Attack trees (ATs) are a widely deployed modelling technique to categorize potential attacks on a system. An attacker of such a system aims at doing as much damage as possible, but might be limited by a cost budget. The maximum possible damage for a given cost budget is an important security metric of a system. In this paper, we find the maximum damage given a cost budget by modelling this problem with ATs, both in deterministic and probabilistic settings. We show that the general problem is NP-complete, and provide heuristics to solve it. For general ATs these are based on integer linear programming. However when the AT is tree-structured, then one can instead use a faster bottom-up approach. We also extend these methods to other problems related to the cost-damage tradeoff, such as the cost-damage Pareto front.
翻译:攻击树(ATs)是一种广泛部署的建模技术,用于对系统可能遭受的攻击进行分类。此类系统的攻击者旨在造成尽可能大的损害,但可能受到成本预算的限制。给定成本预算下的最大可能损害是系统的一项重要安全指标。本文通过使用攻击树对该问题进行建模,在确定性和概率性设定下,寻找给定成本预算下的最大损害。我们证明该一般性问题是NP完全的,并提出了相应的启发式解法。对于通用攻击树,这些解法基于整数线性规划。然而,当攻击树为树形结构时,可以采用更快速的从底向上的方法。我们还将这些方法扩展到与成本-损害权衡相关的其他问题,例如成本-损害帕累托前沿。