作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2012, Vol. 38 ›› Issue (14): 8-12. doi: 10.3969/j.issn.1000-3428.2012.14.003

• 专栏 • 上一篇    下一篇

一种松耦合网络安全态势感知模型

刘 宇 1,2,卢志刚 1,刘宝旭 1   

  1. (1. 中国科学院高能物理研究所计算中心,北京 100049;2. 中国科学院研究生院,北京 100049)
  • 收稿日期:2011-11-21 出版日期:2012-07-20 发布日期:2012-07-20
  • 作者简介:刘 宇(1984-),男,博士研究生,主研方向:网络安全,数据挖掘,风险管理;卢志刚,博士;刘宝旭,研究员、博士
  • 基金资助:

    国家科技支撑计划基金资助重点项目(2009BAH52B06);北京市自然科学基金资助面上项目(4072010);中科院知识创新重点方向基金资助项目(YYYJ-1013)

Loose Coupling Network Security Situation Awareness Model

LIU Yu 1,2, LU Zhi-gang 1, LIU Bao-xu 1   

  1. (1. Computing Center, Institute of High Energy Physics, Chinese Academy of Sciences, Beijing 100049, China; 2. Graduate University of Chinese Academy of Sciences, Beijing 100049, China)
  • Received:2011-11-21 Online:2012-07-20 Published:2012-07-20

摘要:

提出一个基于Kaplan-Meier生存性分析的松耦合网络安全态势评估模型,用于对网络的历史安全状态进行评估以及对未来安全趋势进行预测。采用生存性分析理论实现多源数据融合与态势评估方法的松耦合,利用KDD99评估数据集建立包含多种节点的网络安全态势评估实例进行仿真分析,以阐明该模型在适应网络结构以及多源数据动态变化方面的优势,在此基础上绘制安全态势曲线图,并与历史安全趋势进行比较,结果证明该评估模型具有较高的准确性与较强的适用性。

关键词: 安全态势感知, 风险分析, 生存性分析, 松耦合, 多源数据融合

Abstract:

In order to assess the historical security states and forecasts future network security situation, this paper proposes a loose coupling network security situation awareness model by using survivability analysis based on Kaplan-Meier method. It uses survivability analysis method to get loose coupling between multi-source information fusion and security situation awareness method. A representation analysis of example with multi-type nodes based on KDD99 is given for security situation assessment. And it illustrates the superiority of this model in adapting the dynamic changes of network structure and multi-source data. The applicability and correctness of model is validated by drawing the graph of security situational awareness and comparing the results of security situational awareness with historical security states.

Key words: security situation awareness, risk analysis, survivability analysis, loose coupling, multi-source data fusion

中图分类号: