面向实时业务的网络安全态势评估  被引量:2

REAL-TIME SERVICE-ORIENTED NETWORKS SECURITY SITUATION ASSESSMENT

在线阅读下载全文

作  者:刘一博[1] 殷肖川[1] 方研[1] 

机构地区:[1]空军工程大学信息与导航学院,陕西西安710077

出  处:《计算机应用与软件》2014年第9期304-308,共5页Computer Applications and Software

摘  要:网络安全事件的多样性和复杂性使得传统方法难以对网络安全态势作出实时动态的评估。鉴于此,提出一种面向网络实时业务的网络安全态势评估方法。尝试以网络实时业务为切入点来降低评估复杂度,实时动态地评估网络安全态势。基本思路是采用层次化方法建立实时业务风险模型,采用攻击树方法建立攻击威胁模型,将这两个模型作为评估的数据支撑;对D-S证据理论合成公式进行改进;利用改进后的D-S证据理论实现上述两个模型的关联,进而得出实时的评估结果。最后通过一个测试实验对评估方法进行验证与分析。The complexity and diversity of networks security events make it difficult to give real-time and dynamic assessment on networks security situation. In view of this, in this paper we propose an assessment approach for networks security situation oriented to real-time services of networks. It tries to use real-time network business as the entry point to reduce the complexity of assessment and thus achieves real-time and dynamic assessment on networks security situation. The basic idea is that to adopt hierarchical approach to build real-time business risk model and to use attacking tree method to build attackin.g threat model. We use these two models as the data support of the assessment, and make improvement on D-S evidence theory composition formula. The improved D-S evidence theory is employed to implement the association between two models mentioned above, and in turn the real-time assessment results are obtained. At last, the assessment method is verified and analysed through a test experiment,

关 键 词:网络安全 态势评估 业务风险模型 威胁模型 D-S理论 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象