亲爱的研友该休息了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!身体可是革命的本钱,早点休息,好梦!

SPGNN-API: A Transferable Graph Neural Network for Attack Paths Identification and Autonomous Mitigation

计算机科学 计算机安全 最短路径问题 鉴定(生物学) 攻击模式 路径(计算) 图形 计算机网络 入侵检测系统 理论计算机科学 植物 生物
作者
Houssem Jmal,F. Ben Hmida,Nardine Basta,Muhammad Ikram,Mohamed Ali Kâafar,Michael Walker
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:19: 1601-1613 被引量:4
标识
DOI:10.1109/tifs.2023.3338965
摘要

Attack paths are the potential chain of malicious activities an attacker performs to compromise network assets and acquire privileges through exploiting network vulnerabilities. Attack path analysis helps organizations to identify new/unknown chains of attack vectors exposing critical assets, as opposed to individual attack vectors in signature-based attack analysis. Timely identification of attack paths enables proactive mitigation of threats. Nevertheless, manual analysis of complex network configurations, vulnerabilities, and security events to identify attack paths is rarely feasible. This work proposes a novel transferable graph neural network-based model for shortest path identification. The shortest path, integrated with a novel holistic model for identifying potential network vulnerabilities interactions, is then utilized to detect network attack paths. Our framework automates the risk assessment of attack paths indicating the propensity of the paths to enable the compromise of highly-critical assets (e.g., databases). The proposed framework, named SPGNN-API, incorporates automated threat mitigation through a proactive timely tuning of the network firewall rules and Zero-Trust (ZT) policies to break critical attack paths and bolster cyber defenses. Our evaluation process is twofold; evaluating the performance of the shortest path identification and assessing the attack path detection accuracy. Our results show that SPGNN-API largely outperforms the baseline model for shortest path identification with an average accuracy ≥ 95% and successfully detects 100% of the potentially compromised assets, outperforming the attack graph baseline by 47%.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
5秒前
英姑应助科研通管家采纳,获得10
14秒前
baolong完成签到,获得积分10
15秒前
baolong发布了新的文献求助10
19秒前
34秒前
哈皮波完成签到,获得积分10
35秒前
冯尔蓝发布了新的文献求助10
40秒前
44秒前
研友_VZG7GZ应助慈祥的网络采纳,获得10
50秒前
svikarsk完成签到 ,获得积分10
59秒前
1分钟前
ren完成签到 ,获得积分10
1分钟前
辛勤寻凝发布了新的文献求助10
1分钟前
miaomiao123完成签到 ,获得积分10
1分钟前
1分钟前
1分钟前
风中莫英发布了新的文献求助30
1分钟前
1分钟前
张东震发布了新的文献求助10
1分钟前
思源应助Aaron采纳,获得10
1分钟前
Bi8bo发布了新的文献求助10
1分钟前
1分钟前
1分钟前
MishimaErika发布了新的文献求助10
1分钟前
1分钟前
张东震完成签到,获得积分20
1分钟前
1分钟前
杨世全发布了新的文献求助10
1分钟前
hhh发布了新的文献求助10
1分钟前
酒糟凤爪完成签到,获得积分10
1分钟前
五月完成签到,获得积分10
2分钟前
MishimaErika完成签到,获得积分10
2分钟前
桐桐应助hhh采纳,获得10
2分钟前
2分钟前
2分钟前
斯文败类应助科研通管家采纳,获得10
2分钟前
学者风范完成签到 ,获得积分10
2分钟前
今后应助紧张的大有采纳,获得30
2分钟前
SciGPT应助LouisKing采纳,获得10
2分钟前
2分钟前
高分求助中
Adhesion Science: Principles & Practice 1234
Signals, Systems, and Signal Processing 610
Competition Law: Cases and Materials, 5th edition 500
Introduction to Cosmetic Formulation and Technology, 2nd Edition 400
Petrology and Plate Tectonics,2025 400
Burger's Medicinal Chemistry and Drug Discovery 400
A Step-by-Step Guide to Qualitative Data Coding 2nd Edition 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6706537
求助须知:如何正确求助?哪些是违规求助? 8447299
关于积分的说明 18040294
捐赠科研通 5947206
什么是DOI,文献DOI怎么找? 2991261
邀请新用户注册赠送积分活动 1967198
关于科研通互助平台的介绍 1913304