通信学报 ›› 2021, Vol. 42 ›› Issue (6): 182-194.doi: 10.11959/j.issn.1000-436x.2021106

• 学术论文 • 上一篇    下一篇

基于威胁情报的网络安全态势感知模型

张红斌1,2, 尹彦1, 赵冬梅2, 刘滨3,4   

  1. 1 河北科技大学信息科学与工程学院,河北 石家庄 050018
    2 河北师范大学河北省网络与信息安全重点实验室,河北 石家庄 050024
    3 河北科技大学经济管理学院,河北 石家庄 050018
    4 河北科技大学大数据与社会计算研究中心,河北 石家庄 050018
  • 修回日期:2021-04-09 出版日期:2021-06-25 发布日期:2021-06-01
  • 作者简介:张红斌(1976− ),男,河北赵县人,博士,河北科技大学教授,主要研究方向为网络安全与管理、社交物联网等
    尹彦(1997− ),女,山东德州人,河北科技大学硕士生,主要研究方向为网络安全与管理
    赵冬梅(1966− ),女,河北深州人,博士,河北师范大学教授,主要研究方向为网络空间安全、人工智能及应用等
    刘滨(1975− ),男,河北唐山人,博士,河北科技大学教授,主要研究方向为大数据、社会计算、人工智能等
  • 基金资助:
    国家自然科学基金资助项目(61672206);国家自然科学基金资助项目(61572170);河北省省级科技计划基金资助项目(18210109D);河北省省级科技计划基金资助项目(20310701D);河北省省级科技计划基金资助项目(20310802D);河北省高层次人才基金资助项目(A2016002015);石家庄市科学技术研究与发展计划基金资助项目(19SCX01006);石家庄市科学技术研究与发展计划基金资助项目(191130591A)

Network security situational awareness model based on threat intelligence

Hongbin ZHANG1,2, Yan YIN1, Dongmei ZHAO2, Bin LIU3,4   

  1. 1 School of Information Science and Engineering, Hebei University of Science and Technology, Shijiazhuang 050018, China
    2 Hebei Key Laboratory of Network and Information Security, Hebei Normal University, Shijiazhuang 050024, China
    3 School of Economics and Management, Hebei University of Science and Technology, Shijiazhuang 050018, China
    4 Research Center of Big Data and Social Computing, Hebei University of Science and Technology, Shijiazhuang 050018, China
  • Revised:2021-04-09 Online:2021-06-25 Published:2021-06-01
  • Supported by:
    The National Natural Science Foundation of China(61672206);The National Natural Science Foundation of China(61572170);S&T Program of Hebei(18210109D);S&T Program of Hebei(20310701D);S&T Program of Hebei(20310802D);High-Level Talents Subsidy Project in Hebei Province(A2016002015);S&T Research and Development Program of Shijiazhuang(19SCX01006);S&T Research and Development Program of Shijiazhuang(191130591A)

摘要:

为了解决现实环境中网络规模日益扩大导致网络攻击持续高发的现状,将威胁情报应用到态势感知,构建基于随机博弈的态势感知模型。将外源威胁情报与系统内部安全事件之间的相似度进行比较,对目标系统进行威胁察觉,根据系统内部的威胁信息生成内源威胁情报;在此过程中,利用博弈论的思想量化系统当前的网络安全态势,评估网络的安全状况,最终实现对网络安全态势的预测。实验结果表明,基于威胁情报的网络安全态势感知模型能正确地反映网络安全状态的变化,对攻击行为进行准确的预测。

关键词: 威胁情报, 态势感知, 网络安全, 博弈论, 纳什均衡

Abstract:

In order to deal with the problems that the increasing scale of the network in the real environment leads to the continuous high incidence of network attacks, the threat intelligence was applied to situational awareness, and the situational awareness model based on random game was constructed.Threat perception of the target system was performed by comparing the similarity between the exogenous threat intelligence and the internal security events of the system.At the same time, internal threat intelligence was generated based on the threat information inside the system.In this process, game theory was used to quantify the current network security situation of the system, evaluate the security status of the network.Finally, the prediction of the network security situation was realized.The experimental results show that the network security situation awareness method based on threat intelligence can reflect the changes in the network security situation and predict attack behaviors accurately.

Key words: threat intelligence, situational awareness, network security, game theory, Nash equilibrium

中图分类号: 

No Suggested Reading articles found!