欢迎访问中国科学院大学学报,今天是
计算机科学

基于网络中心性的计算机网络脆弱性评估方法

  • 贾炜 ,
  • 冯登国 ,
  • 连一峰
展开
  • 1. 中国科学技术大学电子工程与信息科学系, 合肥 230026;
    2. 中国科学院软件研究所信息安全 国家重点实验室, 北京 100190;
    3. 信息安全共性技术国家工程研究中心, 北京 100080

收稿日期: 2011-04-15

  修回日期: 2011-06-07

  网络出版日期: 2012-07-15

基金资助

国家高技术研究发展计划(863) (2009AA01Z439)资助

Network-vulnerability evaluation method based on network centrality

  • JIA Wei ,
  • FENG Deng-Guo ,
  • LIAN Yi-Feng
Expand
  • 1. Department of Electronic Engineering and Information Science, University of Science and Technology of China, Hefei 230026, China;
    2. State Key Laboratory of Information Security, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China;
    3. National Engineering Research Center for Information Security, Beijing 100080, China

Received date: 2011-04-15

  Revised date: 2011-06-07

  Online published: 2012-07-15

摘要

提出一种基于网络中心性的计算机网络脆弱性评估方法. 首先基于通用脆弱性评分系统,对攻击者利用脆弱性攻击所花费的代价进行量化评估,根据评估结果对脆弱性攻击图进行最小攻击代价路径分析. 引入网络中心性理论,采用攻击图节点的介数和节点连通度相结合的方法,对攻击图的节点关键程度进行量化分析,判断对网络安全产生关键影响的脆弱性,为计算机网络的安全优化提供依据.

本文引用格式

贾炜 , 冯登国 , 连一峰 . 基于网络中心性的计算机网络脆弱性评估方法[J]. 中国科学院大学学报, 2012 , 29(4) : 529 -535 . DOI: 10.7523/j.issn.2095-6134.2012.4.015

Abstract

We propose a method based on network centrality to evaluate the vulnerabilities of computer networks. We evaluate the attack costs based on CVSS and analyze the minimum attack cost routes by using the quantitative results. Then, we present a new network centrality method which combines betweenness with degree-theory to analyze the importance of the nodes in attack graph. The method helps us to find the key vulnerabilities which have great effect on network security and to enhance the network security.

参考文献

[1] Frigault M, Wang L Y, Singhal A, et al. Measuring network security using dynamic Bayesian network //Conference on Computer and Communications Security Proceedings of the 4th ACM Workshop on Quality of Protection. New York, USA:ACM, 2008:23-30.
[2] Feng P H, Lian Y F, Dai Y X, et al. A vulnerability model of distributed systems based on reliability theory[J]. Journal of Software, 2006,17(7):1633-1640(in Chinese). 冯萍慧,连一峰,戴英侠,等. 基于可靠性理论的分布式系统脆弱性模型[J]. 软件学报, 2006,17(7):1633-1640.
[3] Zhang H X, Su P R, Feng D G. A network security analysis model based on the increase in attack ability[J]. Journal of Computer Research and Development, 2007,44(12):2012-2019(in Chinese). 张海霞,苏璞睿,冯登国. 基于攻击能力增长的网络安全分析模型[J]. 计算机研究与发展, 2007,44(12):2012-2019.
[4] Jiang W, Fang B X, Tian Z H, et al. Evaluating network security and optimal active defense based on attack-defense game model[J]. Chinese Journal of Computers, 2009, 32(4):817-825(in Chinese). 姜伟,方滨兴,田志宏,等. 基于攻防博弈模型的网络安全测评和最优主动防御[J]. 计算机学报, 2009, 32(4): 817-825.
[5] Sawilla R, Ou X M. Googling attack graphs . Defence R & D,Canada,Ottawa, Tech. Rep: TM 2007-205, 2007.
[6] FIRST. A complete guide to the common vulnerability scoring system version 2.0 . .http://www.first.org/cvss/cvss-guide.html.
[7] Barthelemy M. Betweenness centrality in large complex networks[J].Eurpean Physical Journal B,2004,38(2):163-168.
[8] Steven N, Sushil J D, Brian O B, et al. Efficient minimum-cost network hardening via exploit dependency graphs //Proceedings of ACSAC. 2003:86-95.
[9] National Institute of Standards and Technology. National vulnerability database . .http://nvd.nist.gov/.
[10] Bugtraq Vulnerability Archives. SecurityFocus . .http://www.securityfocus.com/vulnerabilities.
文章导航

/