Many sophisticated cyber attack campaigns rely on penetrating multiple layers of the system architecture to achieve their goal. Thus, we need to build in security by evaluating the potential threats to the system at the design stage. Existing state-of-the-practice threat modeling tools are only able to identify isolated threats while state-of-the-art solutions require significant manual effort and expertise to encode the knowledge of the system and the attack steps. In this paper, we propose an automated framework that deals with those challenges by (1) taking in system architecture and data path diagrams as input, (2) modeling those diagrams as an expressive system multigraph, (3) encoding the knowledge of attack flows into a common language that is human-readable and machine-actionable, and (4) automatically generating attack paths using the encoded knowledge. We evaluate our framework on different system architectures of varying complexity and functionality and compare our generated attack paths with those constructed manually by security domain experts. Our results show that while we are limited by the attack flows encoded in our knowledge base, our framework allows more comprehensive attack paths to be found and enumerated. Furthermore, we expect that more security domain experts can contribute to our knowledge base, thus expanding the set of attack paths that can be found.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Lowering the Barrier: An Automatic Attack Flow Generation Framework for Non-Security Experts

  • Carmen Cheh,
  • Nan Shing Kham Shing,
  • Edwin Ching Jitt Ang,
  • Binbin Chen,
  • Desmond Cher,
  • Frank Liauw,
  • Reuben Liang Yi Lim

摘要

Many sophisticated cyber attack campaigns rely on penetrating multiple layers of the system architecture to achieve their goal. Thus, we need to build in security by evaluating the potential threats to the system at the design stage. Existing state-of-the-practice threat modeling tools are only able to identify isolated threats while state-of-the-art solutions require significant manual effort and expertise to encode the knowledge of the system and the attack steps. In this paper, we propose an automated framework that deals with those challenges by (1) taking in system architecture and data path diagrams as input, (2) modeling those diagrams as an expressive system multigraph, (3) encoding the knowledge of attack flows into a common language that is human-readable and machine-actionable, and (4) automatically generating attack paths using the encoded knowledge. We evaluate our framework on different system architectures of varying complexity and functionality and compare our generated attack paths with those constructed manually by security domain experts. Our results show that while we are limited by the attack flows encoded in our knowledge base, our framework allows more comprehensive attack paths to be found and enumerated. Furthermore, we expect that more security domain experts can contribute to our knowledge base, thus expanding the set of attack paths that can be found.