通信学报 ›› 2016, Vol. 37 ›› Issue (Z1): 156-167.doi: 10.11959/j.issn.1000-436x.2016262

• 学术论文 • 上一篇    下一篇

无感状态下基于行为本体的手机用户信息安全能力评估方法

麦丞程1,陈波1(),周嘉坤1,于泠2   

  1. 1 南京师范大学计算机科学与技术学院,江苏 南京 210023
    2 江苏省大规模复杂系统数值模拟重点实验室,江苏 南京 210023
  • 出版日期:2016-10-25 发布日期:2017-01-17
  • 基金资助:
    “赛尔网络”下一代互联网技术创新基金资助项目;江苏省教育科学“十二五”规划重点基金资助项目;中国学位与研究生教育学会研究课题基金资助项目;江苏省高等教育教学改革重点课题基金资助项目

Evaluation method for information security capability of mobile phone user based on behavior ontology under unconscious condition

Cheng-cheng MAI1,Bo CHEN1(),Jia-kun ZHOU1,Ling YU2   

  1. 1 School of Computer Science and Technology,Nanjing Normal University,Nanjing 210023,China
    2 Jiangsu Provincial Key Laboratory for Numerical of Large Scale Complex System,Nanjing 210023,China
  • Online:2016-10-25 Published:2017-01-17
  • Supported by:
    Innovation Project of CERNET Next Generation Internet Technology;Major Program of the 12th Five Years Education Science Plans of Jiangsu Province;Research Subject of Chinese Society of Degree and Postgradu-ate Education;Key Subject of Higher Education Teaching Reform of Jiangsu Province

摘要:

提出了一种基于安全行为本体的员工安全行为检测方法。通过在用户无感状态下的真实手机使用行为采集,解决了安全行为的真实性问题;通过建立手机用户的静态和动态安全行为本体,对用户的通话、短信、网络与App应用等行为进行形式化描述,制定了不安全行为判定规则和行为关联规则;借鉴攻击图的概念,提出了一种基于行为关联图的不安全行为检测算法,发掘不安全行为路径。进一步,提出了信息安全能力评估的胜任力模型,实现了从员工信息安全行为的定性检测到能力的定量评估的过程。实验表明,该方法能够有效检测出用户不安全行为路径,得到安全能力值。

关键词: 安全行为本体, 行为分析, 能力评估, 移动安全

Abstract:

A security capacity assessment method based on security behavior ontology,was proposed to collect users' be-havior data from their smartphones under unconscious condition to solve the problem of detecting mobile phone users' real existing insecure behaviors.A security behavior ontology was set up for formalizing the phone,message,network and App behavior data of mobile phone users and relevant rules were also set down for determining and associating inse-cure actions.Referring to the notion of attack graph,an insecure behavior detection algorithm was proposed based on behavior association graph for analyzing the paths of insecure behaviors dynamically.Furthermore,a competency model of information security capability assessment was presented for realizing the quantitative evaluation of information secu-rity capability of users.The experiment results prove the effectiveness of present competency model for insecure behavior path detection and security ability assessment.

Key words: security behavior ontology, behavior analysis, capability assessment, mobile security

No Suggested Reading articles found!