Impact estimation using data flows over attack graphs
Number of Authors: 1
2009 (English)Conference paper (Refereed)
We propose a novel approach to estimating the impact of an attack using a data model and an impact model on top of an attack graph. The data model describes how data flows between nodes in the network -- how it is copied and processed by softwares and hosts -- while the impact model models how exploitation of vulnerabilities affects the data flows with respect to the confidentiality, integrity and availability of the data. In addition, by assigning a loss value to a compromised data set, we can estimate the cost of a successful attack. We show that our algorithm not only subsumes the simple impact estimation used in the literature but also improves it by explicitly modeling loss value dependencies between network nodes. With our model, the operator will be able to use less time when comparing different security patches to a network.
Place, publisher, year, edition, pages
2009, 6. , 8 p.
Risk analysis, Network security, Attack graphs, Security metrics, Intrusion detection
Computer and Information Science
IdentifiersURN: urn:nbn:se:ri:diva-15976OAI: oai:DiVA.org:ri-15976DiVA: diva2:1038000
The 14th Nordic Conference on Secure IT Systems (NordSec 2009)