Security risk analysis of enterprise networks using probabilistic attack graphs
Anoop Singhal, Ximming Ou · 2011
Today's information systems face sophisticated attackers who combine multiple vulnerabilities to penetrate networks with devastating impact.The overall security of an enterprise network cannot be determined by simply counting the number of vulnerabilities.To more accurately assess the security of enterprise systems, one must understand how vulnerabilities can be combined and exploited to stage an attack.Composition of vulnerabilities can be modeled using probabilistic attack graphs, which show all paths of attacks that allow incremental network penetration.Attack likelihoods are propagated through the attack graph, yielding a novel way to measure the security risk of enterprise systems.This metric for risk mitigation analysis is used to maximize the security of enterprise systems.This methodology based on probabilistic attack graphs can be used to evaluate and strengthen the overall security of enterprise networks. AudienceThis document is intended for three primary audiences: Federal agencies seeking information on how to use probabilistic attack graphs for security risk analysis of their enterprise networks; Vendor communities seeking to understand the methodology of security risk analysis using probabilistic attack graphs and to build new tools in this area; andResearch communities seeking to understand some of the challenges in the area of enterprise network security and new research opportunities to address problems in this area.