期刊文献+

一种基于隐Markov模型的网络安全态势感知方法研究 被引量:9

An Approach to Network Security Situation Awareness Based on Hidden Markov Model
在线阅读 下载PDF
导出
摘要 为了准确评估网络系统的安全状态,文章提出一种基于隐Markov模型(HMM)的网络安全态势感知方法。首先通过对系统多种安全检测数据融合,得到系统的网络结构、资产、威胁和脆弱性数据的规范化数据;接着对系统中的每个资产,将该资产受到的威胁和存在的脆弱性结合起来,分析影响该资产的安全事件序列,分别建立该资产保密性、完整性和可用性三个安全性分量的HMM,采用滑动窗口机制将观测序列分段训练,并采用带遗忘因子的更新算法得到HMM的各个参数;然后根据HMM和观测序列分析该资产安全状态,评估该资产的安全态势分量;最后综合分析网络中所有资产的安全态势分量,评估网络的安全态势分量,并根据应用背景评估网络的整体安全态势。实验分析表明,基于HMM的网络安全态势感知方法符合实际应用,评估结果准确有效。 To accurately evaluate security situation states,this paper proposes an approach to network security situation awareness(NSSA) based on Hidden Markov Model(HMM).It gains standardized data of network structure information,assets,threats and vulnerabilities via fusing variety system security data collected by multi-sensors.For every asset,this paper associates its suffered threats with its vulnerabilities to analyze the sequence of its security incidents,establishes HMMs to analyze security situation factors of confidentiality,integrity and availability.Using sliding window mechanism it trains segmented sequence of security incidents and it gains the parameters of HMM's through update algorithm with forgetting factor.According to the HMMs and security incidents sequence it evaluates security situation factors of one asset's and entire network.Depending on the application background it evaluates security situation states of different network system.The investigation of evaluation to a specific network indicates that the approach is suitable for actual network environment and the evaluation result is precise and efficient.
作者 张勇 谭小彬
出处 《信息网络安全》 2011年第10期47-51,共5页 Netinfo Security
基金 国家高技术研究发展(863)计划(2006AA01Z449) 第42届中国博士后科学基金资助项目(20070420738)
关键词 网络安全 态势感知 隐MARKOV模型 滑动窗口 遗忘因子 network security situation awareness Hidden Markov Model sliding window forgetting factor
  • 相关文献

参考文献11

  • 1Freeman D M.EPA's basins model:good science or serendipitous modeling?[J].Journal of the Americam Water Resources A ssociation,2000,36(3):493.
  • 2姜文来.水源价值论[M].北京 :科学出版社,1999..
  • 3Dai T,Labadie J W.River basin network model for integrated water quantity/quality management [J].Journal of Water Resources Planning and Management,2001,127(5):295-305.
  • 4Campbell S G,Hanna R B,Flug M,et al.Modeling Klamath River system operations for quantity and quality [J].Journal of Water Resources Planning and Management,2001,127(5):284-294.
  • 5Luiten J P A,Groot S.Modeling quantity and quality of surface waters in the Netherlands:policy analysis of water management for the Netherlands [J].European Water Pollution Control, 1992,(2):23-33.
  • 6Vijayan G,Nathan N S,Subramanian R S,et al.Management of water resources for quality and quantity [J].Journal of Indian Water Works Association, 1999,January-Mareh:43-46.
  • 7Azevedo D L,Gabrief T,Gates T K,et al.Integration of water quantity and quality in strategic river basin planning [J].Journal of Water Resources Planning and Management,2000,126(2):85-97.
  • 8Mica R.Endsley.Toward a Theory of Situation Awareness in Dynamic Systems[C].Human Factors Journal,March 1995,Volume 37(7):32-64.
  • 9Wei Hu etc.,A Novel Approach to Cyberspace Security Situation Based on the Vulnerabilities Analysis[C].Proceedings of the 6th World Congress on Intelligent Control and Automation,June 21-23,2006.
  • 10赵国生,王慧强,王健.基于灰色关联分析的网络可生存性态势评估研究[J].小型微型计算机系统,2006,27(10):1861-1864. 被引量:25

二级参考文献4

共引文献25

同被引文献58

引证文献9

二级引证文献32

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部