首页> 外文会议>International Conference on Security, Privacy and Anonymity in Computation, Communication and Storage >A Network Security Situational Awareness Framework Based on Situation Fusion
【24h】

A Network Security Situational Awareness Framework Based on Situation Fusion

机译:一种基于情境融合的网络安全情境意识框架

获取原文

摘要

With the rapid development of the Internet, security issues in cyberspace have received more and more attention, and network security situation awareness has become a research focus. This paper proposes a network security situation awareness framework based on situation fusion, which decomposes the network security situation into two parts: the host security situation and the network attack situation. First, the host asset information and network topology information are used to calculate the weight vector of all hosts to make the weight setting more reasonable. Then using CVSS to evaluate the host security situation value. Meanwhile, security events are extracted from the alarm information of the intrusion detection system, and we designed threat downgrading rules and escalation rules based on system environment matching and the attacker's willingness, so as to calculate the threat of network attacks, and ultimately integrated into the overall network security situation value. The results of the case analysis show that the framework proposed in this paper can quantify the security situation better.
机译:随着互联网的快速发展,网络空间中的安全问题越来越受到关注,网络安全局势意识已成为研究重点。本文提出了一种基于情况融合的网络安全局势意识框架,将网络安全状况分解为两部分:主机安全情况和网络攻击情况。首先,主机资产信息和网络拓扑信息用于计算所有主机的权重向量,以使权重设置更合理。然后使用CVSS来评估主机安全情况值。同时,从入侵检测系统的警报信息中提取安全事件,我们设计了基于系统环境匹配和攻击者的意愿的威胁降级规则和升级规则,以计算网络攻击的威胁,最终集成到整体网络安全情况值。案例分析结果表明,本文提出的框架可以更好地量化安全情况。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号