节点文献

一种新型的脆弱性评估方法及其在IMS中应用的研究

Research on a Novel Method for Vulnerability Assessment and Its Application in IMS

【作者】 王玉龙

【导师】 杨放春;

【作者基本信息】 北京邮电大学 , 计算机科学与技术, 2009, 博士

【摘要】 网络安全一直是计算机科学中一个备受关注的问题。在探究网络安全失败根源的过程中,脆弱性分析逐渐成为一个重要的研究领域,而脆弱性评估是其中的核心问题。同时,IMS网络的开放性必将使其面临大量已存在于互联网中的威胁,因此亟需开展IMS脆弱性评估方面的研究。然而,IMS脆弱性评估的研究尚处空白。现有脆弱性评估的一般方法因存在诸多不足,难以直接应用于IMS。例如,所有评估方法只关注部分评估过程,缺乏从单点脆弱性赋值到整体脆弱程度计算,再到脆弱性削减策略生成的整体解决方案;绝大部分评估方法是从攻击角度提出的,将攻击者能力、攻击模式等威胁信息作为脆弱性评估的输入,使得网络脆弱程度过于依赖网络所处环境,而非网络自身;多数评估采用定性方法,虽然简单易行,但是评估结果易受主观判断随意性影响而大幅波动,从而难以将其用于更高层次的评估,如安全风险计算中。本文以网络脆弱性的定量评估问题为出发点,从分析网络自身缺陷出发,对网络服务单点脆弱性、关联脆弱性和网络结构脆弱性的评估方法及其在IMS中的应用展开深入的研究。本文的研究工作主要包括以下几个方面:1.用形式化方法建立了脆弱性工作机理模型通过对网络运行规则的分析,从脆弱性评估角度,利用谓词逻辑对脆弱性、威胁、安全保护对象等概念进行了严格定义。从宏观角度,分析了脆弱性与网络安全失败的关系,建立了网络脆弱性分析模型。从微观角度,以Petri网为建模工具,定义了脆弱性及安全保护对象状态变迁规则,在此基础上借鉴病理学思想,建立了脆弱性的因果交替模型和损伤抗损伤模型。从而对脆弱性机理进行了深入的分析,为脆弱性定量评估奠定了坚实的理论基础。阐述了IMS面临的潜在威胁并以案例说明了IMS中脆弱性的利用过程。2.提出一套评价“评估方法”的指标和单点脆弱性评估指标建立了从有效、完备、易用、准确、有序五方面评价脆弱性基本指标的方法。提出了评价脆弱性复合指标优劣的指标:值多样性(Score Diversity)和点平均性(Point Variance)。以指标评价方法为指导,阐述了脆弱性指标的生成方法,定义了基于机密性、完整性、可用性及资产价值损失的基本指标。在基本指标的基础上,提出了基本安全损失BL和潜在价值损失VL两级复合指标,并从值多样性和点平均性等方面与CVSS等指标进行了比较。通过对IMS脆弱性从网络接入、会话控制和业务提供三方面进行分类和评估,分析了IMS脆弱区域的分布。3.提出一套网络服务整体脆弱性评估方法和脆弱性削减措施以Petri网描述的脆弱性关联图为脆弱性关联模型,通过分析脆弱性链的数量和长度以及单点脆弱性利用难度对网络安全受损状态可达度的影响,提出网络服务脆弱度指标SV。对SV的取值范围、单调性以及脆弱性关联关系对SV的影响进行了理论分析。通过度量削减单点脆弱性对网络服务整体脆弱程度的直接和间接影响,提出了关键脆弱性集合计算方法。结合量化后的脆弱性削减成本,提出了成本最小化的脆弱性削减策略。给出了上述方法在IMS中的应用示例。4.提出一个网络结构生成模型及网络结构脆弱性评估方法分析了网络扩增中结点度及接入策略对网络拓扑结构的影响,建立了仅由新增结点度m和已有结点度的幂r决定的网络拓扑结构解析模型。提出了给定m和r下度分布的期望值计算方法。通过计算网络遭受攻击时结点的失效与网络连通度之间的关系,建立了网络结构脆弱度指标fc。使用解析方法,深入分析了网络规模不断增大时网络结构脆弱性的渐进性质。对由CSCF组成的IMS核心网络在既定安全目标下参数的选择策略进行了分析。

【Abstract】 Network security has always been a major concern of computer science.In the course of investigating the root cause of network failure, vulnerability analysis has become an important branch in research,of which vulnerability assessment is the core issue.At the same time,the open structure of the IMS network allowed it to be exposed to a large number of threats already existing on the Internet,which is why it is very urgent to carry out IMS vulnerability assessment studies.However, there is till a gap in the study of vulnerability assessment. Due to many reasons,existing vulnerability assessment methods are insufficient when applied to IMS.For example, current assessment methods all focus on only part of the assessment process.None of them can provide a solution that covers all the steps,from setting values for single vulnerabilities to calculating the overall vulnerability level to finally producing the vulnerability eliminating policy.Moreover, most of the methods were designed from the attacking point of view.They use attributes such as the attacker’s capability or attack pattern as input, so that the assessment of the vulnerability level depends heavily on the network’s environment rather than the network itself. The qualitative methods used in most assessments are easy to use but evaluation results vary considerably under different arbitrary assumptions and are insufficient for high level assessments such as security risk calculation.The thesis focuses on the issue of quantitatively assessing vulnerabilities.It starts by looking into network defects, and then gives an in-depth analysis on evaluation methods for single, associated and structural vulnerabilities as well as the their application in the IMS.The main contributions of this thesis are as follows:1.Built models that demonstrate the mechanism of vulnerabilities with the help of formal description language. By analyzing the rules behind network operations from the vulnerability assessment point of view, concepts such as threat and protected objects were strictly defined with predicate logic.The thesis analyzed the relationship between vulnerability and network security failure from a macro-perspective and constructed an vulnerability analysis model.It also gave a set of state transitions rules for vulneralities and protected objects from a micro-perspective.Based on these results,a cause-result model and a damage anti-damage model were built utilizing similar concepts in pathology.The in-depth analysis on vulnerability laid a solid theoretical foundation for further quantitative evaluation.The thesis also elaborated on the potential threats faced by the IMS and gave an example demonstrating a typical IMS vulnerability exploitation process.2.Defined metrics for the evaluation of assessment methods and gave a set of references for single vulnerability assessment.The thesis proposed a way to evaluate the basic metrics of vulnerability according to their effectiveness,completeness, usability, accuracy and orderliness.It defined two metrics named "score diversity" and" point variance" for evaluating the composite metrics of vulnerability. With these two metrics as references,the thesis described how to design vulnerability metrics and defined the basic metrics basing on confidentiality,integrity, availability, and the loss of asset value. Taking the basic metrics into account, two composite metrics named "loss of basic security" and "potential loss of asset value" were introduced.They were compared with the famous CVSS and other similar metrics in terms of "score diversity" and "point variance".Vulnerabilities within the IMS are categorized and evaluated from three aspects including network access,session control,and service delivery.The thesis also analyzed the layout of vulnerable regions in the IMS.3.Brought forward a solution for evaluating the overall vulnerability of network services and established the corresponding elimination policies.Using a vulnerability relationship graph built with Petri net as the model, the network service vulnerable level meric, SV, was created through examining the relationships between the reachability of network failure states,the count and number of vulnerability chains,and the difficulty in exploiting single vulnerabilities.The thesis analyzed,from a theoretical aspect, the range and monotonicity of SV values,as well as how vulnerability correlations affect the SV value.The thesis proposed a method for obtaining the key set of vulnerabilities by examining direct and indirect effects that the elimination of single vulnerabilities has on the overall vulnerable level of the network service. In reference with quantified costs for vulnerability elimination,the thesis presented strategies for the elimination of vulnerabilities at minimum cost.It also gave examples on how to apply such evaluation methods to the IMS vulnerabilities.4.Proposed a model for generating network structures and a method for evaluating the vulnerability of network structures.The influence that node degree and node adding strategies have on the network topology was analyzed.An analytic model of network topology affected only by m (the degree of newly added nodes) and r (the power of the degree of existing nodes) was built. The thesis presented an algorithm for obtaining expectations that indicate the distribution of nodes with particular degrees under the circumstance that m and r is given.The network’s structural vulnerability metric, fc, was created through examining the relationship between the number of failed nodes and the network’s connectivity.The thesis used analytical methods to carryout an in-depth analysis on the asymptotic characteristics of structural vulnerabilities in the network. It also analyzed the parameter selection strategy that meets the established security criteria of an IMS core network that consists of only CSCFs.

节点文献中: