首页 | 本学科首页   官方微博 | 高级检索  
     

基于属性攻击图的动态威胁跟踪与量化分析技术研究
引用本文:杨英杰, 冷强, 潘瑞萱, 胡浩. 基于属性攻击图的动态威胁跟踪与量化分析技术研究[J]. 电子与信息学报, 2019, 41(9): 2172-2179. doi: 10.11999/JEIT181117
作者姓名:杨英杰  冷强  潘瑞萱  胡浩
作者单位:信息工程大学 郑州 450001
基金项目:国家高技术研究发展计划(863计划);国家重点研发计划;国家自然科学基金
摘    要:
网络多告警信息融合处理是有效实施网络动态威胁分析的主要手段之一。基于此该文提出一种利用网络系统多告警信息进行动态威胁跟踪与量化分析的机制。该机制首先利用攻击图理论构建系统动态威胁属性攻击图;其次基于权限提升原则设计了前件推断算法(APA)、后件预测算法(CPA)和综合告警信息推断算法(CAIIA)进行多告警信息的融合与威胁分析,生成网络动态威胁跟踪图进行威胁变化态势的可视化展示。最后通过实验验证了该机制和算法的有效性。

关 键 词:多告警信息   网络动态威胁分析   属性攻击图   权限提升
收稿时间:2018-12-04
修稿时间:2019-04-05

Research on Dynamic Threat Tracking and Quantitative Analysis Technology Based on Attribute Attack Graph
Yingjie YANG, Qiang LENG, Ruixuan PAN, Hao HU. Research on Dynamic Threat Tracking and Quantitative Analysis Technology Based on Attribute Attack Graph[J]. Journal of Electronics & Information Technology, 2019, 41(9): 2172-2179. doi: 10.11999/JEIT181117
Authors:Yingjie YANG  Qiang LENG  Ruixuan PAN  Hao HU
Affiliation:Information Engineering University, Zhengzhou 450001, China
Abstract:
Network multi-alarm information fusion processing is one of the most important methods to implement effectively network dynamic threat analysis. Focusing on this, a mechanism for dynamic threat tracking and quantitative analysis by using network system multi-alarm information is proposed. Firstly, the attack graph theory is used to construct the system dynamic threat attribute attack graph. Secondly, based on the privilege escalation principle, Antecedent Predictive Algorithm(APA), the Consequent Predictive Algorithm(CPA) and the Comprehensive Alarm Information Inference Algorithm(CAIIA) are designed to integrate the multi-alarm information fusion and do threat analysis. Then, the network dynamic threat tracking graph is generated to visualize the threat change situation. Finally, the effectiveness of the mechanism and algorithm is validates through experiments.
Keywords:Multiple alarm information  Network dynamic threat analysis  Attribute attack graph  Privilege escalation
本文献已被 万方数据 等数据库收录!
点击此处可从《电子与信息学报》浏览原始摘要信息
点击此处可从《电子与信息学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号