首页> 外文会议>International Conference on Cyber Security and Protection of Digital Services >Automated Vulnerability Testing via Executable Attack Graphs
【24h】

Automated Vulnerability Testing via Executable Attack Graphs

机译:通过可执行的攻击图自动进行漏洞测试

获取原文

摘要

Cyber risk assessments are an essential process for analyzing and prioritizing security issues. Unfortunately, many risk assessment methodologies are marred by human subjectivity, resulting in non-repeatable, inconsistent findings. The absence of repeatable and consistent results can lead to suboptimal decision making with respect to cyber risk reduction. There is a pressing need to reduce cyber risk assessment uncertainty by using tools that use well defined inputs, producing well defined results. This paper presents Automated Vulnerability and Risk Analysis (AVRA), an end-to-end process and tool for identifying and exploiting vulnerabilities, designed for use in cyber risk assessments. The approach presented is more comprehensive than traditional vulnerability scans due to its analysis of an entire network, integrating both host and network information. AVRA automatically generates a detailed model of the network and its individual components, which is used to create an attack graph. Then, AVRA follows individual attack paths, automatically launching exploits to reach a particular objective. AVRA was successfully tested within a virtual environment to demonstrate practicality and usability. The presented approach and resulting system enhances the cyber risk assessment process through rigor, repeatability, and objectivity.
机译:网络风险评估是分析和优先考虑安全问题的重要过程。不幸的是,许多风险评估方法是受到人类主体性的影响,导致不可重复的,结果不一致。没有可重复和一致的结果可能导致关于网络风险减少的次优决策。通过使用使用良好定义的输入的工具,需要迫切需要减少网络风险评估的不确定性,产生明确的结果。本文提出了自动漏洞和风险分析(AVRA),用于识别和利用漏洞的端到端过程和工具,专为在网络风险评估中使用。由于其对整个网络的分析,整合了主机和网络信息,所呈现的方法比传统漏洞扫描更全面。 AVRA自动生成网络的详细模型及其各个组件,用于创建攻击图。然后,AVRA遵循单独的攻击路径,自动启动漏洞以达到特定目标。 AVRA在虚拟环境中成功测试以展示实用性和可用性。通过严格,可重复性和客观性,提出的方法和结果系统增强了网络风险评估过程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号