Journal on Communications ›› 2017, Vol. 38 ›› Issue (1): 187-198.doi: 10.11959/j.issn.1000-436x.2017021

• Correspondences • Previous Articles    

Network security situation evaluation method for multi-step attack

Hao-pu YANG,Hui QIU,Kun WANG   

  1. The Third Institute,Information Engineering University,Zhengzhou 450001,China
  • Revised:2016-08-03 Online:2017-01-01 Published:2017-01-23
  • Supported by:
    The National Natural Science Foundation of China(61303074);The National Natural Science Foundation of China(61309013);The National Basic Research Program of China(2012CB315900)

Abstract:

Aiming at analyzing the influence of multi-step attack,as well as reflecting the system’s security situation accurately and comprehensively,a network security situation evaluation method for multi-step attack was proposed.This method firstly clustered security events into several attack scenes,which was used to identify the attacker.Then the attack path and the attack phase were identified by causal correlation of every scene.Finally,combined with the attack phase as well as the threat index,the quantitative standard was established to evaluate the network security situation.The proposed method is assessed by two network attack-defense experiments,and the results illustrate accuracy and effectiveness of the method.

Key words: scene clustering, multi-step attack, security situation, quantification analysis

CLC Number: 

No Suggested Reading articles found!