计算机应用 ›› 2010, Vol. 30 ›› Issue (1): 190-195.

• 信息安全 • 上一篇    下一篇

基于粗糙图的网络风险评估模型

黄光球,李艳   

  1. 西安建筑科技大学
  • 收稿日期:2009-07-26 修回日期:2009-08-11 发布日期:2010-01-01 出版日期:2010-01-01
  • 通讯作者: 黄光球
  • 基金资助:
    陕西自然科学基金项目;陕西省教育厅专项基金项目

Network risk assessment model based on rough graph

  • Received:2009-07-26 Revised:2009-08-11 Online:2010-01-01 Published:2010-01-01

摘要: 针对在进行网络安全分析时所获得的信息系统是不完备的、粗糙的这一特性,将网络攻击过程类比于粗糙不确定性问题的关系挖掘过程,提出基于粗糙图的网络风险评估模型。该模型由部件节点粗糙关联网络、攻击图的粗糙图生成算法以及网络风险最大流分析算法三部分主要内容组成;并以一个具有代表性的网络系统实例阐明了该模型的使用方法,验证了模型的正确性。模型优势分析表明其较以往的攻击图、风险评价模型更能真实地反映实际情况,所获得的评估结论、安全建议等也更加准确、合理。

关键词: 网络风险评估, 网络攻击模型, 攻击图, 粗糙图, 粗糙网络

Abstract: Concerning the characteristic that the information system obtained from doing network security analysis is rough and incomplete, this paper compared the process of attack to the rough and uncertain relationship mining process by analogy, and proposed a new network risk assessment model based on rough graph. The model is made up of three parts of main contents including node rough correlation network, attack graph generation algorithm based on rough graph and network risk maximum flow analysis algorithm. In the end, this paper used a representative example of network system to explain the method of model, and verified the correctness. Model advantage analysis shows that the model can reflect the actual situation better than the previous attack graph model and risk assessment model, and the conclusion and safety recommendations are more accurate and reasonable.

Key words: network risk assessment, network attack model, attack graph, rough graph, rough network