摘要
网络多告警信息融合处理是有效实施网络动态威胁分析的主要手段之一。基于此该文提出一种利用网络系统多告警信息进行动态威胁跟踪与量化分析的机制。该机制首先利用攻击图理论构建系统动态威胁属性攻击图;其次基于权限提升原则设计了前件推断算法(APA)、后件预测算法(CPA)和综合告警信息推断算法(CAIIA)进行多告警信息的融合与威胁分析,生成网络动态威胁跟踪图进行威胁变化态势的可视化展示。最后通过实验验证了该机制和算法的有效性。
Network multi-alarm information fusion processing is one of the most important methods to implement effectively network dynamic threat analysis.Focusing on this,a mechanism for dynamic threat tracking and quantitative analysis by using network system multi-alarm information is proposed.Firstly,the attack graph theory is used to construct the system dynamic threat attribute attack graph.Secondly,based on the privilege escalation principle,Antecedent Predictive Algorithm(APA),the Consequent Predictive Algorithm(CPA)and the Comprehensive Alarm Information Inference Algorithm(CAIIA)are designed to integrate the multi-alarm information fusion and do threat analysis.Then,the network dynamic threat tracking graph is generated to visualize the threat change situation.Finally,the effectiveness of the mechanism and algorithm is validates through experiments.
作者
杨英杰
冷强
潘瑞萱
胡浩
YANG Yingjie;LENG Qiang;PAN Ruixuan;HU Hao(Information Engineering University,Zhengzhou 450001,China)
出处
《电子与信息学报》
EI
CSCD
北大核心
2019年第9期2172-2179,共8页
Journal of Electronics & Information Technology
基金
国家“863”高技术研究发展计划基金(2015AA016006)
国家重点研发计划(2016YFF0204003)
国家自然科学基金(61471344)~~
关键词
多告警信息
网络动态威胁分析
属性攻击图
权限提升
Multiple alarm information
Network dynamic threat analysis
Attribute attack graph
Privilege escalation