Towards the Automation of Attack Graph-Based Risk Assessment with OSCAL
摘要
In increasingly dynamic threat landscapes, automated Risk Assessment emerges as an essential approach, highlighting the benefits of enhanced accuracy and operational efficiency in addressing threats. This work combines Attack Graphs with the Open Security Controls Assessment Language (OSCAL), employing compliance-as-code for enforceable, machine-readable security modeling. Utilizing Domain-Specific Languages (DSLs), we aim to simplify the creation and enforcement of security measures, establish connections between components and controls, and uses graph-based algorithms for risk assessment, risk mitigation, and asset management in line with OSCAL standards and requirements. Such approaches aim to streamline RA process, providing real-time insights and allowing for quicker, more efficient decision-making regarding threat mitigation and security measures, without the need for extensive manual intervention.