Space-Integrated-Ground Information Networks ›› 2021, Vol. 2 ›› Issue (3): 57-65.doi: 10.11959/j.issn.2096-8930.2021031

Special Issue: 专题:天地一体化信息网络安全防护技术

• Special Issue: Security Protection Technology for Space-Integrated-Ground Information Network • Previous Articles     Next Articles

Attack Analysis Framework of Space-Integrated-Ground Information Network Based on Cybersecurity Knowledge Graph

Yulu QI1, Rong JIANG1, Xing RONG2, Aiping LI1   

  1. 1 National University of Defense Technology, Changsha 410073, China
    2 China Electronic Device Systems Engineering Corporation, Beijing 100089, China
  • Revised:2021-08-25 Online:2021-09-20 Published:2021-09-01
  • Supported by:
    The Key R&D Program of Guangdong Province(2019B010136003);The National Natural Science Foundation of China(62072131)

Abstract:

While realizing global coverage, random access, on-demand service, security and credibility, the space-integrated-ground information network(SGIN) is confronted with more complex and variable security threats.Compared with the internet, satellite network has a lot of diff erences, such as highly dynamic changes of topology, transfer protocol and data format.In terms of these questions, it was necessary to integrated the rule of satellite network attacks into the rules of APT attacks, developed the cybersecurity knowledge graph and the attack rules library to analyzed the attacks of the SGIN.The pattern of attack rules was expressed based on time-space data model, which was used to completed the attack chain when there were non-continuous missed data or false positives data.The attack analysis framework proposed in this paper could accurately perceived the security status of the SGIN in real time , and provided decision support for the SGIN.

Key words: space-integrated-ground information network, cybersecurity knowledge graph, attack rule library, attack analysis framework, attack chain completion

CLC Number: 

No Suggested Reading articles found!