摘要
针对基于隐马尔可夫(HMM)的网络风险评估中未考虑网络节点相关性的问题,结合图论,建立节点关联(NNC)状态转换矩阵,以入侵告警值(IDS)为输入,用改进的HMM模型计算出攻击路径.通过模型能进一步得到任意长度攻击序列的攻击成功率.实验结果证明,该方法简捷有效,有利于发现网络节点的脆弱性,掌握网络安全状况.
Aimed at the problem that the node correlation in network is not considered in hidden Markov model (HMM) network risk assessment, combining graph theory model, the network node correlation (NNC) state transition matrix is built. With the intrusion defective system (IDS) alert as input, using modified HMM model the attacking route is figured out. Furthermore, the successful probability of any attacking sequence with any length can be got as well. The method can help to find vulnerabilities of network nodes, and reflect network risk well. Experiment demonstrates the validity of it.
出处
《北京邮电大学学报》
EI
CAS
CSCD
北大核心
2010年第6期121-124,共4页
Journal of Beijing University of Posts and Telecommunications
基金
陕西省自然科学基金项目(2009JM8001-1)
军队武器装备科研项目
关键词
隐马尔可夫模型
网络节点关联性
图论
网络安全
hidden Markov model
network node correlation
graph theory
network security
作者简介
龙门(1982-),女,博士生,E—mail:betty506@tom.com;
夏靖波(1963-),男,教授,博士生导师.