Automatic Generation of Attack Scripts from Attack Graphs

William J. Nichols, Zachary Hill, Peter J. Hawrylak, John C. Hale, Mauricio Papa · 2018

While attack graphs are valuable tools for security analysis, their testing and validation is a time-consuming process. Once validated, the attack graph can be used to generate testing scripts or use-cases for system security testing and validation. Furthermore, simply identifying states where a system is critically compromised can also be lengthy and tedious. Since this process is algorithmic, it can be automated. The automation process can extend to not only identifying the paths to reach a compromised state, but also to generate a script (attack scenario) which can be used to validate the results of the attack graph. This validation system can be further improved by automating the analysis of the result of running this script. These capabilities simplify the system security testing and system validation.

Read the paper · More papers on PaperTik