Skip to main content

Research Repository

Advanced Search

Start thinking in graphs: using graphs to address critical attack paths in a Microsoft cloud tenant

Elmiger, Marius; Lemoudden, Mouad; Pitropakis, Nikolaos; Buchanan, William J.

Authors

Marius Elmiger



Abstract

The challenge of securing IT environments has reached a new complexity level as a growing number of organisations adopt cloud solutions. This trend increases the possibility of overseen attack paths in an organisation’s IT infrastructure. This paper proposes a methodology for assessing the security of a Microsoft cloud tenant based on the relationships between different cloud entities through the use of graphs. This paper argues for using graph theory as an effective method to understand and uncover complex entity attack paths. To achieve this, we implemented a graph analytics platform using data from a Microsoft cloud test tenant. Methods based on graph theory proved to measurably reduce possible attack paths. Our research can support defenders who want to better understand the interrelationships of Microsoft cloud entities as well as identify and remediate possible attack paths.

Citation

Elmiger, M., Lemoudden, M., Pitropakis, N., & Buchanan, W. J. (2024). Start thinking in graphs: using graphs to address critical attack paths in a Microsoft cloud tenant. International Journal of Information Security, 23, 467-485. https://doi.org/10.1007/s10207-023-00751-6

Journal Article Type Article
Acceptance Date Jun 1, 2023
Online Publication Date Sep 19, 2023
Publication Date 2024
Deposit Date Sep 25, 2023
Publicly Available Date Sep 27, 2023
Print ISSN 2356-5845
Electronic ISSN 2382-2619
Publisher N&N Global Technology
Peer Reviewed Peer Reviewed
Volume 23
Pages 467-485
DOI https://doi.org/10.1007/s10207-023-00751-6
Keywords Graph theory, Attack path, Microsoft cloud, Azure AD, Cloud security, Neo4j, BloodHound
Public URL http://researchrepository.napier.ac.uk/Output/3201445

Files








You might also like



Downloadable Citations