In the field of network security, the increasing complexity of network environments and their critical importance in economic and social contexts highlight the significance of attack path analysis. However, current attack path analysis methods face significant challenges, such as high computational complexity and inability to adapt to dynamic changes in potential attack paths. These limitations make it difficult to fully reveal attackers’ actions, especially in large-scale network environments where comprehensive prediction and prevention are highly complex and challenging. This paper presents a dynamic analysis method based on Bayesian Attack Graphs (BAG). First, the initial risk state is determined using the Common Vulnerability Scoring System (CVSS), and Bayesian methods are then applied to calculate the reachability probabilities of static nodes, effectively modeling the structural dependencies among asset vulnerabilities. Next, an improved BAG generation method is introduced, which aggregates fine-grained state nodes and vulnerabilities to the device level, thereby simplifying the attack graph’s complexity. Finally, to adapt to dynamic network states, a forward-backward probability propagation mechanism is introduced, allowing for real-time updates of node reachability probabilities. This sequential approach enhances the efficiency and accuracy of security assessments, providing targeted early warnings and improving the overall effectiveness of security measures.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Dynamic Analysis of Attack Paths Based on Bayesian Attack Graph

  • Dongyang Zheng,
  • Chengliang Gao,
  • Jiaxu Xing,
  • Ximing Chen,
  • Rongrong Chen,
  • Jing Qiu

摘要

In the field of network security, the increasing complexity of network environments and their critical importance in economic and social contexts highlight the significance of attack path analysis. However, current attack path analysis methods face significant challenges, such as high computational complexity and inability to adapt to dynamic changes in potential attack paths. These limitations make it difficult to fully reveal attackers’ actions, especially in large-scale network environments where comprehensive prediction and prevention are highly complex and challenging. This paper presents a dynamic analysis method based on Bayesian Attack Graphs (BAG). First, the initial risk state is determined using the Common Vulnerability Scoring System (CVSS), and Bayesian methods are then applied to calculate the reachability probabilities of static nodes, effectively modeling the structural dependencies among asset vulnerabilities. Next, an improved BAG generation method is introduced, which aggregates fine-grained state nodes and vulnerabilities to the device level, thereby simplifying the attack graph’s complexity. Finally, to adapt to dynamic network states, a forward-backward probability propagation mechanism is introduced, allowing for real-time updates of node reachability probabilities. This sequential approach enhances the efficiency and accuracy of security assessments, providing targeted early warnings and improving the overall effectiveness of security measures.