计算机应用 ›› 2013, Vol. 33 ›› Issue (11): 3224-3227.

• 信息安全 • 上一篇    下一篇

基于链路性能分析的网络安全态势评估研究

黄正兴1,苏旸1,2   

  1. 1. 武警工程大学 网络与信息安全武警部队重点实验室,西安 710086
    2. 武警工程大学 网络与信息安全研究所,西安 710086
  • 收稿日期:2013-05-30 修回日期:2013-07-21 出版日期:2013-11-01 发布日期:2013-12-04
  • 通讯作者: 黄正兴
  • 作者简介:黄正兴(1989-),男,浙江衢州人,硕士研究生,主要研究方向:网络与信息安全;苏旸(1975-),男,河南焦作人,教授,博士,主要研究方向:信息安全、密码学。
  • 基金资助:
    国家自然科学基金资助项目;陕西省自然科学基础研究计划项目

Network security situational assessment based on link performance analysis

HUANG Zhengxing1,SU Yang1,2   

  1. 1. Key Laboratory of Network and Information Security under the Chinese Armed Police Force, Engineering University of Armed Police Force, Xian Shaanxi 710086, China;
    2. Institute of Network and Information Security, Engineering University of Armed Police Force, Xian Shaanxi 710086, China
  • Received:2013-05-30 Revised:2013-07-21 Online:2013-12-04 Published:2013-11-01
  • Contact: HUANG Zhengxing

摘要: 针对网络安全态势评估的融合特性和现有层次化态势评估方法存在对未知攻击感知不足的问题,提出融合链路安全态势值来计算网络安全态势值的方法。借助网络性能分析的相关理论,提出了基于链路性能分析的网络安全态势评估模型。在态势值计算过程中,首先计算不同时段各链路的安全态势值,并把结果以矩阵形式表现出来;然后,将各链路安全态势值进行加权融合,得到不同时段的网络安全态势值,并以向量形式表示。实验结果证明,所提方法能够反映网络局部和整体的安全状况变化,并且对未知攻击具有良好的感知能力,给网络安全管理带来了方便。

关键词: 融合, 性能分析, 链路安全态势, 网络安全态势, 未知攻击

Abstract: Concerning the fusion essence of network situational assessment and the defect of being unaware of the unknown attack in the existing Analytic Hierarchy Process (AHP), a network security evaluation method based on link security situation was proposed. With the help of the theory of network performance analysis, the network security situational assessment model based on link performance analysis was proposed. Firstly, the paper calculated every links security situational value and showed them in a matrix; secondly, used every links weight and security situational value to get the network security situational value which was shown in vector. The experimental results show that the proposed method can not only reflect the changes of both the partial and entire security situation but also apperceive unknown attack, which provides administrator with much convenience.

Key words: fusion, performance analysis, link security situation, network security situation, unknown attack

中图分类号: