네트워크 취약성 분석을 위한 확장된 사이버 공격 트리에 관한 연구

We extended a general attack tree to apply cyber attack model for network vulnerability analysis. We defined an extended cyber attack tree (E-CAT) which extends the general attack tree by associating each node of the tree with a transition of attack that could have contributed to the cyber attack. T...

Full description

Saved in:
Bibliographic Details
Published in(사)디지털산업정보학회 논문지, 6(3) Vol. 6; no. 3; pp. 49 - 57
Main Authors 엄정호, 박선호, 정태명, Eom, Jung Ho, Park, Seon Ho, Chung, Tai M
Format Journal Article
LanguageKorean
Published (사)디지털산업정보학회 01.09.2010
Subjects
Online AccessGet full text
ISSN1738-6667
2713-9018

Cover

More Information
Summary:We extended a general attack tree to apply cyber attack model for network vulnerability analysis. We defined an extended cyber attack tree (E-CAT) which extends the general attack tree by associating each node of the tree with a transition of attack that could have contributed to the cyber attack. The E-CAT resolved the limitation that a general attack tree can not express complex and sophisticate attacks. Firstly, the Boolean expression can simply express attack scenario with symbols and codes. Secondary, An Attack Generation Probability is used to select attack method in an attack tree. A CONDITION-composition can express new and modified attack transition which a aeneral attack tree can not express. The E-CAT is possible to have attack's flexibility and improve attack success rate when it is applied to cyber attack model.
Bibliography:KISTI1.1003/JNL.JAKO201007637766117
G704-SER000010259.2010.6.3.019
ISSN:1738-6667
2713-9018