arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.35414cs.CR

基于AI的漏洞评估能力与网络攻击图分析

AI-Based Vulnerability Assessment Capability and Cyber Attack Graph Analysis

Joni Herttuainen, Kirsi Hellsten, Vesa Kuikka, Ambrose Kam, Arlanda Johnson, David Welsh, Kimmo K. Kaski

首次发表 更新
浏览论文内容

中文总结 AI 辅助

针对传统防御无法应对复杂网络威胁的问题,本文结合Vortex/Crow框架与概率攻击图模型两种AI方法,经乌克兰电网攻击场景验证,可有效识别攻击路径、定位关键防御目标并辅助优先级决策。

中文摘要 AI 辅助

针对关键任务基础设施的网络威胁正变得愈发复杂,而发起攻击的门槛却在持续降低。杀毒软件、防火墙这类传统单点解决方案属于被动防御,无法应对现代攻击面的组合式复杂性。本文结合两种互补方法展开研究:洛克希德·马丁公司的Vortex/Crow框架(即涡流/乌鸦框架),该框架在行业标准网络知识图谱上应用多智能体强化学习(MARL),以识别攻击向量与TTPs(战术、技术和程序)并划分优先级;阿尔托大学的概率攻击图模型,该模型结合网络拓扑及其漏洞计算系统级风险指标。研究以2015年乌克兰电网网络攻击作为记录完备的验证场景。将两种方法独立应用于同一运营技术(OT)网络拓扑时,二者得出的攻击向量与利用序列均与事件记录中记载的内容一致,从而实现了相互交叉验证。通过节点级消除实验开展的攻击图分析表明,工业控制系统(ICS)是攻击传播的最关键促成因素,属于防御加固的高优先级目标。对比CVSS(v2.0)与IronMiner的漏洞评分结果,二者总体一致,其中IronMiner在网络外围节点上能提供更具可操作性的区分度。这种基线评估加节点级消除的分层方法经证明可扩展至大型企业网络,从而为防御者提供了一条结构化的AI赋能路径,使其能在现实的时间与资源约束下确定缓解措施的优先级。

英文摘要

Cyber threats targeting mission-critical infrastructure are becoming more sophisticated while the barrier to launching attacks continues to fall. Traditional point solutions like antivirus and firewalls are reactive and fail to address the combinatorial complexity of modern attack surfaces. This paper presents an investigation combining two complementary methodologies: Lockheed Martin's Vortex/Crow framework, which applies multi-agent reinforcement learning (MARL) over industry-standard cyber knowledge graph to identify and prioritize attack vectors and TTPs (tactics, techniques, and procedures); and Aalto's probabilistic attack graph model that combines network topology and its vulnerabilities to compute system-level risk metrics. The 2015 Ukraine Power Grid cyberattack serves as a well-documented validation scenario. Applied independently to the same operational technology (OT) network topology, both methodologies converge on the same attack vectors and exploit sequences as those documented in the incident record, thus providing mutual cross-validation. Attack graph analyses using node-level elimination experiments identify industrial control systems (ICS) as the most critical enablers of attack propagation, representing high-priority targets for defensive hardening. Comparison of CVSS (v2.0) and IronMiner vulnerability scoring yields in general consistent results, with IronMiner providing more actionable differentiation at network periphery nodes. The layered methodology of baseline assessment and node-level elimination proves to be scalable to large enterprise networks, thus offering defenders a structured, AI-enabled path to prioritize mitigation under realistic time and resource constraints.

发表机构

  • Aalto University School of Science(阿尔托大学理学院)
  • Lockheed Martin(洛克希德·马丁)

机构由 AI 辅助整理,请以论文原文为准。

↑