首页 | 本学科首页   官方微博 | 高级检索  
     检索      

基于贝叶斯网络的脆弱性状态评估方法
引用本文:陈思思,连一峰,贾炜.基于贝叶斯网络的脆弱性状态评估方法[J].中国科学院研究生院学报,2008,25(5):639-648.
作者姓名:陈思思  连一峰  贾炜
作者单位:1. 信息安全国家重点实验室(中国科学院研究生院),北京,100049
2. 信息安全国家重点实验室(中国科学院研究生院),北京,100049;中国科学院软件研究所,北京,100080
3. 中国科学技术大学电子工程与信息科学系,合肥,230027
基金项目:国家高技术研究发展计划(863计划)
摘    要:对网络安全性的量化评估问题是目前网络安全领域的研究热点之一。通过对现有的网络安全模型及量化分析方法的研究和比较,针对影响网络安全性的各项因素的全面脆弱性评估,提出了网络可靠度、脆弱点关键度、脆弱性状态图最低阶最小路集和最低阶最小割集4个具体的评估指标,将基于贝叶斯网络的计算方法引入脆弱性评估中,提出了量化评估计算方法。在此基础上构建了网络实例,使用SPIN验证工具对网络攻击进行模拟并对提出的评估指标及算法进行了分析验证。实验结果表明,文中提出的算法和评估指标集能够正确地量化反映网络的安全状态。

关 键 词:脆弱性评估  评估指标  贝叶斯网络  量化评估

A network vulnerability evaluation method based on Bayesian networks
CHEN Si-Si,LIAN Yi-Feng,JIA Wei.A network vulnerability evaluation method based on Bayesian networks[J].Journal of the Graduate School of the Chinese Academy of Sciences,2008,25(5):639-648.
Authors:CHEN Si-Si  LIAN Yi-Feng  JIA Wei
Institution:1State Key Laboratory of Information Security, Graduate University of Chinese Academy of Sciences, Beijing 100049, China;
2 Institute of Software , Chinese Academy of Sciences, Beijing 100080, China; 3 Department of Electronic Engineering and Information Science, University of Science and Technology of China, Hefei 230027, China
Abstract:Network vulnerability evaluation is a hot topic of network security research. In this paper we analyze and compare the existing network security model and quantitative assessment methods. Considering all the security-related factors of network in vulnerability evaluation, we propose a set of evaluation metrics that includes reliability parameters of network, criticality parameters of network, lowest degree minimal path set and lowest degree minimal cut set .We also propose a new method of quantitative assessment based on Bayesian network. Finally we give an example to simulate the net-attack using SPIN and validate vulnerability evaluation indices and methods. The result shows that the method and the evaluation indices could evaluate and reflect the security state of network successfully.
Keywords:vulnerability evaluation  evaluation indices  Bayesian networks  quantitative assessment
本文献已被 万方数据 等数据库收录!
点击此处可从《中国科学院研究生院学报》浏览原始摘要信息
点击此处可从《中国科学院研究生院学报》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号