通信学报 ›› 2023, Vol. 44 ›› Issue (4): 216-225.doi: 10.11959/j.issn.1000-436x.2023073

• 学术通信 • 上一篇    下一篇

基于贝叶斯攻击图的SDN入侵意图识别算法的研究

罗智勇, 张玉, 王青, 宋伟伟   

  1. 哈尔滨理工大学计算机科学与技术学院,黑龙江 哈尔滨 150080
  • 修回日期:2023-03-06 出版日期:2023-04-25 发布日期:2023-04-01
  • 作者简介:罗智勇(1978- ),男,山东平度人,博士,哈尔滨理工大学教授,主要研究方向为计算机网络与信息安全、网络优化等
    张玉(1996- ),男,黑龙江尚志人,哈尔滨理工大学硕士生,主要研究方向为计算机网络与信息安全、网络优化等
    王青(1998- ),女,黑龙江伊春人,哈尔滨理工大学硕士生,主要研究方向为计算机网络与信息安全、自然语言处理等
    宋伟伟(1998- ),男,山西临汾人,哈尔滨理工大学硕士生,主要研究方向为计算机网络与信息安全、网络优化等
  • 基金资助:
    黑龙江省自然科学基金资助项目(LH2021F030)

Study of SDN intrusion intent identification algorithm based on Bayesian attack graph

Zhiyong LUO, Yu ZHANG, Qing WANG, Weiwei SONG   

  1. School of Computer Science and Technology, Harbin University of Science and Technology, Harbin 150080, China
  • Revised:2023-03-06 Online:2023-04-25 Published:2023-04-01
  • Supported by:
    The Natural Science Foundation of Heilongjiang Province(LH2021F030)

摘要:

针对目前已有的软件定义网络(SDN)安全预测方法中未考虑攻击代价以及控制器漏洞对 SDN 安全所产生的影响,提出了一种基于贝叶斯攻击图的SDN入侵意图识别算法。利用PageRank算法求出设备关键度,并与漏洞价值、攻击成本、攻击收益以及攻击偏好相结合构建攻击图,建立风险评估模型,对入侵路径进行预测。通过实验对比可以看出,所提模型能更准确地预测入侵路径,有效地保证安全预测的准确性,并为 SDN 的防御提供依据。

关键词: SDN安全预测, 入侵意图, 攻击图, PageRank算法

Abstract:

Since the existing software defined network (SDN) security prediction methods do not consider the attack cost and the impact of controller vulnerabilities on SDN security, a Bayesian attack graph-based algorithm to assessing SDN intrusion intent was proposed.The PageRank algorithm was used to obtain the criticality of the device, and combining with the vulnerability value, attack cost, attack benefit and attack preference, an attack graph was constructed, and a risk assessment model was established to predict the intrusion path.Through experimental comparison, it is obvious that the proposed model can more accurately predict the intrusion path, effectively ensure the accuracy of security prediction, and provide a basis for SDN defense.

Key words: SDN security prediction, intrusion intention, attack graph, PageRank algorithm

中图分类号: 

No Suggested Reading articles found!