期刊文献+

考虑时间参数的网络安全态势评估模型研究

Network security situation assessment model based on time parameter
下载PDF
导出
摘要 针对已有网络安全态势评估由于缺乏考虑数据源时变性而造成的证据源证据不可靠、评估出现误差的问题,引入时变函数来刻画多源证据的时变性,提出时变D-S证据理论,用以提高证据的可靠性。使用改进的时变D-S证据理论方法对多传感器的证据进行融合,得到威胁的发生概率,并在此基础上提出带有时间参数的网络安全态势评估层次化模型;最后利用网络实例数据,对所提出的网络安全态势评估模型进行了验证。实验对比结果表明,该模型对实际网络运行情况的评估更符合实际情况。 For resolving the problem that due to the lack of consideration of time-varying of data sources,the existing network security situation assessment usually failed to make the source of evidence reliable enough and error existed in the assessment results,this paper introduced the time-varying function to describe the time-varying multi-source evidence.It proposed the time-varying D-S evidence theory to improve the reliability of the evidence.The occurrence probability of the threat was obtained by using the improved time-varying D-S evidence theory to multi-sensor fusion of the evidence.On this basis,it proposed the hierarchical model with time parameter.Finally it gave an example of the actual network datasets to valiadate the network security situa-tion awareness model.The results of the experimental comparison show that this model is more in line with the actual situation.
出处 《计算机应用研究》 CSCD 北大核心 2012年第10期3820-3823,共4页 Application Research of Computers
基金 国家自然科学基金资助项目(90718021 60903027) 自主科研先期投入计划资助项目(2010XQTR04)
关键词 网络安全 态势评估 时变D-S证据理论 多传感器数据融合 评估模型 network security situation assessment time-varying D-S evidence theory multi-sensor data fusion evaluation model
  • 相关文献

参考文献13

  • 1BASS T. Intrusion detection systems & multisensor data fusion :crea- ting cyberspace situational awareness [ J]. Communications of the ACM. 2000,43(4) :99-105.
  • 2BASS T. Multi-sensor data fusion for next generation distributed intru- sion detection systems [ C ]//Proc of IRIS National Symposium on Sen- sor and Data Fusion. 1999:24-27.
  • 3SHIFFLETS J. A technique independent fusion model for network in- trusion detection [ EB/OL]. ( 2005- 10- 13 ). http ://www. jcu. edu/ math/swarm/papers/Jason 2005. pdf.
  • 4D AMBROSIO B. Security situation assessment and response evalua- tion (SSARE)[ C]//Proc of DARPA Information Survivability Con- ference & Exposition II. Washington DC: IEEE Computer Society, 2001 : 387 - 394.
  • 5LAKKARAJU K, YURCIK W, LEE A J. NVision 1P: netflow visualiza- tions of system state for security situational awareness [ C ]//Proc of ACM Workshop on Visualization and Data Mining for Computer Secu- rity. New York: ACM Press, 2004:65-72.
  • 6YIN Xiao-xin, YURCIK W, SLAGELL A. The design of VisFlowCon- nect-lP: a link analysis system for IP security situational awareness [ C]//Proc of the 3rd IEEE International Workshop on Information Assurance. Maryland :IEEE Press,2005 : 141 - 153.
  • 7SHAFER G. A mathematical theory of evidence [ M ]. Princeton: Princeton University Press, 1976.
  • 8陈秀真,郑庆华,管晓宏,林晨光.层次化网络安全威胁态势量化评估方法[J].软件学报,2006,17(4):885-897. 被引量:341
  • 9孙全,叶秀清,顾伟康.一种新的基于证据理论的合成公式[J].电子学报,2000,28(8):116-119. 被引量:440
  • 10韦勇,连一峰,冯登国.基于信息融合的网络安全态势评估模型[J].计算机研究与发展,2009,46(3):353-362. 被引量:165

二级参考文献33

  • 1冯登国,张阳,张玉清.信息安全风险评估综述[J].通信学报,2004,25(7):10-18. 被引量:307
  • 2陈秀真,郑庆华,管晓宏,林晨光.层次化网络安全威胁态势量化评估方法[J].软件学报,2006,17(4):885-897. 被引量:341
  • 3赵国生,王慧强,王健.基于灰色关联分析的网络可生存性态势评估研究[J].小型微型计算机系统,2006,27(10):1861-1864. 被引量:25
  • 4张永铮,方滨兴,迟悦,云晓春.用于评估网络信息系统的风险传播模型[J].软件学报,2007,18(1):137-145. 被引量:76
  • 5Lakkaraju K, Yurcik W, Lee A J. NVisionIP: NetFlow visualizations of system state for security situational awareness [C] //Proc of the 2004 ACM Workshop on Visualization and Data Mining for Computer Security. New York: ACM, 2004:65-72
  • 6Yin Xiaoxin, Yurcik W, Treaster M, et al. VisFlowConnect: NetFlow visualizations of link relationships for security situational awareness [C] //Proc of the 2004 ACM Workshop on Visualization and Data Mining for Computer Security. New York: ACM, 2004:26-34
  • 7朱亮,王慧强,郑丽君.网络安全态势可视化研究评述[OL].[2008-01-08].http://www.paper.edu.cn/downloadpaper.php?serial_number=200607-36
  • 8Bass T. Intrusion detection systems & multisensor data fusion: Creating Cyberspace Situational Awareness [J].Communications of the ACM, 2000, 43(4): 99-105
  • 9D'Ambrosio B. Security situation assessment and response evaluation (SSARE) [C]//DISCEX'01. Proceedings: DARPA Information Survivability Conference & Exposition Ⅱ. Los Alamitos: IEEE Computer Society, 2001:387-394
  • 10Gorodetsky V, Karsaev O, Samoilov V. On-line update of situation assessment based on asynchronous data streams [C]//Knowledge Based Intelligent Information and Engineering Systems. Berlin/Heidelberg: Springer, 2004 : 1136-1142

共引文献945

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部