How Secure Is Your Network? NIST Model Knows

July 23, 2008
Secure Network

Enlarge

The example illustrates three paths that an attacker can take to penetrate the network using FTP server, SSH server or database server. Image: NIST

(PhysOrg.com) -- Data breaches are a recurring nightmare for IT managers responsible for securing not only their company’s confidential data, but possibly also sensitive information belonging to their clients, such as social security numbers or health or financial records. To help managers safeguard valuable information most efficiently, computer scientists at the National Institute of Standards and Technology are applying security metrics to computer network pathways to assign a probable risk of attack to guide IT managers in securing their networks.

“We analyze all of the paths that system attackers could penetrate through a network,” says computer scientist Anoop Singhal, “and assign a risk to each component of the system. Decision makers can use our assigned probabilities to make wise decisions and investments to safeguard their network.” The research was presented at a conference earlier this month.

Computer networks are made up of components varying from individual computers, to servers and routers. Once inside a network’s firewall, for a seemingly mild-mannered purpose as posting an image to a file transfer protocol (FTP) site, a hacker can travel through the network through a variety of routes to hit the jackpot of valuable data. In addition to hardware, the hacker can break in through software on the computers, especially file-sharing applications that have been blamed for some major data breaches recently.

NIST researchers evaluate each route and assign it a risk based on how challenging it is to the hacker. The paths are determined using a technique called “attack graphs.” A new analysis technique based on attack graphs was jointly developed by Singhal and research colleagues at George Mason University. A patent is pending on the technique.

Singhal and his team determine risk by using these attack graphs and NIST’s National Vulnerability Database (NVD). This government repository includes a collection of security-related software weaknesses that hackers can exploit. NVD data was collected from software vendors and scores are assigned from most to least insecure by experts.

For example in a simple system there is an attacker on a computer, a firewall, router, an FTP server and a database server. The goal for the attacker is to find the simplest path into the jackpot—the database server. Attack Graph Analysis determines three potential attack paths. For each path in the graph, the NIST researchers assign an attack probability based on the score in the NVD database.

Because it takes multiple steps to reach the goal, the probabilities of each component are multiplied to determine the overall risk. One path takes only three steps. The first step has an 80 percent chance of being hacked, the second, a 90 percent chance. The final step requires great expertise, so there is only a 10 percent probability it can be breached. By multiplying the three probabilities together, that path is pretty secure with a less than 10 percent chance of being hacked.

The next step is for the researchers to expand their research to handle large-scale enterprise networks.

Citation: L. Wang, T. Islam, T. Long, A. Singhal and S. Jajodia. An Attack Graph Based Probabilistic Security Metric. IFIP WG 11.3 Conference on Data and Application Security, London, United Kingdom.

Provided by NIST

Filter


Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

x646d63
Jul 23, 2008

Rank: 4 / 5 (1)
Another article for the "duh." file.

Hackers can attack computes by following the paths by which they are linked? OMG. I had never thought of that. All this time I've been trying to hack by following the paths of computers that are not linked. Silly me.
dcoder
Jul 23, 2008

Rank: not rated yet
I'd have to agree... if you run a network and you don't know about checking up on your vulnerability like https://secure1.s...dex.html then I guess this could be news to you... that same profile runs an unencrypted wireless router...
Rank 3 /5 (6 votes)
Related Stories
Relevant PhysicsForums posts

More news stories

Soraa LED light may dim 50-watt halogen rivals

(PhysOrg.com) -- Soraa, a Fremont, California company founded in 2008, this week launched its first product, a light that uses LEDS (light emitting diodes). The "Soraa LED MR16 lamp" is the "perfect" replacement ...

Technology / Semiconductors

created 18 hours ago | popularity 4.3 / 5 (17) | comments 15 | with audio podcast report

First Google hire leaving for online academy

The first person hired by Google's founders is leaving the Internet giant to devote himself to an innovative online education website called Khan Academy.

Technology / Internet

created 6 hours ago | popularity 5 / 5 (1) | comments 0

FBI file: Steve Jobs was considered for govt post

(AP) -- FBI background interviews of some people who knew Apple co-founder Steve Jobs reveal a man driven by power and alienating some of the people who worked with him.

Technology / Business

created 6 hours ago | popularity 3.4 / 5 (5) | comments 0

New integrated building model may improve fish farming operations

Today's "locavore" movement with its emphasis on eating more locally-produced food is a natural fit for fruits and vegetables in nearly every region, but few entrepreneurs have dared to apply the concept to ...

Technology / Engineering

created 6 hours ago | popularity not rated yet | comments 0

Samsung can continue selling Galaxy tabs in Germany: court

South Korea's Samsung Electronics can continue to sell its Galaxy Tab 10.1N tablet computer in Germany, a German court ruled Thursday, rejecting a bid by arch-rival Apple to have them banned.

Technology / Business

created 16 hours ago | popularity 5 / 5 (2) | comments 3


'Dark plasmons' transmit energy

Microscopic channels of gold nanoparticles have the ability to transmit electromagnetic energy that starts as light and propagates via "dark plasmons," according to researchers at Rice University.

Hydrogen from acidic water: Researchers develop potential low cost alternative to platinum for splitting water

A technique for creating a new molecule that structurally and chemically replicates the active part of the widely used industrial catalyst molybdenite has been developed by researchers with the Lawrence Berkeley ...

FDA-approved drug rapidly clears amyloid from the brain, reverses Alzheimer's symptoms in mice

Neuroscientists at Case Western Reserve University School of Medicine have made a dramatic breakthrough in their efforts to find a cure for Alzheimer's disease. The researchers' findings, published in the journal Science, show t ...

Ultraviolet protection molecule in plants yields its secrets

Lying around in the sun all day is hazardous not just for humans but also for plants, which have no means of escape. Ultraviolet (UV) radiation from the sun can damage proteins and DNA inside cells, leading ...

Anyone can learn to be more inventive, cognitive researcher says

There will always be a wild and unpredictable quality to creativity and invention, says Anthony McCaffrey, a cognitive psychology researcher at the University of Massachusetts Amherst, because an "Aha moment" is rare and ...

Flexible paper robots

(PhysOrg.com) -- These inexpensive robots can stretch, bend and twist under control, and lift objects up to 120 times their own weight. Being soft, they can apply gentle and even pressure, and adapt to varied ...