IP Library Granted Patent US 12,238,132
Granted Patent B2
US 12,238,132 · App. 17/831,848 · Granted Feb 25, 2025

Method and system for facilitating a ranking score using attack volume to find optimal configurations

Inventors: Massimiliano Albanese (Potomac, MD); Ibifubara Iganibo (Fairfax, VA); Marc E. Mosko (Santa Cruz, CA); Alejandro E. Brito (Mountain View, CA)
Assignee: Xerox Corporation
H04L63/1433H04L41/0816H04L63/1416H04L63/1425H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,238,132
App. No.
17/831,848
Granted
Feb 25, 2025
Kind
B2
Abstract

A system determines, in a graph which represents a system of components: vulnerability nodes representing known vulnerabilities to the system, including exposed and non-exposed vulnerability nodes associated with an exploitation likelihood; and dependency nodes representing components in the system, including direct and indirect dependency nodes associated with an exposure factor indicating an amount of degradation based on exploitation of an associated vulnerability. The system calculates, across all non-exposed vulnerability nodes and all direct dependency nodes, a score which indicates an attack volume based on at least: a respective second likelihood associated with a non-exposed vulnerability node; an exposure factor associated with a dependency node which represents a component directly degraded based on exploitation of a vulnerability; and a loss of utility of the component. The score is calculated for one or more configurations of the system, and the system selects an optimal configuration based on the calculated score.

Claims (103)

1. A computer-executable method, comprising:

determining, in a graph which represents a system of components:

vulnerability nodes which represent known vulnerabilities to the system, wherein exposed vulnerability nodes represent vulnerabilities at a perimeter of the system and non-exposed vulnerability nodes represent vulnerabilities not at the perimeter of the system, and

wherein the exposed vulnerability nodes are each associated with a first likelihood of exploitation and the non-exposed vulnerability nodes are each associated with a second likelihood of exploitation based on a prior likelihood associated with a prior vulnerability node which enables a respective non-exposed vulnerability node; and

dependency nodes which represent the components in the system,

wherein direct dependency nodes are each associated with an exposure factor which indicates an amount of degradation caused to a respective component based on exploitation of a respective vulnerability which directly degrades the respective component;

calculating, across all the non-exposed vulnerability nodes and all the direct dependency nodes, a score which indicates an attack volume of the system using a metric which is based on at least:

a respective second likelihood associated with a first non-exposed vulnerability node;

an exposure factor associated with a respective dependency node which represents a component directly degraded based on exploitation of a vulnerability represented by the first non-exposed vulnerability node; and

a loss of utility of the component represented by the respective dependency node,

wherein the score is calculated for one or more configurations of the system of components; and

selecting, based on the calculated score for the one or more configurations of the system of components, a first configuration of the one or more configurations of the system of components which optimizes a configuration of the system.

2. The method of claim 1 ,

wherein the graph comprises a multi-layer graph which includes a configuration subgraph, a vulnerability subgraph, and a dependency subgraph,

wherein the vulnerability subgraph includes the vulnerability nodes, which include the exposed vulnerability nodes and the non-exposed vulnerability nodes, and

wherein a directed edge from an exposed vulnerability node or a first non-exposed vulnerability node to a second non-exposed vulnerability node is associated with the second likelihood.

3. The method of claim 2 , wherein calculating the score using the metric is further based on:

a weighted summation of a loss of utility, across all the components represented by the direct dependency nodes, caused by an exploitation of any vulnerability which directly or indirectly degrades a respective component,

wherein a respective second likelihood associated with a respective non-exposed vulnerability node is used as a weight in the weighted summation.

4. The method of claim 2 ,

wherein the dependency graph includes the dependency nodes, which include the direct dependency nodes and indirect dependency nodes, and

wherein a respective indirect dependency node is associated with a respective dependency function which indicates a level of dependency of the respective indirect dependency node upon a dependency node reachable by a directed edge from the respective indirect dependency node to the dependency node.

5. The method of claim 4 ,

wherein calculating the score is performed across all the non-exposed vulnerability nodes, all the direct dependency nodes, and all the indirect dependency nodes using the metric and is further based on:

the respective dependency function associated with the respective indirect dependency node.

6. The method of claim 5 , wherein calculating the score using the metric is further based on:

a set of components which depend upon a respective component represented by the respective direct dependency node based on a chain of directed edges.

7. The method of claim 5 , further comprising:

applying a second configuration for the system based on the calculated score for the second configuration using the metric,

wherein the second configuration prioritizes a set of actions based on the calculated score for the second configuration.

8. The method of claim 5 , further comprising:

applying, based on the calculated score for the one or more configurations of the system of components using the metric, an artificial intelligence search or a dynamic programming tool to obtain a third configuration which has an improved security posture over at least one of the one or more configurations of the system of components.

9. The method of claim 5 , further comprising:

displaying, on a screen of a user device, one or more interactive elements which allow the user to:

view the multi-layer graph, including the vulnerability nodes, the dependency nodes, directed edges, the first and second likelihoods of exploitation associated with the exposed and non-exposed vulnerability nodes, exposure factors, and dependency functions in any of the configuration subgraph, the vulnerability subgraph, and the dependency subgraph;

view or modify configuration parameters for the system using a graph generation tool to obtain the one or more configurations of the system of components;

calculate the score using the metric for the one or more configurations of the system of components;

view the calculated score for the one or more configurations of the system of components;

select a first configuration of the one or more configurations of the system of components;

view an average attack volume for the selected first configuration; and

view an explanation of evidence associated with the selected configuration.

10. The method of claim 1 ,

wherein the first likelihood of exploitation and the second likelihood of exploitation are associated with a Common Vulnerability Scoring System exploitability score.

11. The method of claim 1 , wherein the score is at least one of:

a first score calculated based on eliminating security constraints which contradict operational requirements, wherein the first score defines a lower bound on the attack volume;

a second score calculated based on maintaining operation of a testbed while considering settings of current values,

wherein when a current value is not feasible against a set of non-relaxable constraints, the current value is invalidated, which enables a set of vulnerabilities associated with the current value, and

wherein when the current value is feasible against the set of non-relaxable constraints, the system relaxes all conflicting relaxable constraints;

a third score calculated based on a recommended configuration; and

a fourth score calculated based on relaxing all constraints of the testbed, wherein the fourth score defines an upper bound on the attack volume.

12. The method of claim 1 ,

wherein selecting the first configuration which optimizes the configuration of the system is based on at least one of a security priority and an operational priority.

13. A computer system comprising:

a processor; and

a storage device storing instructions that when executed by the processor cause the processor to perform a method, the method comprising:

determining, in a graph which represents a system of components:

vulnerability nodes which represent known vulnerabilities to the system, wherein exposed vulnerability nodes represent vulnerabilities at a perimeter of the system and non-exposed vulnerability nodes represent vulnerabilities not at the perimeter of the system, and

wherein the exposed vulnerability nodes are each associated with a first likelihood of exploitation and the non-exposed vulnerability nodes are each associated with a second likelihood of exploitation based on a prior likelihood associated with a prior vulnerability node which enables a respective non-exposed vulnerability node; and

dependency nodes which represent the components in the system,

wherein direct dependency nodes are each associated with an exposure factor which indicates an amount of degradation caused to a respective component based on exploitation of a respective vulnerability which directly degrades the respective component;

calculating, across all the non-exposed vulnerability nodes and all the direct dependency nodes, a score which indicates an attack volume of the system using a metric which is based on at least:

a respective second likelihood associated with a first non-exposed vulnerability node;

an exposure factor associated with a respective dependency node which represents a component directly degraded based on exploitation of a vulnerability represented by the first non-exposed vulnerability node; and

a loss of utility of the component represented by the respective dependency node,

wherein the score is calculated for one or more configurations of the system of components; and

selecting, based on the calculated score for the one or more configurations of the system of components, a first configuration of the one or more configurations of the system of components which optimizes a configuration of the system.

14. The computer system of claim 13 ,

wherein the graph comprises a multi-layer graph which includes a configuration subgraph, a vulnerability subgraph, and a dependency subgraph,

wherein the vulnerability subgraph includes the vulnerability nodes, which include the exposed vulnerability nodes and the non-exposed vulnerability nodes, and

wherein a directed edge from an exposed vulnerability node or a first non-exposed vulnerability node to a second non-exposed vulnerability node is associated with the second likelihood.

15. The computer system of claim 14 , wherein calculating the score using the metric is further based on:

a weighted summation of a loss of utility, across all the components represented by the direct dependency nodes, caused by an exploitation of any vulnerability which directly or indirectly degrades a respective component,

wherein a respective second likelihood associated with a respective non-exposed vulnerability node is used as a weight in the weighted summation.

16. The computer system of claim 14 ,

wherein the dependency graph includes the dependency nodes, which include the direct dependency nodes and indirect dependency nodes, and

wherein a respective indirect dependency node is associated with a respective dependency function which indicates a level of dependency of the respective indirect dependency node upon a dependency node reachable by a directed edge from the respective indirect dependency node to the dependency node, and

wherein calculating the score is performed across all the non-exposed vulnerability nodes, all the direct dependency nodes, and all the indirect dependency nodes using the metric and is further based on the respective dependency function associated with the respective indirect dependency node.

17. The computer system of claim 16 , wherein calculating the score using the metric is further based on:

a set of components which depend upon a respective component represented by the respective direct dependency node based on a chain of directed edges.

18. The computer system of claim 16 , wherein the method further comprises:

displaying, on a screen of a user device, one or more interactive elements which allow the user to:

view the multi-layer graph, including the vulnerability nodes, the dependency nodes, directed edges, the first and second likelihoods of exploitation associated with the exposed and non-exposed vulnerability nodes, exposure factors, and dependency functions in any of the configuration subgraph, the vulnerability subgraph, and the dependency subgraph;

view or modify configuration parameters for the system using a graph generation tool to obtain the one or more configurations of the system of components;

calculate the score using the metric for the one or more configurations of the system of components;

view the calculated score for the one or more configurations of the system of components;

select a first configuration of the one or more configurations of the system of components;

view an average attack volume for the selected first configuration; and

view an explanation of evidence associated with the selected configuration.

19. A non-transitory computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method, the method comprising:

determining, in a graph which represents a system of components:

vulnerability nodes which represent known vulnerabilities to the system, wherein exposed vulnerability nodes represent vulnerabilities at a perimeter of the system and non-exposed vulnerability nodes represent vulnerabilities not at the perimeter of the system, and

wherein the exposed vulnerability nodes are each associated with a first likelihood of exploitation and the non-exposed vulnerability nodes are each associated with a second likelihood of exploitation based on a prior likelihood associated with a prior vulnerability node which enables a respective non-exposed vulnerability node; and

dependency nodes which represent the components in the system,

wherein direct dependency nodes are each associated with an exposure factor which indicates an amount of degradation caused to a respective component based on exploitation of a respective vulnerability which directly degrades the respective component, and

wherein indirect dependency nodes are each associated with a respective dependency function which indicates a level of dependency of a respective indirect dependency node upon a dependency node;

calculating, across all the non-exposed vulnerability nodes, all the direct dependency nodes, and all the indirect dependency nodes, a score for one or more configurations of the system of components, wherein the score indicates an attack volume of the system using a metric which is based on at least:

a respective second likelihood associated with a first non-exposed vulnerability node;

an exposure factor associated with a respective dependency node which represents a component directly degraded based on exploitation of a vulnerability represented by the first non-exposed vulnerability node;

a loss of utility of the component represented by the respective dependency node; and

a respective dependency function associated with a respective indirect dependency node; and

selecting, based on the calculated score for the one or more configurations of the system of components, a first configuration of the one or more configurations of the system of components which optimizes a configuration of the system.

20. The non-transitory computer-readable storage medium of claim 19 , wherein the method further comprises:

applying, based on the calculated score for the one or more configurations of the system of components using the metric, an artificial intelligence search or a dynamic programming tool to obtain a third configuration which has an improved security posture over at least one of the one or more configurations of the system of components.

Assignments (9)
CONFIRMATORY LICENSE Recorded May 6, 2026
From: PALO ALTO RESEARCH CENTER
To: GOVERNMENT OF THE UNITED STATES AS REPRESENTED BY THE SECRETARY OF THE AIR FORCE
Reel/Frame 075560/0125 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2026
From: XEROX CORPORATION
To: GENESEE VALLEY INNOVATIONS, LLC
Reel/Frame 075020/0755 →
SECOND LIEN NOTES PATENT SECURITY AGREEMENT Recorded Jul 2, 2025
From: XEROX CORPORATION
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 071785/0550 →
FIRST LIEN NOTES PATENT SECURITY AGREEMENT Recorded Apr 11, 2025
From: XEROX CORPORATION
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 070824/0001 →
SECURITY INTEREST Recorded Feb 13, 2024
From: XEROX CORPORATION
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066741/0001 →
SECURITY INTEREST Recorded Nov 20, 2023
From: XEROX CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 065628/0019 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVAL OF US PATENTS 9356603, 10026651, 10626048 AND INCLUSION OF US PATENT 7167871 PREVIOUSLY RECORDED ON REEL 064038 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 28, 2023
From: PALO ALTO RESEARCH CENTER INCORPORATED
To: XEROX CORPORATION
Reel/Frame 064161/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2023
From: PALO ALTO RESEARCH CENTER INCORPORATED
To: XEROX CORPORATION
Reel/Frame 064038/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2022
From: ALBANESE, MASSIMILIANO; IGANIBO, IBIFUBARA; MOSKO, MARC E.; BRITO, ALEJANDRO E.
To: PALO ALTO RESEARCH CENTER INCORPORATED
Reel/Frame 060125/0403 →
Continuity (2)
Provisional Application 63334032 · Apr 22, 2022
Related Publication 20230344855A1 · Oct 26, 2023
References Cited (109)
US 6742128B1 · Joiner · 2004 [cited by applicant]
US 6952779B1 · Cohen · 2005 [cited by examiner]
US 7013395B1 · Swiler · 2006 [cited by applicant]
US 7627900B1 · Noel · 2009 [cited by applicant]
US 9215158B1 · Adogla · 2015 [cited by applicant]
US 9317692B2 · Elder · 2016 [cited by applicant]
US 9684865B1 · Ezick · 2017 [cited by applicant]
US 9705978B1 · Kenigsberg · 2017 [cited by applicant]
US 9736173B2 · Li · 2017 [cited by applicant]
US 9979750B2 · Wu · 2018 [cited by examiner]
US 10104120B2 · Gopalakrishna · 2018 [cited by examiner]
US 10230745B2 · Singh · 2019 [cited by examiner]
US 10270789B2 · Singh · 2019 [cited by examiner]
US 10313382B2 · Noel · 2019 [cited by applicant]
US RE47757E · Hering · 2019 [cited by applicant]
US 10516761B1 · A · 2019 [cited by applicant]
US 10601854B2 · Lokamathe · 2020 [cited by applicant]
US 10771489B1 · Bisht · 2020 [cited by applicant]
US 10812499B2 · Hassanzadeh · 2020 [cited by applicant]
US 10904270B2 · Muddu · 2021 [cited by applicant]
US 11265292B1 · Leviseur · 2022 [cited by applicant]
US 11647039B2 · Crabtree · 2023 [cited by examiner]
US 11757920B2 · Crabtree · 2023 [cited by examiner]
US 20060265324A1 · Leclerc · 2006 [cited by applicant]
US 20070011319A1 · McClure · 2007 [cited by applicant]
US 20080098479A1 · O'Rourke · 2008 [cited by applicant]
US 20080104665A1 · Naldurg · 2008 [cited by applicant]
US 20080172716A1 · Talpade · 2008 [cited by applicant]
US 20090077666A1 · Chen · 2009 [cited by applicant]
US 20090265199A1 · Moerdler · 2009 [cited by applicant]
US 20100095381A1 · Levi · 2010 [cited by applicant]
US 20100192195A1 · Dunagan · 2010 [cited by applicant]
US 20130232331A1 · Farhan · 2013 [cited by applicant]
US 20130247205A1 · Schrecker · 2013 [cited by applicant]
US 20150058993A1 · Choi · 2015 [cited by applicant]
US 20150244734A1 · Olson · 2015 [cited by applicant]
US 20160050116A1 · Sheshadri · 2016 [cited by applicant]
US 20160205122A1 · Bassett · 2016 [cited by applicant]
US 20170034023A1 · Nickolov · 2017 [cited by applicant]
US 20170078320A1 · Hughes · 2017 [cited by applicant]
US 20170177740A1 · Abaya · 2017 [cited by applicant]
US 20170195349A1 · Shabtai · 2017 [cited by applicant]
US 20170286690A1 · Chari · 2017 [cited by applicant]
US 20170289187A1 · Noel · 2017 [cited by applicant]
US 20170324768A1 · Crabtree · 2017 [cited by applicant]
US 20180210927A1 · Karam · 2018 [cited by applicant]
US 20180322407A1 · Baum · 2018 [cited by applicant]
US 20190098039A1 · Gates · 2019 [cited by applicant]
US 20200053116A1 · Soroush · 2020 [cited by applicant]
US 20200110774A1 · Lakshmanan · 2020 [cited by applicant]
US 20200137104A1 · Hassanzadeh · 2020 [cited by applicant]
US 20200167705A1 · Risoldi · 2020 [cited by applicant]
US 20200175174A1 · Bakalli · 2020 [cited by applicant]
US 20200177608A1 · Okunlola · 2020 [cited by applicant]
US 20200177615A1 · Grabois · 2020 [cited by applicant]
US 20200177617A1 · Hadar · 2020 [cited by applicant]
US 20200177618A1 · Hassanzadeh · 2020 [cited by applicant]
US 20200244691A1 · Veeramany · 2020 [cited by applicant]
US 20200311630A1 · Risoldi · 2020 [cited by applicant]
US 20200412758A1 · Trivellato · 2020 [cited by applicant]
US 20210012012A1 · Soroush · 2021 [cited by applicant]
US 20210014065A1 · Gourisetti · 2021 [cited by applicant]
US 20210014264A1 · Soroush · 2021 [cited by applicant]
US 20210014265A1 · Hadar · 2021 [cited by applicant]
US 20210409439A1 · Engelberg · 2021 [cited by applicant]
US 20220014534A1 · Basovskiy · 2022 [cited by applicant]
US 20220191230A1 · Morgan · 2022 [cited by applicant]
US 20220263860A1 · Crabtree · 2022 [cited by applicant]
CN 106991325A · 2017 [cited by applicant]
CN 106997437A · 2017 [cited by applicant]
CN 107038380A · 2017 [cited by applicant]
CN 107066256A · 2017 [cited by applicant]
CN 108123962A · 2018 [cited by applicant]
CN 110138788A · 2019 [cited by applicant]
CN 110188871A · 2019 [cited by applicant]
CN 110191120A · 2019 [cited by applicant]
CN 111611586A · 2020 [cited by applicant]
CN 112766374A · 2021 [cited by applicant]
KR 102079970B1 · 2020 [cited by applicant]
WO 0070463A1 · 2000 [cited by applicant]
WO 2007143226A2 · 2007 [cited by applicant]
WO 2019186722A1 · 2019 [cited by applicant]
Albanese, M., & Jajodia, S. (2017). A Graphical Model to Assess the Impact of Multi-Step Attacks. The Journal of Defense Modeling and Simulation. 79-93. [cited by applicant]
Albanese, M., Pugliese, A., & Subrahmanian, V. (2013). Fast Activity Detection: Indexing for Temporal Stochastic Automaton-Based Activity Models. IEEE Transactions on Knowledge and Data Engineering, 360-373. [cited by applicant]
Bahl, P., Barham, P., & Black, R. (2006). Discovering Dependencies for Network Management. ACM HotNets. [cited by applicant]
BeyondTrust. (2018). Retina. Retrieved from Retina: https://www.beyondtrust.com/products/retina-network-security-scanner/. [cited by applicant]
CyVision. (2018). CyVision. Retrieved from CyVision: https://www.cyvisiontechnologies.com/. [cited by applicant]
GraphX. (2018). GraphX. Retrieved from GraphX: https://spark.apache.org/graphx/. [cited by applicant]
Leversage, D., & Byres, E. (2008). Estimating a system's mean time-to-compromise. IEEE Security & Privacy, 52-60. [cited by applicant]
Mitre. (2018). CVE. Retrieved from CVE: https://cve.mitre.org/. [cited by applicant]
MSR. (2018). Z3 Guide. Retrieved from Z3 Guide: https://rise4fun.com/z3/tutorialcontent/guide#h23. [cited by applicant]
Natarajan, A., Ning, P., Liu, Y., Jajodia, S., & Hutchinson, S. (2012). NSDMiner: Automated Discovery of Network Service Dependencies. IEEE INFOCOM. [cited by applicant]
NIST. (2018). Retrieved form https://nvd.nist.gov/. [cited by applicant]
OMG. (Mar. 2015). Data Distribution Service Specification Version 1.4. Retrieved from OMG DDS: https://www.omg.org/spec/DDS/About-DDS/. [cited by applicant]
RTI. (2017). RTI Routing Service. Retrieved from RTI Routing Service: https://rti.com/products/dds/routing-service.html. [cited by applicant]
SANS. (2002). SANS Institute, “Quantitative Risk Analysis Step-By-Step”. Retrieved from Quantitative Risk Analysis Step-by-Step: https://www.sans.org/reading-room/whitepapers/auditing/quantitative-risk-analysis-step-by-… [cited by applicant]
Schrecker, S., Soroush, H., & Molina, J. (2016). “Industrial Internet of Things vol. G4: Security Framework”,. CreateSpace Independent Publishing Platform. [cited by applicant]
Soroush, H., Irey, P., & Pardo-Castellote, G. (2015). Next-Generation Cybersecurity for Advanced Real-Time Distributed Systems. Intelligent Ships Symposium. [cited by applicant]
StackOverflow. (2018). StackOverflow. Retrieved from StackOverflow: https://stackflow.com/. [cited by applicant]
Tenable. (2018). Nessus. Retrieved from Nessus: https://www.tenable.com/products/nessus/nessus-professional. [cited by applicant]
Venkatesan, S., Albanese, M., & Jajodia, S. (2015). Distributing Stealthy Botnets through Strategic Placement of Detectors. IEEE Conference on Communications and Network Security (IEEE CNS). [cited by applicant]
Venkatesan, S., Albanese, M., Cybenko, G., & Jajodia, S. (2016). A Moving Target Defense Approach to Disrupting Stealthy Botnets. ACM Workshop on Moving Target Defense (MTD). [cited by applicant]
Welsh, M. (2013). What I Wish System Researchers Would Work On. Retrieved from http://matt-welsh.blogspot.com/2013/05/what-i-wish-systems-researchers-would.html. [cited by applicant]
Xu, Tu., & Zhou, Y. (2015). Systems Approaches to Tackling Configuration Errors: A Survey. ACM Comput. Surv. [cited by applicant]
Gemini George, A Graph-Based Security Framework for Securing Industrial IoT Networks From Vulnerability Exploitations, IEEE Access (vol. 6, pp. 43586-43601), Jan. 1, 2018, 16 pages (Year: 2018). [cited by applicant]
Brigitte Boden, Mining Coherent Subgraphs in Multi-Layer Graphs with Edge Labels, Data Management and Data Exploration Group RWTH Aachen University, Germany, Proceedings of the 18th ACM SIGKDD international conference o… [cited by applicant]
Ibifubara Iganibo, Vulnerability Metrics for Graph-based Configuration Security, 2021, Center for Secure Information Systems, George Mason University, Fairfax, U.S.A. ,Palo Alto Research Center, Palo Alto, U.S.A, 12 pag… [cited by applicant]
Massimilliano Albanese, A Graphic Model to Assess the Impact of Multi-Step Attacks, Journal of Defense Modeling and Simulation: Applications, Methodology, Technology, 2018, vol. 15(1) 79-93 (Year: 2018) Retrieved from h… [cited by applicant]
Mridul Sankar Barik, A Graph Data Model for Attack Graph Generation and Analysis, Dept. of Comp. Sc. and Engg., Jadavpur University Kolkata, India {msbarikm,chandanm}@cse.jdvu.ac.In. 2014, 12 pages (Year: 2014). [cited by applicant]
Cited By (1)
US 12,381,903