To quantitatively assess the security level of a cloud environment, a common method is to construct an attack graph which tracks a potentail attacker’s moves through interconnected computing systems by exploiting vulnerabilities of each system, one after another. The state-of-the-art automatic attack graph generation suffers from two limitations: 1) low quality or inconsistency of vulnerability […]
Read More