Towards Automated Network Mitigation Analysis (extended)
Patrick Speicher, Marcel Steinmetz, J\"org Hoffmann, Michael Backes,, Robert K\"unnemann

TL;DR
This paper introduces a novel, theoretically grounded approach for automated network mitigation analysis using Stackelberg planning to optimize security strategies against simulated attacks.
Contribution
It presents the first comprehensive method for conducting what-if analyses for network mitigation using Stackelberg planning based on automated attack simulations.
Findings
Stackelberg planning effectively identifies optimal mitigation strategies.
Automated attack simulations enable scalable analysis across different network sizes.
The approach integrates data from network scans and vulnerability databases.
Abstract
Penetration testing is a well-established practical concept for the identification of potentially exploitable security weaknesses and an important component of a security audit. Providing a holistic security assessment for networks consisting of several hundreds hosts is hardly feasible though without some sort of mechanization. Mitigation, prioritizing counter-measures subject to a given budget, currently lacks a solid theoretical understanding and is hence more art than science. In this work, we propose the first approach for conducting comprehensive what-if analyses in order to reason about mitigation in a conceptually well-founded manner. To evaluate and compare mitigation strategies, we use simulated penetration testing, i.e., automated attack-finding, based on a network model to which a subset of a given set of mitigation actions, e.g., changes to the network topology, system…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Network Security and Intrusion Detection · Advanced Malware Detection Techniques
