Title
A Defense-Centric Model for Multi-step Attack Damage Cost Evaluation
Abstract
Measuring the attack damage cost and monitoring the sequence of privilege escalations play a critical role in choosing the right countermeasure by Intrusion Response System (IRS). The existing attack damage cost evaluation approaches inherit some limitations, such as neglecting the dependencies between system assets, ignoring the backward damage of exploited non-goal services, or omitting the potential damage toward the goal service. In this paper, we propose a defense-centric model to calculate the damage cost of a multi-step attack. The main advantage of this model is providing an accurate damage cost by considering not only the damaged services (non-goal services) but also the potential damage toward the attacker target (goal service). To track the attacker's progress and find the attack path, an Attack-Defense Tree (ADT) is used. The model has been implemented in, but is not limited to, the cloud environment and tested with a multi-step attack scenario.
Year
DOI
Venue
2015
10.1109/FiCloud.2015.39
FiCloud
Keywords
Field
DocType
Multi-step attack, Vulnerability, Attack damage cost, Defense-centric
Countermeasure,Computer science,Computer security,Server,Cost evaluation,Network topology,Hidden Markov model,Intrusion detection system,Cloud computing,Vulnerability
Conference
Citations 
PageRank 
References 
0
0.34
15
Authors
4
Name
Order
Citations
PageRank
Alireza Shameli Sendi1638.08
Habib Louafi2192.86
Wenbo He3111268.06
Mohamed Cheriet42047238.58