Attack Difficulty Metric for Assessment of Network Security

被引:5
|
作者
Mukherjee, Preetam [1 ]
Mazumdar, Chandan [2 ]
机构
[1] Jadavpur Univ, Ctr Distributed Comp, Kolkata, India
[2] Jadavpur Univ, Dept Comp Sci & Engn, Kolkata, India
关键词
Security Metrics; Network security; Attack Graph; RISK;
D O I
10.1145/3230833.3232817
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In recent days,. organizational networks are becoming target of sophisticated multi-hop attacks. Attack Graph has been proposed as a useful modeling tool for complex attack scenarios by combining multiple vulnerabilities in causal chains. Analysis of attack scenarios enables security administrators to calculate quantitative security measurements. These measurements justify security investments in the organization. Different security metrics based on attack graph have been introduced for evaluation of comparable security measurements. Studies show that difficulty of exploiting the same vulnerability changes with change of its position in the causal chains of attack graph. In this paper, a new security metric based on attack graph, namely Attack Difficulty has been proposed to include this position factor. The security metrics are classified in two major categories viz. counting metrics and difficulty-based metrics. The proposed Attack Difficulty Metric employs both categories of metrics as the basis for its measurement. Case studies have been presented for demonstrating applicability of the proposed metric. Comparison of this new metric with other attack graph based security metrics has also been included to validate its acceptance in real life situations.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] Network Security Metric Based on Attack Duration
    Forghani, Shahab
    Habibi, Navid
    Firoozbakht, Mohsen
    [J]. 2015 2ND INTERNATIONAL CONFERENCE ON KNOWLEDGE-BASED ENGINEERING AND INNOVATION (KBEI), 2015, : 1093 - 1096
  • [2] Applying Attack Graphs to Network Security Metric
    Xie, Anming
    Wen, Weiping
    Zhang, Li
    Hu, Jianbin
    Chen, Zhong
    [J]. MINES 2009: FIRST INTERNATIONAL CONFERENCE ON MULTIMEDIA INFORMATION NETWORKING AND SECURITY, VOL 1, PROCEEDINGS, 2009, : 427 - +
  • [3] An Approach for Internal Network Security Metric Based on Attack Probability
    Shan, Chun
    Jiang, Benfu
    Xue, Jingfeng
    Guan, Fang
    Xiao, Na
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2018,
  • [4] Network security situation assessment with network attack behavior classification
    Yang, Hongyu
    Zhang, Zixin
    Xie, Lixia
    Zhang, Liang
    [J]. INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2022, 37 (10) : 6909 - 6927
  • [5] Network Security Risk Assessment Based on Attack Graph
    Xie, Lixia
    Zhang, Xiao
    Zhang, Jiyong
    [J]. JOURNAL OF COMPUTERS, 2013, 8 (09) : 2339 - 2347
  • [6] Difficulty-Level Metric for Cyber Security Training
    Huang, Zequn
    Shen, Chien-Chung
    Doshi, Sheetal
    Thomas, Nimmi
    Duong, Ha
    [J]. 2015 IEEE INTERNATIONAL MULTI-DISCIPLINARY CONFERENCE ON COGNITIVE METHODS IN SITUATION AWARENESS AND DECISION SUPPORT (COGSIMA), 2015, : 172 - 178
  • [7] An Approach for Security Assessment of Network Configurations using Attack Graph
    Ghosh, Nirnay
    Ghosh, S. K.
    [J]. 2009 FIRST INTERNATIONAL CONFERENCE ON NETWORKS & COMMUNICATIONS (NETCOM 2009), 2009, : 283 - 288
  • [9] Multiservice Network Security Metric
    Mozhaev, Oleksandr
    Kuchuk, Heorgii
    Kuchuk, Nina
    Mozhaev, Mykhailo
    Lohyvnenko, Mykhailo
    [J]. 2017 2ND IEEE INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION AND COMMUNICATION TECHNOLOGIES-2017 (AICT 2017), 2017, : 133 - 136
  • [10] A Network Security Situation Assessment Method Based On Attack Intention Perception
    Kou Guang
    Tang Guangming
    Ding Xia
    Wang Shuo
    Wang Kun
    [J]. 2016 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATIONS (ICCC), 2016, : 1138 - 1142