节点文献

内部威胁云模型感知算法

An Algorithm for Sensing Insider Threat Based on Cloud Model

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 张红斌裴庆祺马建峰

【Author】 ZHANG Hong-Bin1),2) PEI Qing-Qi1) MA Jian-Feng1)1)(Key Laboratory of Computer Networks and Information Security of Ministry of Education,Xidian University,Xi’an 710071) 2)(Institute of Information Science & Engineering,Hebei University of Science and Technology,Shijiazhuang 050054)

【机构】 西安电子科技大学计算机网络与信息安全教育部重点试验室河北科技大学信息科学与工程学院

【摘要】 利用系统访问控制关系,定义了主体、客体两个偏序结构和二者间的映射关系,建立了分层映射内部威胁模型;利用此模型定义了表征系统内部威胁状态的内部威胁云模型,并设计了基于云模型的感知算法,实现了对系统内部威胁的评测感知.基于云模型的内部威胁感知算法,利用云模型从多角度将系统的定性、定量内部威胁特征融合分析、决策,克服了原有方法不能同时定量定性分析内部威胁的缺陷,提高了感知的准确性和客观性.实验结果表明,此算法能够实时、有效地感知系统的内部安全威胁.

【Abstract】 Using the access control relationship,the partial-order structures of subjects and objects in the system and their mapping relationship are defined,and a hierarchy-mapping based insider threat model is developed on these definitions.Then,this model is applied to build a cloud model which characterizes the states of insider threat in the system.Based on the proposed cloud model,an algorithm,which improves the accuracy and objectivity in evaluation,is also designed for sensing the insider threat in the system.Compared to the previous works,the algorithm could analyze threats of the system in various respects and makes decision qualitatively and quantitatively.As a result,the experiments show that the algorithm could effectively sense the insider threat in real-time.

【关键词】 模型云模型内部威胁感知评估
【Key words】 modelscloud modelinsider threatsenseevaluation
【基金】 国家“八六三”高技术研究发展计划项目基金(2007AA01Z429,2007AA01Z405);国家自然科学基金重点项目(60633020);国家自然科学基金(60573036,60702059,60503012,60803150,60743005);陕西省“13115”科技创新工程重大科技专项基金(2007ZDKG-56)资助~~
  • 【文献出处】 计算机学报 ,Chinese Journal of Computers , 编辑部邮箱 ,2009年04期
  • 【分类号】TP393.08
  • 【被引频次】29
  • 【下载频次】789
节点文献中: 

本文链接的文献网络图示:

本文的引文网络