Mapping Attack Paths in Black-Box Networks Through Passive Vulnerability Inference

Abstract : This project investigates stealthy techniques for mapping attack graphs through black- box networks. This provides a powerful new capability for network reconnaissance and attack planning, when open scanning is not an option. We employ purely passive inference, as well as new hybrid passive/active techniques that provide more comprehensive attack plans while maintaining nearly zero risk of detection. We infer network configuration (topology, devices, services, etc.), as well as functional semantics of network components for intelligent targeting. We map discovered network elements to potentially exploitable vulnerabilities.