To accurately assess the vulnerability of computer networks, the paper proposes a BNAG model and vulnerability assessment algorithm. Firstly, a new attack graph model is proposed, as well as the E-Loop algorithm, which is used for solving the loop problem in the attack graph. Secondly, to disentangle the confused node relationship during the attack graph conversion process, an algorithm is designed to generate a Bayesian network attack graph model BNAG. Finally, to obtain the reachability of the path, the metrics such as node attack difficulty and node state transition is introduced, and the corresponding algorithm is given. Based on this, the posterior probability is calculated.
Lijian WangBin WangPeng Yongjun
Xinjian LvNan ShiJing WeiYuan TianJie LiJianping Li