Network Vulnerability Assessment Model Applying Host-based Access Graphs

SONG Shun-hong,LU Yu-liang,YANG Guo-zheng,YUAN Huan
2011-01-01
Abstract:In view of the scalability problem in the risk assessment based on attack graphs,we propose a quantitative vulnerability assessment approach based on host-based access graphs from the perspective of internal security threat.First we introduce the concept of network access relationship and host critical degree,and propose host security threat model.Then we obtain network access relationships of all the hosts through the generation of host-based access graphs.The impacts of vulnerabilities to the network are figured out based on the model and the access graphs and then all the vulnerabilities are prioritized by impacts.The experiment shows that this approach is efficient to assess the security state of the network and the severity of the vulnerabilities to the network.The result gives meaningful recommendation for network hardening.
What problem does this paper attempt to address?