Identification of Attack Paths Using Kill Chain and Attack Graphs
Luk\'a\v{s} Sadlek, Pavel \v{C}eleda, Daniel Tovar\v{n}\'ak

TL;DR
This paper introduces a novel kill chain attack graph that combines kill chain and attack graph concepts to identify multi-step cyber threats and suggest targeted countermeasures, validated on real-world data.
Contribution
A new approach merging kill chain and attack graphs to model and identify attack paths, aiding security focus and mitigation strategies.
Findings
Effective identification of attack paths in real-world scenarios
Supports targeted security measures based on attack phases
Provides a proof-of-concept tool for attack graph generation
Abstract
The ever-evolving capabilities of cyber attackers force security administrators to focus on the early identification of emerging threats. Targeted cyber attacks usually consist of several phases, from initial reconnaissance of the network environment to final impact on objectives. This paper investigates the identification of multi-step cyber threat scenarios using kill chain and attack graphs. Kill chain and attack graphs are threat modeling concepts that enable determining weak security defense points. We propose a novel kill chain attack graph that merges kill chain and attack graphs together. This approach determines possible chains of attacker's actions and their materialization within the protected network. The graph generation uses a categorization of threats according to violated security properties. The graph allows determining the kill chain phase the administrator should…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
