資源描述:
《基于markov博弈模型的網(wǎng)絡(luò)安全態(tài)勢感知方法》由會員上傳分享,免費(fèi)在線閱讀,更多相關(guān)內(nèi)容在工程資料-天天文庫。
1、軟件學(xué)報ISSN1000-9825,CODENRUXUEWE-mail:jos@iscas.ac.cnJournalofSoftware,2011,22(3):495?508[doi:10.3724/SP.J.1001.2011.03751]http://www.jos.org.cn?中國科學(xué)院軟件研究所版權(quán)所有.Tel/Fax:+86-10-62562563?基于Markov博弈模型的網(wǎng)絡(luò)安全態(tài)勢感知方法+張勇,譚小彬,崔孝林,奚宏生(中國科學(xué)技術(shù)大學(xué)自動化系,安徽合肥230027)NetworkSecuritySituation
2、AwarenessApproachBasedonMarkovGameModel+ZHANGYong,TANXiao-Bin,CUIXiao-Lin,XIHong-Sheng(DepartmentofAutomation,UniversityofScienceandTechnologyofChina,Hefei230027,China)+Correspondingauthor:E-mail:jzhang@mail.ustc.edu.cnZhangY,TanXB,CuiXL,XiHS.Networksecuritysituationaw
3、arenessapproachbasedonMarkovgamemodel.JournalofSoftware,2011,22(3):495?508.http://www.jos.org.cn/1000-9825/3751.htmAbstract:Toanalyzetheinfluenceofpropagationonanetworksystemandaccuratelyevaluatesystemsecurity,thispaperproposesanapproachtoimprovetheawarenessofnetworkse
4、curity,basedontheMarkovGameModel(MGM).Thisapproachgainsastandarddataofassets,threats,andvulnerabilitiesviafusingavarietyofsystemsecuritydatacollectedbymulti-sensors.Foreverythreat,itanalyzestheruleofpropagationandbuildsathreatpropagationnetwork(TPN).ByusingtheGameTheor
5、ytoanalyzethebehaviorsofthreats,administrators,andordinaryusers,itestablishesathreeplayerMGM.Inordertomaketheevaluationprocessareal-timeoperation,itoptimizestherelatedalgorithm.TheMGMcandynamicallyevaluatesystemsecuritysituationandprovidethebestreinforcementschemaforth
6、eadministrator.Theevaluationofaspecificnetworkindicatesthattheapproachissuitableforarealnetworkenvironment,andtheevaluationresultispreciseandefficient.Thereinforcementschemacaneffectivelycurbthepropagationofthreats.Keywords:networksecuritysituationawareness;threatpropa
7、gationnetwork;Markovgamemodel摘要:為了分析威脅傳播對網(wǎng)絡(luò)系統(tǒng)的影響,準(zhǔn)確、全面地評估系統(tǒng)的安全性,并給出相應(yīng)的加固方案,提出一種基于Markov博弈分析的網(wǎng)絡(luò)安全態(tài)勢感知方法.通過對多傳感器檢測到的安全數(shù)據(jù)進(jìn)行融合,得到資產(chǎn)、威脅和脆弱性的規(guī)范化數(shù)據(jù);對每個威脅,分析其傳播規(guī)律,建立相應(yīng)的威脅傳播網(wǎng)絡(luò);通過對威脅、管理員和普通用戶的行為進(jìn)行博弈分析,建立三方參與的Markov博弈模型,并對相關(guān)算法進(jìn)行優(yōu)化分析,使得評估過程能夠?qū)崟r運(yùn)行.Markov博弈模型能夠動態(tài)評估系統(tǒng)安全態(tài)勢,并為管理員提供最佳的加
8、固方案.通過對具體網(wǎng)絡(luò)的測評分析表明,基于Markov博弈分析的方法符合實際應(yīng)用,評估結(jié)果準(zhǔn)確、有效,提供的加固方案可有效抑制威脅的擴(kuò)散.關(guān)鍵詞:網(wǎng)絡(luò)安全態(tài)勢感知;威脅傳播網(wǎng)絡(luò);Markov博弈模型中圖法分類號:TP393文獻(xiàn)標(biāo)識碼: