摘要
给出一种面向攻防演练的计算机网络防御系统的设计,此系统用计算机网络防御描述语言(CNDDL)描述。针对PDRR模型,CNDDL语言能够将攻防演练中的防御想定转化成保护、检测、响应和恢复等措施及防御逻辑,由解释器进行解释、执行,并部署在平台中。在GTNetS仿真平台中的试验表明,此系统能够实现ACL访问控制功能、对特定攻击进行检测的功能、系统是否对攻击做出响应及恢复的功能,从而为计算机网络攻防模拟演练提供防御支持。
A computer network defense system is designed by computer network defense description language. CNDDL can describe protection, detection, response and recovery measures based on PDRR model. By interpreting, the measures is implemented in the platform. Experiments in GTNetS platform indicated that CND system using CNDDL can describe ACL (access control list) of protection measures, IDS detection command for detection measures, response or not for response measures, recovery information for recovery measures. The above information shows that CND system can provide defense support for computer network attack and defend simulation,
出处
《计算机工程与设计》
CSCD
北大核心
2008年第1期18-20,24,共4页
Computer Engineering and Design
基金
航空科学基金项目(03F51060)
北京教育委员会共建项目建设计划基金项目(SYS100060412)
国防基础科研项目基金项目
关键词
计算机网络防御
攻防演练
计算机网络防御描述语言
PDRR模型
GTNETS
computer network defense (CND)
attack and defense exercise
computer network defense description language (CNDDL)
PDRR model
GTNetS