节点文献

基于扩展攻击树的信息系统安全风险评估

Information System Security Risk Evaluation Based on Extended Attack Tree

【作者】 吴平

【导师】 甘早斌;

【作者基本信息】 华中科技大学 , 计算机应用技术, 2007, 硕士

【摘要】 当前,信息系统的使用越来越广泛,规模也达到空前。这使得信息系统成为攻击者的攻击目标。因此,怎样保护好信息系统,避免其受攻击是亟待解决的问题。风险评估是解决信息系统安全问题的有效方法之一,与传统的“事后”方式不同的是,它是一种“主动”的防御方式。其主要思想是分析系统潜在的风险,评估这些风险可能带来的影响,为安全策略的确定、信息系统的建立及安全运行提供依据,最终将系统的风险降到一个可以接受的程度。攻击树是一种图形化的描述方式,它能很直观地分析系统存在的风险。在其基础上进行扩展,给出了一种基于扩展攻击树模型的风险评估方法。同时,详细介绍了利用该方法进行风险评估的具体步骤,并给出了各步骤具体的算法,如攻击链算法,攻击序列算法等。在对叶子节点(原子攻击)风险值的量化中,采用了多属性效用理论,对各叶子节点的风险值进行量化计算,减少了评估过程中的主观性。针对一些大型的复杂系统,其攻击链、攻击树复杂性问题,给出了攻击树剪枝算法,有效地降低了计算的复杂度。在风险控制过程中,给出了选择控制措施的一些参考度量标准或指标(如风险值指标,成本指标等)以及要考虑的问题。利用Visual C++ 6.0作为开发工具,给出了基于扩展攻击树模型的自动化风险评估工具原型。该工具原型很好地模拟了评估方法的每一步骤,计算得到的结果也非常合理。验证了基于扩展攻击树的风险评估方法是一种切实可行的、有效的评估方法。它为今后建立更自动化、更完备的定量风险评估工具打下了基础。

【Abstract】 With the development of information technology, information system (IS) is widely used, also the scale of IS which is based on Internet and core in information resource is becoming larger and larger. That makes it a virtual breeding ground for attackers. Therefore how to make IS reliable and robust to avoid attacks in a long time is what we should deal with at present. Risk evaluation is one of the best solutions to deal with security problem of IS. It is a proactive method to prevent attacks rather than a reactive method. First, analyzing the potential risk of IS, and then evaluating impact caused by those risks. The result of risk evaluation can be foundation of security alternatives, establishment of IS and IS’s performance. It’s a process to reduce risk and its final aim is to reduce risk to an acceptable level.Attack tree is a graph-based description model, gives a form methodology for describing risks of IS based on goal-oriented attack behavior. A new risk evaluation methodology is proposed with extended attack tree model. It has great advantage in supporting risk evaluation. While conducting risk evaluation based on extended attack tree model, all algorithms are presented for each step of this new evaluation method, such as attack chaining algorithm, attack scenarios algorithm.As a part of the research to quantify risk in security risk evaluation , multi-attribute utility theory is devised and proposed, three attributes are assigned to nodes of extended attack tree which reduces subjectivity of evaluation. Attack pruning method is proposed to facilitate complexity of computing with regard to large-scale IS. In the process of risk control, lots of indexes, such as risk metric, cost metric, and problems should be taken into account to choose the most reasonable countermeasures.Then, implementing the method, a prototype of automatic risk evaluation tool was constructed based on Visual C++ 6.0. The tool has simulated each step of process of the risk evaluation method. And the result is reasonable. This verifies that the risk evaluation method based on extended attack tree model is an effective and tangible way to conducting risk evaluation on IS. The simulation system also offers a good foundation for the implementation of more automatic and more functional evaluation tool.

节点文献中: 

本文链接的文献网络图示:

本文的引文网络