计算机应用 ›› 2010, Vol. 30 ›› Issue (11): 3046-3050.

• 信息安全 • 上一篇    下一篇

基于脆弱性关联模型的网络威胁分析

王纯子1,黄光球2   

  1. 1. 西安建筑科技大学 管理学院,西安 710055;西安工程大学 管理学院,西安710048
    2. 西安建筑科技大学 管理学院
  • 收稿日期:2010-05-18 修回日期:2010-07-15 发布日期:2010-11-05 出版日期:2010-11-01
  • 通讯作者: 王纯子
  • 基金资助:
    陕西自然科学基金项目;陕西省教育厅专项基金项目

Network threat analysis based on vulnerability relation model

WANG Chun-zi1,HUANG Guang-qiu2   

  1. 1. School of Management, Xi'an University of Architecture and Technology, Xi'an Shaanxi 710055, China; School of Management, Xi'an Polytechnic University, Xi'an Shaanxi 710048, China
    2.
  • Received:2010-05-18 Revised:2010-07-15 Online:2010-11-05 Published:2010-11-01
  • Contact: WANG Chun-zi

摘要: 为了解决网络脆弱性建模存在的问题以及威胁评估方法中的不足,结合面向对象技术提出了基于扩展时间Petri网的脆弱性关联模型,通过定义攻击复杂度和危害度因素以及各评估指标的量化方法,给出了脆弱性关联模型的生成算法。结合网络威胁度的计算公式,运用改进的Dijkstra算法给出了无目标导向的网络威胁量化分析方法。该模型能够有效缩减状态空间的规模,适合对复杂网络攻击建模。实验证明了脆弱性关联模型的正确性及其优越的描述性能,基于该模型的威胁分析方法也更为合理、有效。

关键词: 网络安全, 面向对象, 时间Petri网, 脆弱性关联模型, 威胁度

Abstract: To solve the problems in network vulnerability model and threat analysis method, the paper proposed a network vulnerability relation model based on extended time Petri net. By introducing complexity and harmfulness of network attack, and defining each index's quantization, the generation algorithm of vulnerability relation model was proposed. Combined with network threat definition, a non-target oriented network threat analysis method based on improved Dijkstra algorithm was presented. The model was suitable for describing complicated network attack, which could reduce the scale of state space effectively. The experiment proves the correctness and performance of vulnerability relation model, and the threat analysis method based on the model is more reasonable and effective.

Key words: network security, object-oriented, time Petri net, vulnerability relation model, threat