GARNET: A Graphical Attack Graph and Reachability Network Evaluation Tool

VISUALIZATION FOR COMPUTER SECURITY, PROCEEDINGS(2008)

引用 74|浏览1
暂无评分
摘要
Attack graphs enable computation of important network security metrics by revealing potential attack paths an adversary could use to gain control of network assets. This paper presents GARNET (Graphical Attack graph and Reachability Network Evaluation Tool), an interactive visualization tool that facilitates attack graph analysis. It provides a simplified view of critical steps that can be taken by an attacker and of host-to-host network reachability that enables these exploits. It allows users to perform "what-if" experiments including adding new zero-day attacks, following recommendations to patch software vulnerabilities, and changing the attacker starting location to analyze external and internal attackers. Users can also compute and view metrics of assets captured versus attacker effort to compare the security of complex networks. For adversaries with three skill levels, it is possible to create graphs of assets captured versus attacker steps and the number of unique exploits required. GARNET is implemented as a Java application and is built on top of an existing C++ engine that performs reachability and attack graph computations. An initial round of user evaluations described in this paper led to many changes that significantly enhance usability.
更多
查看译文
关键词
graphical attack graph,potential attack path,facilitates attack graph analysis,new zero-day attack,attack graph,internal attacker,attacker effort,attack graph computation,reachability network evaluation tool,attacker step,complex network,visualization,adversary model,gain control,network security,exploit,interactive visualization,treemap,network,vulnerability
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要