Most Vulnerable Attack Trace in a Probabilistic Attack Graph

Oct 28, 2024· Xuanli Lin , Zhaofeng Zhang , Yinxin Wan , Ethan Teo , Guoliang Xue , Yanchao Zhang · 1 min read
Summary
This paper identifies attack traces with the highest cumulative success probability in probabilistic attack graphs, including graphs with cycles. It develops an exact search algorithm and a polynomial-time heuristic, then evaluates both on an extensive dataset to support analysis of exploitable network vulnerabilities.
Type
Publication
MILCOM 2024 - 2024 IEEE Military Communications Conference (MILCOM), 1070-1075. IEEE
publication

Abstract

In this paper, we investigate the properties and computation of attack traces on probabilistic attack graphs, a model that integrates probability into traditional attack graphs to reflect the varying exploitability of network vulnerabilities. We introduce the Most Vulnerable Attack Trace (MVAT) problem, which aims to identify the attack trace with the highest cumulative success probability for an attacker. To address this problem, we propose both an exact algorithm and a heuristic algorithm, each designed to navigate the complexities introduced by cycles in the attack graph. Our exact algorithm explores all possible sequences of node selections to ensure the optimal attack trace, while our heuristic algorithm efficiently approximates the MVAT in polynomial time. We evaluate the performance of our algorithms using an extensive dataset, demonstrating the usefulness of the proposed algorithms.

Xuanli Lin
Authors
PhD Student in Computer Science

Xuanli Lin is a fifth-year PhD student in the Computer Science department at Arizona State University, supervised by Dr. Guoliang Xue.

His research interests include network optimization, network security, artificial intelligence, and the Internet of Things.

Yinxin Wan
Authors
Assistant Professor of Computer Science
Yinxin Wan is an assistant professor in the Department of Computer Science at the University of Massachusetts Boston. His research focuses on cybersecurity, secure and trustworthy artificial intelligence, network measurement, the Internet of Things, and quantum networking. He received his PhD in Computer Science from Arizona State University in 2023, advised by Guoliang Xue and Kuai Xu, and his bachelor’s degree in Information Security from the University of Science and Technology of China.
Guoliang Xue
Authors
Professor of Computer Science and Engineering
Guoliang Xue is a professor in Arizona State University’s School of Computing and Augmented Intelligence and an IEEE Fellow. He investigates wireless and quantum networks, network security and privacy, and optimization. He earned his PhD in computer science from the University of Minnesota in 1991. His honors include the IEEE Communications Society’s 2019 William R. Bennett Prize, and he chaired the IEEE INFOCOM Steering Committee from 2020 through 2025.
Yanchao Zhang
Authors
Professor
Yanchao Zhang is a professor in the School of Electrical, Computer and Energy Engineering at Arizona State University. He directs the Cyber and Network Security Group and the DoD Center of Excellence in Future Generation Wireless Technology. His research addresses security and privacy in networked systems, including wireless and mobile networks, the Internet of Things, and cloud and edge computing. He earned his PhD from the University of Florida in 2006 and is an IEEE Fellow.