How Secure Is Your Network? NIST Model Knows
July 23, 2008
The example illustrates three paths that an attacker can take to penetrate the network using FTP server, SSH server or database server. Image: NIST
(PhysOrg.com) -- Data breaches are a recurring nightmare for IT managers responsible for securing not only their company’s confidential data, but possibly also sensitive information belonging to their clients, such as social security numbers or health or financial records. To help managers safeguard valuable information most efficiently, computer scientists at the National Institute of Standards and Technology are applying security metrics to computer network pathways to assign a probable risk of attack to guide IT managers in securing their networks.
“We analyze all of the paths that system attackers could penetrate through a network,” says computer scientist Anoop Singhal, “and assign a risk to each component of the system. Decision makers can use our assigned probabilities to make wise decisions and investments to safeguard their network.” The research was presented at a conference earlier this month.
Computer networks are made up of components varying from individual computers, to servers and routers. Once inside a network’s firewall, for a seemingly mild-mannered purpose as posting an image to a file transfer protocol (FTP) site, a hacker can travel through the network through a variety of routes to hit the jackpot of valuable data. In addition to hardware, the hacker can break in through software on the computers, especially file-sharing applications that have been blamed for some major data breaches recently.
NIST researchers evaluate each route and assign it a risk based on how challenging it is to the hacker. The paths are determined using a technique called “attack graphs.” A new analysis technique based on attack graphs was jointly developed by Singhal and research colleagues at George Mason University. A patent is pending on the technique.
Singhal and his team determine risk by using these attack graphs and NIST’s National Vulnerability Database (NVD). This government repository includes a collection of security-related software weaknesses that hackers can exploit. NVD data was collected from software vendors and scores are assigned from most to least insecure by experts.
For example in a simple system there is an attacker on a computer, a firewall, router, an FTP server and a database server. The goal for the attacker is to find the simplest path into the jackpot—the database server. Attack Graph Analysis determines three potential attack paths. For each path in the graph, the NIST researchers assign an attack probability based on the score in the NVD database.
Because it takes multiple steps to reach the goal, the probabilities of each component are multiplied to determine the overall risk. One path takes only three steps. The first step has an 80 percent chance of being hacked, the second, a 90 percent chance. The final step requires great expertise, so there is only a 10 percent probability it can be breached. By multiplying the three probabilities together, that path is pretty secure with a less than 10 percent chance of being hacked.
The next step is for the researchers to expand their research to handle large-scale enterprise networks.
Citation: L. Wang, T. Islam, T. Long, A. Singhal and S. Jajodia. An Attack Graph Based Probabilistic Security Metric. IFIP WG 11.3 Conference on Data and Application Security, London, United Kingdom.
Provided by NIST
-
Will you have a heart attack or stroke?
Jan 25, 2012 |
4 / 5 (2) |
0
-
State Department reports progress on bioweapons control
Dec 23, 2011 |
not rated yet |
0
-
A few hacker teams do most China-based data theft
Dec 12, 2011 |
4 / 5 (8) |
1
-
Norway hit by major data-theft attack
Nov 17, 2011 |
5 / 5 (2) |
1
-
Public Wi-Fi convenient, but risky
Nov 10, 2011 |
not rated yet |
1
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (30) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Synergistic relations between computer science and technology.
Feb 06, 2012
-
how do iphone gloves work?
Feb 05, 2012
-
iPhone battery over time
Jan 30, 2012
-
Best alternate Tablet to an iPad for writing math or physics equations?
Jan 26, 2012
-
Sending SMS to a website
Jan 20, 2012
-
Need help with my technical fest!
Jan 19, 2012
- More from Physics Forums - Computing & Technology
More news stories
Soraa LED light may dim 50-watt halogen rivals
(PhysOrg.com) -- Soraa, a Fremont, California company founded in 2008, this week launched its first product, a light that uses LEDS (light emitting diodes). The "Soraa LED MR16 lamp" is the "perfect" replacement ...
First Google hire leaving for online academy
The first person hired by Google's founders is leaving the Internet giant to devote himself to an innovative online education website called Khan Academy.
6 hours ago |
5 / 5 (1) |
0
FBI file: Steve Jobs was considered for govt post
(AP) -- FBI background interviews of some people who knew Apple co-founder Steve Jobs reveal a man driven by power and alienating some of the people who worked with him.
6 hours ago |
3.4 / 5 (5) |
0
New integrated building model may improve fish farming operations
Today's "locavore" movement with its emphasis on eating more locally-produced food is a natural fit for fruits and vegetables in nearly every region, but few entrepreneurs have dared to apply the concept to ...
6 hours ago |
not rated yet |
0
Samsung can continue selling Galaxy tabs in Germany: court
South Korea's Samsung Electronics can continue to sell its Galaxy Tab 10.1N tablet computer in Germany, a German court ruled Thursday, rejecting a bid by arch-rival Apple to have them banned.
16 hours ago |
5 / 5 (2) |
3
'Dark plasmons' transmit energy
Microscopic channels of gold nanoparticles have the ability to transmit electromagnetic energy that starts as light and propagates via "dark plasmons," according to researchers at Rice University.
Hydrogen from acidic water: Researchers develop potential low cost alternative to platinum for splitting water
A technique for creating a new molecule that structurally and chemically replicates the active part of the widely used industrial catalyst molybdenite has been developed by researchers with the Lawrence Berkeley ...
FDA-approved drug rapidly clears amyloid from the brain, reverses Alzheimer's symptoms in mice
Neuroscientists at Case Western Reserve University School of Medicine have made a dramatic breakthrough in their efforts to find a cure for Alzheimer's disease. The researchers' findings, published in the journal Science, show t ...
Ultraviolet protection molecule in plants yields its secrets
Lying around in the sun all day is hazardous not just for humans but also for plants, which have no means of escape. Ultraviolet (UV) radiation from the sun can damage proteins and DNA inside cells, leading ...
Anyone can learn to be more inventive, cognitive researcher says
There will always be a wild and unpredictable quality to creativity and invention, says Anthony McCaffrey, a cognitive psychology researcher at the University of Massachusetts Amherst, because an "Aha moment" is rare and ...
Flexible paper robots
(PhysOrg.com) -- These inexpensive robots can stretch, bend and twist under control, and lift objects up to 120 times their own weight. Being soft, they can apply gentle and even pressure, and adapt to varied ...
Jul 23, 2008
Rank: 4 / 5 (1)
Hackers can attack computes by following the paths by which they are linked? OMG. I had never thought of that. All this time I've been trying to hack by following the paths of computers that are not linked. Silly me.
Jul 23, 2008
Rank: not rated yet