Modeling a Fuzzy Transportation Problem for Securing Mission Critical Servers Using Attack Graph
摘要
The fuzzy transportation problem has been researched extensively in many fields but till now no one has applied it in the field of cybersecurity. In this work, we have modeled a novel security metric system, to calculate the overall security risk of a given network by mapping it to a fuzzy transportation problem. Further, we are quantifying the overall security risk factor of a given network. As an initial step, we are identifying the mission-critical resources like Servers hosted in that network. Then we are using various vulnerability scanners like Nessus to scan the network and to identify the vulnerabilities and their risk factor in all the connected machines in the given network. The attacker’s path from each source extracted out of the attack graph would be mapped to a fuzzy transportation problem and would be used for quantifying the overall vulnerability of a given network. We are trying to minimize the security risk of a given network.