A New Approach for Network Vulnerability Analysis

H. L. Vu, K. K. Khaw, T. Y. Chen
2014 Computer journal  
We propose in this paper a novel approach to analyze network vulnerability and to obtain a quantitative value representing the level of security achieved in an arbitrary network. Unlike previous graph-based algorithms that generate attack trees (or graphs) to cover all possible sequences of vulnerabilities and therefore are not scalable, our method utilizes the attack graph's principles, but directly analyzes and produces the desired security measure for a network without building the actual
more » ... ack graph. The proposed approach relies on a unique evaluation of vulnerability metric defined in this paper and is demonstrated through an example of a network that provides voice over IP services. 200 978-1-4244-2413-9/08/$25.00
doi:10.1093/comjnl/bxt149 fatcat:k3y4cpkbnvcjxnyxfa2voldegi