节点文献

网络攻击效果提取和分类

Mining and taxonomy of network attack effects

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 胡影; 郑康锋; 杨义先;

【Author】 HU Ying1,2,ZHENG Kang-feng1,YANG Yi-xian1(1.Information Security Center,State Key Laboratory of Networking & Switching Technology,Beijing University of Posts & Telecommunications,Beijing 100876,China;2.Police Army Beijing Command Academy,Beijing 100012,China)

【机构】 北京邮电大学网络与交换技术国家重点实验室信息安全中心; 武警北京指挥学院;

【摘要】 针对现有工作提出的网络攻击效果比较简单、含义抽象的缺点,研究了网络攻击效果的提取和分类。首先定义原子功能作为攻击效果的基本单位,指出原子功能提取的原则,通过分析NVD漏洞数据库、Snort规则库和Lincoln实验室攻击工具三个攻击库,最后得到五类100多个原子功能。这些原子功能可以代表大部分典型的网络攻击效果,含义明确、相互独立,且效果分类具有互斥性,可以作为网络攻击效果评估的基础,用于研究各类效果的量化评估方法,及提取各个原子功能的评估指标。

【Abstract】 Aiming at brief and abstract network attack effects proposed by existing researches,this paper studied a mining and taxonomy of network attack effects.Defined atom function as basic unit of network attack effects,and proposed the mining principles of atom functions.Analyzed three attack databases including national vulnerability database(NVD),Snort rules,and Lincoln Laboratory attack tools for intrusion detection evaluation.At last more than 100 atom functions were enumerated and divided into 5 groups.These atomic functions are independent with specific meanings,which can represent most typical network attacks.Network attack effect evaluation can analyze quantitative evaluation methods of every attack effects group and present metrics to assess every atomic function on the basis of these atomic functions.

  • 【文献出处】 计算机应用研究 ,Application Research of Computers , 编辑部邮箱 ,2009年03期
  • 【分类号】TP393.08
  • 【被引频次】4
  • 【下载频次】366
节点文献中: 

本文链接的文献网络图示:

本文的引文网络