- 0
- 0
- 约2.89千字
- 约 14页
- 2020-06-11 发布于湖北
- 举报
A Structural Framework for Modeling Multi-Stage Network Attacks Daley, Larson, Dawkins University of Tulsa 2002 IEEE Outline Introduction Stratified Node Topology Attack Node Correlation Context Sensitive Nodes Example Attack Scenarios Applications Related Work Conclusions Introduction Attack trees represent goal-oriented attack behaviors multistage casual relationships between events or states “AND”, “OR” nodes can be weighted to reflect the likelihood of success for a particular attack Introduction (cont.) Disadvantage do not provide a comprehensive model for the analysis of network vulnerability Extended attack tree paradigm introduce functionality to allow for a comprehensive representation of attack stratified node topology event-level, state-level, top-level nodes Stratified Node Topology (SNT) Stratified Node Topology Three layers partition attack tree based on functionality and allow for a more precise portrayal of the mechanics of an attack. Event-Level direct activities of an attacker nodes correspond directly to intrusion detection system alerts Stratified Node Topology (cont.) State-Level generalized intermediate objectives in an attack conceptual steps (abstract goals) fairly constant ex: “execute arbitrary code”, “modify protected file” Top-Level ultimate intentions of an attacker top-level nodes may also be starting points for other attacks Attack Node Correlation relationship between nodes implicit link allow individual nodes in the tree to imply another node ex: perform a buffer overflow exploit to execute arbitrary code explicit link when an attack provides a capability to execute additional nodes but does not actually invoke an instance of a new node ex: obtain root access, next to compromise additional systems or steal information Context Sensitive Nodes Assign parameter values to attack node bound the search space of attacks reduce the likelihood of false positives Example Attack Scenarios Example Attack Scenarios (cont.) The composable goal-or
您可能关注的文档
最近下载
- 5-6年级健康课件《睡眠、运动与健康》.ppt VIP
- 2、武汉市海绵城市建设设计指南x标准规范.doc VIP
- 八年级语文下册期末复习专练 专题12 作文(期末热点预测与范文)(解释版)2024-2025学年(统编版广东专用).docx VIP
- 2025年金融风险管理师信用组合模型的参数估计与校准技术专题试卷及解析.pdf VIP
- 《建筑防水材料介绍》课件.ppt VIP
- 人教版2025-2026学年三年级下册道德与法治教学工作计划(及进度表).docx
- 2025年宁夏葡萄酒与防沙治沙职业技术学院教师招聘考试笔试备考试题.docx VIP
- DG∕TJ 08-87-2016 道路、排水管道成品与半成品施工及验收规程.docx VIP
- 最新人教版初中八年级下册体育教案全套.doc VIP
- 智能一体化污水处理系统.pptx VIP
原创力文档

文档评论(0)