An Approach for APT Attack Scenario Construction Based on Dynamic Attack Graphs
Ming Jiang, Mi Wen, Yun Xiong, Weiwei Li · 2024
As network complexities and software intricacies escalate, complex attacks such as Advanced Persistent Threat (APT) are growing more challenging. Because APT attacks often lurk within the target environment for a long time, they are not easily detected. Therefore, we use the attack scenario construction method to identify APT attacks. Existing methods for constructing attack scenarios often neglect the influences of the vulnerability life cycle on atomic attacks. Furthermore, these methods rely on extensive prior data, resulting in the inability to directly update the risk probabilities of nodes. Consequently, the hazardous nodes are difficult to be dynamically and effectively identified. To address the above problems, this paper proposes an approach for APT attack scenario construction based on dynamic attack graph. Firstly, this paper analyzes the impact of the vulnerability life cycle on atomic attacks and quantifies the attack graph by incorporating factors such as vulnerability value, attack cost, attack income, and attack preference. Then, this approach integrates the attack graph with a Bayesian network to build a static attack graph, demonstrating the static risk conditions of the network. Finally, the dynamic attack graph is constructed by using forward and backward updates, thus constructing the attack scenarios and efficiently mining out the hazardous nodes. The experimental results show that the proposed method reliably maintains high dynamic reachable probability and adapts node probabilities to actual conditions, helping network administrators assess threats and address potential attacks beforehand.