Network Modelling in Analysing Cyber-related Graphs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Kuikka, Vesa, Pykälä, Lauri, Takko, Tuomas, Kaski, Kimmo
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914014700765184
author Kuikka, Vesa
Pykälä, Lauri
Takko, Tuomas
Kaski, Kimmo
author_facet Kuikka, Vesa
Pykälä, Lauri
Takko, Tuomas
Kaski, Kimmo
contents In order to improve the resilience of computer infrastructure against cyber attacks and finding ways to mitigate their impact we need to understand their structure and dynamics. Here we propose a novel network-based influence spreading model to investigate event trajectories or paths in various types of attack and causal graphs, which can be directed, weighted, and / or cyclic. In case of attack graphs with acyclic paths, only self-avoiding attack chains are allowed. In the framework of our model a detailed probabilistic analysis beyond the traditional visualisation of attack graphs, based on vulnerabilities, services, and exploitabilities, can be performed. In order to demonstrate the capabilities of the model, we present three use cases with cyber-related graphs, namely two attack graphs and a causal graph. The model can be of benefit to cyber analysts in generating quantitative metrics for prioritisation, summaries, or analysis of larger graphs.
format Preprint
id arxiv_https___arxiv_org_abs_2412_14375
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Network Modelling in Analysing Cyber-related Graphs
Kuikka, Vesa
Pykälä, Lauri
Takko, Tuomas
Kaski, Kimmo
Social and Information Networks
In order to improve the resilience of computer infrastructure against cyber attacks and finding ways to mitigate their impact we need to understand their structure and dynamics. Here we propose a novel network-based influence spreading model to investigate event trajectories or paths in various types of attack and causal graphs, which can be directed, weighted, and / or cyclic. In case of attack graphs with acyclic paths, only self-avoiding attack chains are allowed. In the framework of our model a detailed probabilistic analysis beyond the traditional visualisation of attack graphs, based on vulnerabilities, services, and exploitabilities, can be performed. In order to demonstrate the capabilities of the model, we present three use cases with cyber-related graphs, namely two attack graphs and a causal graph. The model can be of benefit to cyber analysts in generating quantitative metrics for prioritisation, summaries, or analysis of larger graphs.
title Network Modelling in Analysing Cyber-related Graphs
topic Social and Information Networks
url https://arxiv.org/abs/2412.14375