🤖 AI Summary
Existing network attack models struggle to capture cyclic dependencies, dynamic propagation, and multi-granularity causal relationships. To address this, we propose a novel probabilistic influence propagation model that unifies directed weighted attack graphs and causal graphs. The model supports cyclic structures and self-avoiding attack chain reasoning, and—uniquely—integrates probabilistic graphical models with stochastic processes into heterogeneous networked security analysis, enabling joint fine-grained inference across vulnerabilities, services, and exploitabilities. Experimental evaluation on two attack graph benchmarks and one causal graph demonstrates that our model generates quantifiable threat-path prioritization metrics and scalable structural summaries for large graphs. These capabilities significantly improve analysts’ efficiency in reasoning about complex attack chains and enhance decision-making accuracy.
📝 Abstract
In order to improve the resilience of computer infrastructure against cyber attacks and finding ways to mitigate their impact we need to understand their structure and dynamics. Here we propose a novel network-based influence spreading model to investigate event trajectories or paths in various types of attack and causal graphs, which can be directed, weighted, and / or cyclic. In case of attack graphs with acyclic paths, only self-avoiding attack chains are allowed. In the framework of our model a detailed probabilistic analysis beyond the traditional visualisation of attack graphs, based on vulnerabilities, services, and exploitabilities, can be performed. In order to demonstrate the capabilities of the model, we present three use cases with cyber-related graphs, namely two attack graphs and a causal graph. The model can be of benefit to cyber analysts in generating quantitative metrics for prioritisation, summaries, or analysis of larger graphs.