Return
Scalable logical attack graph generation for enterprise networks through endpoint data
C
J
Y
D
L
DOI:10.1016/j.cose.2026.104982.png)
Abstract
En 中文
Current logical attack graph technology struggles with real-time compromise propagation analysis in dynamic networks due to scalability and latency constraints. To overcome this, we introduce ThreatWeaver, a scalable method that models attack behaviors as triggerable attack functions. Its core innovation lies in performing incremental updates exclusively for condition-satisfying inputs, thereby avoiding the computational overhead of complete graph regeneration. Based on this, we have designed a dynamic framework to drive attack graph generation. This framework continuously monitors network states through endpoint data, formally converts them into inputs for ThreatWeaver, and uses these to trigger attack functions on demand, thereby achieving instant attack graph generation. By implementing host-centric modeling, update-query separation, and hierarchical search, our framework achieves substantial improvements in both graph generation and query efficiency. Experimental results show that, compared with the baseline method, ThreatWeaver not only achieves faster incremental updates but also demonstrates higher generation efficiency in small-scale scenarios. In dynamic, incremental-update scenarios, ThreatWeaver can interpret MulVAL’s interaction rules, reproduce its reasoning results, and demonstrate strong compatibility with the MulVAL tool. It also overcomes MulVAL’s limitations in handling special and Unicode characters. To evaluate our system’s attack-graph update and query performance in dynamic networks, we collected 1.2 TB of endpoint logs over seven days from 1011 hosts. The results show that our approach reduces graph generation latency from hours to milliseconds, supports sub-second queries in Security Operations Centers (SOCs), and achieves up to 740×faster updates compared with MulVAL.
Keywords:
ThreatWeaver
attack graph generation
endpoint data
incremental updates
dynamic networks
Journal
C
IF:
5.4
Papers:
164
Citations:
0
