NIST Researchers Develop New Technique for Assessing Network Security

NIST Researchers Develop New Technique for Assessing Network Security

Written By
Brian Prince
Brian Prince
Jul 25, 2008
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Researchers at the National Institute of Standards and Technology have developed a new analysis technique to help IT administrators assess security risk.

The patent-pending technique was developed by computer scientist Anoop Singhal and his research colleagues at George Mason University. Though NIST researchers weren’t available this morning to comment on their findings, Singhal and his team use attack graphs and the National Vulnerability Database in their assessment of network pathways.

“We analyze all of the paths that system attackers could penetrate through a network and assign a risk to each component of the system,” Singhal said in a statement. “Decision makers can use our assigned probabilities to make wise decisions and investments to safeguard their network.”

According to NIST, once inside a network’s firewall, a hacker can take a number of routes through the network to find a treasure-trove of confidential data. NIST researchers evaluate each route and assign it a risk based on the level of difficulty for the hacker. For example, in a simple system there is an attacker on a computer, a firewall, router, an FTP server and a database server, NIST officials explained. The goal for the attacker is to find the simplest path into the database server. Using attack graph analysis, NIST determines three potential attack paths and assigns an attack probability for each path in the graph based on the score in the NVD database.

Because it takes multiple steps to reach the goal, the probabilities of each component are multiplied to determine the overall risk, NIST officials said. The next step is for the researchers to expand their research to handle large-scale enterprise networks, officials added.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.