摘要
面对日趋复杂的云安全环境和攻击威胁,传统的被动防御手段已无法从根源上解决安全问题。充分考虑攻防双方策略的相互制约,将博弈引入到云环境风险评估过程中,提出了云环境风险评估的评估架构和评估流程,并通过建立不同应用场景下的动态博弈模型,预测最大攻击意图,提高系统的精准评估能力和最优防御策略选取能力,这对提升云环境安全防御的主动化、精准化水平具有重要意义。
Facing the increasingly complex cloud security environment and attack threats,traditional passive defense methods cannot fundamentally solve security problems.By fully considering the mutual restriction between the attack and defense strategies,this paper introduces the game theory into the cloud environment risk assessment process,and proposes a cloud environment risk assessment framework and process.Then,through the establishment of dynamic game models in different application scenarios,the research can predict the maximum attack intention,improve the system’s accurate evaluation ability and optimal defense strategy selection ability.The results are significant for improving the initiative and precision level of cloud environment security defense.
作者
牛作元
张锋军
陈捷
曾梦岐
李庆华
许杰
NIU Zuoyuan;ZHANG Fengjun;CHEN Jie;ZENG Mengqi;LI Qinghua;XU Jie(No.30 Institute of CETC,Chengdu Sichuan 610041,China)
出处
《通信技术》
2022年第6期776-781,共6页
Communications Technology
关键词
博弈论
云计算
风险评估
主动防御
game theory
cloud computing
risk assessment
active defense