摘要
为了进行网络风险评估,采用隐马尔可夫随机过程作为分析手段,以入侵检测系统的输出(报警事件)为处理对象,建立了描述主机系统受到攻击后状态转化的隐马尔可夫模型(HMM),给出了主机系统风险指数的计算方法,并经过简单叠加得到整个网络风险的定量评价。最后通过实验证实了所提出方法的有效性。
In order to evaluate the network risk, Hidden Markov random procedure was adopted as analysis means. The output of intrusion detection systems ( called alarm events) was used as the processed objects. The Hidden Markov Model (HMM) to describe the state transform of the attacked host system was constructed. The calculation method of the risk coefficient for host systems was given. The risk coefficients for host systems were simply added to obtain the quantitive evaluation of the risk for whole network. The experiments justify that the proposed method is effective.
出处
《计算机应用》
CSCD
北大核心
2008年第10期2471-2473,2477,共4页
journal of Computer Applications
基金
上海工程技术大学科研基金项目(07-22)
关键词
网络安全
隐马尔可夫模型
风险评估
network security
Hidden Markov Model (HMM)
risk evaluation