Identifying Insecure Network Configurations Through Attack Modeling and Explainable AI
摘要
Every day, a multitude of IoT devices connect to the internet, enhancing functionality and user experience. However, this increased connectivity exposes these devices to external threats. Securing the network requires effective modeling of potential attack scenarios. The dynamic nature of IoT networks often alters these scenarios, making attack modeling challenging. In this context, identifying inappropriate network configurations that lead to insecure conditions becomes a practical alternative. Avoiding such configurations helps protect the infrastructure from threat actors. In this paper, an Explainable AI (XAI) approach using the Local Interpretable Model-Agnostic Explanations (LIME) algorithm is employed to assess the impact of various network configurations on security. The framework’s effectiveness is demonstrated through a realistic IoT network example. The experiment explains how network characteristics influence insecurity, offering valuable insights into potential vulnerabilities.