@inproceedings{d1d7d0f11f1d45a9b99e0ecfe8f24590,
title = "Scalable attack path finding for increased security",
abstract = "Software vulnerabilities can be leveraged by attackers to gain control of a host. Attackers can then use the controlled hosts as stepping stones for compromising other hosts until they create a path to the critical assets. Consequently, network administrators must examine the protected network as a whole rather than each vulnerable host independently. To this end, various methods were suggested in order to analyze the multitude of attack paths in a given organizational network, for example, to identify the optimal attack paths. The down side of many of those methods is that they do not scale well to medium-large networks with hundreds or thousands of hosts. We suggest using graph reduction techniques in order to simplify the task of searching and eliminating optimal attacker paths. Results on an attack graph extracted from a network of a real organization with more than 300 hosts and 2400 vulnerabilities show that using the proposed graph reductions can improve the search time by a factor of 4 while maintaining the quality of the results.",
keywords = "Attack graphs, Attack models, Graph reduction, Network security, Planning",
author = "Tom Gonda and Rami Puzis and Bracha Shapira",
note = "Publisher Copyright: {\textcopyright} Springer International Publishing AG 2017.; 1st International Conference on Cyber Security Cryptography and Machine Learning, CSCML 2017 ; Conference date: 29-06-2017 Through 30-06-2017",
year = "2017",
month = jun,
day = "2",
doi = "10.1007/978-3-319-60080-2_18",
language = "English",
isbn = "9783319600796",
series = "Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)",
publisher = "Springer Verlag",
pages = "234--249",
editor = "Shlomi Dolev and Sachin Lodha",
booktitle = "Cyber Security Cryptography and Machine Learning - 1st International Conference, CSCML 2017, Proceedings",
address = "Germany",
}