Network Attack Simulations And You

Kylie McClanahan

S4x24 - ICS Security Conference · Day 3 · Stage 3

Overview

In the ever-escalating landscape of cybersecurity threats, organizations face an overwhelming deluge of newly discovered vulnerabilities. Traditional methods for prioritizing these vulnerabilities, while foundational, often fail to answer the critical question: "Am I at risk, specifically in my network?" This talk, presented by Kylie McClanahan at S4, introduces a novel approach to vulnerability management through network attack simulations, specifically highlighting the Vint project. This initiative aims to bridge the gap between theoretical vulnerability scores and practical, context-aware risk assessment, enabling organizations to make more informed and efficient remediation decisions.

Watch on YouTube

Visual summary for Network Attack Simulations And You by Kylie McClanahan
Visual summary for Network Attack Simulations And You by Kylie McClanahan

Key moments

  1. 0:00 Introduction and challenge of vulnerability prioritization
  2. 2:15 Why network attack vector is crucial for prioritization
  3. 3:45 Limitations of current vulnerability prioritization methods
  4. 4:00 Introducing the Vint network attack simulation project
  5. 4:45 Vint project's characteristics and scope clarified
  6. 5:30 Overview of the Vint project's five steps
  7. 7:10 Detailed explanation of reachability and safety analysis

Network Attack Simulations And You

Speakers: Kylie McClanahan

Conference: S4

YouTube: https://www.youtube.com/watch?v=3NMx9x45bu0

Overview

In the ever-escalating landscape of cybersecurity threats, organizations face an overwhelming deluge of newly discovered vulnerabilities. Traditional methods for prioritizing these vulnerabilities, while foundational, often fail to answer the critical question: "Am I at risk, specifically in my network?" This talk, presented by Kylie McClanahan at S4, introduces a novel approach to vulnerability management through network attack simulations, specifically highlighting the Vint project. This initiative aims to bridge the gap between theoretical vulnerability scores and practical, context-aware risk assessment, enabling organizations to make more informed and efficient remediation decisions.

The core premise of the Vint project is to provide a low-cost, computationally efficient method for frequently assessing an organization's actual exposure to network-based attacks. By simulating adversary actions within a network's specific architecture, firewall rules, and asset configurations, the project offers a dynamic and realistic view of potential attack paths. This matters immensely for critical infrastructure, such as electric utilities, where the consequences of a successful cyberattack can be catastrophic. The Vint project empowers defenders to move beyond generic vulnerability scores to understand precisely how a threat actor might exploit a vulnerability within their unique operational environment.

Kylie McClanahan, a software developer involved in this Department of Energy (DOE) funded collaboration, detailed how the Vint project leverages static analysis, integrating data from various sources to construct a comprehensive model of a network. This model then serves as the canvas for simulating an adversary's movements, identifying reachable assets, potential exploitation points, and possible pivot paths. The goal is not to solve the overarching challenges of asset management or vulnerability discovery, but rather to maximize the security posture using existing information and providing actionable intelligence for remediation.

Background

▶ Watch: Introduction and challenge of vulnerability prioritization (0:00)

The sheer volume of new vulnerabilities reported annually presents a significant challenge for security teams. Last year alone, approximately 28,000 vulnerabilities were published. A common initial approach to prioritization involves the Common Vulnerability Scoring System (CVSS), which assigns a base score between 0 and 10, correlating to a base severity (e.g., high or critical for scores between 7 and 10). However, even when filtering for high and critical vulnerabilities, organizations are still left with an estimated 15,000 issues to address, a number that remains unmanageable for most.

The CVSS attack vector component plays a significant role in this calculation. The speaker highlighted that over the past five years, an average of 75% of high or critical vulnerabilities have been exploitable over the network, underscoring the importance of network-based threats. Despite its utility, relying solely on the CVSS base score is insufficient. Organizations often look to other prioritization methods:

  • CVSS Environmental Score: This allows an operator or analyst to re-score CVSS components based on their specific network and system context. For example, a vulnerability reported with a high confidentiality impact might be re-scored as low if the analyst knows their network architecture significantly mitigates that specific impact. While valuable, this method demands a high degree of confidence and maturity from the analyst, which not all organizations possess.
  • CISA Known Exploited Vulnerabilities (KEV) Catalog: This catalog identifies vulnerabilities that are actively being exploited in the wild, providing a strong indicator for urgent remediation. While excellent for highlighting immediate threats, it doesn't tell an organization if that specific vulnerability is exploitable within their unique network context.
  • Exploit Prediction Scoring System (EPSS): EPSS provides a probability value for how likely a vulnerability is to be exploited, leveraging extensive research in exploit prediction. Like the KEV catalog, it offers a broader prediction but still doesn't provide the granular, network-specific risk assessment many organizations need.

The fundamental limitation of these methods is their inability to answer the question: "Are they in my network? Am I at risk?" This critical gap led to the inception of the Vint project, a four-year grant funded by the Department of Energy (DOE). This project is a collaborative effort involving academia (the University of Arkansas and the University of Arkansas at Little Rock), two commercial vendors (Bastazo and Network Perception), and an unnamed utility partner providing real-world testing and feedback. The project's goal is to develop and implement a methodology for network attack simulations that directly addresses this gap, providing a more accurate and actionable understanding of an organization's true cyber risk posture.

Key Findings

▶ Watch: Limitations of current vulnerability prioritization methods (3:45)

The central contribution of the Vint project is the development of a static network attack simulation methodology that transcends the limitations of traditional vulnerability prioritization. This method focuses on determining the actual exploitability and reachability of vulnerabilities within an organization's unique network environment, rather than relying solely on theoretical severity scores.

Key findings and contributions of the Vint project include:

  • Context-Aware Risk Assessment: The project shifts the paradigm from generic vulnerability severity to a practical, context-aware understanding of risk. By integrating specific network topology, firewall rules, asset characteristics, and adversary capabilities, it provides a much more precise assessment of whether a vulnerability can actually be exploited and leveraged to compromise critical assets.
  • Low-Cost, Computationally Efficient Approach: A core design principle of Vint is to be low-cost both in terms of financial investment and computational resources. The simulations are designed to be run frequently without requiring supercomputers or specialized GPUs, making them accessible and practical for regular use within an organization's security operations.
  • Static Analysis, Not Active Scanning: The methodology explicitly defines itself as a static analysis approach. It is not a network scan, penetration test, or virtual reality simulation. This means it operates on collected data (asset lists, firewall configurations, vulnerability reports) rather than actively interacting with the live network, minimizing potential disruption and operational overhead.
  • Integration of Diverse Data Sources: The project demonstrates the ability to effectively combine and utilize various existing data sources, including static asset lists (like those mandated by NERC SIP standards for electric utilities), CPE (Common Platform Enumeration) data from the NVD (National Vulnerability Database), vulnerability scan results, and firewall rule sets. This integration allows for a holistic view of the network's security posture.
  • Iterative Reach and Safety Analysis: A fundamental component is the iterative process of reach analysis and safety analysis. This involves placing a hypothetical adversary at an initial point (e.g., an external IP) and then systematically determining what assets they can reach, if they can exploit vulnerabilities on those assets, and if those exploited assets can be used as pivot points to move deeper into the network. This provides a dynamic mapping of potential attack paths.
  • Factoring in Operational Realities: The simulation explicitly accounts for practical operational details, such as whether a vulnerability requires user interaction and if the target asset even supports user logins. It also considers the specific network protocols and ports associated with vulnerabilities and verifies if these are permitted by existing firewall rules, providing a realistic assessment of exploitability.
  • Foundational for Critical Infrastructure: While not solving the universal asset management problem, the Vint project's goal is to deliver "better security with what we have." This pragmatic approach is particularly valuable for critical infrastructure sectors, where comprehensive asset inventories and network models are often already maintained due to regulatory requirements.

In essence, the Vint project's key finding is a robust, practical methodology for performing network attack simulations that can significantly enhance an organization's ability to prioritize and mitigate cyber risks based on their unique operational context.

Technical Deep Dive

▶ Watch: Introducing the Vint network attack simulation project (4:00)

The Vint project's methodology is structured around five main steps, designed for static analysis and frequent execution. This approach is not resource-intensive, aiming for low computational cost and time, making it suitable for regular operational use rather than specialized, infrequent assessments.

1. Find Assets and Vulnerabilities:

The foundational step involves gathering comprehensive information about an organization's assets and their associated vulnerabilities. The Vint project acknowledges that solving the universal asset management problem is a separate, complex challenge, but it makes effective use of existing data:

  • Static Asset Lists: Many organizations, especially those in regulated sectors like electric utilities (e.g., NERC SIP compliance), maintain static lists of assets. These lists, containing vendor and product information, are crucial inputs.
  • CPE and NVD Matching: The system matches the vendor and product details from asset lists against Common Platform Enumeration (CPE) identifiers found in the National Vulnerability Database (NVD). This allows for the identification of known vulnerabilities (CVEs) relevant to specific assets, despite the NVD's acknowledged limitations.
  • Vulnerability Scan Results: Outputs from existing vulnerability scanning tools can be ingested directly. The system can infer assets based on the vulnerabilities reported against specific IPs or hostnames.
  • Network Graph Model Inference: In some cases, individual IP addresses or ranges listed within firewall rule sets (part of the network graph model) can also serve as a source for identifying assets, especially if detailed asset lists are incomplete.

2. Identify Network Protocols:

For each identified vulnerability and asset, the system determines the associated network protocols and ports. This information is critical for understanding how a vulnerability might be exploited and whether the necessary communication channels are open within the network.

3. Obtain a Network Model:

This is a cornerstone of the simulation, providing the architectural context for adversary movement.

  • Firewall Rule Set Ingestion: The Vint project leverages tools like those from Network Perception to read and parse an organization's firewall rule sets.
  • Graph Model Construction: From these rules, a graph model of the network is built. This model represents network segments, devices, and the allowed traffic flows between them, providing a detailed understanding of network segmentation, access controls, and potential communication paths.

4. Adversarial Analysis:

This step is where the "simulation" truly begins, modeling how an adversary might traverse and exploit the network.

  • Adversary Placement: The simulation starts by placing a hypothetical adversary at an initial point, typically an external IP address, representing an internet-facing threat.
  • Looping Reach Analysis and Safety Analysis: This iterative process maps the adversary's potential progression:
  • Reach Analysis: From the current adversary position, the system determines what assets are reachable based on the network graph model (firewall rules, routing, etc.).
  • Safety Analysis (Exploitability): For each reachable asset, the system checks if there are known vulnerabilities that the adversary could exploit. This check considers several factors:
  • Vulnerability Features: The CVSS features of a vulnerability are critical: attack complexity, privileges required, user interaction required, and exploit code maturity.
  • Asset Features: The characteristics of the target asset are compared against the vulnerability requirements. For example, if a vulnerability requires user interaction (e.g., downloading a malicious PDF) but the asset has no user login interface, that exploit path is deemed impractical.
  • Protocol and Port Alignment: The system verifies if the protocols and ports associated with a vulnerability are actually permitted by the network's firewall rules between the adversary's current position and the target asset.
  • Pivoting: If an asset is successfully exploited, it becomes a new potential pivot point for the adversary. The simulation then repeats the reach and safety analysis from this new internal position, exploring deeper into the network (e.g., into another subnet, past a VPN or internal firewall). This process continues until the adversary's reach is exhausted.
  • Considering Advanced Adversary Capabilities: The project is beginning to incorporate more advanced adversary models, such as the impact of possessing Active Directory credentials, to simulate how far an adversary could progress with elevated privileges.
  • Adversary Modeling Flexibility: In a Q&A session, it was clarified that the system allows for both standardized and bespoke adversary models. Predefined Design Basis Threats (DBTs), such as those representing specific ransomware groups or APTs with known characteristics, can be provided. Crucially, organizations can customize or add their own adversary intelligence, perhaps from an ISAC (Information Sharing and Analysis Center) or internal threat intelligence, allowing for highly tailored simulations while keeping sensitive data local to their network.

5. Run the Simulation:

This step involves the execution of the defined adversarial analysis over the network model, generating the attack paths and outcomes.

Upon exhausting the adversary's potential reach, an impact analysis is performed. This determines "what level of harm were they able to achieve?" — whether they established a foothold in the system, reached a critical asset, or were successfully blocked by network defenses, forcing them to "hit a wall." This comprehensive, context-aware simulation provides a much clearer picture of an organization's actual risk exposure than any single vulnerability score.

Demo / Proof of Concept

▶ Watch: Overview of the Vint project's five steps (5:30)

While the talk provided a detailed explanation of the Vint project's methodology, its five main steps, and the underlying technical considerations, it did not include a live demonstration or a specific walk-through of a simulated attack scenario. The speaker referred to "the results" and described a table structure outlining vulnerability features, asset features, and modeled adversary capabilities, indicating the type of output the system generates. However, a concrete example of a simulated attack path or the visual representation of such a path within a network model was not presented during the session.

Defensive Implications

▶ Watch: Detailed explanation of reachability and safety analysis (7:10)

The Vint project's approach to network attack simulations offers profound implications for cybersecurity defenders, enabling a strategic shift in how vulnerabilities are prioritized and mitigated:

  • Risk-Based Prioritization: Defenders can move beyond generic CVSS scores to prioritize vulnerabilities based on their actual exploitability and reachability within their unique network environment. This ensures that remediation efforts are focused on the vulnerabilities that pose the most significant, demonstrable risk, rather than simply the highest-scoring ones in a vacuum.
  • Optimized Resource Allocation: By identifying specific, viable attack paths, organizations can allocate their limited security resources more effectively. Instead of patching thousands of theoretical vulnerabilities, they can target critical weaknesses that adversaries could realistically leverage, potentially saving significant time, effort, and cost.
  • Enhanced Network Design and Configuration: The simulations can reveal critical choke points, misconfigured firewalls, or unintended network reachability that might not be apparent through traditional audits. This intelligence can guide improvements in network segmentation, access control lists, and security architecture, strengthening the overall defensive posture.
  • Proactive Threat Hunting and Mitigation: Running these simulations frequently allows defenders to proactively assess the impact of new vulnerability disclosures, changes in network configuration, or the deployment of new assets. This continuous assessment helps identify and mitigate potential attack paths before they can be exploited by real adversaries.
  • Improved Situational Awareness: The ability to visualize and understand how an adversary might move through the network, from an initial ingress point to critical assets, provides unparalleled situational awareness. This knowledge empowers security teams to anticipate attacks, develop more effective detection strategies, and prepare incident response plans tailored to realistic scenarios.
  • Data-Driven Decision Making: The Vint project provides concrete, analytical data to support security decisions. This reduces the reliance on subjective assumptions, such as those sometimes required for CVSS environmental scores, and provides a stronger basis for communicating risk to management and stakeholders.
  • Validation of Controls: Simulations can effectively validate the efficacy of existing security controls, such as firewalls, VPNs, and intrusion prevention systems. If an adversary simulation successfully bypasses a control, it indicates a potential misconfiguration or weakness that requires attention.
  • Strategic Asset Management Focus: The project implicitly highlights the critical importance of accurate and up-to-date asset inventories and vulnerability data as foundational inputs. While not solving these problems directly, it demonstrates how leveraging even existing, imperfect data can yield significant security improvements.

By integrating network context with vulnerability intelligence and adversary modeling, the Vint project equips defenders with a powerful tool to understand, predict, and ultimately prevent successful cyberattacks more efficiently and effectively.

Key Takeaways

  • Traditional vulnerability prioritization methods like CVSS base scores, the CISA KEV catalog, and EPSS are valuable but often fall short in answering the critical question: "Am I at risk in my specific network?"
  • The DOE-funded Vint project introduces a novel approach using static network attack simulations to provide context-aware risk assessments, specifically designed to be low-cost and computationally efficient for frequent execution.
  • The simulation methodology follows five main steps: identifying assets and vulnerabilities, associating network protocols, obtaining a comprehensive network graph model (e.g., from firewall rules), conducting iterative adversarial analysis (reach and safety), and running the simulation.
  • Key factors considered in the adversarial analysis include firewall rules, asset features (e.g., requirements for user interaction), vulnerability characteristics (attack complexity, privileges, exploit maturity), and the ability of an adversary to pivot through exploited systems.
  • The Vint project allows for flexible adversary modeling, including the use of predefined Design Basis Threats (DBTs) and the ability for organizations to incorporate their own threat intelligence locally.
  • By understanding potential attack paths and impacts within their unique network, defenders can prioritize vulnerability remediation more effectively, optimize resource allocation, and enhance their overall security posture.

About the Speaker(s)

Kylie McClanahan is a software developer deeply involved in the Vint project, a collaborative initiative funded by the Department of Energy (DOE). This project brings together academic institutions (the University of Arkansas and the University of Arkansas at Little Rock), commercial vendors like Bastazo (focused on vulnerability management in electric utilities, particularly in the SIP 7 space) and Network Perception (specializing in building network graph models from firewall rule sets), and an unnamed utility partner for real-world testing. McClanahan's work focuses on developing and implementing the static network attack simulation methodology that aims to provide more practical and context-aware vulnerability risk assessments for critical infrastructure.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk introduces the DOE-funded Vint project, a novel static network attack simulation methodology. It directly addresses the critical gap in vulnerability management by providing context-aware risk assessments that move beyond generic vulnerability scores. By focusing on actual exploitability and reachability within a unique network environment, Vint offers a low-cost, computationally efficient way to integrate diverse data sources for iterative adversarial analysis and pivot point identification, giving defenders actionable intelligence for prioritizing remediation efforts.

Heather Calloway (CISO) — STRONG ACCEPT

This presentation on the Vint project offers a pragmatic and highly valuable approach to vulnerability management. It correctly identifies the critical gap in translating generic vulnerability scores into context-specific, actionable risk for organizations, especially in critical infrastructure. By leveraging static network attack simulations with existing data, it provides a computationally efficient method to understand real-world business exposure and prioritize remediation based on actual attack paths. This is precisely the kind of institutional realism and decision-making clarity that security leaders need to drive effective governance and allocate resources wisely.

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference