论文部分内容阅读
目的为了评估网络的安全威胁态势,提出了一种基于隐马尔可夫模型的评估方法.方法建立了一个简单的用于描述主机安全状态的隐马尔可夫模型,利用该模型计算主机处于被攻击状态的概率.在此基础上,结合主机重要度计算主机的威胁指数,进而评估网络的整体威胁态势.结果实验结果表明,通过对威胁指数的分析和处理,能够获得主机和网络两个层次的威胁态势曲线,安全管理人员可以从中发现目标主机和网络的安全规律.结论利用该方法获得的评估结果能够指导安全管理人员调整安全策略,以便提高主机和网络的安全性.
Aim To evaluate the security threat situation of the network, a method based on Hidden Markov Model is proposed.Methods A simple hidden Markov model for describing the security status of the host computer is established, which is used to calculate the host being attacked State probability.On this basis, the threat index of the host computer is calculated based on the importance of the host, and then the overall threat situation of the network is evaluated.Results The experimental results show that through the analysis and processing of the threat index, the host and network can be obtained at two levels Threat situation curve, the safety management personnel can discover the safety rules of the target host and the network.Conclusion The evaluation results obtained by this method can guide the safety management personnel to adjust the safety strategy so as to improve the security of the host and the network.