data structure and vulnerability information transformations, to construct attack graphs with an existing attack graph tool. Zusammenfassung (German Abstract) Computernetzwerke durchdringen das alltagliche Leben in vielen Bereichen. Zur selben Zeit werden Angriffe auf diese zunehmend komplizierter und erschweren die Verteidigung von Netzwerken immer mehr. Aus diesem Grund ist Netzwerksicherheit ein nicht mehr zu vernachlassigendes Thema. Fur die Modellierung und Bewertung der Sicherheit komplexer Netze werden Angriffsgraphen verwendet, da sie ein formales Modell zur Beschreibung von Netzwerksicherheit zur Verfugung stellen. Mit Hilfe von Angriffsgraphen ist es beispielsweise moglich aus scheinbar ungefahrlichen Systemeinstellungen drohende Gefahren zu erkennen. Zur Erstellung von Angriffsgraphen werden Informationen uber das zu analysierende System sowie uber Schwachstellen benotigt. Diese Schwachstelleninformationen beschreiben notwendige Bedingungen fur einen Angriff und aus einem solchen Angriff erwachsene Konsequenzen. Die automatische Gewinnung von Schwachstelleninformationen bleibt eine bisher ungeloste Herausforderung. Die vorliegende Masterarbeit adressiert diese Herausforderung und untersucht, wie aus existierenden Datenbanken Schwachstelleninformation extrahiert und in ein einheitliches Datenformat transformiert werden konnen, alles mit dem Ziel sie anschliesend Angriffsgraphenanwendungen zur Verfugung zu stellen. Zuerst werden die technischen Grundlagen beschrieben, unter anderem der Ablauf zur Erstellung von Angriffsgraphen. Weiterhin werden wichtige Arbeiten zur Darstellung und Gewinnung von Schwachstelleninformationen sowie zur Erstellung und Analyse von Angriffsgraphen dargelegt. Als nachstes wird eine Datenstruktur vorgeschlagen, die in der Lage ist Schwachstelleninformationen zu beschreiben. Basierend auf vorherigen Arbeiten wird eine pradikatenbasierte Struktur empfohlen, welche die Anforderungen der Angriffsgraphenmodellierung erfullt. Anschliesend wird der momentane Zustand von Schwachstellendatenbanken und eine Gewinnung von entsprechenden Informationen analysiert. Ein Schwerpunkt wird auf die Informationsgewinnung aus textuellen Beschreibungen gelegt, welche in bisherigen Arbeiten vernachlassigt wurde. Schlieslich wird eine Beispielimplementation vorgestellt, die eine Angriffsgraphenapplikation sowie transformierte Schwachstelleninformation verwendet um Angriffsgraphen zu erstellen. Es werden vier Beitrage zur aktuellen Forschung geleistet: Verfugbare Informationen aus Schwachstellendatenbanken werden analysiert und ihr Nutzen fur die Erzeugung von Angriffsgraphen bewertet. Es wird eine Datenstruktur vorgeschlagen, welche die Vereinheitlichung von Schwachstelleninformation in einem ganzheitlichen Modell ermoglicht. Transformationen werden realisiert, mit Hilfe derer Schwachstelleninformationen von existierenden Datenbanken in das vorgeschlagende Modell umgewandelt und somit Angriffsgraphenanwendungen zur Verfugung gestellt werden konnen. Ein Prototyp wird implementiert, welcher die vorgeschlagenden Datenstrukturen und Transformationen benutzt um Angriffsgraphen mit einer vorhandenen Angriffsgraphenapplikation zu erstellen.

Read the paper · More papers on PaperTik