摘要
传统入侵响应决策模型只考虑攻击损失和响应成本。在此基础上增加攻击目标的资产价值、响应风险在决策过程中的两个重要因素,分析了各成本的计算方法。提出一种把攻击目标作为无形资产进行评估的方法,并详细描述了采用SVM创建成本决策分析模型的过程。最后,基于日志记录进行攻击响应分析,给出了实验结果,显示该模型的决策结果有较高的正确率。
Traditional intrusion detection model only considers attack damage and response cost. In this study, two important factors in decision process, the property value of attack target and the response risk were added, and the calculation methods with each cost were analyzed. Moreover, a method for assessing attack target as the immaterial asset was proposed and the process that adopted support vector machine (SVM) model to set up the analysis model of the cost decision was described in detail. At last, according to the daily record, the experimental results show that the decision result of this model has higher accuracy.
出处
《计算机应用》
CSCD
北大核心
2007年第11期2704-2706,共3页
journal of Computer Applications
基金
山西省高校科技开发项目(20051202)
山西大学科研项目(2005103)
关键词
入侵响应
资产评估
成本决策
支持向量机
intrusion response
worth assessment of assets
cost-sensitive decision
Support Vector Machine (SVM)