首页> 外文会议>Annual International Conference on Advanced Computing and Communications >Efficient generation of exploit dependency graph by customized attack modeling technique
【24h】

Efficient generation of exploit dependency graph by customized attack modeling technique

机译:通过自定义攻击建模技术有效地产生利用依赖图

获取原文

摘要

A major challenge in today's network is to maintain a secure interconnected world of computing where confidentiality, integrity, availability of information and resources are restored. Traditionally, security is enforced by access control and authentication. However, these security best practices do not take operating system, or network service-based vulnerabilities into account. With the evolution of sophisticated hacking tools, attackers exploit these vulnerabilities and gain legitimate access to network resources, bypassing the access control and authentication policies. Exploit dependency graph models service or application-based attacks and depicts all possible multi-host multi-step attack scenarios that an attacker can launch to penetrate into a network. An important step in the generation of exploit dependency graph is to characterize exploits in terms of a set of precondition and postcondition. Most of the reported works have generated exploit dependency graphs using proprietary vulnerability databases not available in the public domain. This work proposes a customized exploit dependency graph generation through modeling of exploits from open-source databases. Analysis of the developed algorithm shows considerable improvement in terms of time and space complexity in comparison to the reported works.
机译:当今网络中的一项重大挑战是维持一个安全的互联的计算世界,其中保密,完整性,信息和资源的可用性都是恢复的。传统上,通过访问控制和身份验证强制执行安全性。但是,这些安全最佳实践不会考虑操作系统或基于网络服务的漏洞。随着复杂的黑客工具的演变,攻击者利用这些漏洞并获得对网络资源的合法访问,绕过访问控制和认证策略。利用依赖图模型模型服务或基于应用程序的攻击,并描绘了攻击者可以启动渗透到网络的所有可能的多主机多步攻击方案。 Exploit依赖关系图的一个重要步骤是在一组前提条件和后照管方面表征漏洞利用。大多数报告的工程使用公共域中不可用的专有漏洞数据库生成了利用依赖关系图。这项工作提出了通过从开源数据库的利用建模来提出自定义的利用依赖关系图。与报告的作品相比,发达算法的分析显示了时间和空间复杂性的相当大。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号