|
|
A Network Attack Decision-making Algorithm Based on the Extended Attack Graph |
Wang Hui-mei Xian Ming Wang Guo-yu |
College of Electronic Science and Engineering, National University of Defense Technology, Changsha 410073, China |
|
|
Abstract Considering the characteristics of attack decision-making issue in the domain of network attack and defense, the network attack graph model is extended from the view of attacker. Atomic attack is built by instantiating the attack pattern according the vulnerability. Maintaining the causality of precondition and effect condition of the atomic attack, therefore, the Extended Attack Graph (EAG) model is proposed. Furthermore, a network attack decision-making algorithm based on the extended attack graph is put forward; which can forecast attack effect dynamically and build the valid attack path and its occurrence probability through the in-depth analysis of the models’ features. Through the network attack and defense experiments, the results show the completeness and soundness of the algorithm.
|
Received: 02 May 2010
|
|
Corresponding Authors:
Wang Hui-mei
E-mail: freshcdwhm@163.com
|
|
|
|
|
|
|