Title :
RAPn: Network Attack Prediction Using Ranking Access Petri Net
Author :
Traore, Moussa Djiriba ; Jin, Hai ; Zou, Deqing ; Qiang, Weizhong ; Xiang, Guofu
Author_Institution :
Services Comput. Technol. & Syst. Lab., Huazhong Univ. of Sci. & Technol., Wuhan, China
Abstract :
Exploits sequencing is a typical way by which an attacker breaks into a network. In such a scenario, each exploit lays as an atomic proposition for subsequent exploits. An attack path is seen as a succession of exploits which take an attacker right to his/her final goal. The set of all possible attack paths form an attack graph. Researchers have proposed a multitude of techniques to generate attack graph which grows exponentially in the size of the network. Hence it is preferable to optimize the choice of solutions which avoid the cost of scalability and cumbersome. In this paper, we propose a comprehensive approach to network vulnerability analysis by ranking access Petri net graph and utilizing a penetration tester´s perspective of maximal level of access possible on a host. Our approach has the following benefits: it provides a simple model in which an analyst can work, its algorithmic complexity is polynomial in the size of the network, and has the ability of scaling well to large size networks. Nevertheless, it has some drawback as in place of all possible attack paths, we seek only good attack paths. An analyst may make suboptimal choices when repairing the network.
Keywords :
Petri nets; computational complexity; security of data; algorithmic complexity; atomic proposition; attack graph; attack path; network attack prediction; network vulnerability analysis; penetration tester perspective utilization; ranking access Petri net graph; Analytical models; Automata; Databases; Finite element methods; Mathematical model; Permission; access petri net; ranking; security; vulnerability;
Conference_Titel :
Chinagrid Conference (ChinaGrid), 2011 Sixth Annual
Conference_Location :
Liaoning
Print_ISBN :
978-1-4577-0885-5
DOI :
10.1109/ChinaGrid.2011.22