Graphene: Infrastructure Security Posture Analysis with AI-generated Attack Graphs

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Jin, Xin, Katsis, Charalampos, Sang, Fan, Sun, Jiahao, Bertino, Elisa, Kompella, Ramana Rao, Kundu, Ashish
Formato: Preprint
Publicado: 2023
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866909186171863040
author Jin, Xin
Katsis, Charalampos
Sang, Fan
Sun, Jiahao
Bertino, Elisa
Kompella, Ramana Rao
Kundu, Ashish
author_facet Jin, Xin
Katsis, Charalampos
Sang, Fan
Sun, Jiahao
Bertino, Elisa
Kompella, Ramana Rao
Kundu, Ashish
contents The rampant occurrence of cybersecurity breaches imposes substantial limitations on the progress of network infrastructures, leading to compromised data, financial losses, potential harm to individuals, and disruptions in essential services. The current security landscape demands the urgent development of a holistic security assessment solution that encompasses vulnerability analysis and investigates the potential exploitation of these vulnerabilities as attack paths. In this paper, we propose Graphene, an advanced system designed to provide a detailed analysis of the security posture of computing infrastructures. Using user-provided information, such as device details and software versions, Graphene performs a comprehensive security assessment. This assessment includes identifying associated vulnerabilities and constructing potential attack graphs that adversaries can exploit. Furthermore, Graphene evaluates the exploitability of these attack paths and quantifies the overall security posture through a scoring mechanism. The system takes a holistic approach by analyzing security layers encompassing hardware, system, network, and cryptography. Furthermore, Graphene delves into the interconnections between these layers, exploring how vulnerabilities in one layer can be leveraged to exploit vulnerabilities in others. In this paper, we present the end-to-end pipeline implemented in Graphene, showcasing the systematic approach adopted for conducting this thorough security analysis.
format Preprint
id arxiv_https___arxiv_org_abs_2312_13119
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Graphene: Infrastructure Security Posture Analysis with AI-generated Attack Graphs
Jin, Xin
Katsis, Charalampos
Sang, Fan
Sun, Jiahao
Bertino, Elisa
Kompella, Ramana Rao
Kundu, Ashish
Cryptography and Security
Computation and Language
Machine Learning
The rampant occurrence of cybersecurity breaches imposes substantial limitations on the progress of network infrastructures, leading to compromised data, financial losses, potential harm to individuals, and disruptions in essential services. The current security landscape demands the urgent development of a holistic security assessment solution that encompasses vulnerability analysis and investigates the potential exploitation of these vulnerabilities as attack paths. In this paper, we propose Graphene, an advanced system designed to provide a detailed analysis of the security posture of computing infrastructures. Using user-provided information, such as device details and software versions, Graphene performs a comprehensive security assessment. This assessment includes identifying associated vulnerabilities and constructing potential attack graphs that adversaries can exploit. Furthermore, Graphene evaluates the exploitability of these attack paths and quantifies the overall security posture through a scoring mechanism. The system takes a holistic approach by analyzing security layers encompassing hardware, system, network, and cryptography. Furthermore, Graphene delves into the interconnections between these layers, exploring how vulnerabilities in one layer can be leveraged to exploit vulnerabilities in others. In this paper, we present the end-to-end pipeline implemented in Graphene, showcasing the systematic approach adopted for conducting this thorough security analysis.
title Graphene: Infrastructure Security Posture Analysis with AI-generated Attack Graphs
topic Cryptography and Security
Computation and Language
Machine Learning
url https://arxiv.org/abs/2312.13119