Mode Recognition in Attack Graphs Based on Conditional State Probability
Omar Amri, Dimitri Lefebvre · 2023
Attack Graphs are modeling tools to visualize the behaviour of an attacker (intruder) throughout the network. By using attack graphs, the cyber-security agent can evaluate the security of the network as well as know the potential actions of the attacker or even know at what level the system can be compromised. Attack graphs are usually used offline to measure the resilience of a network against cyber-attacks. This paper shows that such models can also be used online to recognize the current actions of an attacker throughout the network, while it is under attack using a conditional state probability. Our setting is that during the attack some events are observed with their time stamps. This information is used to refine the estimation of each mode i.e., attack action, in the graph over time.