Access Graph to Analyze Network Vulnerabilities

Xiaochun Xiao,Tiange Zhang,Gendu Zhang
DOI: https://doi.org/10.1109/paciia.2008.183
2008-01-01
Abstract:Protecting computer network security is critical today. Many graph-based approaches have been proposed to analyze network vulnerabilities. Attack Graph is the most influential one. But attack graphs grow exponentially with the size of the network. In this paper, we propose a comprehensive framework for network vulnerabilities modeling and analysis based on the access graph. As a complement to the attack graph approach, the access graph is host-centric approach, which grows polynomially with the number of hosts and so has the benefit of being computationally feasible on large networks. Compared with related works, our approach improves in both performance and computational cost.
What problem does this paper attempt to address?