中文

迈向自动化的网络缓解分析(扩展版)

密码学与安全 2019-01-07 v2 人工智能

摘要

渗透测试是识别潜在可利用安全弱点的成熟实践概念,也是安全审计的重要组成部分。然而,对于由数百台主机组成的网络提供整体安全评估,若无某种机械化手段则几乎不可行。缓解(在给定预算下对对策进行优先级排序)目前缺乏坚实的理论理解,因此更多是艺术而非科学。在这项工作中,我们提出第一种方法进行全面的假设分析(what-if analyses),以便以概念上合理的方式推理缓解措施。为评估和比较缓解策略,我们使用模拟渗透测试(即自动化攻击发现),基于网络模型,对该模型应用给定缓解动作集合的子集(例如网络拓扑更改、系统更新、配置更改等)。利用Stackelberg规划,我们确定最小化最大攻击者成功概率的最优组合(类似于Stackelberg博弈),从而为一整体缓解策略提供合理基础。我们展示这些Stackelberg规划模型可大量从网络扫描、公共漏洞数据库和人工检查中以不同自动化程度和细节推导出来,并且我们在不同规模和漏洞的网络上模拟了缓解分析。

关键词

引用

@article{arxiv.1705.05088,
  title  = {Towards Automated Network Mitigation Analysis (extended)},
  author = {Patrick Speicher and Marcel Steinmetz and Jörg Hoffmann and Michael Backes and Robert Künnemann},
  journal= {arXiv preprint arXiv:1705.05088},
  year   = {2019}
}

备注

Cleaned up presentation to focus on mitigation analysis in simulated pentesting. Stackelberg planning in a more general scope and the algorithm proposed in v1 are extended and discussed in more detail in Speicher et.al.: Stackelberg Planning: Towards Effective Leader-Follower State Space Search, AAAI'18