Improving Security Policy Validation in Distributed Systems Using Attack Graph Simulations
Zaid J. Al-Araji, Balqees Talal Hasan, Fahad Ahmed Shaban, Ali Khairi Al-Toohafi, Hussein M. Farhood, Alaa Al-Dabbagh, Omar Nazar HamdoonValidation of security policies in distributed systems is difficult because rules are heterogeneous, interact in non-obvious ways, and static checks often overlook multi-stage attacker chains. We offer a unified framework to translate real policies, and in parallel give visibility into policy-aware attack graphs (PAAGs), then we evaluate them using deterministic as well as probabilistic simulations, with Monte Carlo (MC) included. The policies are naturally embedded in the construction; firewall semantics deny or remove exploit edges, RBAC limits privilege transitions, and IDS/IPS lower the success likelihood of edges, so the resulting graph reflects both the vulnerability surface and the enforcement posture. To keep the analysis manageable at scale, we apply pruning such as reachability-based minimisation, dominance removal, path equivalence simplification, plus probability-threshold heuristics, which should preserve security-relevant ideas while still shrinking the graph size. The Critical Asset Exposure Level (CAEL) metric we introduce in this paper measures successful attack paths that terminate at critical assets. The metric CAEL exists in three different presentation forms, which include deterministic, probabilistic, and MC modalities to support traditional metrics, which include probability of compromise (PC), time-to-compromise (TTC), path length, and a Policy Effectiveness Ratio (PER) that rescales baseline vs policy-hardened graphs. We examine synthetic topologies that use 10 to 20,000 nodes for testing. The framework achieves better scalability and efficiency, as the results demonstrate a 40% reduction in attack graph generation time while maintaining security-related semantic information