Popular open source frameworks are used today to automat
ically combat attack threats in DCCNs. However, they cannot visualize
logical conditions well enough in representing network protocol vulnera
bilities in attacks such as ARP poisoning, DNS spoofing, and SYN flood
ing, and they do not support advanced types of communication, such
as wireless, vehicular, and tethering communications on networks. To
address the above shortcomings, we present an AND/OR attack graph
based security model for DCCNs, which is capable of modeling multi
ple attack types (e.g., ARP poisoning, spoofing, man-in-the-middle, and
many others). A novel efficient algorithm is proposed to extract the most
vulnerable attack path from the AND/OR graph. Unlike previous heuris
tic pathfinding algorithms, the proposed algorithm runs in polynomial
time and efficiently handles positive-length cycles. We demonstrate the
effectiveness of the proposed model and the new algorithm on several
testbed problems implementing a network architecture of IT and indus
trial components.