MODELING ATTACK SCENARIO WITH CAPABILITY

Zhang Lianhua,Zhang Renlong,Bai Yingcai
DOI: https://doi.org/10.3969/j.issn.1000-386X.2007.10.074
2007-01-01
Abstract:Attack scenario modeling and recognizing technology can provide the security system operator(SSO) with the high-level attack views and precise decision information for response,and it has been a hot research direction in network and information security domain.In order to succeed in attacking,attackers often use different steps and various skills such as mutation,re-sequencing,substitution,distribution,looping etc.to construct almost infinite attack scenarios.The variation in attack steps and diversity in scenario constructions lead to difficulties in attack scenario modeling and recognizing.On the basis of researches of the present attack scenario modeling technologies,a new attack scenario modeling using Requires/Provides relation represented by Capability is proposed,which can take both the various attack steps and diverse scenario constructions into consideration simultaneously.
What problem does this paper attempt to address?