首页 | 本学科首页   官方微博 | 高级检索  
     

信度向量正交投影分解的网络安全风险评估方法
引用本文:刘刚*,李千目,张宏.信度向量正交投影分解的网络安全风险评估方法[J].电子与信息学报,2012,34(8):1934-1938.
作者姓名:刘刚*  李千目  张宏
作者单位:南京理工大学计算机科学与技术学院南京210094
基金项目:国家自然科学基金(60903027);江苏省自然科学重大研究项目(BK2011023);江苏省自然科学基金(BK2011370)资助课题
摘    要:传统安全风险评估方法大都存在着主观性和片面性问题,该文针对网络节点的漏洞和攻击层面的风险分析需求,提出了漏洞信度和攻击信度的概念,设计了一种信度向量正交投影分解的网络安全风险评估方法。该方法首先将攻击所依赖的漏洞信息和节点本身漏洞信息相关联,结合网络中各节点自身的权重,量化从节点至全网的安全风险分析;其次,在漏洞信度计算时,为了排除漏洞扫描工具自身的不确定因素和数据源的单一性,将多个扫描工具的检测结果融合,构成数据源;最后,基于欧式空间向量投影的思想提出了一个信度向量投影分解算法。实验结果验证了该文方法的有效性。

关 键 词:网络安全    安全风险评估    信度向量正交投影分解
收稿时间:2011-12-27

Reliability Vector Orthogonal Projection Decomposition Method of Network Security Risk Assessment
Liu Gang Li Qian-mu Zhang Hong.Reliability Vector Orthogonal Projection Decomposition Method of Network Security Risk Assessment[J].Journal of Electronics & Information Technology,2012,34(8):1934-1938.
Authors:Liu Gang Li Qian-mu Zhang Hong
Affiliation:Liu Gang Li Qian-mu Zhang Hong(School of Computer Science and Technology,Nanjing University of Science and Technology,Nanjing 210094,China)
Abstract:Most traditional security risk assessment methods have the shortcomings of subjectivity and one-sidedness.Considering the risk analysis demand of vulnerabilities and attacks of network nodes,this paper proposes the concept of vulnerability reliability and attack reliability,and designs a reliability vector orthogonal projection decomposition method of network security risk assessment.First,this method associates vulnerability information which attacks relying on with vulnerability information of the node itself,and quantifies the security risk analysis from the node to the whole network,with the own weight of each node in the network.Second,in order to exclude the own uncertainties of vulnerability scanning tools and the unity of the data source,this method fuses several test results of scan tool,and constitutes the data source when calculating the vulnerability reliability.Finally,based on the idea of Euclidean space vector projection,the method puts forward an algorithm of reliability vector projection decomposition.The result of the experiment of the network security risk evaluation procedure is given to verify the proposed evaluate method.
Keywords:Network security  Security risk assessment  Reliability vector orthogonal projection decomposition
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《电子与信息学报》浏览原始摘要信息
点击此处可从《电子与信息学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号