A Probability-Based Approach to Attack Graphs Generation

Anming Xie,Li Zhang,Jianbin Hu,Zhong Chen
DOI: https://doi.org/10.1109/ISECS.2009.113
2009-01-01
Abstract:Attack graphs are important tools for analyzing network security vulnerabilities. Recently, the generation method of attack graphs is a hot topic to the security researchers. As previous works encounter the scalability problem and inaccurate input information problem, we propose a novel method to automatic construction of attack graphs based on probability. After introducing prior-probability, match-probability,and transition-probability into attack graphs generation process, we develop a new attack model and relevant generation algorithms. Our method uses threshold and key states to control the scale of result attack graphs with important attack paths reserved. The following experiments show our approach could get meaningful results with less time and space, especially when one wants to get a few shortest attack paths quickly.
What problem does this paper attempt to address?