Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
Research Projects
SHARE

ATTACK PLANNING



In order to better secure a network from attack, it is necessary to evaluate the infrastructure as an attacker would. However, current methods are insufficient to comprehensively assess the security of a network. The CoreLabs team addresses this problem by researching cyberwarfare and network intrusion scenarios from the attackers' perspective. As a result, the team has produced a novel solution that implements the best possible attack strategy.

The user is able to input a scenario and attack goals, and the solution then considers every possible attack path before selecting the optimal one. One may choose to gain root privileges on a machine with a given IP address minimizing the time; or to delete the database in a given server maximizing stealth capabilities, etc. The solution automatically crafts the planning, step-by-step, required to achieve each target.

This solution will help CORE IMPACT, Core Security Technologies' penetration testing product to automatically and interactively craft and execute real-life attacks, so that at each step, IMPACT selects the best possible action.


Project Resources:

Carlos Sarraute and Alejandro Weil, "Advances in Automated Attack Planning", PacSec Conference, Tokyo, Japan, November 12/13, 2008.
Ivan Arce, Gerardo Richarte, "State of the art Security from an attacker's viewpoint", PacSec Conference, Tokyo, Japan, November 2003.
Gerardo Richarte, "Modern Intrusion Practices", Black Hat Conference, Las Vegas, NV, July 2003.
Ariel Futoransky, Luciano Notarfrancesco, Gerardo Richarte, Carlos Sarraute, "Building Computer Network Attacks", CoreLabs Technical Report, March 2003.
Maximiliano Caceres, "Syscall Proxying - Simulating remote execution", Black Hat Conference, Las Vegas, NV, July 2002.



« Back to Projects List
Related Content