跳到主要导航 跳到搜索 跳到主要内容

Defense scheme generation method using mixed path attack graph

  • Yang Yu
  • , Chun He Xia*
  • , Xiao Yun Hu
  • *此作品的通讯作者
  • Beihang University

科研成果: 期刊稿件文章同行评审

摘要

The common properties of known vulnerability were discussed; the formal description of vulnerability and its exploiting rule were proposed. A mixed path attack graph (MPAG) model was constructed to extend the description semantic of attack graph. MPAG could describe the hidden attack path introduced by 0-day vulnerability and the explicit one introduced by known vulnerability in the same attack graph. Also, the risk of 0-day vulnerability exploiting ratio was calculated. At last, based on MPAG and multi-objective theory, the method of defense scheme generation was proposed, which could generate defense scheme cost and risk balanced. The experiment shows that MAPG could describe hidden attack path, and new known vulnerabilities, which are not exploited in traditional attack graph, may be introduced in MPAG; the ratio of path cover of defense scheme generated based on MPAG is better, and the method can help the security manager find out the omission of defense measure library.

源语言英语
页(从-至)1745-1759
页数15
期刊Zhejiang Daxue Xuebao (Gongxue Ban)/Journal of Zhejiang University (Engineering Science)
51
9
DOI
出版状态已出版 - 9月 2017

指纹

探究 'Defense scheme generation method using mixed path attack graph' 的科研主题。它们共同构成独一无二的指纹。

引用此