摘要
随着互联网的普及,网络攻击已经成为制约互联网发展的重要安全问题。随着社交工程等新型攻击手段的出现,网络攻击呈现出复杂性、隐蔽性和分布式等特点,不断威胁着网络安全和信息安全。因此,提出了一种基于本体的潜在网络攻击路径的发现方法。具体地,通过本体构建网络信息系统模型,描述攻击者、安全弱点和攻击方法,利用SWRL规则刻画攻击者能力,并结合本体推理机来自动识别信息系统潜在的多步网络攻击途径。
With the popularity of the Internet, the cyber attack becomes an important problem in restricting the development of the Internet. With the advent of new-type attacks such as social engineering, the cyber attack is characterized by complexity, invisibility and distribution, directly threatening network security and information security. In this paper, an ontology-based method to find out potential network attack paths is proposed. By constructing a network information system model based on ontology, the attacker, security vulnerabilities and attack methods are described, and with SWRL rules, the capabilities of the attacker portrayed, and meanwhile, the ontology reasoning engine is used to automatically identify potential multi-step network attack toute.
出处
《通信技术》
2018年第2期419-424,共6页
Communications Technology
基金
科技部国家重点研发计划(No.2016YFB0800100,No.2016YFB0800105)
国家自然科学地区科学基金项目(No.61562004)
关键词
网络攻击
网络安全
本体
社交工程
cyber attack
network security
ontology
social engineering