论文标题
Mulval扩展及其攻击场景的调查
A Survey of MulVAL Extensions and Their Attack Scenarios Coverage
论文作者
论文摘要
组织采用各种对手模型来评估攻击对网络的风险和潜在影响。攻击图代表攻击者可以采取的识别和妥协组织资产所采取的漏洞和行动。攻击图有助于以攻击路径的形式对攻击场景进行视觉表现和算法分析。 Mulval是用于构建逻辑攻击图的通用开源框架,研究人员和从业人员已广泛使用,并通过其他攻击方案扩展了其扩展。本文调查了所有现有的Mulval扩展名,并将所有Mulval互动规则映射到MITER ATT&CK技术,以估算其攻击方案的覆盖范围。这项调查使沿统一的本体论概念的当前Mulval扩展一致,并突出了现有的差距。它为有条不紊地改善Mulval和在MITER ATT&CK中捕获的对抗行为的整个景观的全面建模铺平了道路。
Organizations employ various adversary models in order to assess the risk and potential impact of attacks on their networks. Attack graphs represent vulnerabilities and actions an attacker can take to identify and compromise an organization's assets. Attack graphs facilitate both visual presentation and algorithmic analysis of attack scenarios in the form of attack paths. MulVAL is a generic open-source framework for constructing logical attack graphs, which has been widely used by researchers and practitioners and extended by them with additional attack scenarios. This paper surveys all of the existing MulVAL extensions, and maps all MulVAL interaction rules to MITRE ATT&CK Techniques to estimate their attack scenarios coverage. This survey aligns current MulVAL extensions along unified ontological concepts and highlights the existing gaps. It paves the way for methodical improvement of MulVAL and the comprehensive modeling of the entire landscape of adversarial behaviors captured in MITRE ATT&CK.