检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:陶礼靖 邱菡[1] 朱俊虎[1] 李航天 TAO Li-jing;QIU Han;ZHU Jun-hu;LI Hang-tian(Information Engineering University,Zhengzhou 450001,China)
出 处:《计算机科学》2022年第S01期480-484,704,共6页Computer Science
摘 要:对受训者训练表现的评估是提升网络安全训练成效的关键环节之一,对评估方法的研究包含了基于训练结果和基于训练行为建模的评估两个阶段,前者存在无法评价训练细节的问题,后者存在仅能对部分训练路径预建模,无法判定非预设训练路径下训练行为正确性的问题。为解决上述问题,提出了一种基于有向图和有限状态自动机的双层网络安全训练评估受训者行为描述模型,结合训练行为和训练结果各自的特点,实现对非预设训练行为的正确性判定和细节评价。针对典型网络安全训练场景的实验结果表明,相比仅关注训练行为的描述模型,该模型在提高训练行为判定准确性的同时,实现了对非预设路径训练行为正确性的判定和训练细节的刻画。The evaluation of trainee performance is one of the key points to improve the effectiveness of cyber security exercises,and the study of evaluation method includes two stages:evaluation based on training results and evaluation based on training behavior modeling.The first one cannot figure out the training details,the other can only pre-model some training paths so that it can’t determine the correctness of non-preset training path training behavior.In order to solve the problems,a two-layer cyber security exercises trainee behavior description model based on the orientation graph and finite state automatic machine is proposed,and the correctness determination and detail evaluation of non-preset training behavior are realized by combining the characteri-stics of training behavior and training results.An experiment on typical computer network security training scenario shows that,compared with the description model that focuses only on training behavior,the model improves the accuracy of training behavior determination,and realizes the determination of non-preset path training behavior correctness and training details.
关 键 词:网络安全训练 训练行为建模 有向图 有限状态自动机
分 类 号:TP393[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:3.148.179.141