The attack graph methodology can be used to identify the potential attack paths that an attack can propagate. A risk assessment model based on Bayesian attack graph is presented in this paper. Firstly, attack graphs a...The attack graph methodology can be used to identify the potential attack paths that an attack can propagate. A risk assessment model based on Bayesian attack graph is presented in this paper. Firstly, attack graphs are generated by the MULVAL(Multi-host, Multistage Vulnerability Analysis) tool according to sufficient information of vulnerabilities, network configurations and host connectivity on networks. Secondly, the probabilistic attack graph is established according to the causal relationships among sophisticated multi-stage attacks by using Bayesian Networks. The probability of successful exploits is calculated by combining index of the Common Vulnerability Scoring System, and the static security risk is assessed by applying local conditional probability distribution tables of the attribute nodes. Finally, the overall security risk in a small network scenario is assessed. Experimental results demonstrate our work can deduce attack intention and potential attack paths effectively, and provide effective guidance on how to choose the optimal security hardening strategy.展开更多
为确立船舶营运过程中的风险涌现特征,需要考虑复杂系统组成因子的不确定结构问题。以复杂性系统为视角,提出了一种复杂网络不确定结构的风险功能共振分析模型。首先,利用Apriori算法对船舶系统组分进行风险分析,计算组成因子间的非线...为确立船舶营运过程中的风险涌现特征,需要考虑复杂系统组成因子的不确定结构问题。以复杂性系统为视角,提出了一种复杂网络不确定结构的风险功能共振分析模型。首先,利用Apriori算法对船舶系统组分进行风险分析,计算组成因子间的非线性交互效用,生成交互强度矩阵,从而确立船舶营运安全风险的功能共振分析模型(Functional Resonance Analysis Model,FRAM)。随后,采用图卷积网络(Graph Convolutional Network,GCN)构建系统组分网络,识别关键节点,并对因子交互关系网络结构进行重塑。最后,引入深度优先搜索(Depth First Search,DFS)算法,识别关键风险路径,计算出船舶系统组分因子的影响度。结合港口国监督(Port State Control,PSC)缺陷数据,运用前述模型对船舶营运风险进行仿真应用。应用结果表明,船舶的不安全状态受到内外部组成因子的属性影响,并存在关键共振路径关系,其中消防系统、船舶结构状态等是影响船舶不安全状态的核心节点。构建的风险功能共振分析模型能够基于不同的数据输入,自适应生成相应的风险路径依赖。基于复杂网络结构的风险功能共振模型有助于分析不确定结构复杂系统的风险涌现。展开更多
随着大数据环境下数据安全风险复杂化,现有数据安全审计技术因碎片化特征利用及扩展能力不足,难以实现全生命周期风险覆盖,限制了风险检测效能.因此,提出一种基于风险要素的图嵌入数据安全审计方案(graph-embedded data security audit ...随着大数据环境下数据安全风险复杂化,现有数据安全审计技术因碎片化特征利用及扩展能力不足,难以实现全生命周期风险覆盖,限制了风险检测效能.因此,提出一种基于风险要素的图嵌入数据安全审计方案(graph-embedded data security audit scheme based on risk elements,RE-GDSA).首先构建含数据属性D(data)、用户特征U(user)、载体环境C(carrier)、操作行为A(action)的安全风险要素空间,实现数据全生命周期风险特征的结构化映射;然后利用图嵌入技术将风险要素映射为低维语义向量,构建跨维度关联模型以实现高效风险检测.通过有效性分析和性能分析验证了该方案的可行性.展开更多
基金Supported by the National Natural Science Foundation of China(61373176)the Natural Science Foundation of Shaanxi Province of China(2015JQ7278)the Scientific Research Plan Projects of Shaanxi Educational Committee(17JK0304,14JK1693)
文摘The attack graph methodology can be used to identify the potential attack paths that an attack can propagate. A risk assessment model based on Bayesian attack graph is presented in this paper. Firstly, attack graphs are generated by the MULVAL(Multi-host, Multistage Vulnerability Analysis) tool according to sufficient information of vulnerabilities, network configurations and host connectivity on networks. Secondly, the probabilistic attack graph is established according to the causal relationships among sophisticated multi-stage attacks by using Bayesian Networks. The probability of successful exploits is calculated by combining index of the Common Vulnerability Scoring System, and the static security risk is assessed by applying local conditional probability distribution tables of the attribute nodes. Finally, the overall security risk in a small network scenario is assessed. Experimental results demonstrate our work can deduce attack intention and potential attack paths effectively, and provide effective guidance on how to choose the optimal security hardening strategy.
文摘为确立船舶营运过程中的风险涌现特征,需要考虑复杂系统组成因子的不确定结构问题。以复杂性系统为视角,提出了一种复杂网络不确定结构的风险功能共振分析模型。首先,利用Apriori算法对船舶系统组分进行风险分析,计算组成因子间的非线性交互效用,生成交互强度矩阵,从而确立船舶营运安全风险的功能共振分析模型(Functional Resonance Analysis Model,FRAM)。随后,采用图卷积网络(Graph Convolutional Network,GCN)构建系统组分网络,识别关键节点,并对因子交互关系网络结构进行重塑。最后,引入深度优先搜索(Depth First Search,DFS)算法,识别关键风险路径,计算出船舶系统组分因子的影响度。结合港口国监督(Port State Control,PSC)缺陷数据,运用前述模型对船舶营运风险进行仿真应用。应用结果表明,船舶的不安全状态受到内外部组成因子的属性影响,并存在关键共振路径关系,其中消防系统、船舶结构状态等是影响船舶不安全状态的核心节点。构建的风险功能共振分析模型能够基于不同的数据输入,自适应生成相应的风险路径依赖。基于复杂网络结构的风险功能共振模型有助于分析不确定结构复杂系统的风险涌现。
文摘随着大数据环境下数据安全风险复杂化,现有数据安全审计技术因碎片化特征利用及扩展能力不足,难以实现全生命周期风险覆盖,限制了风险检测效能.因此,提出一种基于风险要素的图嵌入数据安全审计方案(graph-embedded data security audit scheme based on risk elements,RE-GDSA).首先构建含数据属性D(data)、用户特征U(user)、载体环境C(carrier)、操作行为A(action)的安全风险要素空间,实现数据全生命周期风险特征的结构化映射;然后利用图嵌入技术将风险要素映射为低维语义向量,构建跨维度关联模型以实现高效风险检测.通过有效性分析和性能分析验证了该方案的可行性.