Network security modeling with intelligent and complexity analysis

Phongphun Kijsanayothin · ThinkTech (Texas Tech University) · 2010

Protecting network-accessible resources from unauthorized use requires understanding of network vulnerability. Modeling network attacks as chains of exploitable vulnerabilities, referred to as vulnerability exploits, can help security administrators locate security flaws and implement appropriate preventative measures. However,mostmodel generation approaches do not scalewell to very large networks due to the combinatorial explosion of the size of the search space. Much research has focused on how to automatically and efficiently generate such models. To realize the full benefits of network securitymodels, effectivemodel analysis is crucial. Since security models are often too large and complex for pinpointing critical attacks manually, there is a need for automated approaches to security model analysis. Moreover, network security has to deal with the trade off between accessibility and safety protection. Thus, selecting suitable counter-measures to secure a network may involve conflicting judgments and subjective preferences. There has been little research in this area and most current approaches lack the ability to directly assist in making informed decisions. This dissertation presents a principled and practical approach to developing automated preventative network security systems that show possible attacks, in terms of chains of vulnerability exploits, and offer mechanisms to assist in selecting appropriate counter-measures. To address the problem of scalability, this dissertation proposes host-centric model checking, an analytical framework that provides efficient generation of a new network security model, namely a host-centric attack graph, using a model checking technique along with a monotony assumption (i.e., valid preconditions of a vulnerability exploit are never invalidated). Using model abstraction and efficient reachability computation by a model checker together with the assumption, the proposed approach can be shown, both theoretically and empirically, to reduce the time complexity of model generation to a quadratic polynomial in the number of hosts. At the time of this research, compared with all other existing model generation approaches, this is the best computational bound obtained. To address the issue of security model analysis, this dissertation proposes two automated approaches to intelligent analysis of a security attack model, namely exploit-based analysis and preference-based analysis. The former is quantitative and the latter is qualitative analysis. Exploit-based analysis proposes a heuristic algorithm that uses knowledge about the exploitability of network vulnerability and a link analysis technique that employs a Markov property to rank each node in the security attack model in order of its likelihood of being successfully attacked. Preference-based analysis provides a semi-automated analysis by means of logical reasoning and an explicitmodel of conditional preferences. The analysis result can assist a security administrator in making informed decisions about cost-effective counter-measures based on the administrator’s preference criteria. To the best of our knowledge, preference-based analysis is the first of its kind for approaches to network security model analysis. This research also proposes an efficient method for computing attack path expressions and includes a study of a simple but realistic case scenario. The proposed analysis approaches can be applied to any form and any topological structure of a security model. These approaches are general and theoretically grounded.

Read the paper · More papers on PaperTik