通信学报 ›› 2016, Vol. 37 ›› Issue (10): 188-198.doi: 10.11959/j.issn.1000-436x.2016210

• 学术通信 • 上一篇    

基于因果知识网络的攻击路径预测方法

王硕1,汤光明1,寇广1,2,宋海涛1   

  1. 1 解放军信息工程大学,河南 郑州 450001
    2 信息保障技术重点实验室,北京 100072
  • 出版日期:2016-10-25 发布日期:2016-10-25
  • 基金资助:
    国家自然科学基金资助项目;信息保障技术重点实验室开放基金资助项目

Attack path prediction method based on causal knowledge net

Shuo WANG1,Guang-ming TANG1,Guang KOU1,2,Hai-tao SONG1   

  1. 1 PLA Information Engineering University,Zhengzhou 450001,China
    2 Science and Technology on Information Assurance Laboratory,Beijing 100072,China
  • Online:2016-10-25 Published:2016-10-25
  • Supported by:
    The National Natural Science Foundation of China;Foundation of Science and Technology on Information Assurance Laboratory

摘要:

针对现有攻击路径预测方法无法准确反映攻击者攻击能力对后续攻击路径的影响,提出了基于因果知识网络的攻击路径预测方法。借助因果知识网络,首先通过告警映射识别已发生的攻击行为;然后分析推断攻击者能力等级,进而根据攻击者能力等级动态调整概率知识分布;最后利用改进的Dijkstra算法计算出最有可能的攻击路径。实验结果表明,该方法符合网络对抗实际环境,且能提高攻击路径预测的准确度。

关键词: 攻击路径预测, 因果知识网络, 攻击者能力, 概率知识分布, Dijkstra算法

Abstract:

The existing attack path prediction methods can not accurately reflect the variation of the following attack path caused by the capability of the attacker.Accordingly an attack path prediction method based on causal knowledge net was presented.The proposed method detected the current attack actions by mapping the alarm sets to the causal knowledge net.By analyzing the attack actions,the capability grade of the attacker was inferred,according to which adjust the probability knowledge distribution dynamically.With the improved Dijkstra algorithm,the most possible attack path was computed.The experiments results indicate that the proposed method is suitable for a real network confrontation environment.Besides,the method can enhance the accuracy of attack path prediction.

Key words: attack path prediction, causal knowledge net, attacker capability, probability knowledge distribution, Dijkstra algorithm

No Suggested Reading articles found!