作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2011, Vol. 37 ›› Issue (5): 172-174,178. doi: 10.3969/j.issn.1000-3428.2011.05.058

• 安全技术 • 上一篇    下一篇

针对复合攻击的网络攻击预测算法

陈 灿1,2,阎保平1     

  1. (1. 中国科学院计算机网络信息中心,北京 100190;2. 中国科学院研究生院,北京 100039)
  • 出版日期:2011-03-05 发布日期:2012-10-31
  • 作者简介:陈 灿(1982-),男,博士研究生,主研方向:网络安全;阎保平,研究员

Network Attack Forecast Algorithm for Multi-step Attack

CHEN Can 1,2, YAN Bao-ping 1   

  1. (1. Computer Network Information Center, Chinese Academy of Sciences, Beijing 100190, China; 2. Graduate University of Chinese Academy of Sciences, Beijing 100039, China)
  • Online:2011-03-05 Published:2012-10-31

摘要: 网络攻击以复合攻击形式为主,但当前的安全设备只能检测无法预测。针对该问题,提出一种基于攻击效用的复合攻击预测方法,通过该方法识别攻击者的最终意图,并预测攻击者下一步可能进行的攻击行为。该方法利用攻击意图描述复合攻击过程,建立基于攻击意图的复合攻击逻辑关系图,引入攻击效用的概念,表示入侵者在攻击过程中完成每步攻击所获得的收益大小,是复合攻击预测的参考。实验结果验证了该方法的有效性。

关键词: 攻击预测, 复合攻击, 攻击意图, 攻击效用

Abstract: The main form of network attack is multi-step attack. The current security equipments can only detect but not forecast. For this issue, this paper presents an approach based on attack utility to recognize the attacker’s finally intention and forecast the next possible attack. It describes a multi-attack by the attack intent, and establishes the multi-attack logic diagram based on the attack intention. During the procedure of the attack forecast, attack utility is used to represent the attackers benefit for each attack step. The attack utility is an important reference for the multi-step attack forecast. Experimental results prove the validity of the algorithm.

Key words: attack forecast, multi-step attack, attack intention, attack utility

中图分类号: