A Multi-Objective Approach for Security Hardening and Probabilistic Vulnerability Assessment on Attack Graphs
Shuvo Bardhan · 2022 IEEE 46th Annual Computers, Software, and Applications Conference (COMPSAC) · 2022
Assessing vulnerabilities of a network and mitigating them is a challenging task owing to the complexity and scale of the problem. Various probabilistic security metrics on attack graphs are presented in the literature to handle realistic attack scenarios involving large attack graphs. In our work, we propose a generalized path-enumeration based technique for computing attack probabilities on attack graphs that can handle repeated vulnerabilities as well as cyclic graphs. A multiplicative idempo-tency based approach is used for computation while aggregating the path probabilities. We employ the inclusion-exclusion principle to prove the soundness of our proposed technique. Also, in practice, we found that attackers retain experience and face reduced difficulty in exploiting a vulnerability in repeated attacks. In this paper, we extend the proposed probabilistic measure to incorporate such conditions leveraging possible decay functions. Our proposed metric is helpful in service management for network hardening. Network hardening is formulated as a multi-objective optimization problem that generates pareto-optimal solutions which trade off utility with vulnerability. Case studies are presented for complex attack graphs having interesting pareto-optimal solutions for service management.