An Efficient Approach to Minimum-Cost Network Hardening Using Attack Graphs

Feng Chen,Lingyu Wang,Jinshu Su
DOI: https://doi.org/10.1109/ias.2008.38
2008-01-01
Abstract:Attack graphs can reveal the threat of sophisticated multi-step attacks by enumerating possible sequences of exploits leading to the compromise of given critical resources. Finding a solution to remove such threats by hands is tedious and error prone, particularly for larger and poorly secured networks. Existing automated approaches for hardening a network has an exponential complexity and is not scalable to large networks. This paper proposes a novel approach of applying the Reduced Ordered Binary Decision Diagram (ROBDD) method to network hardening. Existing mature optimization techniques in ROBDD makes the proposed approach an efficient solution that can potentially be applied to large networks.
What problem does this paper attempt to address?