Realtime Intrusion Risk Assessment Model based on Attack and Service Dependency Graphs


Shameli-Sendi, Alireza, Dagenais, Michel and Wang, Lingyu (2017) Realtime Intrusion Risk Assessment Model based on Attack and Service Dependency Graphs. Computer Communications . pp. 1-37. ISSN 01403664 (In Press)

Official URL: http://dx.doi.org/10.1016/j.comcom.2017.12.003


Network services are becoming larger and increasingly complex to manage. It is extremely critical to maintain the users QoS, the response time of applications, and critical services in high demand. On the other hand, we see impressive changes in the ways in which attackers gain access to systems and infect services. When an attack is detected, an Intrusion Response System (IRS) is responsible to accurately assess the value of the loss incurred by a compromised resource and apply the proper responses to mitigate attack. Without having a proper risk assessment, our automated IRS will reduce network performance, wrongly disconnect users from the network, or result in high costs for administrators reestablishing services, and become a DoS attack for our network, which will eventually have to be disabled. In this paper, we address these challenges and we propose a new model to combine the Attack Graph and Service Dependency Graph approaches to calculate the impact of an attack more accurately compared to other existing solutions. To show the effectiveness of our model, a sophisticated multi-step attack was designed to compromise a web server, as well as to acquire root privilege. Our results illustrate the efficiency of the proposed model and confirm the feasibility of the approach in real-time.

Divisions:Concordia University > Gina Cody School of Engineering and Computer Science > Concordia Institute for Information Systems Engineering
Item Type:Article
Authors:Shameli-Sendi, Alireza and Dagenais, Michel and Wang, Lingyu
Journal or Publication:Computer Communications
Date:10 December 2017
Digital Object Identifier (DOI):10.1016/j.comcom.2017.12.003
Keywords:Network attack graph; Network service dependency graph; Attack impact; Forward impact propagation; Backward impact propagation; Response cost computation; Response system; Trace; Kernel event
ID Code:983308
Deposited On:14 Dec 2017 01:41
Last Modified:08 Dec 2018 01:00


