作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2013, Vol. 39 ›› Issue (4): 158-164. doi: 10.3969/j.issn.1000-3428.2013.04.037

• 安全技术 • 上一篇    下一篇

基于情景感知的网络安全风险评估模型与方法

戚 湧,王 艳,李千目   

  1. (南京理工大学计算机学院,南京 210094)
  • 收稿日期:2012-07-16 出版日期:2013-04-15 发布日期:2013-04-12
  • 作者简介:戚 湧(1970-),男,教授、博士后、CCF会员,主研方向:信息安全风险评估;王 艳,硕士研究生;李千目,副教授、博士后
  • 基金资助:
    国家自然科学基金资助项目(61272419);中国航天CAST创新基金资助项目(CAST200839);中国航天CALT创新基金资助项目(CALT201102)

Network Security Risk Assessment Model and Method Based on Situation Awareness

QI Yong, WANG Yan, LI Qian-mu   

  1. (School of Computer, Nanjing University of Science & Technology, Nanjing 210094, China)
  • Received:2012-07-16 Online:2013-04-15 Published:2013-04-12

摘要: 现有情景感知框架对网络安全风险评估没有精确的量化方法,为此,结合DS证据理论和协商目标风险分析系统,提出一种基于情景感知框架的网络安全风险评估模型。基于DS理论进行网络安全威胁信息融合和情景识别,采用概率风险分析进行逐层风险量化和网络安全风险判别,并以低轨道卫星通信网为例进行网络安全风险评估仿真实验,结果验证了该评估模型和方法能有效识别威胁情景,并提高风险评估判别的准确性。

关键词: DS证据理论, 协商目标风险分析系统, 情景感知, 低轨道卫星通信, 网络安全, 风险评估

Abstract: In view of network security situation awareness framework’s lack of a precise mathematical quantitative method to network information security risk assessment, a network risk assessment model based on network security situation awareness framework is proposed by combining DS evidence theory and Consultative Objective Risk Analysis System(CORAS). Network security threats information fusion and situation perception based on DS evidence theory, hierarchical risk quantitative analysis based on probabilistic risk analysis, and risk discrimination. Low earth orbit satellite communication network is taken as an example to make a simulation and assessment. Experimental results show the proposed model and method can effectively identify threat situation, and increase the accuracy of risk assessment discriminant.

Key words: DS evidence theory, Consultative Objective Risk Analysis System(CORAS), situation awareness, low earth orbit satellite communication, network security, risk assessment

中图分类号: