arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

用于活动目录安全强化的实用图优化和人工智能驱动模型

Practical Graph Optimisation and AI-Driven Models for Active Directory Security Hardening

Huy Q. Ngo

arXiv 2607.22009首次发表:更新:

发表机构

University of Adelaide(阿德莱德大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究针对活动目录安全强化问题,提出基于博弈论和优化的决策模型,包括蜜罐/诱饵放置、考虑动态性的防御策略、自适应优先级排序及端到端模型,以应对现有方案不足,虽模型计算难但有重要意义。

AI 中文摘要

微软的活动目录(AD)是一种目录服务,使IT管理员能够管理安全权限并控制Windows域网络内的访问。作为许多组织的核心管理系统,AD已成为攻击者的主要目标。虽然存在许多强化攻击图的解决方案,但在应对AD攻击图特有的几个关键实际挑战方面存在不足。现有模型常假设图是静态的,而实际AD环境高度动态;多数解决方案限于撤销漏洞的防御措施,更积极的防御机制未充分研究;由于并非所有补救措施都可实施,实用的端到端模型必须将系统管理员反馈纳入优先级排序过程。本文旨在通过研究和提出一些基于博弈论和优化的决策模型来解决这些限制。首先提出基于最小化最短路径数量和域管理员可到达节点数量原则的蜜罐/诱饵放置模型;在此基础上引入考虑AD图动态/时间性质的防御策略;引入向IT管理员查询每个高风险攻击路径以进行调解的自适应优先级排序模型;最后引入通过找到通用自适应边删除策略来最小化系统管理员批准工作量的端到端自适应优先级排序模型。我们表明所有贡献模型背后的问题在计算上都是难以处理的。

英文摘要

Microsoft's Active Directory (AD) is a directory service that enables the IT admin to manage security permissions and control access within a Windows domain network. As a core management system in many of organisation, AD has become a primary target for adversaries. While many solutions for hardening attack graphs exist, these efforts fall short in addressing several key practical challenges specific to the AD attack graph. First, existing models often assume the graph is static, whereas a real-world AD environment is highly dynamic. Second, most proposed solutions are limited to the defensive measure of revoking vulnerabilities (edge removal), while more active defence mechanisms are largely unstudied. Third, because not all remediations are implementable, a practical end-to-end model must incorporate system admin feedback into the prioritisation process. This thesis aims to address these limitations by studying and proposing a number of game-theoretic and optimisation-based decision-making models. First, we propose a honeypot/decoy placement model based on the principle of minimising the number of shortest paths and the number of Domain Admin-reachable nodes. Second, building on this model, we introduce a defence strategy that considers the dynamic/temporal nature of the AD graph, where the objective is to find the location to deploy decoys that maximises the worst-case incident response time. Third, we introduce an adaptive prioritisation model that queries each high-risk attack path to the IT administrator for mediation. Finally, we introduce an end-to-end adaptive prioritisation model that minimises the approval effort of the system admin by finding a general adaptive edge-removal policy that generalises the system admin's decisions to edges with similar risk features. We show that the problems underlying all of the contributed models are computationally intractable.

CommentsPhD Thesis

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑