MulVAL: A logic-based network security analyzer
Xinming Ou, Sudhakar Govindavajhala, and Andrew W. Appel Princeton University
MulVAL: A logic-based network security analyzer Xinming Ou, - - PowerPoint PPT Presentation
14th USENIX Security Symposium, August 2005 MulVAL: A logic-based network security analyzer Xinming Ou, Sudhakar Govindavajhala, and Andrew W. Appel Princeton University Outline Introduction Representation Vulnerability
Xinming Ou, Sudhakar Govindavajhala, and Andrew W. Appel Princeton University
MulVAL: A logic-based network security analyzer
2
MulVAL: A logic-based network security analyzer
3
Conducts multi-host, multi-stage vulnerability analysis
Bug spec, configuration, reasoning rules, system permission, privilege
for networks with thousands of machines
MulVAL: A logic-based network security analyzer
4
such as CERT, BugTraq etc
MulVAL: A logic-based network security analyzer
5
What vulnerabilities have been reported and do they exist on my
What software and services are running on my hosts, and how are
How are my network routers and firewalls configured?
Who are the users of my network?
What is the model of how all these components interact?
What accesses do I want to permit?
MulVAL: A logic-based network security analyzer
6
MulVAL: A logic-based network security analyzer
7
MulVAL: A logic-based network security analyzer
8
a formal specification language for recognizing vulnerabilities http://oval.mitre.org/documents/docs-03/intro/intro.html
a database that provides a vulnerability’s effect http://icat.nist.gov/icat.cfm
MulVAL: A logic-based network security analyzer
9
MulVAL: A logic-based network security analyzer
10
MulVAL: A logic-based network security analyzer
11
MulVAL: A logic-based network security analyzer
12
MulVAL: A logic-based network security analyzer
13
MulVAL: A logic-based network security analyzer
14
MulVAL: A logic-based network security analyzer
15
MulVAL: A logic-based network security analyzer
16
MulVAL: A logic-based network security analyzer
17
MulVAL: A logic-based network security analyzer
18
MulVAL: A logic-based network security analyzer
19
MulVAL: A logic-based network security analyzer
20
MulVAL: A logic-based network security analyzer
21
MulVAL: A logic-based network security analyzer
22
MulVAL: A logic-based network security analyzer
23