期刊文献+

基于信息融合的网络安全态势评估模型 被引量:42

Network security situational awareness model based on information fusion
下载PDF
导出
摘要 针对分布式拒绝服务(DDoS)攻击评估不准确和网络安全态势评估不全面的问题,提出了一种基于信息融合的网络安全态势评估模型。首先,提出了以数据包信息为原始数据的DDoS攻击威胁评估方法,提高了评估的准确性;然后,对原有的通用弱点评价体系(CVSS)进行改进并对漏洞脆弱性进行评估,使得评估更加全面;其次,结合客观权重和主观权重,并以序列二次规划(SQP)算法对组合权重进行寻优,降低了融合的不确定性;最后,将三者进行融合得到网络的安全态势。通过搭建入侵检测平台,利用不同的规则库,针对相同DDoS攻击的报警数会相差3个数量级,与依赖报警数评估方法相比,以数据包信息评估DDoS攻击的方法可得到准确的DDoS攻击威胁态势。仿真对比结果表明,提出的模型和方法能够提高评估结果准确度。 Since the evaluation of Distributed Denial of Service (DDoS) is inaccurate and network security situational evaluation is not comprehensive, a new network security situational awareness model based on information fusion was proposed. Firstly, to improve the accuracy of evaluation, a situation assessment method of DDoS attack based on the information of data packet was proposed; Secondly, the original Common Vulnerability Scoring System (CVSS) was improved and the leak vulnerability was evaluated to make the assessment more comprehensive; Then, according to the combination of objective weight and subjective weight, the method of calculating the combined weights and optimizing the results by Sequence Quadratic Program (SQP) algorithm was raised to reduce the uncertainty of fusion; Finally, the network security situation was got by fusing three aspects evaluation. To verify the original evaluation of DDoS was inaccurate, a testing platform was built and the alarm of the same DDoS differed by 3 orders of magnitude. Compared to the original method based on alarm, the steady and accurate result of evaluation was obtained based on data packet. The experimental results show that the proposed method can improve the accuracy of evaluation results.
出处 《计算机应用》 CSCD 北大核心 2015年第7期1882-1887,共6页 journal of Computer Applications
基金 国家自然科学基金资助项目(61271260 61301122) 教育部科学研究重点项目(212145)
关键词 拒绝服务攻击评估 通用弱点评价体系 组合权重 序列二次规划 态势评估 Distributed Denial of Service (DDoS) evaluation Common Vulnerability Scoring System (CVSS) combined weight Sequence Quadratic Program (SQP) situation assessment
  • 相关文献

参考文献14

  • 1XU Z. Demand-oriented traffic measuring method for network security situation assessment [J]. Journal of Networks, 2014, 9(4): 221-224.
  • 2FISCHER Y, BEYERER J. Ontologies for probabilistic situation assessment in the maritime domain [C]// CogSIMA 2013: Proceedings of the 2013 IEEE International Multi-Disciplinary Conference on Cognitive Methods in Situation Awareness and Decision Support. Piscataway: IEEE, 2013: 102-105.
  • 3BASS T. Intrusion detection systems & multisensor data fusion: cre-ating cyberspace situational awareness [J]. Communications of the ACM, 2000, 43(4): 99-105.
  • 4GORODETSKY V, KARSAEV O, SAMOILOV V. On-line update of situation assessment based on asynchronous data streams [C]// Proceedings of the 8th International Conference on Knowledge-Based Intelligent Information and Engineering Systems, LNCS 3213. Berlin: Springer, 2004: 1136-1142.
  • 5FRIGAULT M, WANG L, SINGHAL A, et al. Measuring network security using dynamic Bayesian network [C]// Proceedings of the 4th ACM Workshop on Quality of Protection. New York: ACM, 2008: 23-30.
  • 6WANG L, WANG B, PENG Y. Research the information security risk assessment technique based on Bayesian network [C]// Proceedings of the 3rd International Conference on Advanced Computer Theory and Engineering. Piscataway: IEEE, 2010: 600-604.
  • 7JI X, PATTINSON C. AHP implemented security assessment and security weight verification [C]// Proceedings of the 2010 IEEE Second International Conference on Social Computing. Piscataway: IEEE, 2010: 1026-1031.
  • 8陈秀真,郑庆华,管晓宏,林晨光.层次化网络安全威胁态势量化评估方法[J].软件学报,2006,17(4):885-897. 被引量:341
  • 9付钰,吴晓平,叶清.基于改进FAHP-BN的信息系统安全态势评估方法[J].通信学报,2009,30(9):135-140. 被引量:14
  • 10刘奇旭,张翀斌,张玉清,张宝峰.安全漏洞等级划分关键技术研究[J].通信学报,2012,33(S1):79-87. 被引量:36

二级参考文献43

共引文献400

同被引文献278

引证文献42

二级引证文献179

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部