基于服务影响分析的网络安全态势定量感知方法  被引量:2

Service impact analysis-based quantitative method for networksecurity situational awareness

在线阅读下载全文

作  者:梁颖[1] 王慧强[1] 刘磊[1] 

机构地区:[1]哈尔滨工程大学计算机科学与技术学院,哈尔滨150001

出  处:《东南大学学报(自然科学版)》2008年第A01期64-67,共4页Journal of Southeast University:Natural Science Edition

基  金:国家高技术研究发展计划(863计划)资助项目(2007AA01Z401);国家自然科学基金重大研究计划资助项目(90718003)

摘  要:根据服务与配置间的资源依存关系,选取服务可用性与服务性能作为影响分析的重要指标,将网络服务运行状态抽象为安全态势基本要素.引入混合策略博弈刻画网络空间攻防双方的安全交互,建立网络攻防博弈形式化模型,并对模型中的策略空间、转移规则、效用函数等给出了明确定义.实验结果表明,该方法可定量刻画Nash均衡时博弈双方的收益情况,完成了网络安全态势的量化分析与自动生成,为安全管理员正确决策提供支持.采用服务影响分析方法屏蔽了系统配置及入侵行为细节,效率高、实时性强,有助于网络安全态势感知研究的发展.According to dependencies between service and configuration, service availability and performance were selected as important indexes in impact analysis, and network service states were abstracted as basic security situational elements. Mixed strategy game was introduced to depict the security interaction between attackers and defenders in cyberspace, and formal modeling of network attack-defense game was constructed in which parameters, such as strategy space, transition rules and payoff functions were clearly defined. Experimental results show that payoffs of game players at Nash equilibrium can be quantified, further more quantitative analysis and automatic generation of network security situation is achieved, which will help security administrators make correct decisions. Adopting service impact analysis can shield details about system configurations and intrusions, and it is of high efficiency and real-time performance and helpful in development of network security situational awareness.

关 键 词:网络安全 态势感知 混合策略博弈 可用性 性能 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象