计算机应用研究
計算機應用研究
계산궤응용연구
APPLICATION RESEARCH OF COMPUTERS
2013年
3期
906-908
,共3页
李庆朋%王布宏%王晓东%张春明
李慶朋%王佈宏%王曉東%張春明
리경붕%왕포굉%왕효동%장춘명
网络安全%攻击图%原子攻击%累积可达概率
網絡安全%攻擊圖%原子攻擊%纍積可達概率
망락안전%공격도%원자공격%루적가체개솔
network security%attack graph%atomic attack%cumulative reachable probability
为了保护网络中关键信息资产, 评估分析网络的整体安全性, 提出了一种基于攻击图节点概率的网络安全度量方法。该方法改进了原子攻击节点自身概率的计算模型, 引入累积可达概率, 在此基础上, 研究了网络安全风险评估模型。实验结果表明, 所提评估方法能够准确地评估目标状态的安全级别和网络的整体风险。
為瞭保護網絡中關鍵信息資產, 評估分析網絡的整體安全性, 提齣瞭一種基于攻擊圖節點概率的網絡安全度量方法。該方法改進瞭原子攻擊節點自身概率的計算模型, 引入纍積可達概率, 在此基礎上, 研究瞭網絡安全風險評估模型。實驗結果錶明, 所提評估方法能夠準確地評估目標狀態的安全級彆和網絡的整體風險。
위료보호망락중관건신식자산, 평고분석망락적정체안전성, 제출료일충기우공격도절점개솔적망락안전도량방법。해방법개진료원자공격절점자신개솔적계산모형, 인입루적가체개솔, 재차기출상, 연구료망락안전풍험평고모형。실험결과표명, 소제평고방법능구준학지평고목표상태적안전급별화망락적정체풍험。
To protect critical information resources in networked environment and evaluate the overall security of network, this paper paper proposed a approach to network security assessment based on probabilities of attack graph nodes. By improving individual probability's computational model of atomic attack and introducing cumulative reachable probability of nodes in the attack graph, it proposed the assessment model of network security risk. Experimental results show that the proposed approach can accurately assess the security level of target states and overall security risk of network.