• Home
  • Search
  • Boolean Similarity Measure for Assessing Temporal Variation in the Network Attack Surface
  • Cite Icon1
  • https://doi.org/10.1109/comsnets56262.2023.10041303Copy DOI Icon

Boolean Similarity Measure for Assessing Temporal Variation in the Network Attack Surface

  • Jan 3, 2023
  • Ghanshyam S Bopche +2 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

The network security assessment is vital for improving the overall security posture. With diverse opportunities for using networking devices and configuring them, varying software application portfolios, and the increased flexibility of using numerous applications, today's computer networks are subject to continuous evolution. Such ever-growing computer networks in size and complexity lead to information exposure to an increased threat landscape and attack surface variation. The network attack surface constitutes exploitable technical vulnerabilities, software/hardware misconfigurations (i.e., configuration gaps), vulnerable service connectivities, and service-cum-user privileges. An adversary may exploit the network attack surface to penetrate the enterprise networks incrementally. The discovery of new vulnerabilities and vague access control rules can further set off the attack surface variation. Hence, it is essential to consider the temporal aspect of network security. Attack graph, a graphical network security modeling tool, succinctly captures the attack surface of a vulnerable network in the form of initial security conditions, much needed for an adversary for successful incremental network penetration. Existing attack graph-based metrics are inadequate in capturing the variation in the attack surface. We propose to use a Boolean similarity metric to assess the similarity between the goal-oriented attack graphs generated successively for an enterprise network within the chosen sampling interval. We represent individual attack graphs as a Boolean expression to serve our purpose. A Boolean expression is a sum-of-product expression, i.e., a disjunction of attack paths, each a conjunction of initial conditions. We have conducted a set of experiments to validate the efficacy and applicability of the Boolean similarity metric. The results indicate that the Boolean similarity measure can detect the variation in the network attack surface.

Similar Papers
  • Conference Article

Quantitative Analysis of the Network Attack Surface: Identifying Reachable Paths from the External Network to the Intranet Based on Simulation

  • Nov 07, 2025
  • Yu Chen +4
  • Book Chapter

A Memetic Particle Swarm Optimization Algorithm for Network Vulnerability Analysis

  • Apr 26, 2011
  • Mahdi Abadi +1
  • Conference Article
  • Citations4

A Mobile Ambients-Based Approach for Network Attack Modelling and Simulation

  • Jan 01, 2009
  • Virginia N.L Franqueira +3
  • Conference Article
  • Citations9

Time Independent Security Analysis for Dynamic Networks Using Graphical Security Models

  • Aug 01, 2018
  • Simon Yusuf Enoch +2
  • Research Article
  • Citations1

A Short-Normalized Attack Graph Based Approach for Network Attack Analysis

  • Jan 01, 2014
  • IOSR Journal of Computer Engineering
  • Gouri R Patil +1
  • Research Article

Continuous Internal Penetration Testing (CIPT)

  • Aug 30, 2023
  • Journal of Mathematical Techniques and Computational Mathematics
  • Book Chapter
  • Citations2

An Attack Graph Based Approach for Threat Identification of an Enterprise Network

  • Jan 01, 2009
  • Somak Bhattacharya +2
  • Research Article
  • Citations5

Attack Graph Algorithm in the Application of Intrusion Detection System

  • Sep 30, 2013
  • International Journal of Security and Its Applications
  • Zhiyong Luo +4
  • Conference Article
  • Citations11

Automatic Generation of Host-Based Network Attack Graph

  • Jan 01, 2009
  • Shangqin Zhong +2
  • Conference Article
  • Citations13

Using vulnerability information and attack graphs for intrusion detection

  • Aug 01, 2010
  • Sebastian Roschke +2
  • Conference Article
  • Citations8

Attack Graph-based Solution for Vulnerabilities Impact Assessment in Dynamic Environment

  • Mar 28, 2022
  • Antoine Boudermine +2
  • Conference Article
  • Citations640

A scalable approach to attack graph generation

  • Oct 30, 2006
  • Xinming Ou +2
  • Conference Article

A Simplified Model for Attack Paths Construction in Multiple Hosts

  • Sep 01, 2010
  • Xiao-Song Zhang +2
  • Book Chapter
  • Citations95

GARNET: A Graphical Attack Graph and Reachability Network Evaluation Tool

  • Sep 15, 2008
  • Leevar Williams +2
  • Single Book

Graph Neural Networks and Transformers for Advanced Cyber Threat Detection and Network Security

  • Apr 21, 2026
  • Murali Krishna Pasupuleti
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.