Attack graph optimization method based on key vulnerability and attack feasibility

Through an attack map optimization method based on key vulnerabilities and attack feasibility, the redundant paths in the attack map in the Internet of Vehicles are optimized, complex attack map analysis problems are solved, system-level security is maintained, and attack analysis process is simplified.

CN119995957AInactive Publication Date: 2025-05-13CHONGQING UNIV OF POSTS & TELECOMM
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510081760.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

As the scale and number of vulnerabilities increase, the scale and time required for attack maps are significantly increased, making it difficult for managers to analyze complex cyber attack maps. Existing path optimization methods may delete critical information and undermine system-level security risk assessments.

Method used

An attack map optimization method based on key vulnerabilities and attack feasibility was designed, including four modules: acquisition of attack maps, quantification of attack paths, search for key vulnerabilities and redundant path optimization. Through these modules, the paths with smaller weights in the attack graph are optimized, the critical paths are retained, and the complexity of attack analysis is simplified.

Benefits of technology

It effectively optimizes the redundant path of the attack map, maintains system-level security, simplifies the complexity of attack analysis, and reduces the possibility of attackers choosing long-path attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995957A_ABST
    Figure CN119995957A_ABST
Patent Text Reader

Abstract

The invention discloses an attack graph optimization method based on key vulnerabilities and attack feasibility. The method comprises the following steps: generating a vulnerability attack graph; performing feasibility quantification on each vulnerability attack behavior in the attack graph in combination with a general vulnerability scoring system; searching a key vulnerability set in the attack graph based on Edmonds-Karp maximum flow-minimum cut; on the basis of the key vulnerability set, attack graph path optimization is carried out by using a breadth-first algorithm and introducing a difficulty factor. An attack graph optimization system based on key vulnerabilities and attack feasibility is provided by means of a maximum flow minimum cut algorithm, the attack graph generated by a large-scale complex system is optimized, the number of nodes and the number of edges of the attack graph are effectively reduced, the attack feasibility is dynamically adjusted by introducing difficult factors, and the attack efficiency is improved. And the optimization accuracy of the attack graph is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to an attack graph optimization method based on key vulnerabilities and attack feasibility. Background Art

[0002] Cyber ​​attacks can steal vehicle data, control vehicle driving, and even affect vehicle driving safety by attacking the communication between the vehicle and the server. Data leakage can lead to privacy leakage of drivers, passengers, and other relevant parties, and may also pose a threat to vehicle driving safety. Malicious tampering of the vehicle control system may cause the vehicle control system to lose control, posing a great risk to driving safety. Under the "cloud-edge-end" architecture of the Internet of Vehicles, it is necessary not only to understand the information of isolated vulnerabilities, but also to understand the mutual influence between vulnerabilities, and comprehensively consider and analyze various attack surfaces to discover potential attack paths against the target. The attack graph can not only describe the attacker's attack scenario, display all possible vulnerability sequences and their relationships, but also show the dependencies between vulnerabilities, describe the entire path of the attack, and provide key information to prevent multi-step attacks. Network attack analysis based on attack graphs no longer simply considers a certain isolated vulnerability, but links the vulnerabilities of the network system for comprehensive analysis and evaluation, considers the vulnerabilities and their dependencies, can affect the network, and displays the attacker's possible attack path in the form of a graph, which is convenient for network administrators to carry out targeted security reinforcement and improve network security.

[0003] In practical applications, with the increase in the scale of the Internet of Vehicles and the number of vulnerabilities, the scale of the attack graph and the time required to generate it have increased significantly, and the complexity of the generated attack path graph has increased significantly, making it difficult for managers to analyze complex network attack graphs. Although there have been related studies in recent years, using graph search algorithms to retrieve attack paths, and using the shortest path algorithm to calculate the risk level and determine the minimum weighted path, thereby filtering out paths with less threat and reducing the number of attack graph nodes and paths, there are still some problems to be solved. The attack graph represents all attack scenarios in the form of an attack sequence, which means that attackers can use these attacks to destroy the system. The attack graph is generated to derive a complex system-level vulnerability sequence from the atomic component-level vulnerabilities, thereby performing a system-level security risk assessment. The path optimization method directly eliminates paths with a path length greater than a certain threshold or paths with a path cumulative threat lower than a certain threshold, which may delete some key information in the attack graph, thereby destroying the system-level security risk reflected in the attack graph.

[0004] In view of the above problems, the purpose of this paper is to optimize the redundant paths of the network attack graph without affecting the system-level security reflected by the network attack graph. To this end, this paper designs an attack graph optimization method based on key vulnerabilities and attack feasibility. Summary of the invention

[0005] In order to overcome the shortcomings of the prior art, an attack graph optimization method based on key vulnerabilities and attack feasibility is proposed. The content of the invention is as follows:

[0006] An attack graph optimization method based on key vulnerabilities and attack feasibility, characterized by comprising four modules: acquiring attack graphs, quantifying attack graph paths, finding key vulnerabilities, and optimizing redundant paths;

[0007] Wherein, the attack graph acquisition module is used to convert the original data into a vulnerability attack graph;

[0008] The attack path quantification module is used to weight vulnerability attack behaviors;

[0009] The key vulnerability search module is used to find the minimum key vulnerability set in the attack graph;

[0010] The redundant path optimization module is used to eliminate paths with smaller weights in the attack graph.

[0011] Furthermore, the attack graph acquisition module is used to obtain the initial vulnerability attack graph, specifically including:

[0012] Before traversing the vulnerability nodes, it is necessary to input the network connectivity L and vulnerability information V to instantiate the attack behavior. The instantiation is represented by EP, including the preconditions and consequences of the attack. EP = L P ∪L N , L P is the attack premise set, L N is the set of attack consequences. Then the vulnerability nodes are matched to generate vulnerability nodes and obtain the vulnerability attack graph, which is expressed as:

[0013] The attack graph is represented as in

[0014] N is the set of nodes in the network, including the starting node N s , attack target node N t , and attack path nodes N other than the above nodes p Satisfy N=N s ∪N t ∪N p ;

[0015] E is the edge set of all nodes, Each edge e(u,v) represents an attack;

[0016] V is a set of vulnerability labels, each element represents a vulnerability;

[0017] E→V is the mapping from edge set to vulnerability set. Each edge (e∈E) corresponds to a vulnerability attack behavior V(e);

[0018] w is the vulnerability label weight information, according to the mapping relationship Assign corresponding weights to the corresponding edge e Assign corresponding weights Assign corresponding weights w(l)

[0019] Furthermore, the attack path quantification module is used to obtain the feasibility of vulnerability attacks, including:

[0020] CVSS vulnerability measurement: The vulnerability value of a node is related to the ease with which its vulnerability is exploited by attackers and the impact of the vulnerability on the node itself. The Common Vulnerability Scoring System (CVSS) is usually used to quantify the vulnerability. CVSS is currently the most widely used vulnerability scoring system. It is part of the Security Content Automation Protocol (SCAP) and is supported by the National Vulnerability Database (NVD) of the United States. The CVSS quantification table consists of a basic measurement group, a time measurement group, and an environmental measurement group. The main function of the time measurement group and the environmental measurement group is to modify the basic measurement group. In order to simplify the problem, we did not consider the impact of the time measurement group and the environmental measurement group on quantification. This paper uses CVSS to measure the attack vector (Access Vector, AV), attack complexity (Access Complexity, AC), authentication (Authentication, AU), confidentiality (Confidentiality, C), integrity (Integrity, I) and availability (Availability, A), and consider the executable exp of each vulnerability, that is:

[0021] exp=8.22*AV*AC*AU

[0022] w=MAX_EXP-exp

[0023] Attackers tend to choose vulnerabilities with higher executable exp to attack. When the vulnerability exp is higher, the corresponding edge weight w is lower. Therefore, our search for the minimum critical attack set in the attack graph can be converted into the problem of finding the minimum cut set in a weighted directed graph.

[0024] Furthermore, the key vulnerability search module is used to find the key vulnerability set in the attack graph, specifically including:

[0025] Given an attack graph A subset of vulnerabilities V′ satisfies w(V′)=min{w(V i ):V i ∈2 V}, and after removing the edge E(V′) corresponding to V′ in VAG, N s and N t No longer connected, V' is called the minimum critical attack set.

[0026] Initialization: The residual capacity c′(u,v) is initially set to the weight of the edge, that is, the corresponding vulnerability weight

[0027] Find the augmenting path: Use breadth-first search (BFS) to find the path from the starting node N in the residual graph. s To the target node N t The augmenting path.

[0028] Update residual capacity: For each augmenting path, find the minimum residual capacity on the path and update the residual capacity of each edge on the path.

[0029] Minimum cut: After the algorithm is completed, the vulnerability label corresponding to each edge in the minimum cut will be added to the critical vulnerability set, and the final returned set C is the minimum critical vulnerability set.

[0030] Furthermore, the redundant path optimization module is used to optimize the number of attack graph nodes and paths, specifically including:

[0031] After obtaining the minimum cut set C, we calculate s To each cut edge starting point, and from each cut edge end point to the target node N t The attack graph is optimized by using the shortest paths. These shortest paths take into account the impact of the number of path hops on the attack difficulty and adjust the path weights, thereby effectively reducing the possibility of attackers choosing long paths to attack.

[0032] Process each edge in the minimum cut set: For each edge e(u,v) belonging to the minimum cut set C, first check whether u is the source node N s If yes, then add the edge e(u,v) directly to the optimized attack graph. If u is not the source node, then call the shortest path algorithm to calculate the path from the source node N s The shortest path to u is found and the path is added to OAG.

[0033] Processing the end point of the cut edge: Similarly, first check whether v is the target node N t If yes, then add the edge e(u,v) directly to OAG. If v is not the target node, then call the shortest path algorithm to calculate the path from v to the target node N. t The shortest path is found and added to OAG.

[0034] Path weight adjustment: When calculating the shortest path, the algorithm takes into account the number of hops in the attack path. As the number of hops in the path increases, the algorithm adjusts the path weight by the difficulty factor α. For the weight of each edge e, the calculation formula is: w′(e)=α k-1 *w(e), where k is the number of hops in the current path, w(e) is the original edge weight, and w′(e) is the adjusted weight. In this way, the algorithm can reflect the reality that the longer the path, the greater the difficulty of attack, thereby optimizing the attack graph more accurately.

[0035] After processing all the edges in the minimum cut set, the algorithm outputs the optimized attack graph OAG, which only retains the critical path and removes unnecessary redundant paths, thus effectively simplifying the complexity of attack analysis.

[0036] An attack graph optimization method based on key vulnerabilities and attack feasibility, characterized by comprising four parts: acquiring attack graphs, quantifying attack graph paths, finding key vulnerabilities, and optimizing redundant paths; wherein,

[0037] The attack graph acquisition module is used to convert the original data into a vulnerability attack graph;

[0038] The attack path quantification module is used to weight vulnerability attack behaviors;

[0039] The key vulnerability search module is used to find the minimum key vulnerability set in the attack graph;

[0040] The redundant path optimization module is used to eliminate paths with smaller weights in the attack graph. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1 This is the applicable scenario of the attack graph of the present invention;

[0042] Figure 2 It is a flow chart of the attack graph optimization framework of the present invention;

[0043] Figure 3 It is the overall idea diagram of the present invention. DETAILED DESCRIPTION

[0044] An attack graph optimization method based on key vulnerabilities and attack feasibility, referring to Figure 2 ,The specific implementation methods include four modules: acquiring attack graph, quantifying attack graph paths, finding key vulnerabilities and optimizing redundant paths;

[0045] Wherein, the attack graph acquisition module is used to convert the original data into a vulnerability attack graph;

[0046] The attack path quantification module is used to weight vulnerability attack behaviors;

[0047] The key vulnerability search module is used to find the minimum key vulnerability set in the attack graph;

[0048] The redundant path optimization module is used to eliminate paths with smaller weights in the attack graph.

[0049] Furthermore, the attack graph acquisition module is used to obtain the initial vulnerability attack graph, specifically including:

[0050] Based on information such as network configuration, the initial attack graph is generated through MulVAL. MulVAL converts the network information provided by tools such as Nessus / OVAL and the configuration information set by the administrator into facts described in the Datalog language as input. The internal XBS logical reasoning engine performs attack process reasoning and finally generates the initial attack graph.

[0051] After obtaining the initial attack graph, the vulnerability nodes are traversed to generate attack subgraphs, and the subgraphs generate global attack graphs, which are converted into vulnerability attack graphs.

[0052] Before traversing the vulnerability nodes, it is necessary to input the network connectivity L and vulnerability information V to instantiate the attack behavior. The instantiation is represented by EP, including the preconditions and consequences of the attack. EP = L P ∪L N , L P is the attack premise set, L N It is the attack consequence set. Then the vulnerability nodes are matched to generate vulnerability nodes.

[0053] The generation of vulnerability attack graph is based on traversing the last segment of vulnerability node, generating attack subtree, and performing merge elimination cycle. The generation process of vulnerability attack graph includes attack subtree (vulnerability node) and attack graph elimination cycle process.

[0054] In the process of merging vulnerable nodes, we first traverse the vulnerable node set Prenodes, then search for the edge starting with the current node, get the node ending with the edge, and use the node as the root node to generate the global attack graph AG. After the attack target is determined, the target node is used as the starting point of the reverse depth search to search the entire attack graph. The loop elimination algorithm is a recursive algorithm, which includes four parameters N s , N t , AG and the output result VAG. AG is the global attack graph, N s is the source node, N t is the target node, and VAG is the generated directed acyclic graph.

[0055] From the target node N s First, search for vulnerable nodes Vnodes outside the ring from the global attack graph AG and the node side, and put the edges and nodes into VAG. Then, N sSet as the parent node of the current node, and set the child node N t Set as the target node. Recursively call the generation algorithm to traverse all nodes.

[0056] When the algorithm searches for a path, if the node is already in the VAG, it means that the node has been found and the node N is t The edge is added to the VAG. The algorithm uses TP to record the traversal of the previous node on a path. If the cycle appears in the path, the search continues along another path.

[0057] The attack graph is represented as in

[0058] N is the set of nodes in the network, including the starting node N s , attack target node N t , and attack path nodes N other than the above nodes p Satisfy N=N s ∪N t ∪N p ;

[0059] E is the edge set of all nodes, Each edge e(u,v) represents an attack;

[0060] V is a set of vulnerability labels, each element represents a vulnerability;

[0061] E→V is the mapping from edge set to vulnerability set. Each edge (e∈E) corresponds to a vulnerability attack behavior V(e);

[0062] w is the vulnerability label weight information, according to the mapping relationship Assign corresponding weights to the corresponding edge e Assign corresponding weights Assign corresponding weights w(l)

[0063] Furthermore, the attack path quantification module is used to obtain the feasibility of vulnerability attacks, including:

[0064] CVSS vulnerability measurement: The vulnerability value of a node is related to the ease with which its vulnerability is exploited by attackers and the impact of this vulnerability on the node itself. The Common Vulnerability Scoring System (CVSS) is usually used to quantify the vulnerability. CVSS is currently the most widely used vulnerability scoring system. It is part of the Security Content Automation Protocol (SCAP) and is supported by the National Vulnerability Database (NVD) of the United States. The CVSS quantification table consists of a basic measurement group, a time measurement group, and an environmental measurement group. The main function of the time measurement group and the environmental measurement group is to modify the basic measurement group. In order to simplify the problem, we did not consider the impact of the time measurement group and the environmental measurement group on quantification. This article uses CVSS to evaluate the attack vector (Access Vector, AV), attack complexity (Access Complexity, AC), authentication (Authentication, AU), confidentiality (Confidentiality, C), integrity (Integrity, I) and availability (Availability, A). The corresponding specific scoring criteria are shown in the table:

[0065] Table 1

[0066]

[0067]

[0068] Consider the executable exp of each vulnerability, namely:

[0069] exp=8.22*AV*AC*AU

[0070] w=MAX_EXP-exp

[0071] Attackers tend to choose vulnerabilities with higher executable exp to attack. When the vulnerability exp is higher, the corresponding edge weight w is lower. Therefore, our search for the minimum critical attack set in the attack graph can be converted into the problem of finding the minimum cut set in a weighted directed graph.

[0072] Furthermore, the key vulnerability search module is used to find the key vulnerability set in the attack graph, specifically including:

[0073] Given an attack graph A subset of vulnerabilities V′ satisfies w(V′)=min{w(V i ):V i ∈2 V}, and after removing the edge E(V′) corresponding to V′ in VAG, N s and N tNo longer connected, V' is called the minimum critical attack set.

[0074] Initialization: The residual capacity c′(u,v) is initially set to the weight of the edge, that is, the corresponding vulnerability weight

[0075] Find the augmenting path: Use breadth-first search (BFS) to find the path from the starting node N in the residual graph. s To the target node N t The augmenting path.

[0076] Update residual capacity: For each augmenting path, find the minimum residual capacity on the path and update the residual capacity of each edge on the path.

[0077] Minimum cut: After the algorithm is completed, the vulnerability label corresponding to each edge in the minimum cut will be added to the critical vulnerability set, and the final returned set C is the minimum critical vulnerability set.

[0078] Furthermore, the redundant path optimization module is used to optimize the number of attack graph nodes and paths, specifically including:

[0079] After obtaining the minimum cut set C, we calculate s To each cut edge starting point, and from each cut edge end point to the target node N t The attack graph is optimized by using the shortest paths. These shortest paths take into account the impact of the number of path hops on the attack difficulty and adjust the path weights, thereby effectively reducing the possibility of attackers choosing long paths to attack.

[0080] Process each edge in the minimum cut set: For each edge e(u,v) belonging to the minimum cut set C, first check whether u is the source node N s If yes, then add the edge e(u,v) directly to the optimized attack graph. If u is not the source node, then call the shortest path algorithm to calculate the path from the source node N s The shortest path to u is found and the path is added to OAG.

[0081] Processing the end point of the cut edge: Similarly, first check whether v is the target node N t If yes, then add the edge e(u,v) directly to OAG. If v is not the target node, then call the shortest path algorithm to calculate the path from v to the target node N. t The shortest path is found and added to OAG.

[0082] Path weight adjustment: When calculating the shortest path, the algorithm takes into account the number of hops in the attack path. As the number of hops in the path increases, the algorithm adjusts the path weight by the difficulty factor α. For the weight of each edge e, the calculation formula is: w′(e)=α k-1*w(e), where k is the number of hops in the current path, w(e) is the original edge weight, and w′(e) is the adjusted weight. In this way, the algorithm can reflect the reality that the longer the path, the greater the difficulty of attack, thereby optimizing the attack graph more accurately.

[0083] After processing all the edges in the minimum cut set, the algorithm outputs the optimized attack graph OAG, which only retains the critical path and removes unnecessary redundant paths, thus effectively simplifying the complexity of attack analysis.

Claims

1. An attack graph optimization method based on key vulnerabilities and attack feasibility, characterized in that: include: There are four parts in total: obtaining attack graph, quantifying attack graph paths, finding key vulnerabilities, and optimizing redundant paths; Wherein, the attack graph acquisition module is used to convert the original data into a vulnerability attack graph; The attack path quantification module is used to weight vulnerability attack behaviors; The key vulnerability search module is used to find the minimum key vulnerability set in the attack graph; The redundant path optimization module is used to eliminate paths with smaller weights in the attack graph.

2. The attack graph optimization method based on key vulnerabilities and attack feasibility according to claim 1 is characterized in that: The attack graph acquisition module specifically includes: There are two main parts: vulnerability node matching and attack graph generation. The vulnerability node matching algorithm recursively traverses the attack instance set, dynamically generates vulnerability nodes and edge sets based on the premise and result conditions, and updates the attack instance set and processes the newly added nodes. The attack graph generation algorithm starts from the target node, uses depth-first search to generate the attack subgraph, and constructs the final directed acyclic attack graph through path merging and cycle elimination.

3. The attack graph optimization method based on key vulnerabilities and attack feasibility according to claim 1 is characterized in that: The attack path quantification module uses the vulnerability scoring system (CVSS) to weight vulnerability attack behaviors, specifically including: The basic metric group of the Common Vulnerability Scoring System (CVSS) is used to quantify the attack feasibility (exp) of the vulnerability, and the edge weight (w) of the corresponding path is calculated according to the attack feasibility of the vulnerability; Assign a corresponding weight to each path in the attack graph, and record the weight information for subsequent key vulnerability analysis and redundant path optimization.

4. The attack graph optimization method based on key vulnerabilities and attack feasibility according to claim 1 is characterized in that: The key vulnerability set search module specifically includes: Initialize the residual capacity, take the edge weights in the attack graph as the initial residual capacity, and initialize the critical vulnerability set C to an empty set. Find augmenting paths, use breadth-first search (BFS) to find augmenting paths from the start node to the target node in the residual graph. The residual capacity is updated, and for the augmented path, the minimum residual capacity on the path is calculated. Determine the minimum cut set, after updating the residual capacity, traverse the edges in the attack graph, identify the edges in the minimum cut, and add the vulnerability labels of the edges to the critical vulnerability set C.

5. The attack graph optimization method based on key vulnerabilities and attack feasibility according to claim 1 is characterized in that: The redundant path optimization module specifically includes: Processing the starting point of the minimum cut set edge: Analyze each edge in the minimum cut set to determine whether the starting point node of the edge is the source node; If the starting node is a source node, the edge is added to the optimized attack graph OAG; If the starting node is not the source node, the shortest path from the source node to the node is calculated using the shortest path algorithm, and the path is added to the optimized attack graph OAG. Process the endpoint of the minimum cut set edge to determine whether the endpoint node of the edge is the target node; If the end node is the target node, the edge is added to the optimized attack graph OAG; If the end node is the target node, the shortest path from the node to the target node is calculated using the shortest path algorithm, and the path is added to the optimized attack graph OAG. Path weight adjustment: When executing the shortest path algorithm, the path weight is dynamically adjusted by introducing the difficulty factor α; When the path is extended to the kth step, the weight of edge e in the current path is adjusted. Output optimized attack graph. After the above steps, an optimized attack graph OAG is generated. The optimized attack graph only contains critical paths and eliminates redundant paths, thereby reducing the complexity of attack analysis and improving the pertinence and practicality of the graph.

Citation Information

Patent Citations

  • Intrusion intension recognition system and method based on hidden markov and probability inference

    CN106682502A

  • Global safety detection system for intelligent manufacturing production line and working method thereof

    CN112904817A

  • Permeation test attack path selection method and system based on attack graph

    CN113949570A

  • Node classification defense method and system based on graph purification and decision boundary

    CN114648065A

  • Penetration testing of a networked system

    US10038711B1