Risk-aware Decision Support System to Counter Coordinated and Simultaneous Attacks
Léa El Samarji · 2015
Unlike early attacks launched by a single attacker to a single victim, recent attacks are better coordinated, difficult to discover, and inflict severe damages to networks. However, existing response systems still handle simultaneous attacks as being individual and independent. First, most of attack modeling languages are limited to 1st order logic, which renders them obsolete in quantifying over coordination properties, such as, synchronization and knowledge sharing. Therefore, based on the Situation Calculus (SC) language, we introduce a new coordination-aware attack scheme. By combining Graph Theory and SC planning, our framework establishes a graphical view of all the potential attack scenarios that can endanger a network. Consequently, each of the generated attack graph forecasts a combination of attack scenarios that simultaneous attackers, ongoing in the network, may perform in the future. Thereby, the response system may estimate the overall risk and prepare preventive measures. Second, real-time risk management models have been recently explored to assist the security officer in order to identify the most appropriate and effective security measures to deploy. Referring to the National Institute of Standards and Technology, Risk is a function of the attack?s likelihood and impact. However, today?s models have major drawbacks in such evaluation since they cannot model coordinated and simultaneous attacks. Consequently, being able to represent the possibility of detection and reaction of the response system in the decision process of the attacker, Game Theory provides the most adequate framework to assess the attack likelihood. This latter considers the number of collaborating attackers, making our model able to assess not only the likelihood of individual attacks, but also that of coordinated ones. Afterwards, we propose a framework to prioritize the different attack graphs regarding the number of risky attack scenarios they contain. Third, existing response systems do not consider the conflict between parallel response measures, nor the response side effects. Moreover, the majority of automated response systems rely on mapping attack scenarios to pre-defined responses. While this approach allows a system administrator to deal with intrusions faster, it lacks flexibility as things do not always turn out the way we planned. Consequently, we propose a radically new response scheme against simultaneous threats, as a sequence of non conflicting parallel actions. Our response is dynamically designed based on a new definition of capability-aware logic anticorrelation, and modeled using Situation Calculus. Furthermore, we propose a response co-simulator that considers each response candidate apart and reasons about its risk mitigation, in order to select the most efficient response. Finally, our proposal is experimented on a multi-service system in order to demonstrate its efficiency.