计算机科学 ›› 2010, Vol. 37 ›› Issue (9): 94-96.

• 计算机网络与信息安全 • 上一篇    下一篇

基于攻击检测的网络安全风险评估方法

陈天平,许世军,张串绒,郑连清   

  1. (空军工程大学电讯工程学院 西安710077);(西北工业大学365研究所 西安710072)
  • 出版日期:2018-12-01 发布日期:2018-12-01
  • 基金资助:
    本文受国家自然科学基金项目(60873233),陕西省科技攻关项目(2008-k04-21)资助。

Risk Assessment Method for Network Security Based on Intrusion Detection System

CHEN Tian-ping,XU Shi-jun,ZHANG Chuan-rong,ZHENG Lian-qing   

  • Online:2018-12-01 Published:2018-12-01

摘要: 为了实时评估网络安全风险,建立了用于描述主机安全状态的隐马尔可夫模型,以入侵检测系统的报警信息作为模型输入,计算主机处于被攻击状态的概率。针对攻击报警,提出了一种新的攻击成功概率计算方法,然后结合攻击威胁度计算主机节点的风险指数。最后利用主机节点重要性权重与节点风险指数量化计算网络风险。实例分析表明,该方法能够动态绘制网络安全风险态势曲线,有利于指导安全管理员及时调整安全策略。

关键词: 网络安全,风险评估,入侵检测系统,隐马尔可夫模型

Abstract: The Hidden Markov Model(HMM) for describing host security states was established to evaluate the real time security risk of network, whose input is Intrusion Detection System alers. The probability for host to be attacked was calculated by this model. Aimed at the attack alers, a new calculating method for attack success probability was presented, and used attack threat level to calculate the risk index of the host node. Finally, the importance weight and risk index of all the host nodes were used to calculated the risk of the network ctuantitatively. The case study demonstrated this method can provide the real-time risk curves of host system for security managers to adjust security policies.

Key words: Network security, Risk assessment, Intrusion detection system, Hidden markov model

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!