期刊文献+

一种基于脆弱点依赖图的脆弱性评估方法 被引量:4

A vulnerability assessing method based on vulnerability dependence graph
原文传递
导出
摘要 为弥补目前网络脆弱性评估系统比较简单、评估结果不全面不准确的不足,提出一种基于脆弱点依赖图的网络脆弱性评估方法,并在该评估方法基础上开发出相应的评估系统.该方法吸收了通用弱点评价体系(CVSS)的优势,同时与目标网络的脆弱点依赖图很好地结合起来,可对网络脆弱性做出一个客观评价.在计算过程中,该方法将脆弱性可利用性和脆弱性影响分开计算,并与实际目标网络中的脆弱点依赖图相结合,从而使得计算值更有参考和实用价值. To make up the deficiencies of the network vulnerability assessing system which was quite simple and had incomprehensive and inaccurate assessing result,a network vulnerability assessing method based on vulnerability dependence graph was presented,and the corresponding assessing system was developed.The method absorbs the superiority of common vulnerability scoring system(CVSS) and well combines with vulnerability dependence graph of goal network,which can make an impersonal and quantitative evaluation roundly for the network vulnerability.The method computes vulnerability,exploitability and vulnerability influence individually,and combines with actual goal network's vulnerability dependence graph,therefore the results have more important reference and practical value.
出处 《大连海事大学学报》 CAS CSCD 北大核心 2010年第4期92-95,共4页 Journal of Dalian Maritime University
基金 国家高技术研究发展计划(863)资助项目(2009AA01Z432)
关键词 计算机网络 脆弱点依赖图 通用弱点评价体系(CVSS) computer network vulnerability dependence graph common vulnerability scoring system(CVSS)
  • 相关文献

参考文献7

  • 1陈秀真,郑庆华,管晓宏,林晨光.层次化网络安全威胁态势量化评估方法[J].软件学报,2006,17(4):885-897. 被引量:342
  • 2茼大鹏.基于图论的网络安全评估系统的设计与实现[M].哈尔滨:哈尔滨工程大学出版社,2007.
  • 3张海霞,连一峰,苏璞睿,冯登国.基于安全状态域的网络评估模型[J].软件学报,2009,20(2):451-461. 被引量:19
  • 4VARDI Y, ZHANG Cunhui. Measures of network vulnerability[ J ]. IEEE Signal Processing Letters, 2007, 14 ( 5 ) : 313-316.
  • 5ZHANG Lufeng,TANG Hong, CUI Yiming, et al. Network security evaluation through attack graph generation[J].World Academy of Science, Engineering and Technology, 2009, 54:412-415.
  • 6陈峰.基于多目标攻击图的层次化网络安全风险评估方法研究[M].长沙:国防科技大学出版社,2009.
  • 7MELL P. The common vulnerability scoring system (CVSS) and its applicability to federal agency systems [R]. NIST Interagency Report 7435, 2007.

二级参考文献4

共引文献353

同被引文献5

引证文献4

二级引证文献8

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部