A network security analysis method using vulnerability correlation

  • Authors:
  • Zhi-Yong Li;Chao-Hai Xie;Ran Tao;Hao Zhang;Na Shi

  • Affiliations:
  • School of Information Science and Technology, Beijing Institute of Technology, Beijing, China;School of Information Science and Technology, Beijing Institute of Technology, Beijing, China;School of Information Science and Technology, Beijing Institute of Technology, Beijing, China;School of Information Science and Technology, Beijing Institute of Technology, Beijing, China;School of Information Science and Technology, Beijing Institute of Technology, Beijing, China

  • Venue:
  • ICNC'09 Proceedings of the 5th international conference on Natural computation
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Recently in-depth analysis of network security vulnerability must consider attacker exploits not just in isolation, but also in combination. The general approach to this problem is to compute attack graphs using a variety of graph-based algorithms. However, such methods generally suffer the exponential state space problem. Therefore, this paper brings forward two conceptions of vulnerability correlation matrix and vulnerability correlation graph (VCG). An algorithm based on vulnerability correlation matrix was proposed to generate VCGs. An example was given to illustrate the application and effect of the algorithm in network security analysis. Deep analysis proves that VCGs have polynomial complexity of the number of network vulnerabilities and scale well for large networks. Moreover, the example shows that VCGs are a good help to and convenient for network security management.