摘要
提出了一种基于模拟攻击的网络安全风险评估分析方法.在提取目标系统及其脆弱性信息和攻击行为特征的基础上,模拟攻击者的入侵状态改变过程,生成攻击状态图,并给出其生成算法.研究了利用攻击状态图对网络系统安全进行评估的方法.提出了一种新的评估系统的设计方案,给出评估系统的总体框架结构及各模块功能组成。
The novel network security risk analysis model is proposed based on simulation attacks. First, the information about 'target network and the vulnerable information is studied and described. By correlating the system' s vulnerabilities and attacker's behaviors, attack state graph was introduced, and its generating algorithm presented. Then a new network vulnerability evaluation system is studied and designed based on attack graph modeling method. The block scheme of the computer network vulnerability evaluation system is proposed.The function and structure of all modules are analyzed.
出处
《微计算机信息》
2009年第18期45-46,29,共3页
Control & Automation
关键词
网络安全
模拟攻击
攻击状态图
风险评估
network security
attack simulating
state graph
risk assessment