摘要
研究了攻击树建模攻击的方法,主要研究目的是如何有效地用攻击树建模和表示多阶段网络攻击。对传统攻击树进行扩充和改进,重新定义了攻击节点,量化了叶子节点的攻击风险,提出了一种用MLL-AT(多级分层攻击树)建模攻击的思想和方法,并给出了一种基于攻击树的MLL-ATDL攻击描述语言。改进后的攻击树能更准确地建模攻击,尤其是表示多阶段网络攻击,并可以用于评估系统风险,区分不同攻击序列对系统的不同安全威胁程度。
The method of modeling attack using attack tree was researched.The main research goal was how to effectively use the attack tree model and denote the multi-stage network attacks.Traditional attack tree was expanded and improved.Nodes of attack tree were redefined,and attack risk of leaf node was quantified.Then the mentality and method for estab-lishing MLL-AT(multi-level layer attack tree) were proposed.Based on the given attack tree,the MLL-ATDL(mul-ti-level layer attack tree description language) attack description language was given.The improved attack tree can model the attacks more accurately,in particular the multi-stage network attacks.And it can also be used for appraising system risk,distinguishing the different degrees of system security threats caused by different attack sequences.
出处
《通信学报》
EI
CSCD
北大核心
2011年第3期115-124,共10页
Journal on Communications
基金
国家高技术研究发展计划("863"计划)基金资助项目(2007AA01Z409)
国家自然科学基金资助项目(60473093)
江苏省高技术研究计划基金资助项目(BG2004030)
江苏省科技支撑计划基金资助项目(BE2008124)
江苏省高校自然科学研究项目(10KJB520020)~~
关键词
网络安全
网络攻击
攻击建模
攻击树
攻击描述语言
network security
network attack
intrusion modeling
attack tree
attack description language