Next Article in Journal
Novelty in Intelligent Controlled Oscillations in Smart Structures
Previous Article in Journal
Parallelization of the Bison Algorithm Applied to Data Classification
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Fast Algorithm for Cyber-Attack Estimation and Attack Path Extraction Using Attack Graphs with AND/OR Nodes

by
Eugene Levner
1,* and
Dmitry Tsadikovich
2
1
Faculty of Sciences, Holon Institute of Technology, 58102 Holon, Israel
2
Department of Management, Bar Ilan University, 5290002 Ramat Gan, Israel
*
Author to whom correspondence should be addressed.
Algorithms 2024, 17(11), 504; https://doi.org/10.3390/a17110504
Submission received: 11 September 2024 / Revised: 28 October 2024 / Accepted: 31 October 2024 / Published: 4 November 2024
(This article belongs to the Section Algorithms for Multidisciplinary Applications)

Abstract

This paper studies the security issues for cyber–physical systems, aimed at countering potential malicious cyber-attacks. The main focus is on solving the problem of extracting the most vulnerable attack path in a known attack graph, where an attack path is a sequence of steps that an attacker can take to compromise the underlying network. Determining an attacker’s possible attack path is critical to cyber defenders as it helps identify threats, harden the network, and thwart attacker’s intentions. We formulate this problem as a path-finding optimization problem with logical constraints represented by AND and OR nodes. We propose a new Dijkstra-type algorithm that combines elements from Dijkstra’s shortest path algorithm and the critical path method. Although the path extraction problem is generally NP-hard, for the studied special case, the proposed algorithm determines the optimal attack path in polynomial time, O(nm), where n is the number of nodes and m is the number of edges in the attack graph. To our knowledge this is the first exact polynomial algorithm that can solve the path extraction problem for different attack graphs, both cycle-containing and cycle-free. Computational experiments with real and synthetic data have shown that the proposed algorithm consistently and quickly finds optimal solutions to the problem.
Keywords: cybersecurity; cyber-attack; cyclic attack graph; attack path; AND/OR graph; attack time assessment; attack path extraction; polynomial algorithm cybersecurity; cyber-attack; cyclic attack graph; attack path; AND/OR graph; attack time assessment; attack path extraction; polynomial algorithm

Share and Cite

MDPI and ACS Style

Levner, E.; Tsadikovich, D. Fast Algorithm for Cyber-Attack Estimation and Attack Path Extraction Using Attack Graphs with AND/OR Nodes. Algorithms 2024, 17, 504. https://doi.org/10.3390/a17110504

AMA Style

Levner E, Tsadikovich D. Fast Algorithm for Cyber-Attack Estimation and Attack Path Extraction Using Attack Graphs with AND/OR Nodes. Algorithms. 2024; 17(11):504. https://doi.org/10.3390/a17110504

Chicago/Turabian Style

Levner, Eugene, and Dmitry Tsadikovich. 2024. "Fast Algorithm for Cyber-Attack Estimation and Attack Path Extraction Using Attack Graphs with AND/OR Nodes" Algorithms 17, no. 11: 504. https://doi.org/10.3390/a17110504

APA Style

Levner, E., & Tsadikovich, D. (2024). Fast Algorithm for Cyber-Attack Estimation and Attack Path Extraction Using Attack Graphs with AND/OR Nodes. Algorithms, 17(11), 504. https://doi.org/10.3390/a17110504

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop