论文部分内容阅读
针对传统的网络脆弱性评估系统无法对目标网络的脆弱性评估结果进行量化描述的不足,在CVSS的基础上设计了一种量化的网络脆弱性评价体系。该评价体系全面综合了脆弱性的固有属性、脆弱性的威胁随时间的变化而变化的情况、脆弱性随目标网络环境的变化而变化的情况,并在此基础上实现了一种量化的目标网络脆弱性评估系统,便于系统管理人员了解和交流目标网络的脆弱性综合评价结果。
In view of the traditional network vulnerability assessment system can not quantitatively describe the vulnerability assessment result of the target network, a quantitative evaluation system of network vulnerability is designed on the basis of CVSS. The evaluation system comprehensively combines the intrinsic attributes of vulnerability, the changes of vulnerability threats with time, the change of vulnerability with the change of the target network environment, and based on this, a quantitative target is achieved Network vulnerability assessment system to facilitate system administrators to understand and exchange the vulnerability of the target network comprehensive evaluation results.