A logic-based approach to network security risk assessment

Ji Yi,Wen Danyan,Wang Haiquan,Xia Chunhe
DOI: https://doi.org/10.1109/CCCM.2009.5267887
2009-01-01
Abstract:An important problem in network security risk assessment is to uncover network threats due to current software vulnerabilities and misconfigurations. This paper proposes a logic-programming approach to conduct this risk assessment automatically. We use Datalog to specify network security property states and attack rules. The threat analysis could be conducted by a logic-programming engine that can evaluate Datalog efficiently (such as XSB [1]). We analyze trace proofs produced by the reasoning engine, and get threat information of evaluated network system. After identifying the threats, we apply game theory to compute threat risks. A simple network attack has been simulated to illuminate the appliance of the new approach. Results on how the approach has been able to help the system administrator understand the threat risks of attacks and take countermeasures accordingly are also analyzed. ©2009 IEEE.
What problem does this paper attempt to address?