Skip to main navigation Skip to search Skip to main content

Improving attack graph scalability for the cloud through SDN-based decomposition and parallel processing

  • Oussama Mjihil*
  • , Dijiang Huang
  • , Abdelkrim Haqiq
  • *Corresponding author for this work
  • Hassan I University
  • Informatics and Decision Systems Engineering
  • Arizona State University
  • E-NGN Research Group

Research output: Chapter in Book or Report/Conference proceedingConference Proceedingpeer-review

8 Citations (Scopus)

Abstract

Due to its fast growth, Cloud computing is a quick evolving research area. Security, which is among the most required Cloud features, is a very hard and challenging task when it’s addressed for large networked systems. To automate security assessment, one should use an Attack Representation Model (ARM), such as Attack Graph (AG) or Attack Tree, to represent and analyze multi-host multi-stage attacks. In order to improve AG analysis for large-scale networked systems, our framework uses Software-defined Networking (SDN) to build a detailed and dynamic knowledge about the network configuration and the host access control list. Altogether with machine configuration information, our framework will be able to construct loosely connected sub-groups of virtual machines and perform a parallel security analysis. We have performed experimental validation using a real networked system to show the performance improvement in comparison with MULVAL network security analyzer.

Original languageEnglish
Title of host publicationUbiquitous Networking -3rd International Symposium, UNet 2017, Revised Selected Papers
EditorsAna Garcia Armada, Mounir Ghogho, Essaid Sabir, Mounir Ghogho, Merouane Debbah
PublisherSpringer Verlag
Pages193-205
Number of pages13
ISBN (Print)9783319681788
DOIs
Publication statusPublished - 2017
Externally publishedYes
Event3rd International Symposium on Ubiquitous Networking, UNet 2017 - Casablance, Morocco
Duration: 9 May 201712 May 2017

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume10542 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference3rd International Symposium on Ubiquitous Networking, UNet 2017
Country/TerritoryMorocco
CityCasablance
Period9/05/1712/05/17

Keywords

  • Attack representation models
  • Graph theory
  • Scalability

Cite this