Abstract
Validation of security policies in distributed systems is difficult because rules are heterogeneous, interact in non-obvious ways, and static checks often overlook multi-stage attacker chains. We offer a unified framework to translate real policies, and in parallel give visibility into policy-aware attack graphs (PAAGs), then we evaluate them using deterministic as well as probabilistic simulations, with Monte Carlo (MC) included. The policies are naturally embedded in the construction; firewall semantics deny or remove exploit edges, RBAC limits privilege transitions, and IDS/IPS lower the success likelihood of edges, so the resulting graph reflects both the vulnerability surface and the enforcement posture. To keep the analysis manageable at scale, we apply pruning such as reachability-based minimisation, dominance removal, path equivalence simplification, plus probability-threshold heuristics, which should preserve security-relevant ideas while still shrinking the graph size. The Critical Asset Exposure Level (CAEL) metric we introduce in this paper measures successful attack paths that terminate at critical assets. The metric CAEL exists in three different presentation forms, which include deterministic, probabilistic, and MC modalities to support traditional metrics, which include probability of compromise (PC), time-to-compromise (TTC), path length, and a Policy Effectiveness Ratio (PER) that rescales baseline vs policy-hardened graphs. We examine synthetic topologies that use 10 to 20,000 nodes for testing. The framework achieves better scalability and efficiency, as the results demonstrate a 40% reduction in attack graph generation time while maintaining security-related semantic information
Recommended Citation
Al-Araji, Zaid J.; Hasan, Balqees Talal; Shaban, Fahad Ahmed; Al-Toohafi, Ali Khairi; Farhood, Hussein M.; Al-Dabbagh, Alaa; and Hamdoon, Omar Nazar
(2026)
"Improving Security Policy Validation in Distributed Systems Using Attack Graph Simulations,"
Al-Bahir: Vol. 9:
Iss.
2, Article 5.
Available at: https://doi.org/10.55810/2313-0083.1147
References
[1] Al-Araji ZJ, Ahmad SSS, Farhood HM, Mutlag AA, Al-Khaldee MS. Attack graph-based security metrics: concept, taxonomy, challenges and open issues. In: BIO web conf. EDP Sciences; 2024. https://doi.org/10.1051/bioconf/ 20249700085.
[2] Polinsky I, Datta P, Bates A, Enck W. GRASP: Hardening serverless applications through graph reachability analysis of security policies. In: Proceedings of the ACM web conference; 2024, 2024. p. 1644—55.
[3] Andalib A, Babamir SM. Anomaly detection of policies in distributed firewalls using data log analysis. J Supercomput 2023;79:19473—514.
[4] Wolf FA, Müller P. Verifiable Security Policies for Distributed Systems. In: Proceedings of the 2024 on ACM SIGSAC conference on computer and communications security; 2024. p. 4—18.
[5] Saint-Hilaire KA, Neal C, Cuppens F, Boulahia-Cuppens N, Bassi F, Hadji M. a real-time automated attack-defense graph generation approach. J Inf Secur Appl 2025;94:104266.
[6] Al-Araji ZJ, Ahmad SSS, Abdullah RS. Attack Prediction to Enhance Attack Path Discovery Using Improved Attack Graph. Karbala Int J Mod Sci 2022;8:313—29. https://doi.org/ 10.33640/2405-609X.3235.
[7] Kuikka V, Pykal € a € L, Takko T, Kaski KK. Network modelling in analysing cyber-related graphs. Frontiers in Complex Systems 2025;3:1620260.
[8] Pal R, Sequeira RX, Zeijlmaker S, Siegel M. Optimizing cyber-resilience in critical infrastructure networks. Winter Simulation Conference (WSC); 2024. p. 774—85. 2024.
[9] Wang X, Yuan S, Magableh SK, Dawaghreh O, Wang C, Wang LY. Graph-based Simulation Framework for Power Resilience Estimation and Enhancement. ArXiv preprint ArXiv:2411.16909. 2024.
[10] Catta D, Leneutre J, Mijatovic A, Ulin J, Malvone V. A Formal Verification Approach to Handle Attack Graphs. ICAART 2024;3:125—32.
[11] Wang S, Shao D, Wu J. Algorithm of attack graph generation based on attack cost of CVSS. ISME 2015 - Proceedings of the Information Science and Management Engineering 2015;III:471—6. https://doi.org/10.5220/0006028804710476.
[12] Wang J. A Generation Method of Attack Graph Based on Evolutionary Computation. In: 2nd international conference on advances in energy, environment and chemical engineering; 2016. p. 28—31. https://doi.org/10.2991/aeece-16. 2016.6.
[13] Luan J, Wang J, Xue M. Automated vulnerability modeling and verification for penetration testing using petri nets. In: Lecture notes in computer science (including subseries lecture notes in artificial intelligence and lecture notes in bioinformatics); 2016. p. 71—82. https://doi.org/10.1007/978- 3-319-48674-1_7.
[14] Wang H, Chen Z, Zhao J, Di X, Liu D. A Vulnerability Assessment Method in Industrial Internet of Things Based on Attack Graph and Maximum Flow. IEEE Access 2018;6: 8599—609. https://doi.org/10.1109/ACCESS.2018.2805690.
[15] Polatidis N, Pimenidis E, Pavlidis M, Papastergiou S, Mouratidis H. From product recommendation to cyberattack prediction: generating attack graphs and predicting future attacks. Evolving Systems 2018;11:1—12. https://doi. org/10.1007/s12530-018-9234-z.
[16] Moulin M, Eyisi E, Shila DM, Zhang Q. Automatic Construction of Attack Graphs in Cyber Physical Systems Using Temporal Logic. In: Proceedings - IEEE military communications conference MILCOM; 2018. p. 933—8. https://doi. org/10.1109/MILCOM.2018.8599799. IEEE.
[17] Chen Y, Liu Z, Liu Y, Dong C. Distributed attack modeling approach based on process mining and graph segmentation. Entropy 2020;22:1—21. https://doi.org/10. 3390/e22091026.
[18] Palma A, Cicimurri C, Angelini M. Progressive attack graph: a technique for scalable and adaptive attack graph generation: A Palma et al. Int J Inf Secur 2025;24:212.
[19] Liu X, Jiang W, Li Z, Jin X, Ma Z, Li Q. FuzzAGG: A fuzzingdriven attack graph generation framework for industrial robot systems. Comput Secur 2025;150:104223.
[20] Kaynar K, Sivrikaya F. Distributed Attack Graph Generation. IEEE Trans Dependable Secure Comput 2015;13: 519—32. https://doi.org/10.1109/TDSC.2015.2423682.
[21] Li M, Hawrylak P, Hale J. Concurrency Strategies for Attack Graph Generation. In: Proceedings - 2nd international conference on data intelligence and security; 2019. p. 174—9. https://doi.org/10.1109/ICDIS.2019.00033. ICDIS, IEEE.
[22] Feng Y, Sun G, Liu Z, Wu C, Zhu X, Wang Z, Wang B. Attack Graph Generation and Visualization for Industrial Control Network. Chinese control conference, CCC 2020- July. 2020. p. 7655—60. https://doi.org/10.23919/CCC50068. 2020.9189450.
[23] Yang M, Jia Y, Mei Y, Yang J, Han W, Zhang J, Yu Z. A selfevolution cyber attack scheme generation system for cybersecurity evaluation. Sci Rep 2026;16. https://doi.org/10. 1038/s4159





Indexed in: