Network Hardening Method by Small-Scale Reconfiguration with Vulnerability Consideration
Gaku Tatebatake, Shingo Yamaguchi · 2024
This paper proposes a network hardening method with small-scale reconfiguration based on vulnerabilities. It focuses on the vulnerability of devices in the network and the edges connecting them, and solves the problem by changing the edges. This method, in addition to preventing the spread of malware, focuses on only the vulnerable areas in the network and removes edges, thereby reducing the negative impact of edge changes on the network to a small scale. By keeping the changes to the network small, network characteristics such as maintaining the communication distance between each device can continue to be maintained. The simulation results confirm that it is possible to reduce the maximum infection spread area to 1% when 80% of the devices in the network are vulnerable. It was also found that the average shortest path length after reconfiguration and the number of edges were not significantly affected. This result confirms that it is possible to prevent the spread of malware infection while reducing the impact on the network.