Research of Network Vulnerability Analysis Based on Attack Capability Transfer

Yong Wang,Xiao-chun Yun,Yongzheng Zhang,Shuyuan Jin,Yanchen Qiao
DOI: https://doi.org/10.1109/cit.2012.32
2012-01-01
Abstract:Network vulnerability analysis is one of the important techniques to protect network security. Modeling and classification of network vulnerability are introduced firstly, then the concept of attack capability transfer and the algorithm to produce it are presented, which can aggregate vulnerabilities with the same exploitation attributes and satisfying some constrains to simplify the further analysis. Based on the attack capability transfer, a new method constructing attack graph is presented, and the complexity is O(N2) where N is the number of hosts in a network. Through the analysis of attack graph, network vulnerability quantitative analysis is taken and security hardening method based on approximate greedy algorithm is presented, the complexity of which is O(V), where V is the number of vulnerabilities in a network. Experiment shows the effectiveness of the method.
What problem does this paper attempt to address?