首页 | 本学科首页   官方微博 | 高级检索  
     

基于环境属性的网络威胁态势量化评估方法
引用本文:席荣荣,云晓春,张永铮.基于环境属性的网络威胁态势量化评估方法[J].软件学报,2015,26(7):1638-1649.
作者姓名:席荣荣  云晓春  张永铮
作者单位:中国科学院 信息工程研究所, 北京 100093,中国科学院 信息工程研究所, 北京 100093,中国科学院 信息工程研究所, 北京 100093
基金项目:国家高技术研究发展计划(863)(2012AA012803, 2013AA014703); 国家科技支撑计划(2012BAH46B02); 国家自然科学基金(61070185); 中国科学院知识创新工程基金(XDA06030200)
摘    要:传统的网络威胁态势评估方法主要是基于原始的警报信息,未结合目标网络的环境信息,使得方法的准确性受到很大的影响.提出了一种基于环境属性的网络威胁态势量化评估方法,该方法首先根据目标网络的环境属性对警报进行验证,判定引发警报的安全事件发生的可能性;然后,基于安全事件的风险级别及所针对的资产价值,分析安全事件发生后造成的损失;最后,基于安全事件发生的可能性及造成的损失量化评估网络的威胁态势.实例分析结果表明,该方法可以准确地量化评估网络的威胁态势.

关 键 词:威胁态势量化评估  警报验证  环境属性  资产价值
收稿时间:2013/8/20 0:00:00
修稿时间:4/2/2014 12:00:00 AM

Quantitative Threat Situational Assessment Based on Contextual Information
XI Rong-Rong,YUN Xiao-Chun and ZHANG Yong-Zheng.Quantitative Threat Situational Assessment Based on Contextual Information[J].Journal of Software,2015,26(7):1638-1649.
Authors:XI Rong-Rong  YUN Xiao-Chun and ZHANG Yong-Zheng
Affiliation:Institute of Information Engineering, The Chinese Academy of Sciences, Beijing 100093, China,Institute of Information Engineering, The Chinese Academy of Sciences, Beijing 100093, China and Institute of Information Engineering, The Chinese Academy of Sciences, Beijing 100093, China
Abstract:Traditional network threat situational assessment is based on primary alerts, however, its lack of access to contextual information compromises the accuracy of assessment. This paper proposes a method to quantitatively assess network threat situation based on not only alerts but also contextual information. The new method first verifies alerts along with contextual information to determine the successful possibility of events; then analyzes the loss caused by events according to the risk and the corresponding asset value of events; and finally quantitatively assesses network threat situation based on the successful possibility and the loss of events. Case studies show that the proposed method can evaluate network threat situations accurately.
Keywords:threat situational assessment  alert verification  contextual information  asset value
点击此处可从《软件学报》浏览原始摘要信息
点击此处可从《软件学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号