首页 | 本学科首页   官方微博 | 高级检索  
     检索      

基于脆弱性变换的网络动态防御有效性分析方法
引用本文:李立勋,张斌,董书琴,唐慧林.基于脆弱性变换的网络动态防御有效性分析方法[J].电子学报,2018,46(12):3014-3020.
作者姓名:李立勋  张斌  董书琴  唐慧林
作者单位:1. 信息工程大学, 河南郑州 450001; 2. 河南省信息安全重点实验室, 河南郑州 450001
摘    要:有效性分析对合理制订最优网络动态防御策略至关重要.首先利用随机抽样模型从脆弱性变换角度给出入侵成功概率计算公式,用于刻画变换空间、变换周期及脆弱性数量对网络入侵过程的影响;然后针对单、多脆弱性变换两种情况,分别给出相应的入侵成功概率极限定理并予以证明,同时给出两种情况下的最优变换空间计算方法;仿真结果表明,增大单条入侵路径上依次攻击的脆弱性数量、减小变换周期可持续提高网络动态防御有效性,而增大变换空间初始可以提升网络动态防御有效性,但是由于入侵成功概率会随变换空间的持续增大而逐渐收敛,在入侵成功概率收敛时,有效性无法持续提高.

关 键 词:网络安全  网络动态防御  安全策略分析  入侵成功概率  动态变换  脆弱性变换  随机抽样  
收稿时间:2017-11-28

Effectiveness Analysis Approach Based on Vulnerability Mutation for Network Dynamic Defense
LI Li-xun,ZHANG Bin,DONG Shu-qin,TANG Hui-lin.Effectiveness Analysis Approach Based on Vulnerability Mutation for Network Dynamic Defense[J].Acta Electronica Sinica,2018,46(12):3014-3020.
Authors:LI Li-xun  ZHANG Bin  DONG Shu-qin  TANG Hui-lin
Institution:1. Information and Engineering University, Zhengzhou, Henan 450001, China; 2. Key Laboratory of Information Security, Zhengzhou, Henan 450001, China
Abstract:Effectiveness analysis is critical for making optimal network dynamic defense (NDD) strategies.Firstly,the attack success probability formula is derived by constructing the random sampling model from the perspective of vulnerability mutation,which can depict the influence caused by the mutation space,the mutation period and the number of vulnerabilities on the process of network attack.Then,two limit theorems of attack success probability are given and proved in single and multiple vulnerabilities cases respectively,and the calculating methods of optimal mutation space are given according to the two theorems.The simulation results show that the NDD's effectiveness improves with the mutation period reducing and the number of vulnerability attacked successively on a single attack path growing,meanwhile,although enlarging the mutation space is beneficial to improving the NDD's effectiveness in the beginning,the attack success probability would converge with the persistent enlargement of mutation space,which limits the continuous improvement of NDD's effectiveness.
Keywords:cyber security  network dynamic defense  security policy analysis  attack success probability  dynamic mutation  vulnerability mutation  random sampling  
点击此处可从《电子学报》浏览原始摘要信息
点击此处可从《电子学报》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号