首页> 外文会议>Computer security-ESORICS 2008 >Identifying Critical Attack Assets in Dependency Attack Graphs
【24h】

Identifying Critical Attack Assets in Dependency Attack Graphs

机译:在依赖攻击图中识别关键攻击资产

获取原文
获取原文并翻译 | 示例

摘要

Attack graphs have been proposed as useful tools for analyzing security vulnerabilities in network systems. Even when they are produced efficiently, the size and complexity of attack graphs often prevent a human from fully comprehending the information conveyed. A distillation of this overwhelming amount of information is crucial to aid network administrators in efficiently allocating scarce human and financial resources. This paper introduces AssetRank, a generalization of Google's PageRank algorithm which ranks web pages in web graphs. AssetRank addresses the unique semantics of dependency attack graphs and incorporates vulnerability data from public databases to compute metrics for the graph vertices (representing attacker privileges and vulnerabilities) which reveal their importance in attacks against the system. The results of applying the algorithm on a number of network scenarios show that the numeric ranks computed are consistent with the intuitive importance that the privileges and vulnerabilities have to an attacker. The vertex ranks can be used to prioritize countermeasures, help a human reader to better comprehend security problems, and provide input to further security analysis tools.
机译:已经提出了攻击图作为分析网络系统中安全漏洞的有用工具。即使有效地生成攻击图,攻击图的大小和复杂度也常常使人们无法完全理解所传达的信息。大量信息的提取对于帮助网络管理员有效分配稀缺的人力和财力至关重要。本文介绍了AssetRank,这是Google的PageRank算法的概括,该算法在Web图形中对网页进行排名。 AssetRank解决了依赖攻击图的独特语义,并结合了来自公共数据库的漏洞数据来计算图顶点的度量(代表攻击者特权和漏洞),从而揭示了它们在针对系统的攻击中的重要性。在多种网络情况下应用该算法的结果表明,计算出的数字等级与特权和漏洞对攻击者的直观重要性相一致。顶点等级可用于确定对策的优先级,帮助人类读者更好地理解安全问题,并为进一步的安全分析工具提供输入。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号