摘要
安全性分析研究工作需要把计算机网络与安全相关的系统资源和安全因素抽取出来建立一种面向安全性分析的安全模型。从安全需求的类别、等级和面临的主要威胁出发,分析了系统设备、访问权限、主体连接关系和弱点,从攻击者目的是提升特权的角度对攻击作了形式化的描述。针对计算机系统的安全故障树方法和网络信息系统的攻击图方法应用了这一安全分析建模工作。
The research of security analysis needed a systemic security analysis model that was from the system resource and security factor of computer network. For the classification, rate and the main threaten of the security requirement, system devices, access privilege, host connection relation and vulnerability were analyzed, and the computer network attack from the point of view that the attacker's objective was to get privilege escalation was described. The computer system security analysis by fault tree and the network system security analysis by attack graph use the security analysis model.
出处
《通信学报》
EI
CSCD
北大核心
2005年第12期100-109,共10页
Journal on Communications
基金
国家自然科学基金资助项目(60403033)
国防十五预研基金资助项目(41315.7.1)
关键词
计算机网络安全
安全模型
弱点
攻击
故障树
攻击图
computer network security
security model
vulnerability
attack
fault tree
attack graph