Depth-first method for attack graph generation

Yang Yong-tian · Journal of Jilin University · 2009

Existing attack graph generation methods have the problem of state explosion,which results in the scale of the generated graphs to be large.To solve this problem,a depth-first attack graph generation method was proposed on the basis of the formal description of network security elements.A depth-first search algorithm was employed to find the attack paths in the network.The strategies to restrain the number of the attack steps and the success probability of attack paths were adapted to reduce the scale of attack graphs.Experiment results show that the proposed method can efficiently remove redundant edges and nods in the attack graphs,consequently decreases the scale of the attack graphs.

Read the paper · More papers on PaperTik