DocumentCode
1936751
Title
RAPn: Network Attack Prediction Using Ranking Access Petri Net
Author
Traore, Moussa Djiriba ; Jin, Hai ; Zou, Deqing ; Qiang, Weizhong ; Xiang, Guofu
Author_Institution
Services Comput. Technol. & Syst. Lab., Huazhong Univ. of Sci. & Technol., Wuhan, China
fYear
2011
fDate
22-23 Aug. 2011
Firstpage
108
Lastpage
115
Abstract
Exploits sequencing is a typical way by which an attacker breaks into a network. In such a scenario, each exploit lays as an atomic proposition for subsequent exploits. An attack path is seen as a succession of exploits which take an attacker right to his/her final goal. The set of all possible attack paths form an attack graph. Researchers have proposed a multitude of techniques to generate attack graph which grows exponentially in the size of the network. Hence it is preferable to optimize the choice of solutions which avoid the cost of scalability and cumbersome. In this paper, we propose a comprehensive approach to network vulnerability analysis by ranking access Petri net graph and utilizing a penetration tester´s perspective of maximal level of access possible on a host. Our approach has the following benefits: it provides a simple model in which an analyst can work, its algorithmic complexity is polynomial in the size of the network, and has the ability of scaling well to large size networks. Nevertheless, it has some drawback as in place of all possible attack paths, we seek only good attack paths. An analyst may make suboptimal choices when repairing the network.
Keywords
Petri nets; computational complexity; security of data; algorithmic complexity; atomic proposition; attack graph; attack path; network attack prediction; network vulnerability analysis; penetration tester perspective utilization; ranking access Petri net graph; Analytical models; Automata; Databases; Finite element methods; Mathematical model; Permission; access petri net; ranking; security; vulnerability;
fLanguage
English
Publisher
ieee
Conference_Titel
Chinagrid Conference (ChinaGrid), 2011 Sixth Annual
Conference_Location
Liaoning
Print_ISBN
978-1-4577-0885-5
Type
conf
DOI
10.1109/ChinaGrid.2011.22
Filename
6051741
Link To Document