期刊文献+

面向网络架构的系统攻击面建模方法

System Attack Surface Modeling Method in Network
下载PDF
导出
摘要 针对空管信息系统与互联网隔离、利用公开发布的漏洞信息不能切实体现网络安全性等问题,文章提出网络架构的空管信息系统风险评估模型。该模型综合各资源组件的端口、协议、数据进行资源节点的攻击面建模,使用贝叶斯网络为资源间的相互关系建立资源图。在上述模型的基础上,融合各资源攻击面与在资源图约束下的脆弱性严重程度为系统攻击面三元组,以表征三维度的威胁程度,计算网络结构的整体风险。在空管自动化系统中进行仿真实验,量化系统在不同攻击路径、不同维度上的威胁情况,多角度、多层次分析网络结构风险情况。实验结果表明,文章提出的系统攻击面风险评估模型具有合理性和实践有效性,为空管信息系统网络安全保障提供了指导性建议,从而在有限条件下最大限度地保障系统安全。 Aiming at the problems that the air traffic control information system is isolated from the Internet and the use of public released vulnerability information cannot effectively reflect its network security,this paper proposed a risk measurement model of air traffic management information system at the network level.The dimension of attack surface modeling had ports,protocols,data for each resource component.This model used Bayesian network to represent the relationship among resources to establish resource graph.Each resource component’s attack surface and vulnerability severity based on resource graph were fused into network attack surface triple.It represented the threat level of three dimensions and calculated the overall risk of the network architecture.Simulation experiments were carried out in the air traffic management automation system.Experiments quantified the threat situation of the system in different attack paths and dimensions.Besides,the network structure risk was analyzed from different angles and levels.Experimental results demonstrate the rationality and practical effectiveness of the proposed system attack surface risk assessment method.The attack surface model provides guidance for network security measures of air traffic management information system.Thus,security administrator can maximize system security under finite conditions.
作者 顾兆军 杨睿 隋翯 GU Zhaojun;YANG Rui;SUI He(Information Security Evaluation Center,Civil Aviation University of China,Tianjin 300300,China;College of Computer Science and Technology,Civil Aviation University of China,Tianjin 300300,China;College of Aeronautical Engineering,Civil Aviation University of China,Tianjin 300300,China)
出处 《信息网络安全》 CSCD 北大核心 2022年第3期29-38,共10页 Netinfo Security
基金 民航安全能力建设基金[PESA2020100,PESA2021007,PESA2021009] 中国民航大学研究生科技创新基金[2020YJS030]。
关键词 风险评估模型 贝叶斯网络 攻击面测量 空管信息系统 risk measurement model Bayesian network attack surface metric air traffic information system
  • 相关文献

参考文献3

二级参考文献36

  • 1冯登国,张阳,张玉清.信息安全风险评估综述[J].通信学报,2004,25(7):10-18. 被引量:308
  • 2王卫东.安全度量及其面临的挑战[J].保密科学技术,2011(3):54-58. 被引量:1
  • 3陈秀真,郑庆华,管晓宏,林晨光.层次化网络安全威胁态势量化评估方法[J].软件学报,2006,17(4):885-897. 被引量:342
  • 4Phillips C, Swiler L P. A graph-hased system for network- vulnerability analysis [C] //Proc of the 1998 Workshop on New Security Paradigms. New York: ACM, 1998:71-79.
  • 5Swiler L P, Phillips C, Ellis D, et al. Computerattack graph generation tool [C] //Proe of DARPA Information Survivability Conf. Piscataway, NJ: IEEE, 2001: 307-321.
  • 6Jha S, Sheyner O, Wing J. Two formal analyses of attack graphs [C] //Proc of Computer Security Foundations Workshop. Piscataway, NJ: IEEE, 2002: 49-63.
  • 7Ammann P, Wijesekera D, Kaushik S. Scalable, graph- based network vulnerability analysis [C] //Proc of the 9th ACM Conf on Computer and Communications Security. New York: ACM, 2002:217-224.
  • 8Sheyne O, Haines J, Jha S, et al. Automated generation and analysis of attack graphs [C] //Proc of IEEE Syrup on Security and Privacy. Los Alamitos, CA: IEEE Computer Sciety, 2002:273-284.
  • 9Wang Lingyu, Yao Chao, Singhal A, et al. Interactive analysis of attack graphs using relational queries [C] //Proc of the 20th Annual IFIP Working Conf on Data Applications Security. Berlin: Springer, 2006:119-132.
  • 10Ingols K, Chu M, Lippmann R, et al. Modeling modern network attacks and counter measures using attack graphs [C] //Proc of Computer Security Applications Conf. Piscataway, NJ: IEEE, 2009:117-126.

共引文献31

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部