Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2009, Vol. 35 ›› Issue (18): 116-118. doi: 10.3969/j.issn.1000-3428.2009.18.041

• Security Technology • Previous Articles     Next Articles

Analysis of Network Connectivity for Attack Graph Construction

LI Han, ZHANG Shao-jun, CHEN Xiu-zhen, CHEN Xiao-hua   

  1. (Information Security Engineering Institute, Shanghai Jiaotong University, Shanghai 200240)
  • Received:1900-01-01 Revised:1900-01-01 Online:2009-09-20 Published:2009-09-20

面向攻击图构建的网络连通性分析

黎 翰,张少俊,陈秀真,陈晓桦   

  1. (上海交通大学信息安全工程学院,上海 200240)

Abstract: This paper designs a network connectivity analysis algorithm according to the present techniques and the need of attack graph construction system. By using connectivity analysis, network topology and firewall rule analysis can be performed offline, which determines the connectivity between two hosts. It introduces a conception of Critical Entity Collection(CEC). An effective way of CEC detection is presented on the basis of classic Apriori algorithm. Deep analysis and comparison show that CEC provides effective information for the assessment of the importance of nodes in the network in the process of connectivity analysis.

Key words: network connectivity, attack graph, Critical Entity Collection(CEC)

摘要: 针对目前网络攻击图构建系统的需求,设计网络连通性分析算法。通过对网络拓扑及防火墙规则进行离线分析,可以判断网络中由若干台过滤设备分隔的任意2台主机间的连通性。引入关键实体集的概念,结合经典的Apriori算法提出一种快速有效的获取关键实体集的方法。分析对比表明,关键实体集可以在连通性分析过程中为网络中各节点的重要性评估提供有力依据。

关键词: 网络连通性, 攻击图, 关键实体集

CLC Number: