通信学报 ›› 2017, Vol. 38 ›› Issue (11): 121-132.doi: 10.11959/j.issn.1000-436x.2017213

• 综述 • 上一篇    下一篇

攻击图技术应用研究综述

叶子维1,2,郭渊博1,2,王宸东1,2,琚安康1,2   

  1. 1 解放军信息工程大学网络空间安全学院,河南 郑州 450001
    2 数学工程与先进计算国家重点实验室,江苏 无锡 214000
  • 修回日期:2017-11-06 出版日期:2017-11-01 发布日期:2017-12-13
  • 作者简介:叶子维(1990-),男,吉林通化人,解放军信息工程大学博士生,主要研究方向为网络安全、态势感知。|郭渊博(1975-),男,陕西周至人,解放军信息工程大学教授、博士生导师,主要研究方向为大数据安全、态势感知。|王宸东(1992-),男,江西抚州人,解放军信息工程大学硕士生,主要研究方向为网络安全。|琚安康(1995-),男,河南新乡人,解放军信息工程大学博士生,主要研究方向为多步网络攻击检测、威胁情报。
  • 基金资助:
    国家自然科学基金资助项目(61602515);国家自然科学基金资助项目(61501515)

Survey on application of attack graph technology

Zi-wei YE1,2,Yuan-bo GUO1,2,Chen-dong WANG1,2,An-kang JU1,2   

  1. 1 School of Cyberspace Security,PLA Information Engineering University,Zhengzhou 450001,China
    2 State Key Laboratory of Mathematical Engineering and Advanced Computing,Wuxi 214000,China
  • Revised:2017-11-06 Online:2017-11-01 Published:2017-12-13
  • Supported by:
    The National Natural Science Foundation of China(61602515);The National Natural Science Foundation of China(61501515)

摘要:

攻击图是一种预判攻击者对目标网络发动攻击的方式和过程,指导防御方对网络中的节点采取针对性防御措施,提高网络安全性的技术。首先介绍了攻击图的基本构成,列举了攻击图的几种类型及其各自的优缺点,然后介绍了攻击图技术目前在风险评估和网络加固、入侵检测和告警关联等方面的应用现状以及现有的几种攻击图生成和分析工具,最后指出了攻击图技术面临的挑战和未来可能的研究方向。

关键词: 攻击图, 安全漏洞, 网络加固, 告警关联

Abstract:

Attack graph technology was a measure to predict the pattern and process used by attacker to compromise the target network,so as to guide defender to take defensive measures and improve network security.The basic component,types of attack graphs and respective advantages and disadvantages of each type were reviewed.The application status of attack graph technology in risk assessment and network hardening,intrusion detection and alarm correlation,and other aspects were introduced.Several kinds of existing attack graph generation and analysis tools were also presented.At last a survey of some challenges and research trends in future research work was provided.

Key words: attack graph, vulnerability, network hardening, alert correlation

中图分类号: 

No Suggested Reading articles found!