Study of Attack Graph Construction Based on Distributed Parallel Processing

Chen Shan · Acta Armamentarii · 2012

In order to resolve the existed problems when analyzing large and complex network systems,a novel attack graph construction method is proposed which is based on distributed parallel processing technology.Firstly,from the defender's point of view,all the vulnerable hosts are considered as attack targets,using positive,breadth-first search strategy to construct attack graph,which resolves the problem of which the attack target is defined and single in the existed methods.Secondly,the optimization technology is researched,and the total network is divided into different areas,through multi-engine parallel processing technology,to meet the distribution scalability requirements,the problem of existed methods with high complexity and low scalability is resolved,and which is difficult for large-scale complex network.Finally,the optimization strategy,limited number of attack steps is used,which resolves the existing state explosion problem when constructing the attack graph.Experimental results show that this method can improve the efficiency of attack graph's generation,and reduce the system resource consumption greatly,and it has value for assessing the security of large-scale complex network.

Read the paper · More papers on PaperTik