计算机应用 ›› 2013, Vol. 33 ›› Issue (12): 3506-3510.

• 信息安全 • 上一篇    下一篇

多评估时间段的网络安全态势感知方法

李淳1,赵建保2,申晓留1   

  1. 1. 华北电力大学 控制与计算机工程学院,北京 102206;
    2. 河南省电力公司 科技通信部,郑州 450052
  • 收稿日期:2013-06-19 修回日期:2013-08-02 出版日期:2013-12-01 发布日期:2013-12-31
  • 通讯作者: 李淳
  • 作者简介:李淳(1990-),女,河北保定人,硕士研究生,主要研究方向:决策支持、信息安全;
    赵建保(1968-),男,河南郑州人,高级工程师,主要研究方向:电力信息化、信息安全;
    申晓留(1953-),男,山西太原人,教授,主要研究方向:决策支持、大型数据库管理。

Network security situational awareness method of multi-period assessment

LI Chun1,ZHAO Jianbao2,SHEN Xiaoliu1   

  1. 1. School of Control and Computer Engineering, North China Electric Power University, Beijing 102206, China
    2. Department of Information Technology, State Grid Henan Electric Power Company, Zhengzhou Henan 450052, China
  • Received:2013-06-19 Revised:2013-08-02 Online:2013-12-31 Published:2013-12-01
  • Contact: LI Chun

摘要: 分析比较了已有的安全态势评估方法,提出了一种基于时间维的网络安全态势评估方法,重点论述网络安全态势短期评估与长期评估使用不同方法的必要性。其中短期评估以防火墙、入侵检测等安全设备产生的告警信息作为数据基础,依据告警确定目的主机的状态得分进而得到整体短期安全态势;长期评估指标体系将短期评估结果纳入其中,综合静态指标数据,以熵值法确定指标权重。此评估方法将网络安全态势短中长期评估细分,弥补了态势评估在时间段划分方面的缺失。

关键词: 网络安全态势, 主机评估, 动态修正, 日志审计, 熵值法

Abstract: After analyzing and comparing the existing security situation assessment methods, a network security situation assessment method was proposed based on time dimension, which focused on the necessity of using different methods for short-term and long-term assessment respectively. Based on the alarm information which came from security device such as firewall and Intrusion Detection Systems (IDS), the whole short-term situation was got according to the score of destination host. Combining the result of short-term assessment and static index, the weight of long-term assessment system was determined by entropy method. The proposed assessment method divides network security situation into short-term and long-term, and makes up for the lack of setting situation assessment boundaries in terms.

Key words: network security situation, host assessment, dynamic correction, audit log, entropy

中图分类号: