返回
Security Countermeasures Selection Using the Meta Attack Language and Probabilistic Attack Graphs
DOI:10.1109/ACCESS.2022.3200601.png)
摘要
En 中文
Connecting critical infrastructure assets to the network is absolutely essential for modern industries. In contrast to the apparent advantages, network connectivity exposes other infrastructure vulnerabilities that can be exploited by attackers. To protect the infrastructure, precise countermeasure identification is necessary. In this regard, the objective for the security officers is to identify the optimal set of countermeasures under a variety of budgetary restrictions. Our approach is based on the Meta Attack Language framework, which allows for convenient modelling of said infrastructures, as well as for automatic generation of attack graphs describing attacks against them. We formalize the problem of the selection of countermeasures in this context. The formalization makes it possible to deal with an arbitrary number of budgets, expressing available resources of both monetary and time-like nature, and to model numerous dependencies between countermeasures, including order dependencies, mutual exclusivity, and interdependent implementation costs. We propose a flexible and scalable algorithm for the problem. The whole methodology is validated in practice on realistic models.
Keyword:
Security
DSL
Costs
Analytical models
Optimization
Computational modeling
Stochastic processes
Risk assessment
Threat modeling
Attack graphs
attack simulations
countermeasure selection
graphical security modeling
threat modeling
期刊
IF:
3.6
论文数:
9.8W
被引数:
29.4W
机构
引用论文
Utilization of Artificial Intelligence in Disease Prevention: Diagnosis, Treatment, and Implications for the Healthcare Workforce人工智能在疾病预防中的应用: 诊断,治疗以及对医疗保健人员的影响
Healthcare
IF0
VehicleLang: A probabilistic modeling and simulation language for modern vehicle IT infrastructures
COMPUTERS & SECURITY
IF5.4
Clinical Significance of SERPINA1 Gene and Its Encoded Alpha1-antitrypsin Protein in NSCLC
Cancers
IF0

