Model Assigns Probable Risk Of Attack To Computer Networks

Data breaches are a recurring nightmare for IT managers responsible for securing not only their company’s confidential data, but possibly also sensitive information belonging to their clients, such as social security numbers or health or financial records. To help managers safeguard valuable information most efficiently, computer scientists at the National Institute of Standards and Technology (NIST) are applying security metrics to computer network pathways to assign a probable risk of attack to guide IT managers in securing their networks.

“We analyze all of the paths that system attackers could penetrate through a network,” said computer scientist Anoop Singhal, “and assign a risk to each component of the system. Decision makers can use our assigned probabilities to make wise decisions and investments to safeguard their network.” The research was presented at a conference earlier this month.

Computer networks are made up of components varying from individual computers, to servers and routers. Once inside a network’s firewall, for a seemingly mild-mannered purpose as posting an image to a file transfer protocol (FTP) site, a hacker can travel through the network through a variety of routes to hit the jackpot of valuable data. In addition to hardware, the hacker can break in through software on the computers, especially file-sharing applications that have been blamed for some major data breaches recently.

NIST researchers evaluate each route and assign it a risk based on how challenging it is to the hacker. The paths are determined using a technique called “attack graphs.” A new analysis technique based on attack graphs was jointly developed by Singhal and research colleagues at George Mason University. A patent is pending on the technique.

Singhal and his team determine risk by using these attack graphs and NIST’s National Vulnerability Database (NVD). This government repository includes a collection of security-related software weaknesses that hackers can exploit. NVD data was collected from software vendors and scores are assigned from most to least insecure by experts.

For example in a simple system there is an attacker on a computer, a firewall, router, an FTP server and a database server. The goal for the attacker is to find the simplest path into the jackpot -- the database server. Attack Graph Analysis determines three potential attack paths. For each path in the graph, the NIST researchers assign an attack probability based on the score in the NVD database.

Because it takes multiple steps to reach the goal, the probabilities of each component are multiplied to determine the overall risk. One path takes only three steps. The first step has an 80 percent chance of being hacked, the second, a 90 percent chance. The final step requires great expertise, so there is only a 10 percent probability it can be breached. By multiplying the three probabilities together, that path is pretty secure with a less than 10 percent chance of being hacked.

The next step is for the researchers to expand their research to handle large-scale enterprise networks.

Featured

  • Brivo, Eagle Eye Networks Merge

    Dean Drako, Chairman of Brivo, the leading global provider of cloud-native access control and smart space technologies, and Founder of Eagle Eye Networks, the global leader in cloud AI video surveillance, today announced the two companies will merge, creating the world’s largest AI cloud-native physical security company. The merged company will operate under the Brivo name and deliver a truly unified cloud-native security platform. Read Now

  • Security Industry Association Announces the 2026 Security Megatrends

    The Security Industry Association (SIA) has identified and forecasted the 2026 Security Megatrends, which form the basis of SIA’s signature annual Security Megatrends report defining the top 10 factors influencing both near- and long-term change in the global security industry. Read Now

  • The Future of Access Control: Cloud-Based Solutions for Safer Workplaces

    Access controls have revolutionized the way we protect our people, assets and operations. Gone are the days of cumbersome keychains and the security liabilities they introduced, but it’s a mistake to think that their evolution has reached its peak. Read Now

  • A Look at AI

    Large language models (LLMs) have taken the world by storm. Within months of OpenAI launching its AI chatbot, ChatGPT, it amassed more than 100 million users, making it the fastest-growing consumer application in history. Read Now

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

New Products

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.