ACM Home Page
Please provide us with feedback. Feedback
Toward measuring network security using attack graphs
Full text PdfPdf (149 KB)
Source
Conference on Computer and Communications Security archive
Proceedings of the 2007 ACM workshop on Quality of protection table of contents
Alexandria, Virginia, USA
SESSION: Risk analysis table of contents
Pages: 49 - 54  
Year of Publication: 2007
ISBN:978-1-59593-885-5
Authors
Lingyu Wang  Concordia University, Montreal, PQ, Canada
Anoop Singhal  National Institute of Standards and Technology, Gaithersburg, MD
Sushil Jajodia  George Mason University, Fairfax, VA
Sponsors
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
ACM: Association for Computing Machinery
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 64,   Downloads (12 Months): 541,   Citation Count: 3
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1314257.1314273
What is a DOI?

ABSTRACT

In measuring the overall security of a network, a crucial issue is to correctly compose the measure of individual components. Incorrect compositions may lead to misleading results. For example, a network with less vulnerabilities or a more diversified configuration is not necessarily more secure. To obtain correct compositions of individual measures, we need to first understand the interplay between network components. For example, how vulnerabilities can be combined by attackers in advancing an intrusion. Such an understanding becomes possible with recent advances in modeling network security using attack graphs. Based on our experiences with attack graph analysis, we propose an integrated framework for measuring various aspects of network security. We first outline our principles andmethodologies. We then describe concrete examples to buildintuitions. Finally, we present our formal framework. It is our belief that metrics developed based on the proposed framework will lead to novel quantitative approaches to vulnerability analysis, network hardening, and attack response.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

1
 
2
Applied Computer Security Associates. Workshop on. In Information Security System Scoring and Ranking, 2001.
 
3
D. Balzarotti, M. Monga, and S. Sicari. Assessing the risk of using vulnerable components. In Proceedings of the 1st Workshop on Quality of Protection, 2005.
 
4
P. Balzarotti, M. Monga, and S. Sicari. Assessing the risk of using vulnerable components. In Proceedings of the 2nd ACM workshop on Quality of protection, 2005.
 
5
6
 
7
M. Dacier. Towards quantitative evaluation of computer security. Ph.D. Thesis, Institut National Polytechnique de Toulouse, 1994.
 
8
M. Dacier, Y. Deswarte, and M. Kaaniche. Quantitative assessment of operational security: Models and tools. Technical Report 96493, 1996.
 
9
D. Farmer and E.H. Spafford. The COPS security checker system. In USENIX Summer, pages 165--170, 1990.
 
10
K.S. Hoo. Metrics of network security. White Paper, 2004.
 
11
M. Howard, J. Pincus, and J. Wing. Measuring relative attack surfaces. In Workshop on Advanced Developments in Software and Systems Security, 2003.
 
12
S. Jajodia, S. Noel, and B. O'Berry. Topological analysis of network attack vulnerability. In V. Kumar, J. Srivastava, and A. Lazarevic, editors, Managing Cyber Threats: Issues, Approaches and Challenges. Kluwer Academic Publisher, 2003.
13
 
14
 
15
 
16
National Institute of Standards and Technology. Technology assessment: Methods for measuring the level of computer security. NIST Special Publication 500-133, 1985.
 
17
 
18
J. Wing P. Manadhata. Measuring a system's attack surface. Technical Report CMU-CS-04-102, 2004.
 
19
J. Wing P. Manadhata. An attack surface metric. Technical Report CMU-CS-05-155, 2005.
 
20
J. Wing P. Manadhata. An attack surface metric. In First Workshop on Security Metrics (MetriCon), 2006.
21
22
 
23
24
 
25
 
26
 
27
M. Swanson, N. Bartol, J. Sabato, J. Hash, and L. Graffo. Security metrics guide for information technology systems. NIST Special Publication 800-55, 2003.
 
28
L. Swiler, C. Phillips, D. Ellis, and S. Chakerian. Computer attack graph generation tool. In Proceedings of the DARPA Information Survivability Conference & Exposition II (DISCEX'01), 2001.
 
29
L. Wang, A. Liu, and S. Jajodia. An efficient and unified approach to correlating, hypothesizing, and predicting intrusion alerts. In Proceedings of the 10th European Symposium on Research in Computer Security (ESORICS 2005), pages 247--266, 2005.
 
30
 
31
 
32
L. Wang, A. Singhal, and S. Jajodia. Measuring the overall security of network configurations using attack graphs. In Proceedings of 21th IFIP WG 11.3 Working Conference on Data and Applications Security (DBSec 2007), 2007.
 
33
L. Wang, C. Yao, A. Singhal, and S. Jajodia. Interactive analysis of attack graphs using relational queries. In Proceedings of 20th IFIP WG 11.3 Working Conference on Data and Applications Security (DBSec 2006), pages 119--132, 2006.
 
34


Collaborative Colleagues:
Lingyu Wang: colleagues
Anoop Singhal: colleagues
Sushil Jajodia: colleagues