Fetching the paper…
Reading the bibliography…
Organizations employ various adversary models in order to assess the risk and potential impact of attacks on their networks.
D. F. Haasl, N. H. Roberts, W. E. Vesely, and F. F. Goldberg, “Fault tree handbook,” Nuclear Regulatory Commission, Tech. Rep., 1981
1981
Earlier work this paper cites.
P. Rao, K. Sagonas, T. Swift, D. S. Warren, and J. Freire, “Xsb: A system for efficiently computing well-founded semantics,” in International Conference on Logic Programming and Nonmonotonic Reasoning , Springer. Springer, 1997, pp. 430–440
1997
Earlier work this paper cites.
C. Phillips and L. P. Swiler, “A graph-based system for network-vulnerability analysis,” in Proceedings of the 1998 workshop on New security paradigms , 1998, pp. 71–79
1998
Earlier work this paper cites.
L. P. Swiler, C. Phillips, and T. Gaylor, “A graph-based network-vulnerability analysis system,” Sandia National Labs., Albuquerque, NM (United States), Tech. Rep., 1998
1998
Earlier work this paper cites.
B. Schneier, “Attack trees,” Dr. Dobb’s journal , vol. 24, no. 12, pp. 21–29, 1999
1999
Earlier work this paper cites.
O. Sheyner, J. Haines, S. Jha, R. Lippmann, and J. M. Wing, “Automated generation and analysis of attack graphs,” in Proceedings 2002 IEEE Symposium on Security and Privacy , IEEE. IEEE, 2002, pp. 273–284
2002
Earlier work this paper cites.
P. Ammann, D. Wijesekera, and S. Kaushik, “Scalable, graph-based network vulnerability analysis,” in Proceedings of the 9th ACM Conference on Computer and Communications Security . ACM, 2002, pp. 217–224
2002
Earlier work this paper cites.
M. L. Artz, “Netspa: A network security planning architecture,” Ph.D. dissertation, Massachusetts Institute of Technology, 2002
2002
Earlier work this paper cites.
S. Noel, S. Jajodia, B. O’Berry, and M. Jacobs, “Efficient minimum-cost network hardening via exploit dependency graphs,” in 19th Annual Computer Security Applications Conference, 2003. Proceedings. , IEEE. IEEE, 2003, pp. 86–95
2003
Earlier work this paper cites.
D. J. Landoll and D. Landoll, The security risk assessment handbook: A complete guide for performing security risk assessments . CRC Press, 2005
2005
Earlier work this paper cites.
S. Jajodia, S. Noel, and B. O’berry, “Topological analysis of network attack vulnerability,” in Managing cyber threats . Springer, 2005, pp. 247–266
2005
Earlier work this paper cites.
X. Ou and A. W. Appel, A logic-programming approach to network security analysis . Princeton University Princeton, 2005
2005
Earlier work this paper cites.
Y. Liu and H. Man, “Network vulnerability assessment using bayesian networks,” in Data mining, intrusion detection, information assurance, and data networks security 2005 , vol. 5812. SPIE, 2005, pp. 61–71
2005
Earlier work this paper cites.
X. Ou, W. F. Boyer, and M. A. McQueen, “A scalable approach to attack graph generation,” in Proceedings of the 13th ACM conference on Computer and communications security . ACM, 2006, pp. 336–345
2006
Earlier work this paper cites.
K. Ingols, R. Lippmann, and K. Piwowarski, “Practical attack graph generation for network defense,” in 2006 22nd Annual Computer Security Applications Conference (ACSAC’06) , IEEE. IEEE, 2006, pp. 121–130
2006
Earlier work this paper cites.
L. Wang, S. Noel, and S. Jajodia, “Minimum-cost network hardening using attack graphs,” Computer Communications , vol. 29, no. 18, pp. 3812–3824, 2006
2006
Earlier work this paper cites.
E. Bacic, M. Froh, and G. Henderson, “Mulval extensions for dynamic asset protection,” CINNABAR NETWORKS INC OTTAWA (ONTARIO), Tech. Rep., 2006
2006
Earlier work this paper cites.
S. Bhatt, W. Horne, J. Pato, R. Rajagopalan, and P. Rao, “Model-based validation of enterprise access policies,” NATO SECURITY THROUGH SCIENCE SERIES D-INFORMATION AND COMMUNICATION SECURITY , vol. 2, p. 107, 2006
2006
Earlier work this paper cites.
S. Govindavajhala, “Status of the mulval project,” Technical Report TR-743-06, Department of Computer Science, Princeton University, Tech. Rep., 2006
2006
Earlier work this paper cites.
S. Govindavajhala and A. W. Appel, “Windows access control demystified,” Princeton university , 2006
2006
Earlier work this paper cites.
S. Govindavajhala, A formal approach to practical network security management . Princeton University, 2006
2006
Earlier work this paper cites.
S. Govindavajhala and A. W. Appel, “Automatic configuration vulnerability analysis,” Technical report, Technical Report TR-773-07, Department of Computer Science …, Tech. Rep., 2007
2007
Earlier work this paper cites.
S. Noel and S. Jajodia, “Optimal ids sensor placement and alert prioritization using attack graphs,” Journal of Network and Systems Management , vol. 16, no. 3, pp. 259–275, 2008
2008
Earlier work this paper cites.
P. H. Meland, D. G. Spampinato, E. Hagen, E. T. Baadshaug, K.-M. Krister, and K. S. Velle, “Seamonster: Providing tool support for security modeling,” Norsk informasjonssikkerhetskonferanse, NISK , 2008
2008
Earlier work this paper cites.
J. Homer, X. Ou, and M. A. McQueen, “From attack graphs to automated configuration management-an iterative approach,” Kansas State University Technical Report , 2008
2008
Earlier work this paper cites.
D. Saha, “Extending logical attack graphs for efficient vulnerability analysis,” in Proceedings of the 15th ACM conference on Computer and communications security . ACM, 2008, pp. 63–74
2008
Earlier work this paper cites.
V. Katta, P. Karpati, A. L. Opdahl, C. Raspotnig, and G. Sindre, “Comparing two techniques for intrusion visualization,” in IFIP Working Conference on The Practice of Enterprise Modeling , Springer. Springer, 2010, pp. 1–15
2010
Earlier work this paper cites.
E. M. Hutchins, M. J. Cloppert, R. M. Amin et al. , “Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains,” Leading Issues in Information Warfare & Security Research , vol. 1, no. 1, p. 80, 2011
2011
Earlier work this paper cites.
J. Baker, M. Hansbury, and D. Haynes, “The oval® language specification,” MITRE, Bedford, Massachusetts , 2011
2011
Earlier work this paper cites.
X. Ou and A. Singhal, Quantitative security risk assessment of enterprise networks . Springer, 2011
2011
Earlier work this paper cites.
C. Liu, A. Singhal, and D. Wijesekera, “Using attack graphs in forensic examinations,” in 2012 Seventh International Conference on Availability, Reliability and Security , IEEE. IEEE, 2012, pp. 596–603
2012
Earlier work this paper cites.
L. Wang, S. Jajodia, A. Singhal, P. Cheng, and S. Noel, “k-zero day safety: A network security metric for measuring the risk of unknown vulnerabilities,” IEEE Transactions on Dependable and Secure Computing , vol. 11, no. 1, pp. 30–44, 2013
2013
Earlier work this paper cites.
S. Roschke, F. Cheng, and C. Meinel, “High-quality attack graph-based ids correlation,” Logic Journal of IGPL , vol. 21, no. 4, pp. 571–591, 2013
2013
Cited alongside, same era.
H. Holm, T. Sommestad, M. Ekstedt, and L. NordströM, “Cysemol: A tool for cyber security analysis of enterprises,” in 22nd International Conference and Exhibition on Electricity Distribution (CIRED 2013) , IET. IET, 2013, pp. 1–4
2013
Cited alongside, same era.
H. Holm, M. Ekstedt, T. Sommestad, and M. Korman, “A manual for the cyber security modeling language,” Royal Institute of Technology (KTH), Tech. Rep , 2013
2013
Cited alongside, same era.
S. Yi, Y. Peng, Q. Xiong, T. Wang, Z. Dai, H. Gao, J. Xu, J. Wang, and L. Xu, “Overview on attack graph generation and visualization technology,” in 2013 International Conference on Anti-Counterfeiting, Security and Identification (ASID) , IEEE. IEEE, 2013, pp. 1–6
2013
Cited alongside, same era.
P. Mensah, “Generation and dynamic update of attack graphs in cloud providers infrastructures,” Ph.D. dissertation, CentraleSupélec, 2019
2019
Later among the works it cites.
P. Appana, X. Sun, and Y. Cheng, “What to do first: Ranking the mission impact graph for effective mission assurance,” in 2019 International Conference on Computing, Networking and Communications (ICNC) , IEEE. IEEE, 2019, pp. 567–571
2019
Later among the works it cites.
N. Khakpour, C. Skandylas, G. S. Nariman, and D. Weyns, “Towards secure architecture-based adaptations,” in 2019 IEEE/ACM 14th International Symposium on Software Engineering for Adaptive and Self-Managing Systems (SEAMS) , IEEE. IEEE, 2019, pp. 114–125
2019
Later among the works it cites.
M. Inokuchi, Y. Ohta, S. Kinoshita, T. Yagyu, O. Stan, R. Bitton, Y. Elovici, and A. Shabtai, “Design procedure of knowledge base for practical attack graph generation,” in Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security , 2019, pp. 594–601
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
H. Almohri, “High assurance models for secure systems,” Ph.D. dissertation, Virginia Tech, 2013
2013
Cited alongside, same era.
C. Liu, A. Singhal, and D. Wijesekera, “A model towards using evidence from security events for network attack analysis.” in WOSIS . WOSIS, 2014, pp. 83–95
2014
Cited alongside, same era.
C. Liu., A. Singhal, and D. Wijesekera, “Relating admissibility standards for digital evidence to attack scenario reconstruction,” The Journal of Digital Forensics, Security and Law: JDFSL , vol. 9, no. 2, p. 181, 2014
2014
Cited alongside, same era.
X. Sun, J. Dai, A. Singhal, and P. Liu, “Inferring the stealthy bridges between enterprise network islands in cloud using cross-layer bayesian networks,” in International Conference on Security and Privacy in Communication Networks , Springer. Springer, 2014, pp. 3–23
2014
Cited alongside, same era.
H. M. Almohri, L. T. Watson, D. Yao, and X. Ou, “Security optimization of dynamic networks with probabilistic graph modeling and linear programming,” IEEE Transactions on Dependable and Secure Computing , vol. 13, no. 4, pp. 474–487, 2015
2015
Cited alongside, same era.
C. Liu, A. Singhal, and D. Wijesekera, “A logic-based network forensic model for evidence analysis,” in IFIP International Conference on Digital Forensics , Springer. Springer, 2015, pp. 129–145
2015
Cited alongside, same era.
C. Liu, “A probabilistic logic programming based model for network forensics,” Ph.D. dissertation, George Mason University, 2015
2015
Cited alongside, same era.
J. Sembiring, M. Ramadhan, Y. S. Gondokaryono, and A. A. Arman, “Network security risk analysis using improved mulval bayesian attack graphs,” International Journal on Electrical Engineering and Informatics , vol. 7, no. 4, p. 735, 2015
2015
Cited alongside, same era.
2019
Later among the works it cites.
K. Oosthoek and C. Doerr, “Sok: Att&ck techniques and trends in windows malware,” in International Conference on Security and Privacy in Communication Systems , Springer. Springer, 2019, pp. 406–425
2019
Later among the works it cites.
N. Munaiah, A. Rahman, J. Pelletier, L. Williams, and A. Meneely, “Characterizing attacker behavior in a cybersecurity penetration testing competition,” in 2019 ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM) , IEEE. IEEE, 2019, pp. 1–6
2019
Later among the works it cites.
K. Nickels. (2019) How to be a savvy att&ck consumer. [Online]. Available: https://medium.com/mitre-attack/how-to-be-a-savvy-attack-consumer-63e45b8e94c9
2019
Later among the works it cites.
W. He, H. Li, and J. Li, “Unknown vulnerability risk assessment based on directed graph models: a survey,” IEEE Access , vol. 7, pp. 168 201–168 225, 2019
2019
Later among the works it cites.
V. S. M. Legoy, “Retrieving att&ck tactics and techniques in cyber threat reports,” Master’s thesis, University of Twente, 2019
2019
Later among the works it cites.
E. Aghaei and E. Al-Shaer, “Threatzoom: neural network for automated vulnerability mitigation,” in Proceedings of the 6th Annual Symposium on Hot Topics in the Science of Security , 2019, pp. 1–3
2019
Later among the works it cites.
E. Johns. (2020) Cyber security breaches survey 2020. [Online]. Available: https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/893399/Cyber_Security_Breaches_Survey_2020_Statistical_Release_180620.pdf
2020
Later among the works it cites.
S. Furnell, H. Heyburn, A. Whitehead, and J. N. Shah, “Understanding the full cost of cyber security breaches,” Computer Fraud & Security , vol. 2020, no. 12, pp. 6–12, 2020
2020
Later among the works it cites.
B. Fila and W. Wideł, “Exploiting attack–defense trees to find an optimal set of countermeasures,” in 2020 IEEE 33rd Computer Security Foundations Symposium (CSF) , IEEE. IEEE, 2020, pp. 395–410
2020
Later among the works it cites.
H. Nishihara, Y. Kawanishi, D. Souma, and H. Yoshida, “On validating attack trees with attack effects,” in International Conference on Computer Safety, Reliability, and Security , Springer. Springer, 2020, pp. 309–324
2020
Later among the works it cites.
H. S. Lallie, K. Debattista, and J. Bal, “A review of attack graph and attack tree visual syntax in cyber security,” Computer Science Review , vol. 35, p. 100219, 2020
2020
Later among the works it cites.
O. Stan, R. Bitton, M. Ezrets, M. Dadon, M. Inokuchi, Y. Ohta, Y. Yamada, T. Yagyu, Y. Elovici, and A. Shabtai, “Extending attack graphs to represent cyber-attacks in communication protocols and modern it networks,” IEEE Transactions on Dependable and Secure Computing , pp. 1–1, 2020
2020
Later among the works it cites.
D. Malzahn, Z. Birnbaum, and C. Wright-Hamor, “Automated vulnerability testing via executable attack graphs,” in 2020 International Conference on Cyber Security and Protection of Digital Services (Cyber Security) . IEEE, 2020, pp. 1–10
2020
Later among the works it cites.
T. Wang, Q. Lv, B. Hu, and D. Sun, “Cvss-based multi-factor dynamic risk assessment model for network system,” in 2020 IEEE 10th International Conference on Electronics Information and Emergency Communication (ICEIEC) . IEEE, 2020, pp. 289–294
2020
Later among the works it cites.
L. Zhou, “Security risk analysis based on data criticality,” 2020
2020
Later among the works it cites.
M. McCormack, S. Chandrasekaran, G. Liu, T. Yu, S. D. Wolf, and V. Sekar, “Security analysis of networked 3d printers,” in 2020 IEEE Security and Privacy Workshops (SPW) , IEEE. IEEE, 2020, pp. 118–125
2020
Later among the works it cites.
P. Maynard and K. McLaughlin, “Big fish, little fish, critical infrastructure: An analysis of phineas fisher and the ‘hacktivist’threat to critical infrastructure,” in 2020 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA) , IEEE. IEEE, 2020, pp. 1–7
2020
Later among the works it cites.
R. Kwon, T. Ashley, J. Castleberry, P. Mckenzie, and S. N. G. Gourisetti, “Cyber threat dictionary using mitre att&ck matrix and nist cybersecurity framework mapping,” in 2020 Resilience Week (RWS) , IEEE. IEEE, 2020, pp. 106–112
2020
Later among the works it cites.
M. D. Purba, B. Chu, and E. Al-Shaer, “From word embedding to cyber-phrase embedding: Comparison of processing cybersecurity texts,” in 2020 IEEE International Conference on Intelligence and Security Informatics (ISI) , IEEE. IEEE, 2020, pp. 1–6
2020
Later among the works it cites.
2020
Later among the works it cites.
A. Nadeem, S. Verwer, S. Moskal, and S. J. Yang, “Alert-driven attack graph generation using s-pdfa,” IEEE Transactions on Dependable and Secure Computing , 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
O. Stan, R. Bitton, M. Ezrets, M. Dadon, M. Inokuchi, Y. Ohta, T. Yagyu, Y. Elovici, and A. Shabtai, “Heuristic approach for countermeasure selection using attack graphs,” in 2021 IEEE 34th Computer Security Foundations Symposium (CSF) , IEEE Computer Society. IEEE Computer Society, 2021, pp. 63–78
2021
Later among the works it cites.
H. Binyamini, R. Bitton, M. Inokuchi, T. Yagyu, Y. Elovici, and A. Shabtai, “A framework for modeling cyber attack techniques from security vulnerability descriptions,” in Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining , 2021, pp. 2574–2583
2021
Later among the works it cites.
2021
Later among the works it cites.
A. Sabur, A. Chowdhary, D. Huang, and A. Alshamrani, “Toward scalable graph-based security analysis for cloud networks,” Computer Networks , p. 108795, 2022
2022
Closest in time.
T. Li, Y. Jiang, C. Lin, M. Obaidat, Y. Shen, and J. Ma, “Deepag: Attack graph construction and threats prediction with bi-directional deep learning,” IEEE Transactions on Dependable and Secure Computing , 2022
2022
Closest in time.