A Risk Assessment Model Based On Petri Nets

Nian-Dong Liao,Sheng-Feng Tian
2008-01-01
Abstract:This paper considers the real-time and dynamic network risk assessment method for information systems and networks. The networks/systems risk is evaluated using Petri nets model. The model is constructed based on the mapping of networks/systems onto an attack graph, which takes to accurately determine the local traffic risk value of every participating router in the attack Petri graph. We address how locate and calculate the network risk, and eliminate potential attackers. We also present a novel Petri nets risk assessment algorithm. An important technical contribution is that our approach can determine the dangerous victim in the real-time, and get the potential attack trace. We have carried out experiments to illustrate the effectiveness and robustness of our method. Experiment results clearly show that we can locate the attackers in a short time, help user to improve the networks/systems security. This method can play an important role for network security assessment.
What problem does this paper attempt to address?