作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2021, Vol. 47 ›› Issue (5): 104-116. doi: 10.19678/j.issn.1000-3428.0060128

• 网络空间安全 • 上一篇    下一篇

融合社交网络威胁的攻击图生成方法

杨艳丽, 宋礼鹏   

  1. 中北大学 大数据学院, 太原 030051
  • 收稿日期:2020-11-27 修回日期:2021-01-15 发布日期:2021-01-20
  • 作者简介:杨艳丽(1994-),女,硕士研究生,主研方向为网络安全、知识图谱;宋礼鹏,教授、博士生导师。
  • 基金资助:
    国家自然科学基金(61772478)。

Attack Graph Generation Method Integrating Social Network Threats

YANG Yanli, SONG Lipeng   

  1. School of Big Data, North University of China, Taiyuan 030051, China
  • Received:2020-11-27 Revised:2021-01-15 Published:2021-01-20

摘要: 针对现有攻击图生成和分析方法多数未考虑社交网络威胁的问题,提出一种基于知识图谱融合社交网络威胁的攻击图生成方法。根据攻击图的构建需求和收集的内网环境数据,设计融合社交网络威胁的网络安全本体模型和知识图谱,以实现对社交网络和物理网络数据的关联分析以及对攻击图输入信息的扩展,基于知识图谱采用广度优先搜索算法生成融合社交网络威胁的攻击图,并给出内部社交网络威胁的攻击成功率计算方法。基于真实网络拓扑和脆弱性信息的实验结果表明,与现有攻击图的相关方法相比,该方法可有效发现网络中潜在的借助社交网络入侵的攻击路径。

关键词: 网络安全, 知识图谱, 社交网络威胁, 属性攻击图, 本体模型

Abstract: The existing methods for attack graph generation and analysis do not consider the threats of social network. This paper proposes a method to generate an attack graph integrating social network threats based on a knowledge graph. According to attack graph construction requirements and the collected intranet data,a network security ontology model and knowledge graph that integrate social network threats are designed.The model and the knowledge graph enable the analysis of the association between social network data and physical network data,as well as the extension of the input information of the attack graph.Then based on the knowledge graph,a breadth-first search algorithm is used to generate an attack graph that integrates social network threats,and a method for calculating the attack success rate of internal social network threats is given.Experiments are carried out based on the real-world network topology and real-world vulnerability information.The results show that compared with the existing attack graph-related techniques,this method can effectively discover the paths of potential attacks based on social network.

Key words: network security, knowledge graph, social network threats, attribute attack graph, ontology model

中图分类号: