We present a novel methodology for modelling, visualising, and analysing cyber threats, attack paths, as well as their impact on user services in enterprise or infrastructure networks of digital devices and services they provide. Using probabilistic methods to track the propagation of an attack through attack graphs, via the service or application layers, and on physical communication networks, our model enables us to analyse cyber attacks at different levels of detail. Understanding the propagation of an attack within a service among microservices and its spread between different services or application servers could help detect and mitigate it early. We demonstrate that this network-based influence spreading modelling approach enables the evaluation of diverse attack scenarios and the development of protection and mitigation measures, taking into account the criticality of services from the user's perspective. This methodology could also aid security specialists and system administrators in making well-informed decisions regarding risk mitigation strategies.
翻译:本文提出了一种新颖的方法论,用于建模、可视化及分析网络威胁、攻击路径,及其对数字设备与企业或基础设施网络所提供用户服务的影响。通过采用概率方法追踪攻击经由攻击图、通过服务或应用层以及在物理通信网络中的传播,我们的模型能够从不同详细程度分析网络攻击。理解攻击在微服务间于单一服务内的传播及其在不同服务或应用服务器间的扩散,有助于及早检测与缓解攻击。我们证明,这种基于网络的影响力传播建模方法能够评估多样化的攻击场景,并制定防护与缓解措施,同时从用户角度考量服务的关键性。该方法论亦有助于安全专家与系统管理员就风险缓解策略做出明智决策。