Big-Data Architecture for Cyber Attack Graphs Representing Security Relationships in NoSQL Graph Databases

Steven Noel, Eric T. Harley, Kam Him Tam, Greg Gyor · 2014

Abstract—We introduce a new modeling framework for mapping vulnerability paths through networks and associating them with observed attacker activities. We merge a complex blend of network relationships and events, such as topology, firewall policies, host configurations, vulnerabilities, attack patterns, intrusion alerts, and logs. Our persistence layer includes Neo4j, a Not Only SQL (NoSQL) database optimized for graphs. We explore how the Neo4j property-graph data model supports analysis and queries within our problem domain. For interoperability with other tools, we employ standardized cyber-security data exchange language. We show that our approach supports the same kinds of graph analytics as an existing attack graph tool, through the application of the Neo4j Cypher query language. We then extend those analytics through a much richer model of the network environment and attacker/defender activities. Our work represents the first investigation of cyber attack graph analysis based on graph databases – an important class of NoSQL database. Keywords-attack graphs; topological vulnerability analysis; network attack modeling; cyber security standards; cluster computing; NoSQL databases I.

Read the paper · More papers on PaperTik