Evaluation of Network Risk Using Attack Graph Based Security Metrics

Santosh Kumar, Anuradha Negi, Keshav Prasad, Aniket Mahanti · 2016

Network security management is a big challenge for network administrators due to increasing vulnerabilities. Vulnerabilities are the weakness of the network and allow malicious attackers access to resources controlled by an organization. To keep networks secure network administrators should be aware of all vulnerabilities through which an attacker can gain access. In this paper, we have considered the attack graph which describes how an attacker can compromise with the security of a network. To generate the attack graph, Multihost Multistage Vulnerability Analysis (MulVAL) tool is used. The generated graphs by this tool are logical attack graphs. These graphs are based on logical programming and based on dependencies among attack goal and configuration information. We have taken two security metrics, namely, exploitability metric and impact metric to analyze the risk associated with the network. Our preliminary results suggest that the size of the network has an impact on the vulnerability of a network.

Read the paper · More papers on PaperTik