计算机工程与应用 ›› 2011, Vol. 47 ›› Issue (28): 106-109.

• 网络、通信、安全 • 上一篇    下一篇

引入交叉确认机制的安全态势评估模型

吴志刚,苏安婕,王文奇   

  1. 中原工学院 计算机学院,郑州 451191
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2011-10-01 发布日期:2011-10-01

Assessment model of security situation introduced cross-validation mechanism

WU Zhigang,SU Anjie,WANG Wenqi   

  1. School of Computer Science,Zhongyuan University of Technology,Zhengzhou 451191,China
  • Received:1900-01-01 Revised:1900-01-01 Online:2011-10-01 Published:2011-10-01

摘要: 针对当前网络安全态势评估数据源较单一,评估结果欠准确等问题,提出了基于交叉确认机制的安全态势评估模型。该模型根据网络安全事件间的关联性以及告警信息的不确定性,提出多源告警信息交叉确认机制,利用模糊推理将海量的告警信息进行交叉确认,提取出可靠的评估信息,并结合静态评估数据进行安全态势评估。利用实例网络数据,对该模型进行了验证,实验结果表明该模型评估结果的全面性和准确性有很大程度的提高。

关键词: 态势评估, 交叉确认, 模糊论域, 模糊推理

Abstract: According to the fact that the data sources of the network security situation assessment are one-sided and the results are not accurate and other issues,this paper proposes a method of network security situation assessment based on cross-validation.On the basis of the correlation of network security events and the uncertainty of alarm information,a kind of cross-validation mechanism on multi-source warnings is presented.Thus,a large amount of data from multi-source warnings are identified and confirmed by the mechanism with fuzzy reasoning,and then the situation assessment is implemented on the basis of the extract accurate and tidy attack information with combining static assessment data.An example of actual network is given to validate the method.The results show that this method is more effective and accurate than the existing methods.

Key words: situation assessment, cross-validation, fuzzy domain, fuzzy reasoning