Attack Difficulty Metric for Assessment of Network Security

被引:5
|
作者
Mukherjee, Preetam [1 ]
Mazumdar, Chandan [2 ]
机构
[1] Jadavpur Univ, Ctr Distributed Comp, Kolkata, India
[2] Jadavpur Univ, Dept Comp Sci & Engn, Kolkata, India
关键词
Security Metrics; Network security; Attack Graph; RISK;
D O I
10.1145/3230833.3232817
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In recent days,. organizational networks are becoming target of sophisticated multi-hop attacks. Attack Graph has been proposed as a useful modeling tool for complex attack scenarios by combining multiple vulnerabilities in causal chains. Analysis of attack scenarios enables security administrators to calculate quantitative security measurements. These measurements justify security investments in the organization. Different security metrics based on attack graph have been introduced for evaluation of comparable security measurements. Studies show that difficulty of exploiting the same vulnerability changes with change of its position in the causal chains of attack graph. In this paper, a new security metric based on attack graph, namely Attack Difficulty has been proposed to include this position factor. The security metrics are classified in two major categories viz. counting metrics and difficulty-based metrics. The proposed Attack Difficulty Metric employs both categories of metrics as the basis for its measurement. Case studies have been presented for demonstrating applicability of the proposed metric. Comparison of this new metric with other attack graph based security metrics has also been included to validate its acceptance in real life situations.
引用
收藏
页数:10
相关论文
共 50 条
  • [31] A Security Resilience Metric Framework Based on the Evolution of Attack and Defense Scenarios
    Zuo, Jinxin
    Guo, Ziyu
    An, Tong
    Xu, Zhongwei
    Lu, Yueming
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (19) : 17007 - 17021
  • [32] Cyber Security Risk Assessment of a DDoS Attack
    Wangen, Gaute
    Shalaginov, Andrii
    Hallstensen, Christoffer
    INFORMATION SECURITY, (ISC 2016), 2016, 9866 : 183 - 202
  • [33] VEA-bility security metric: A network security analysis tool
    Tupper, Melanie
    Zincir-Heywood, A. Nur
    ARES 2008: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON AVAILABILITY, SECURITY AND RELIABILITY, 2008, : 950 - 957
  • [34] Network Security Situation Assessment Approach Based on Attack-Defense Stochastic Game Model
    Liu, Jianyi
    Weng, Fangyu
    Zhang, Ru
    Guo, Yunbiao
    CLOUD COMPUTING AND SECURITY, PT III, 2018, 11065 : 161 - 173
  • [35] Research on Multi-Target Network Security Assessment with Attack Graph Expert System Model
    Li, Yunpeng
    Li, Xi
    SCIENTIFIC PROGRAMMING, 2021, 2021
  • [36] Network Security Situation Assessment Methods and Tactics Based on Multivariate Spatiotemporal Attack Graph Model
    Zhou, Anshun
    Huo, Mingde
    20TH INT CONF ON UBIQUITOUS COMP AND COMMUNICAT (IUCC) / 20TH INT CONF ON COMP AND INFORMATION TECHNOLOGY (CIT) / 4TH INT CONF ON DATA SCIENCE AND COMPUTATIONAL INTELLIGENCE (DSCI) / 11TH INT CONF ON SMART COMPUTING, NETWORKING, AND SERV (SMARTCNS), 2021, : 541 - 548
  • [37] Security Assessment of Computer Networks Based on Attack Graphs and Security Events
    Kotenko, Igor
    Doynikova, Elena
    INFORMATION AND COMMUNICATION TECHNOLOGY, 2014, 8407 : 462 - 471
  • [38] RESEARCH OF SECURITY METRIC ARCHITECTURE FOR NEXT GENERATION NETWORK
    Huang, Rui
    Yan, Danfeng
    Yang, Fangchun
    2009 IEEE INTERNATIONAL CONFERENCE ON NETWORK INFRASTRUCTURE AND DIGITAL CONTENT, PROCEEDINGS, 2009, : 207 - 212
  • [39] A Review on Attack and Security Tools at Network Layer of IoT
    Agarwal, Vidur
    Mishra, Preeti
    Kumar, Sachin
    Pilli, Emmanuel S.
    OPTICAL AND WIRELESS TECHNOLOGIES, OWT 2020, 2022, 771 : 497 - 506
  • [40] GENERATING NETWORK ATTACK GRAPHS FOR SECURITY ALERT CORRELATION
    Zhang, Shaojun
    Li, Jianhua
    Chen, Xiuzhen
    Fan, Lei
    2008 THIRD INTERNATIONAL CONFERENCE ON COMMUNICATIONS AND NETWORKING IN CHINA, VOLS 1-3, 2008, : 220 - 225