1
Return

Scalable logical attack graph generation for enterprise networks through endpoint data

delete2026-05-27
delete0
PRE
AI
C
Chengliang Gao
J
Jing Qiu *
Y
Yifei Sun
D
Du Cheng
L
Lihua Yin
DOI:10.1016/j.cose.2026.104982delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Current logical attack graph technology struggles with real-time compromise propagation analysis in dynamic networks due to scalability and latency constraints. To overcome this, we introduce ThreatWeaver, a scalable method that models attack behaviors as triggerable attack functions. Its core innovation lies in performing incremental updates exclusively for condition-satisfying inputs, thereby avoiding the computational overhead of complete graph regeneration. Based on this, we have designed a dynamic framework to drive attack graph generation. This framework continuously monitors network states through endpoint data, formally converts them into inputs for ThreatWeaver, and uses these to trigger attack functions on demand, thereby achieving instant attack graph generation. By implementing host-centric modeling, update-query separation, and hierarchical search, our framework achieves substantial improvements in both graph generation and query efficiency. Experimental results show that, compared with the baseline method, ThreatWeaver not only achieves faster incremental updates but also demonstrates higher generation efficiency in small-scale scenarios. In dynamic, incremental-update scenarios, ThreatWeaver can interpret MulVAL’s interaction rules, reproduce its reasoning results, and demonstrate strong compatibility with the MulVAL tool. It also overcomes MulVAL’s limitations in handling special and Unicode characters. To evaluate our system’s attack-graph update and query performance in dynamic networks, we collected 1.2 TB of endpoint logs over seven days from 1011 hosts. The results show that our approach reduces graph generation latency from hours to milliseconds, supports sub-second queries in Security Operations Centers (SOCs), and achieves up to 740×faster updates compared with MulVAL.
Keywords:
ThreatWeaver
attack graph generation
endpoint data
incremental updates
dynamic networks

Journal

C
COMPUTERS & SECURITY
IF:
5.4
Papers:
164
Citations:
0

Organization

T
tsinghua university
Scholars:
11.5W
Papers: 9.9W
Citations: 137
G
Guangzhou University
Scholars:
1.7W
Papers: 1.2W
Citations: 1.8W
Cited Papers

Cited Papers

Citing Papers

Citing Papers