Journal on Communications ›› 2016, Vol. 37 ›› Issue (10): 188-198.doi: 10.11959/j.issn.1000-436x.2016210

• Correspondences • Previous Articles    

Attack path prediction method based on causal knowledge net

Shuo WANG1,Guang-ming TANG1,Guang KOU1,2,Hai-tao SONG1   

  1. 1 PLA Information Engineering University,Zhengzhou 450001,China
    2 Science and Technology on Information Assurance Laboratory,Beijing 100072,China
  • Online:2016-10-25 Published:2016-10-25
  • Supported by:
    The National Natural Science Foundation of China;Foundation of Science and Technology on Information Assurance Laboratory

Abstract:

The existing attack path prediction methods can not accurately reflect the variation of the following attack path caused by the capability of the attacker.Accordingly an attack path prediction method based on causal knowledge net was presented.The proposed method detected the current attack actions by mapping the alarm sets to the causal knowledge net.By analyzing the attack actions,the capability grade of the attacker was inferred,according to which adjust the probability knowledge distribution dynamically.With the improved Dijkstra algorithm,the most possible attack path was computed.The experiments results indicate that the proposed method is suitable for a real network confrontation environment.Besides,the method can enhance the accuracy of attack path prediction.

Key words: attack path prediction, causal knowledge net, attacker capability, probability knowledge distribution, Dijkstra algorithm

No Suggested Reading articles found!