The fuzzy transportation problem has been researched extensively in many fields but till now no one has applied it in the field of cybersecurity. In this work, we have modeled a novel security metric system, to calculate the overall security risk of a given network by mapping it to a fuzzy transportation problem. Further, we are quantifying the overall security risk factor of a given network. As an initial step, we are identifying the mission-critical resources like Servers hosted in that network. Then we are using various vulnerability scanners like Nessus to scan the network and to identify the vulnerabilities and their risk factor in all the connected machines in the given network. The attacker’s path from each source extracted out of the attack graph would be mapped to a fuzzy transportation problem and would be used for quantifying the overall vulnerability of a given network. We are trying to minimize the security risk of a given network.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Modeling a Fuzzy Transportation Problem for Securing Mission Critical Servers Using Attack Graph

  • Edithstine Rani Mathew,
  • Lovelymol Sebastian

摘要

The fuzzy transportation problem has been researched extensively in many fields but till now no one has applied it in the field of cybersecurity. In this work, we have modeled a novel security metric system, to calculate the overall security risk of a given network by mapping it to a fuzzy transportation problem. Further, we are quantifying the overall security risk factor of a given network. As an initial step, we are identifying the mission-critical resources like Servers hosted in that network. Then we are using various vulnerability scanners like Nessus to scan the network and to identify the vulnerabilities and their risk factor in all the connected machines in the given network. The attacker’s path from each source extracted out of the attack graph would be mapped to a fuzzy transportation problem and would be used for quantifying the overall vulnerability of a given network. We are trying to minimize the security risk of a given network.