A NETWORK SECURITY GRADE BASED ATTACK GRAPH GENERATION PARALLEL APPROACH

Hu Xin,Sun Yonglin,Wang Yongjun
DOI: https://doi.org/10.3969/j.issn.1000-386X.2011.11.006
2011-01-01
Abstract:Attack graph is becoming a key technology for network security analysis.The paper introduces the concept of network security grade to reflect the direction of network attacks and the hierarchy of network defense.Therefore the paper improves its monotony assumption to reduce the attack graph scale,depending on the concept of network security grade,executes sub-task division on attack graph generation; then designs a parallel attack graph generation algorithm.Compared to previous algorithms,experiment results show that the parallel algorithm effectively improves the attack graph generation efficiency;on a 8-cored server with 32GB of memory,the parallel algorithm can generate an attack graph with a network size of 400 within 20 seconds.Moreover the efforts by the paper may help attack graph analysis and network remedy technology with large size network applications.
What problem does this paper attempt to address?