期刊文献+

主动网络安全风险管理系统

An Active Network Security Risk Management System
下载PDF
导出
摘要 针对日益严峻的网络安全威胁,文章从加强内部安全管理入手,依据BS7799信息安全管理体系标准的规范及指标,提出了一个主动网络安全风险管理系统。该系统利用信息侦察代理获得园区网的基本配置及漏洞信息,在此基础上建立潜在入侵事件扩散模型,分析模型并对网络所面临的安全风险进行定性和定量评估,最后根据评估结果执行相应的风险控制措施,使风险等级降低到可接受的水平。文章还介绍了主动安全风险管理系统的结构,入侵扩散模型以及风险评估算法的具体细节,实验结果表明该系统能够有效地协助管理员建立完善的安全风险管理体系。 Network threats are more and more relentless. From the point of strengthening internal security management, an active network security risk management system (ANSRMS) complying with BS7799 is presented. ANSRMS uses information detecting agents to get configuration and vulnerabilities of the network, develops the spread model of underlying intrusion, provides qualitative and quantitive assessment of security risk, and finally adopts corresponding risk control policy to decrease the risk level. This paper introduces the details of the architecture of ANSRMS, spread model of intrusion and our risk assessment algorithm. The experiment results given shows that ANSRMS can efficiently help administrators to set up a completed security risk management framework.
作者 颉钰 李卫
出处 《微电子学与计算机》 CSCD 北大核心 2004年第6期1-5,9,共6页 Microelectronics & Computer
基金 国家自然科学基金重点项目(59937150) 国家863计划项目(2001AA413910)
关键词 网络安全 风险评估 入侵扩散模型 风险管理 BS7799 Network security, Risk assessment, Spread model of intrusion, Risk management, BS7799
  • 相关文献

参考文献6

  • 1Information Assurance Technical Framework. IATF Document [EB/OL]. Release 3.1, http:∥www.iaff. net/framework_docs/version-3_ 1/index.cfm, 2002.
  • 2Common Criteria for IT Security Evaluation [EB/OL]. Version2.1, http:∥csrc.nist.gov/cc/index.html, 1999.
  • 3Department of Defense. Trusted Computer System Evaluation Criteria [EB/OL]. http:∥www.radium.ncsc.mil/tpep/library/rainbow/5200.28-STD.html, 1985.
  • 4International Organization for Standardization. ISO/IEC17799: 2000[S]. http:∥www.iso.org, 2000.
  • 5Fyodor. Remote OS Detection via TCP/IP Stack Finger Printing [EB/OL]. http:∥www.insecure.org/nmap/nmap -fingerprinting-article.html, 1999.
  • 6David Moore, Vern Paxson, Stefan Savage, etc. The Spread of the Sapphire/Slammer Worm[EB/OL]. http:∥www.silicondefense.com/research/worms/slammer.php, 2003.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部