An Attack Graph-Based Probabilistic Computing Approach of Network Security
Xu Xi · Chinese Journal of Computers · 2010
To protect critical resources in networked environments,it is important to quantify the likelihood of potential multi-step attacks in attack graphs.Aimed at the problems that the difficulty to understand the attack graphs and the probabilistic re-computing caused by cyclic paths in attack graphs and probabilistic incorrect computing caused by shared dependencies in exploits,a methodology for security risk analysis that is based on the model of attack graphs and the Common Vulnerability Scoring System(CVSS)is presented,attack graph is simplified by removing unreachable paths,and the problem of probabilistic re-computing is solved and the problem of probabilistic incorrect computing is avoided successfully by proposing the concept and computing approach of maximum reachable probability which can be adapted to a large-scale network,reasonableness and effectiveness of proposed method is verified in the real experiment and simulation.Compared with the related research,maximum reachable probability computing approach can be adapted to a more complex attack graph,and have good scalability.