Journal on Communications ›› 2021, Vol. 42 ›› Issue (1): 1-17.doi: 10.11959/j.issn.1000-436x.2021004

• Papers •     Next Articles

Construction method of attack scenario in cloud environment based on dynamic probabilistic attack graph

Wenjuan WANG, Xuehui DU, Dibin SHAN   

  1. Information Engineering University, Zhengzhou 450001, China
  • Revised:2020-09-23 Online:2021-01-25 Published:2021-01-01
  • Supported by:
    The National Natural Science Foundation of China(61802436)

Abstract:

Aiming at the problem of complex multi-step attack detection, the method of attack scenario construction oriented to cloud computing environment was studied.Firstly, a dynamic probabilistic attack graph model was constructed, and a probabilistic attack graph updating algorithm was designed to make it update periodically with the passage of time and space, so as to adapt to the elastic and dynamic cloud computing environment.Secondly, an attack intention inference algorithm and a maximum probability attack path inference algorithm were designed to solve the uncertain problems such as error and fracture of attack scenarios caused by false positive or false negative, and ensure the accuracy of attack scenario.Meanwhile, the attack scenario was dynamically evolved along with the dynamic probability attack graph to ensure the completeness and freshness of the attack scenario.Experimental results show that the proposed method can adapt to the elastic and dynamic cloud environment, restore the penetration process of attacker’s and reconstruct high-level attack scenario, and so provide certain references for building supervised and accountable cloud environment.

Key words: cloud computing, attack scenario, dynamic probabilistic attack graph, attack intention, maximum probability attack path

CLC Number: 

No Suggested Reading articles found!