计算机科学 ›› 2009, Vol. 36 ›› Issue (7): 63-67.doi: 10.11896/j.issn.1002-137X.2009.07.013

• 计算机网络与信息安全 • 上一篇    下一篇

基于WOWA-FAHP的网络安全态势评估

吕镇邦,周波   

  1. (中国航空计算技术研究所 西安710068);(西安电子科技大学计算机学院 西安710071)
  • 出版日期:2018-11-16 发布日期:2018-11-16
  • 基金资助:
    本文受国家自然科学基金资助项目(60573036),航空基础科学基金资助项目(03B31007)资助。

Network Security Situation Assessment Based on WOWA-FAHP

LU Zhen-bang,ZHOU Bo   

  • Online:2018-11-16 Published:2018-11-16

摘要: 从入侵响应决策与安全管理的实际需求出发,提出了基于WOWA合成的模糊层次分析法(WOWA-FAHP)和基于WOWA-FAHP的网络安全态势评估模型。WOWA-FAHP方法在继承模糊层次分析法优点的基础上兼顾属性间的客观、主观关联性,能够适应各种决策偏好。基于WOWA-FAHP的评估模型把动态评估与静态评估相结合,充分利用系统安全风险评佑、入侵警报融合关联、异常监测与安全审计所提供的多种信息,综合考虑警报类、异常类、脆弱性、后果性等多方面的评价指标,并依据不同安全策略,通过WOWA-FAHP方法处理诸如评价要素间的复杂关系。网络应用服务系统安全态势评估实例证明了方法与模型的有效性。

关键词: 网络安全,态势评估,WOWA算子,模糊层次分析法,决策偏好

Abstract: For the practical purposes of intrusion response decision-making and security management, a Fuzzy Analytic Hierarchy Process approach based on Weighted Ordered Weighted Averaging aggregation(WOWA-FAHP) and a network security situation assessment model based on WOWA-FAHP were proposed. Besides preserving the merits of the FAHP, the WOWA-FAHP approach takes into account both objective and subjective associations among the attributes,and is able to adapt various decision preferences. I}he assessment model based on WOWA-FAHP combines static and dynamic assessments; utilizes multiple information sources, such as system security risk evaluation, intrusion alert fusion and correlation, anomaly monitor and security audit; considers multiple aspects, such as intrusion alerts, anomalies, vulnerabilitics,and attack effects;and handles the complex relations among the factors with the WOWA-FAHP approach according to different security policies. The effectiveness of the proposed approach and model is illustrated via an actual security situation assessment for a network application service system.

Key words: Network security, Situation assessment, Weighted ordered weighted averaging operator, Fuzzy analytic hierarchy process, Decision preference

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!