Inferring Attack Paths in Networks with Periodic Topology Changes
Fanfan Hao, Zhu Wang, Mengyao Shi, Tingting Peng, Liang Fang, Fenghua Li · 2022
The attack graph model is an effective method for analyzing multi-step attacks. Most existing related works only focus on networks with static topology and are unsuitable for the satellite Internet, whose backbone network periodically changes in topology. They are inefficient in path retrieval and unreasonable in attack path inference. To improve the retrieval efficiency of attack paths, we first propose a network logical attack graph with periodic changes. It can reduce retrieval space while preserving the exploitation relationship among hosts in a period. Then we design a hierarchical parallel search algorithm to quickly retrieve attack paths by dividing the path retrieval space into independent subspaces that can compute in parallel. To reasonably infer the attack paths, considering the impact of attack moment and topological connection duration on the selection probability of the attack path, we calculate it in combination with the basic exploitability probability, the total attack duration intention, the asset value, the time-based PageRank centrality, and the attack completion ratio. The experimental results demonstrate the effectiveness of our method.