首页> 外文会议>Computer Security Applications Conference, 2009. ACSAC '09 >Modeling Modern Network Attacks and Countermeasures Using Attack Graphs
【24h】

Modeling Modern Network Attacks and Countermeasures Using Attack Graphs

机译:使用攻击图建模现代网络攻击及对策

获取原文

摘要

By accurately measuring risk for enterprise networks, attack graphs allow network defenders to understand the most critical threats and select the most effective countermeasures. This paper describes substantial enhancements to the NetSPA attack graph system required to model additional present-day threats (zero-day exploits and client-side attacks) and countermeasures (intrusion prevention systems, proxy firewalls, personal firewalls, and host-based vulnerability scans). Point-to-point reachability algorithms and structures were extensively redesigned to support "reverse" reachability computations and personal firewalls. Host-based vulnerability scans are imported and analyzed. Analysis of an operational network with 84 hosts demonstrates that client-side attacks pose a serious threat. Experiments on larger simulated networks demonstrated that NetSPA's previous excellent scaling is maintained. Less than two minutes are required to completely analyze a four-enclave simulated network with more than 40,000 hosts protected by personal firewalls.
机译:通过准确测量企业网络的风险,攻击图可使网络防御者了解最关键的威胁并选择最有效的对策。本文介绍了对NetSPA攻击图系统的实质性增强,该模型可用于对其他当前威胁(零日漏洞和客户端攻击)进行建模和对策(入侵防御系统,代理防火墙,个人防火墙以及基于主机的漏洞扫描) 。对点对点可达性算法和结构进行了广泛的重新设计,以支持“反向”可达性计算和个人防火墙。导入并分析基于主机的漏洞扫描。对具有84个主机的运营网络的分析表明,客户端攻击构成了严重威胁。在较大的模拟网络上进行的实验表明,NetSPA可以保持以前的出色扩展能力。只需不到两分钟的时间就可以完全分析一个由四台模拟主机组成的网络,其中有40,000多台受个人防火墙保护的主机。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号