{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/102416"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/102416","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"An approach to incorporating uncertainty in network security analysis","abstract":"Attack graphs used in network security analysis are analyzed to determine sequences of exploits that lead to successful acquisition of privileges or data at critical assets. An attack graph edge corresponds to a vulnerability, tacitly assuming a connection exists and tacitly assuming the vulnerability is known to exist. In this thesis, we explore use of {\\em uncertain graphs} to extend the paradigm to include lack of certainty in connection and/or existence of a vulnerability. We extend the standard notion of uncertain graph (where the existence of each edge is probabilistically independent) however, as significant correlations on edge existence probabilities exist in practice, owing to common underlying causes for disconnectivity and/or presence of vulnerabilities. Our extension describes each edge probability as a Boolean expression of independent indicator random variables. This thesis (i) shows that this formalism is maximally descriptive in the sense that it can describe any joint probability distribution function of edge existence, (ii) shows that when these Boolean expressions are monotone then we can easily perform uncertainty analysis of edge probabilities, and (iii) uses these results to model a partial attack graph of the Stuxnet worm and a small enterprise network and to answer important security-related questions in a probabilistic manner.","abstract_html":"Attack graphs used in network security analysis are analyzed to determine sequences of exploits that lead to successful acquisition of privileges or data at critical assets. An attack graph edge corresponds to a vulnerability, tacitly assuming a connection exists and tacitly assuming the vulnerability is known to exist. In this thesis, we explore use of {\\em uncertain graphs} to extend the paradigm to include lack of certainty in connection and/or existence of a vulnerability. We extend the standard notion of uncertain graph (where the existence of each edge is probabilistically independent) however, as significant correlations on edge existence probabilities exist in practice, owing to common underlying causes for disconnectivity and/or presence of vulnerabilities. Our extension describes each edge probability as a Boolean expression of independent indicator random variables. This thesis (i) shows that this formalism is maximally descriptive in the sense that it can describe any joint probability distribution function of edge existence, (ii) shows that when these Boolean expressions are monotone then we can easily perform uncertainty analysis of edge probabilities, and (iii) uses these results to model a partial attack graph of the Stuxnet worm and a small enterprise network and to answer important security-related questions in a probabilistic manner.","abstract_has_math":false,"creators":["Nguyen, Hoang Hai"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Nicol, David M."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2019,"date_issued":"2019-02-06T19:32:46Z","date_published":"2019-02-06T19:32:46Z","updated_at":"2026-07-22T22:24:40Z","subjects":["network security, uncertainty, attach graph, reachability"],"languages":["en"],"rights":["Copyright 2018 Hoang Hai Nguyen"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/102416","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Nicol, David M."]},{"key":"dc:creator","label":"Author","values":["Nguyen, Hoang Hai"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2019-02-06T19:32:46Z","2018-10-29","2018-12"]},{"key":"dc:type","label":"Dc Type","values":["text"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["network security, uncertainty, attach graph, reachability"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2018 Hoang Hai Nguyen"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/102416"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Attack graphs used in network security analysis are analyzed to determine sequences of exploits that lead to successful acquisition of privileges or data at critical assets. An attack graph edge corresponds to a vulnerability, tacitly assuming a connection exists and tacitly assuming the vulnerability is known to exist. In this thesis, we explore use of {\\em uncertain graphs} to extend the paradigm to include lack of certainty in connection and/or existence of a vulnerability. We extend the standard notion of uncertain graph (where the existence of each edge is probabilistically independent) however, as significant correlations on edge existence probabilities exist in practice, owing to common underlying causes for disconnectivity and/or presence of vulnerabilities. Our extension describes each edge probability as a Boolean expression of independent indicator random variables. This thesis (i) shows that this formalism is maximally descriptive in the sense that it can describe any joint probability distribution function of edge existence, (ii) shows that when these Boolean expressions are monotone then we can easily perform uncertainty analysis of edge probabilities, and (iii) uses these results to model a partial attack graph of the Stuxnet worm and a small enterprise network and to answer important security-related questions in a probabilistic manner.","Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2019-02-05 without embargo terms","The student, Hoang Hai Nguyen, accepted the attached license on 2018-10-29 at 10:38.","The student, Hoang Hai Nguyen, submitted this Thesis for approval on 2018-10-29 at 10:39.","This Thesis was approved for publication on 2018-10-29 at 13:13.","DSpace SAF Submission Ingestion Package generated from Vireo submission #13046 on 2019-02-05 at 11:08:36","Made available in DSpace on 2019-02-06T19:32:46Z (GMT). No. of bitstreams: 2 NGUYEN-THESIS-2018.pdf: 1018360 bytes, checksum: bd1a5f067ae257716251d75722893a84 (MD5) LICENSE.txt: 4213 bytes, checksum: c67851b19e648ff6ee8e639873ca201c (MD5) Previous issue date: 2018-10-29"]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["An approach to incorporating uncertainty in network security analysis"]}]}],"canonical_facts":{"dc:contributor":["Nicol, David M."],"dc:creator":["Nguyen, Hoang Hai"],"dc:date":["2019-02-06T19:32:46Z","2018-10-29","2018-12"],"dc:description":["Attack graphs used in network security analysis are analyzed to determine sequences of exploits that lead to successful acquisition of privileges or data at critical assets. An attack graph edge corresponds to a vulnerability, tacitly assuming a connection exists and tacitly assuming the vulnerability is known to exist. In this thesis, we explore use of {\\em uncertain graphs} to extend the paradigm to include lack of certainty in connection and/or existence of a vulnerability. We extend the standard notion of uncertain graph (where the existence of each edge is probabilistically independent) however, as significant correlations on edge existence probabilities exist in practice, owing to common underlying causes for disconnectivity and/or presence of vulnerabilities. Our extension describes each edge probability as a Boolean expression of independent indicator random variables. This thesis (i) shows that this formalism is maximally descriptive in the sense that it can describe any joint probability distribution function of edge existence, (ii) shows that when these Boolean expressions are monotone then we can easily perform uncertainty analysis of edge probabilities, and (iii) uses these results to model a partial attack graph of the Stuxnet worm and a small enterprise network and to answer important security-related questions in a probabilistic manner.","Submission original under an indefinite embargo labeled 'Open Access'. The submission was exported from vireo on 2019-02-05 without embargo terms","The student, Hoang Hai Nguyen, accepted the attached license on 2018-10-29 at 10:38.","The student, Hoang Hai Nguyen, submitted this Thesis for approval on 2018-10-29 at 10:39.","This Thesis was approved for publication on 2018-10-29 at 13:13.","DSpace SAF Submission Ingestion Package generated from Vireo submission #13046 on 2019-02-05 at 11:08:36","Made available in DSpace on 2019-02-06T19:32:46Z (GMT). No. of bitstreams: 2 NGUYEN-THESIS-2018.pdf: 1018360 bytes, checksum: bd1a5f067ae257716251d75722893a84 (MD5) LICENSE.txt: 4213 bytes, checksum: c67851b19e648ff6ee8e639873ca201c (MD5) Previous issue date: 2018-10-29"],"dc:format":["application/pdf"],"dc:identifier":["http://hdl.handle.net/2142/102416"],"dc:language":["en"],"dc:rights":["Copyright 2018 Hoang Hai Nguyen"],"dc:subject":["network security, uncertainty, attach graph, reachability"],"dc:title":["An approach to incorporating uncertainty in network security analysis"],"dc:type":["text"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:40Z"}