• DocumentCode
    1936751
  • Title

    RAPn: Network Attack Prediction Using Ranking Access Petri Net

  • Author

    Traore, Moussa Djiriba ; Jin, Hai ; Zou, Deqing ; Qiang, Weizhong ; Xiang, Guofu

  • Author_Institution
    Services Comput. Technol. & Syst. Lab., Huazhong Univ. of Sci. & Technol., Wuhan, China
  • fYear
    2011
  • fDate
    22-23 Aug. 2011
  • Firstpage
    108
  • Lastpage
    115
  • Abstract
    Exploits sequencing is a typical way by which an attacker breaks into a network. In such a scenario, each exploit lays as an atomic proposition for subsequent exploits. An attack path is seen as a succession of exploits which take an attacker right to his/her final goal. The set of all possible attack paths form an attack graph. Researchers have proposed a multitude of techniques to generate attack graph which grows exponentially in the size of the network. Hence it is preferable to optimize the choice of solutions which avoid the cost of scalability and cumbersome. In this paper, we propose a comprehensive approach to network vulnerability analysis by ranking access Petri net graph and utilizing a penetration tester´s perspective of maximal level of access possible on a host. Our approach has the following benefits: it provides a simple model in which an analyst can work, its algorithmic complexity is polynomial in the size of the network, and has the ability of scaling well to large size networks. Nevertheless, it has some drawback as in place of all possible attack paths, we seek only good attack paths. An analyst may make suboptimal choices when repairing the network.
  • Keywords
    Petri nets; computational complexity; security of data; algorithmic complexity; atomic proposition; attack graph; attack path; network attack prediction; network vulnerability analysis; penetration tester perspective utilization; ranking access Petri net graph; Analytical models; Automata; Databases; Finite element methods; Mathematical model; Permission; access petri net; ranking; security; vulnerability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Chinagrid Conference (ChinaGrid), 2011 Sixth Annual
  • Conference_Location
    Liaoning
  • Print_ISBN
    978-1-4577-0885-5
  • Type

    conf

  • DOI
    10.1109/ChinaGrid.2011.22
  • Filename
    6051741