SoK: Harmonizing Attack Graphs and Intrusion Detection Systems
Andrea Agiollo, Enkeleda Bardhi, Alessandro Palma, Riccardo Lazzeretti, Silvia Bonomi, Fernando Kuipers

TL;DR
This paper systematically analyzes the integration of Attack Graphs and Intrusion Detection Systems, introduces a formal lifecycle framework, and demonstrates its benefits for improved cyber threat detection and response.
Contribution
It provides the first comprehensive taxonomy of AG-IDS integration and proposes a unifying, feedback-driven lifecycle framework to enhance cybersecurity defenses.
Findings
Current research is dominated by specialized, single-purpose integrations.
The proposed lifecycle improves threat detection accuracy.
A proof-of-concept demonstrates practical benefits of the framework.
Abstract
Detecting and responding to cyber attacks is increasingly difficult as high-volume, complex network traffic allows threats to remain concealed. While Intrusion Detection Systems (IDSs) identify anomalous behavior, Attack Graphs (AGs) serve as the primary threat model for analyzing attacker strategies and informing any response. Despite the conceptual connection being recognized in early research, the field of AG and IDS integration lacks a common structure. This paper presents the first systematic analysis of AG-IDS integration, reviewing a 73 comprehensive works in literature. We introduce a novel taxonomy revealing that current research is dominated by specialized, single-purpose integrations, such as using AGs to filter IDS false positives or using IDS alerts to prune AGs. Our analysis highlights a critical gap: the absence of a unifying framework that treats IDSs and AGs as a…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Information and Cyber Security · Smart Grid Security and Resilience
