Using Bayesian inference for computing attack graph node beliefs

ZHANG Shao-Jun,LI Jian-Hua,Shan Shan Song,Lan Li,CHEN Xiu-Zhen
DOI: https://doi.org/10.3724/SP.J.1001.2010.03632
2010-01-01
Ruan Jian Xue Bao/Journal of Software
Abstract:Network attack graphs are widely used as templates to extrapolate network security state by analyzing observed intrusion evidence. Existing attack graph node belief computation methods are suffering from generality problems, high computational complexity, or the overuse of empirical formulas to solve problems. This paper improves one of the Bayesian network inference algorithms-the likelihood weighting algorithm into a novel graph node belief computation algorithm, which supports the temporal partial ordering relationship among intrusion evidences. Experiment results show that the method can achieve high computation accuracy in linear computational complexity, a feature making it feasible to be used to process large scale attack graphs in real-time. © by Institute of Software, the Chinese Academy of Sciences. All rights reserved.
What problem does this paper attempt to address?