期刊文献+

基于攻击路径图的威胁评估方法 被引量:2

Threat evaluation method based on attack-path graph
下载PDF
导出
摘要 为解决复杂系统安全威胁评估问题,研究并建立了基于攻击路径图的系统安全威胁模型。该模型首先提出了漏洞利用可能性及利用结果的评估标准,进而在分析漏洞之间利用关系的基础上生成目标系统的攻击路径图,并以图论、概率论等理论作为基本方法对将复杂攻击路径分解为以串、并联形式为基本构成单元的简单路径,从而降低了安全威胁评估问题的规模和难度,实现了对漏洞威胁以及攻击路径威胁的量化评估。 In order to solve the problem of evaluation of system security threat in the complex information system, a system security threat model based on the attack-path graph was proposed. The model gives an evaluating standard of the possibility and harmful level of the vulnerability exploitation. Then an attack-path graph of the target system can be generated based on the exploitation relationship among vulnerabilities. Based on methods in the graph theory and probability theory, we can decompose the complicated attack-paths into several simple paths whose basal unit is series or parallel form. So, the dimensions and difficulty of evaluation of security threat is lowered greatly, and the quantitative evaluation to the threat of vulnerability and attack-path can be well done.
作者 蔡林 刘学忠
出处 《计算机应用》 CSCD 北大核心 2009年第B06期74-76,共3页 journal of Computer Applications
基金 国家自然科学基金资助项目(60572162)
关键词 攻击路径图 图论 概率论 威胁评估 attack-path graph graph theory probability theory evaluation of threat
  • 相关文献

参考文献8

  • 1.CCIMB-99-031.Common criteria for information technology security evaluation(Version2.1)[].Concise Oxford Dictionary.1999
  • 2Department of defense standard. ht-tp://csrc.nist.gov/publications/history/dod85.pdf . 2008
  • 3SCHNEIER B.Attach trees[].DrDobb s Journal.1999
  • 4Siewiorek D P,Swarz R S.The theory and practice of reliable system design[]..1982
  • 5Oleg Mikhail Sheyner.Scenario Graphs and Attack Graphs[]..2004
  • 6Gibbons A.Algorithmic Graph Theory[]..1985
  • 7Bodsberg L.Comparative Study of Quantitative Models for Hardware,Software and Human Reliability Assessment[].Quality and Reliability.2007
  • 8Ng,S.W.Reliability & Availability of Duplex Systems: Some Simple Models[].IEEE Transactions on Reliability.1986

同被引文献15

引证文献2

二级引证文献17

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部