论文标题

对概率攻击图的最佳安全性硬化:使用Cysectool工具对工业控制系统的案例研究

Optimal security hardening over a probabilistic attack graph: a case study of an industrial control system using the CySecTool tool

论文作者

Buczkowski, Przemysław, Malacaria, Pasquale, Hankin, Chris, Fielder, Andrew

论文摘要

Cysectool是一种工具,可以在给定预算中找到概率攻击图中的成本优势安全控制组合。投资组合是针对计算机系统采用的漏洞的一组反测量或控件,而攻击图是威胁场景模型的一种类型。在攻击图中,节点是攻击者的特权状态,边缘是脆弱性升级特权,并且控件减少了某些漏洞的概率。该工具基于Khouzani等人发表的优化算法。 (2019年),使用户能够快速创建,编辑和逐步改进模型,分析给定投资组合的结果,并以帕累托边境的形式显示所有可能的预算的最佳解决方案。使用系统图和工业安全工程师根据其工作的工业来源编制的可疑攻击路径进行了案例研究。案例研究的目的是对监督控制和数据获取(SCADA)工业系统进行建模,该系统由于有可能损害人们的潜力,因此需要强大的保护,同时不允许使用诸如脆弱性扫描仪的典型渗透工具。分析结果以显示网络安全分析师如何使用Cysectool来存储网络安全智能并得出进一步的结论。

CySecTool is a tool that finds a cost-optimal security controls portfolio in a given budget for a probabilistic attack graph. A portfolio is a set of counter-measures, or controls, against vulnerabilities adopted for a computer system, while an attack graph is a type of a threat scenario model. In an attack graph, nodes are privilege states of the attacker, edges are vulnerabilities escalating privileges, and controls reduce the probabilities of some vulnerabilities being exploited. The tool builds on an optimisation algorithm published by Khouzani et al. (2019), enabling a user to quickly create, edit, and incrementally improve models, analyse results for given portfolios and display the best solutions for all possible budgets in the form of a Pareto frontier. A case study was performed utilising a system graph and suspected attack paths prepared by industrial security engineers based on an industrial source with which they work. The goal of the case study is to model a supervisory control and data acquisition (SCADA) industrial system which, due to having the potential to harm people, necessitates strong protection while not allowing the use of typical penetration tools like vulnerability scanners. Results are analysed to show how a cyber-security analyst would use CySecTool to store cyber-security intelligence and draw further conclusions.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源