{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T13:41:44Z","timestamp":1777902104411,"version":"3.51.4"},"reference-count":34,"publisher":"SAGE Publications","issue":"8","license":[{"start":{"date-parts":[[2006,8,1]],"date-time":"2006-08-01T00:00:00Z","timestamp":1154390400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["SIMULATION"],"published-print":{"date-parts":[[2006,8]]},"abstract":"<jats:p>In this article, a modeling process is defined to address challenges in analyzing attack scenarios and mitigating vulnerabilities in networked environments. Known system vulnerability data, system configuration data, and vulnerability scanner results are considered to create exploitation graphs ( e-graphs) that are used to represent attack scenarios. Experiments carried out in a cluster computing environment showed the usefulness of proposed techniques in providing in-depth attack scenario analyses for security engineering. Critical vulnerabilities can be identified by employing graph algorithms. Several factors were used to measure the difficulty in executing an attack. A cost\/benefit analysis was used for more accurate quantitative analysis of attack scenarios. The authors also show how the attack scenario analyses better help deployment of security products and design of network topologies.<\/jats:p>","DOI":"10.1177\/0037549706072046","type":"journal-article","created":{"date-parts":[[2006,11,21]],"date-time":"2006-11-21T15:05:14Z","timestamp":1164121514000},"page":"523-541","source":"Crossref","is-referenced-by-count":15,"title":["An Approach to Model Network Exploitations Using Exploitation Graphs"],"prefix":"10.1177","volume":"82","author":[{"given":"Wei","family":"Li","sequence":"first","affiliation":[{"name":"Graduate School of Computer and Information Sciences, Nova Southeastern University, 3301 College Avenue, Fort Lauderdale, FL 33314,"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rayford B.","family":"Vaughn","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Mississippi State University, Box 9637, Mississippi State, MS 39762"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yoginder S.","family":"Dandass","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Mississippi State University, Box 9637, Mississippi State, MS 39762"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2006,8,1]]},"reference":[{"key":"atypb1","unstructured":"STAT scanner. 2004. Available from: http:\/\/www.stat.harris.com\/solutions\/vuln_assess\/scanner_index.asp"},{"key":"atypb2","doi-asserted-by":"publisher","DOI":"10.1109\/3468.935052"},{"key":"atypb3","first-page":"245","volume-title":"Proceedings of the 9th ACM Conference on Computer and Communications Security","author":"Ning, P."},{"issue":"12","key":"atypb4","first-page":"21","volume":"24","author":"Schneier, B.","year":"1999","journal-title":"Dr. Dobb\u2019s Journal"},{"key":"atypb5","first-page":"187","volume-title":"Proceedings of the 2002 IEEE Symposium on Security and Privacy","author":"Cuppens, F."},{"key":"atypb6","doi-asserted-by":"publisher","DOI":"10.1145\/366173.366187"},{"key":"atypb7","first-page":"217","volume-title":"Proceedings of the 9th ACM Conference on Computer and Communications Security","author":"Ammann, P."},{"key":"atypb8","first-page":"49","volume-title":"Proceedings of the 15th IEEE Computer SecurityFoundationsWorkshop","author":"Jha, S."},{"key":"atypb9","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2000.848453"},{"key":"atypb10","first-page":"254","volume-title":"Proceedings of the 2002 IEEE Symposium on Security and Privacy","author":"Sheyner, O."},{"key":"atypb11","first-page":"1307","volume-title":"Proceedings of the DARPA Information Survivability Conference and Exposition","author":"Swiler, L. P."},{"key":"atypb12","doi-asserted-by":"publisher","DOI":"10.2172\/573291"},{"key":"atypb13","volume-title":"Managing cyber threats: Issues, approaches and challenges","author":"Jajodia, S.","year":"2003"},{"key":"atypb14","first-page":"284","volume-title":"Proceedings of the DARPA Information Survivability Conference and Exposition","author":"Cheung, S."},{"key":"atypb15","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2002-101-209"},{"key":"atypb16","first-page":"50","volume-title":"Proceedings of the 6th IEEE Information Assurance Workshop","author":"Li, W."},{"key":"atypb17","unstructured":"Common Vulnerability Exposures. 2004. Available from: http:\/\/cve.mitre.org\/"},{"key":"atypb18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-04558-9"},{"key":"atypb19","first-page":"109","volume-title":"Proceedings of the ACM CCS Workshop on Visualization and Data Mining for Computer Security","author":"Noel, S."},{"key":"atypb20","volume-title":"Proceedings of the 19th Annual Computer Security Applications Conference","author":"Noel, S."},{"key":"atypb21","volume-title":"The integration of security sensors into the intelligent intrusion detection system (IIDS) in a cluster environment","author":"Li, W.","year":"2002"},{"key":"atypb22","first-page":"309","volume-title":"Proceedingsofthe38th Hawaii International Conference on System Sciences","author":"Li, W."},{"key":"atypb23","unstructured":"BugtraqVulnerabilitiesArchive.2004.Availablefrom:http:\/\/www.securityfocus.com\/bid"},{"key":"atypb24","unstructured":"CERT\u00ae Advisories. 2004. Available from: http:\/\/www.cert.org\/advisories"},{"key":"atypb25","unstructured":"National Vulnerability Database. 2005. Available from: http:\/\/nvd.nist.gov\/"},{"key":"atypb26","unstructured":"SANS Top 20 Vulnerabilities. 2004. Available from: http:\/\/www.sans.org\/top20\/"},{"key":"atypb27","unstructured":"Li, W. 2005.An approach to graph-based modeling of network exploitations. PhD diss., Department of Computer Science, Mississippi State University."},{"key":"atypb28","unstructured":"Graphviz. 2004. Available from: http:\/\/www.research.att.com\/sw\/tools\/graphviz\/"},{"key":"atypb29","unstructured":"ICAT Metabase. 2004.Available from: http:\/\/icat.nist.gov\/icat.cfm"},{"key":"atypb30","unstructured":"Kumar, S. 1995. Classification and detection of computer intrusions. PhD diss., Department of Computer Science, Purdue University, West Lafayette, IN."},{"key":"atypb31","unstructured":"Das, K. J. 2000. Attack development for intrusion detection evaluation. Master\u2019s thesis, Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology."},{"key":"atypb32","volume-title":"Graphs & digraphs","author":"Chartrand, G.","year":"1986","edition":"2"},{"key":"atypb33","doi-asserted-by":"publisher","DOI":"10.1145\/366173.366185"},{"key":"atypb34","doi-asserted-by":"publisher","DOI":"10.1109\/32.815323"}],"container-title":["SIMULATION"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0037549706072046","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0037549706072046","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T11:19:55Z","timestamp":1777634395000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.1177\/0037549706072046"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006,8]]},"references-count":34,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2006,8]]}},"alternative-id":["10.1177\/0037549706072046"],"URL":"https:\/\/doi.org\/10.1177\/0037549706072046","relation":{},"ISSN":["0037-5497","1741-3133"],"issn-type":[{"value":"0037-5497","type":"print"},{"value":"1741-3133","type":"electronic"}],"subject":[],"published":{"date-parts":[[2006,8]]}}}