Research Article

Implement Edge pruning to Enhance attack graph generation using Naïve approach algorithm

Volume: 11 Number: 3 September 17, 2024
EN

Implement Edge pruning to Enhance attack graph generation using Naïve approach algorithm

Abstract

The use of network technologies has increased in recent years. Although the network is beneficial for individuals to work and live in, it does have security challenges that should be rectified. One of these issues is cyberattacks. The attack surface for hackers is growing as more devices are linked to the internet. The next-generation cyber defense concentrating on predictive analysis seems more proactive than existing technologies based on intrusion detection. Recently, many approaches have been proposed to detect and predict attacks; one of these approaches is attack graphs. The main reason for designing the attack graph is to predict the attack as well as to predict the attack's next step in the network. The attack graph depicts the many paths an attacker may attempt to get around a security policy by leveraging interdependencies between disclosed vulnerabilities. The attack graph is categorized into three sections: generation, analysis, and use of attack graph. However, current attack graphs are suffering from a few issues. Scalability is the main issue the attack graph generation is facing. The reason for this issue is that the increase in the usage of devices connected to the network leads to increased vulnerabilities in the network, which leads to an increment in the complexity as well as generation time of the attack graph. For this issue, this study proposes use the naïve approach prune algorithm and using Personal agents to reduce the reachability time in calculating between the nodes and to remove unnecessary edges, minimizing the attack graph's complexity. For the results, the proposed attack graph performs better than the existing attack graph by using a naïve approach and a personal agent. The proposed attack graph reduced the generation time by 20% and the attack graph complexity.

Keywords

References

  1. [1] J. Jang-Jaccard and S. Nepal, ‘‘A survey of emerging threats in cybersecurity,’’ Journal of computer and system sciences, vol. 80, no. 5, pp. 973–993, 2014.
  2. [2] E. Bertino, L. Martino, F. Paci, A. Squicciarini, E. Bertino, L. D. Martino, F. Paci, and A. C. Squicciarini, ‘‘Web services threats, vulnerabilities, and countermeasures,’’ Security for web services and service-oriented architectures, pp. 25–44, 2010.
  3. [3] J. M. Kizza, W. Kizza, and Wheeler, Guide to computer network security, vol. 8. Springer, 2013.
  4. [4] M. Abomhara and G. M. Køien, ‘‘Cyber security and the internet of things: vulnerabilities, threats, intruders and attacks,’’ Journal of Cyber Security and Mobility, pp. 65–88, 2015.
  5. [5] A. O’driscoll, ‘‘Cyber security vulnerability statistics and facts of 2022,’’ Comparitech, 2021.
  6. [6] Y. Yang, L. Wu, G. Yin, L. Li, and H. Zhao, ‘‘A survey on security and privacy issues in internet-of-things,’’ IEEE Internet of things Journal, vol. 4, no. 5, pp. 1250–1258, 2017.
  7. [7] J. Wang, ‘‘A generation method of attack graph based on evolutionary computation,’’ in 2016 2nd International Conference on Advances in Energy, Environment and Chemical Engineering (AEECE 2016), pp. 28–31, Atlantis Press, 2016.
  8. [8] M. U. Aksu, K. Bicakci, M. H. Dilek, A. M. Ozbayoglu, and E. ı. Tatli, ‘‘Automated generation of attack graphs using nvd,’’ in Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy, pp. 135–142, 2018.

Details

Primary Language

English

Subjects

Risk Engineering

Journal Section

Research Article

Publication Date

September 17, 2024

Submission Date

October 13, 2023

Acceptance Date

January 18, 2024

Published in Issue

Year 2024 Volume: 11 Number: 3

APA
Alaaraji, Z., Mutlag, A., & Syed Ahmad, S. S. (2024). Implement Edge pruning to Enhance attack graph generation using Naïve approach algorithm. El-Cezeri, 11(3), 298-306. https://doi.org/10.31202/ecjse.1375755
AMA
1.Alaaraji Z, Mutlag A, Syed Ahmad SS. Implement Edge pruning to Enhance attack graph generation using Naïve approach algorithm. El-Cezeri Journal of Science and Engineering. 2024;11(3):298-306. doi:10.31202/ecjse.1375755
Chicago
Alaaraji, Zaid, Ammar Mutlag, and Sharifah Sakinah Syed Ahmad. 2024. “Implement Edge Pruning to Enhance Attack Graph Generation Using Naïve Approach Algorithm”. El-Cezeri 11 (3): 298-306. https://doi.org/10.31202/ecjse.1375755.
EndNote
Alaaraji Z, Mutlag A, Syed Ahmad SS (September 1, 2024) Implement Edge pruning to Enhance attack graph generation using Naïve approach algorithm. El-Cezeri 11 3 298–306.
IEEE
[1]Z. Alaaraji, A. Mutlag, and S. S. Syed Ahmad, “Implement Edge pruning to Enhance attack graph generation using Naïve approach algorithm”, El-Cezeri Journal of Science and Engineering, vol. 11, no. 3, pp. 298–306, Sept. 2024, doi: 10.31202/ecjse.1375755.
ISNAD
Alaaraji, Zaid - Mutlag, Ammar - Syed Ahmad, Sharifah Sakinah. “Implement Edge Pruning to Enhance Attack Graph Generation Using Naïve Approach Algorithm”. El-Cezeri 11/3 (September 1, 2024): 298-306. https://doi.org/10.31202/ecjse.1375755.
JAMA
1.Alaaraji Z, Mutlag A, Syed Ahmad SS. Implement Edge pruning to Enhance attack graph generation using Naïve approach algorithm. El-Cezeri Journal of Science and Engineering. 2024;11:298–306.
MLA
Alaaraji, Zaid, et al. “Implement Edge Pruning to Enhance Attack Graph Generation Using Naïve Approach Algorithm”. El-Cezeri, vol. 11, no. 3, Sept. 2024, pp. 298-06, doi:10.31202/ecjse.1375755.
Vancouver
1.Zaid Alaaraji, Ammar Mutlag, Sharifah Sakinah Syed Ahmad. Implement Edge pruning to Enhance attack graph generation using Naïve approach algorithm. El-Cezeri Journal of Science and Engineering. 2024 Sep. 1;11(3):298-306. doi:10.31202/ecjse.1375755
Creative Commons License El-Cezeri is licensed to the public under a Creative Commons Attribution 4.0 license.
88x31.png