Network Modelling in Analysing Cyber-related Graphs

📅 2024-12-18
🏛️ arXiv.org
📈 Citations: 1
✨ Influential: 0
📄 PDF
🤖 AI Summary
Existing network attack models struggle to capture cyclic dependencies, dynamic propagation, and multi-granularity causal relationships. To address this, we propose a novel probabilistic influence propagation model that unifies directed weighted attack graphs and causal graphs. The model supports cyclic structures and self-avoiding attack chain reasoning, and—uniquely—integrates probabilistic graphical models with stochastic processes into heterogeneous networked security analysis, enabling joint fine-grained inference across vulnerabilities, services, and exploitabilities. Experimental evaluation on two attack graph benchmarks and one causal graph demonstrates that our model generates quantifiable threat-path prioritization metrics and scalable structural summaries for large graphs. These capabilities significantly improve analysts’ efficiency in reasoning about complex attack chains and enhance decision-making accuracy.

Technology Category

Reasoning under Uncertainty: Relational Probabilistic ModelsMachine Learning: Probabilistic Circuits and Graphical ModelsPlanning, Routing, and Scheduling: Model-Based Reasoning

Application Category

Graph Algorithms and Modeling for the Web: Foundation models and LLMs for Web-related graphsUser Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systemsSecurity and Privacy: Large-scale security measurements
📝 Abstract
In order to improve the resilience of computer infrastructure against cyber attacks and finding ways to mitigate their impact we need to understand their structure and dynamics. Here we propose a novel network-based influence spreading model to investigate event trajectories or paths in various types of attack and causal graphs, which can be directed, weighted, and / or cyclic. In case of attack graphs with acyclic paths, only self-avoiding attack chains are allowed. In the framework of our model a detailed probabilistic analysis beyond the traditional visualisation of attack graphs, based on vulnerabilities, services, and exploitabilities, can be performed. In order to demonstrate the capabilities of the model, we present three use cases with cyber-related graphs, namely two attack graphs and a causal graph. The model can be of benefit to cyber analysts in generating quantitative metrics for prioritisation, summaries, or analysis of larger graphs.
Problem

Research questions and friction points this paper is trying to address.

Modeling attack paths in cyber graphs for resilience
Analyzing probabilistic structures beyond traditional visualization
Generating quantitative metrics for cyber attack prioritization
Innovation

Methods, ideas, or system contributions that make the work stand out.

Novel network-based influence spreading model
Analyzes directed weighted cyclic attack graphs
Performs probabilistic analysis beyond traditional visualization
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
Aalto University School of Science
V
Vesa Kuikka
Department of Computer Science, Aalto University School of Science, Finland
L
Lauri Pykala
Department of Computer Science, Aalto University School of Science, Finland
T
Tuomas Takko
Department of Computer Science, Aalto University School of Science, Finland
K
Kimmo K. Kaski
Department of Computer Science, Aalto University School of Science, Finland