Graphene: Infrastructure Security Posture Analysis with AI-generated Attack Graphs
Xin Jin, Charalampos Katsis, Fan Sang, Jiahao Sun, Elisa Bertino,, Ramana Rao Kompella, Ashish Kundu

TL;DR
Graphene is an AI-driven system that analyzes infrastructure security by generating attack graphs from vulnerability data, assessing exploitability, and providing a comprehensive security posture score across multiple layers.
Contribution
The paper introduces Graphene, a novel system that automates security assessment and attack graph generation using AI, integrating multi-layer vulnerability analysis for infrastructure security.
Findings
Successfully generates attack graphs from user data
Quantifies security posture with a scoring mechanism
Analyzes vulnerabilities across hardware, system, network, and cryptography layers
Abstract
The rampant occurrence of cybersecurity breaches imposes substantial limitations on the progress of network infrastructures, leading to compromised data, financial losses, potential harm to individuals, and disruptions in essential services. The current security landscape demands the urgent development of a holistic security assessment solution that encompasses vulnerability analysis and investigates the potential exploitation of these vulnerabilities as attack paths. In this paper, we propose Graphene, an advanced system designed to provide a detailed analysis of the security posture of computing infrastructures. Using user-provided information, such as device details and software versions, Graphene performs a comprehensive security assessment. This assessment includes identifying associated vulnerabilities and constructing potential attack graphs that adversaries can exploit.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Network Security and Intrusion Detection · Advanced Malware Detection Techniques
