Proactive Risk Assessment Based on Attack Graphs: An Element of the Risk Management Process on System, Enterprise and National Level

Damian Hermanowski, Rafal Piotrowski · 2018

The paper discusses graph based risk assessment approach to the evaluation of computer systems' security. The method is based on MulVAL attack graph generation tool, adapted for risk calculation, generating possible attack paths leading to crucial assets of the audited IT system. It uses information from the security audits (hosts vulnerabilities) and detailed topology information. The authors present the approach to standard IT system security evaluation and risk assessment as well as advantages of the graph – based method. As the follow up, high level risk assessment of a broader, multi-domain national level environment is proposed.

Read the paper · More papers on PaperTik