Representing Tcp/Ip Connectivity For Topological Analysis Of Network Security

R Ritchey,B O'Berry,S Noel

ACSAC '02 Proceedings of the 18th Annual Computer Security Applications Conference(2002)

引用 75|浏览1
暂无评分
摘要
The individual vulnerabilities of hosts on a network can be combined by an attacker to gain access that would not be possible if the hosts were not interconnected. Currently available tools report vulnerabilities in isolation and in the context of individual hosts in a network. Topological vulnerability analysis (TVA) extends this by searching for sequences of interdependent vulnerabilities, distributed among the various network hosts. Model checking has been applied to the analysis of this problem with some interesting initial result. However previous efforts did not take into account a realistic representation of network connectivity. These models were enough to demonstrate the usefulness of the model checking approach but would not be sufficient to analyze real-world network security problems. This paper presents a modem of network connectivity at multiple levels of the TCP/IP stack appropriate for use in a model checker. With this enhancement, it is possible to represent realistic networks including common network security devices such as firewalls, filtering routers, and switches.
更多
查看译文
关键词
network canbe,network connectivityat multiple level,real-world network securityproblems,realistic network,various network host,model checker,model checking approach,model checking hasbeen,Topologicalvulnerability analysis,individual host,IP Connectivity,Network Security,Representing TCP,Topological Analysis
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要