Journal Article10.1016/J.COMCOM.2006.06.018
Minimum-cost network hardening using attack graphs
TL;DR: This paper proposes a solution to automate the task of hardening a network against multi-step intrusions using a formal framework of the minimum network hardening problem, and an improved one-pass algorithm in deriving the logic proposition while avoiding logic loops.
read more
About: This article is published in Computer Communications. The article was published on 01 Nov 2006.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Dynamic Security Risk Management Using Bayesian Attack Graphs
TL;DR: This paper proposes a risk management framework using Bayesian networks that enable a system administrator to quantify the chances of network compromise at various levels and shows how to use this information to develop a security mitigation and management plan.
650
An Attack Graph-Based Probabilistic Security Metric
Lingyu Wang,Tania Islam,Tao Long,Anoop Singhal,Sushil Jajodia +4 more
- 13 Jul 2008
TL;DR: This paper proposes an attack graph-based probabilistic metric for network security and studies its efficient computation, and defines and proposes heuristics to improve the efficiency of such computation.
DAG-based attack and defense modeling: don’t miss the forest for the attack trees
TL;DR: This paper presents the current state of the art on attack and defense modeling approaches that are based on directed acyclic graphs (DAGs), and proposes a taxonomy of the described formalisms.
353
Measuring network security using dynamic bayesian network
Marcel Frigault,Lingyu Wang,Anoop Singhal,Sushil Jajodia +3 more
- 27 Oct 2008
TL;DR: A Dynamic Bayesian Networks-based model is proposed to incorporate temporal factors, such as the availability of exploit codes or patches, for continuously measuring network security in a dynamic environment.
Using Bayesian networks for cyber security analysis
Peng Xie,Jason H. Li,Xinming Ou,Peng Liu,Renato Levy +4 more
- 09 Aug 2010
TL;DR: This paper builds an example Bayesian network based on a current security graph model, justifies the modeling approach through attack semantics and experimental study, and shows that the resulting Bayesian networks is not sensitive to parameter perturbation.
278
References
Automated generation and analysis of attack graphs
Oleg Sheyner,J.W. Haines,Somesh Jha,Richard P. Lippmann,Jeannette M. Wing +4 more
- 12 May 2002
TL;DR: This paper presents an automated technique for generating and analyzing attack graphs, based on symbolic model checking algorithms, letting us construct attack graphs automatically and efficiently.
1.4K
•Book
Introduction to mathematical logic
Hans Hermes,Diana Schmidt +1 more
- 01 Jan 1973
TL;DR: This book discusses the semantics of Predicate Logic, and some of theorems of A. Robinson, Craig and Beth's treatment of Peano's Axiom System.
1K
A graph-based system for network-vulnerability analysis
Cynthia A. Phillips,Laura Painton Swiler +1 more
- 01 Jan 1998
TL;DR: A graph-based tool can identify the set of attack paths that have a high probability of success (or a low effort cost) for the attacker, and is used to test the effectiveness of making configuration changes, implementing an intrusion detection system, etc.
Scalable, graph-based network vulnerability analysis
Paul Ammann,Duminda Wijesekera,Saket Kaushik +2 more
- 18 Nov 2002
TL;DR: This paper revisits the idea of attack graphs themselves, and argues that they represent more information explicitly than is necessary for the analyst, and proposes a more compact and scalable representation.
Two formal analyses of attack graphs
Somesh Jha,Oleg Sheyner,Jeannette M. Wing +2 more
- 24 Jun 2002
TL;DR: This paper presents an algorithm for generating attack graphs using model checking as a subroutine, and provides a formal characterization of this problem, proving that it is polynomially equivalent to the minimum hitting set problem and presenting a greedy algorithm with provable bounds.
Related Papers (5)
Paul Ammann,Duminda Wijesekera,Saket Kaushik +2 more
- 18 Nov 2002
Cynthia A. Phillips,Laura Painton Swiler +1 more
- 01 Jan 1998
Xinming Ou,Wayne F. Boyer,Miles McQueen +2 more
- 30 Oct 2006