A Robust and Efficient Risk Assessment Framework for Multi-Step Attacks

Huimei Liao, Siyuan Leng, Junhai Yang, Jinbo Xu, Junhao Zhang, Jin-Ling Tang · 2024

Multi-step attacks are launched by external attackers, leading to private data theft and extortion. Researchers have proposed risk assessment (RA) technology to evaluate real-time security situations and quantify network threats. However, existing RA approaches cannot handle the errors for the Intrusion Detection System (IDS) and depend on specific high-coupling data structures for attack knowledge, leading to the shortcomings of robustness and scalability. This paper proposed an efficient and robust risk assessment framework for multi-step attacks. A host security evaluation model based on the Markov Chain is proposed, which is capable of assessing real-time risk stably for a host even if the IDS goes wrong. Further, this paper promotes the traditional Attack Tree (AT) as the Status-based Attack Tree (S-AT) to organize attack knowledge with high scalability. Experimental results show the proposed model works effectively to defend against various technologies of multi-step attacks.

Read the paper · More papers on PaperTik