北京理工大学机电学院,北京,100081
纸质出版:2011
移动端阅览
胡鹤 1. 应用部分马尔科夫博弈的网络安全主动响应决策模型[J]. 西安交通大学学报, 2011,45(4):18-24.
胡鹤 1. Decision Model of Optimal Active Response for Network Security Using Partial Observable Markov Game[J]. 2011, 45(4): 18-24.
针对传统被动响应模型滞后于攻击且频繁误警和虚警导致不当响应的问题
提出一种基于部分马尔科夫博弈(POMG)的主动响应决策模型. 该模型针对入侵过程生成入侵状态转换图
并根据攻击过程中得到的观察事件匹配入侵状态转换图
在考虑状态不确定的情况下确定系统信念状态. 将概率值超过信念状态阈值的状态作为初始节点生成入侵状态转换子图
根据子图的入侵过程确定攻防策略集
最终利用POMG算法选择最优主动响应策略. 实验结果表明
基于POMG的主动响应模型较映射型模型响应速度快67%
平均响应效率高24.5%.
Aiming at the problem that the traditional passive response model lags behind the attacks
and false alarms and missed alarms frequently lead to inappropriate responses
an active response decision-making model based on partial Markov game(POMG)is proposed. The model generates the attack state transmission graph according to the invasion processes. During the invasions
the model determines the system's belief states based on the observations of events so that the attacks are mapped to the nodes of the attack state transmission graph
considering the attacker and the uncertainty of system states.The sub-graphs of the attack state transmission graph are created
in which the belief state value of each sub-graph's initial node is over the belief state threshold. The attack and defense strategy sets are determined according to the invasion process of sub-graphs. The model generates the decision of the optimal active response policies according to POMG algorithm in the end. Experimental results show that the response speed of the active response model based on POMG is 67% faster than the map-based model
and the average response efficiency of the proposed model is 24.5% higher than the map-based model.
张永铮,方滨兴,迟悦,等. 用于评估网络信息系统的风险传播模型 [J]. 软件学报, 2007, 18(1): 137-145.
ZHANG Yongzheng, FANG Binxing, CHI Yue, et al. Risk propagation model for assessing network information systems [J]. Journal of Software, 2007, 18(1): 137-145.
CARVER C, HILL J M, SURDU J R. A methodology for using intelligent agents to provide automated intrusion response [C]∥Proceedings of the 2000 IEEE Workshop on Information Assurance and Security. Los Alamitos, CA,USA: IEEE Computer Society, 2000: 110-116.
RAGSDALE D, CARVER C, HUMPHRIES J, et al. Adaptation techniques for intrusion detection and intrusion response system [C]∥The IEEE International Conf on Systems, Man, and Cybernetics. Los Alamitos, CA,USA: IEEE Computer Society, 2000: 2344-2349.
MUSMAN S, FLESHER P. System of security managers' adaptive response tool [C]∥Proceedings of DARPA Information Survivalability Conference and Exposition. Los Alamitos, CA, USA: IEEE Computer Society, 2000:56-68.
FOO Bingrui, WU Yusung, MAO Yuchun, et al. ADEPTS: adaptive intrusion response using attack graphs in an E-commerce environment [C]∥Proceedings of the 2005 International Conference on Dependable Systems and Networks. Los Alamitos, CA,USA: IEEE Computer Society, 2005:508-517.
WU Yusung, FOO Bingrui, MAO Yuchun, et al. Automated adaptive intrusion containment in systems of interacting services [J]. Computer Networks, 2007, 5(51):1334-1360.
LYE K W, WING M J. Game strategies in network security [J]. International Journal of Information Security, 2005, 4(1/2): 71-86.
石进, 郭山清, 陆音, 等. 一种基于攻击图的入侵响应方法 [J]. 软件学报, 2008, 19(10): 2746-2753.
SHI Jin, GUO Shanqing, LU Yin, et al. An intrusion response method based on attack graph [J]. Journal of Software, 2008, 19(10): 2746-2753.
张波. 不确定情形下的规划及行动:理论与应用 [D]. 合肥: 中国科学技术大学计算机科学与技术学院, 2001.
王伟, 陈秀真, 管晓宏, 等. 深度防卫的自适应入侵检测系统 [J]. 西安交通大学学报, 2005, 39(4):339-346.
WANG Wei, CHEN Xiuzhen, GUAN Xiaohong, et al. Defense-in-depth adaptive intrusion detection system [J]. Journal of Xi'an Jiaotong University, 2005, 39(4): 339-346.
李响, 陈小平. 一种动态不确定性环境中的持续规划系统[J]. 计算机学报, 2005, 7(28): 1163-1170.
LI Xiang, CHEN Xiaoping. A real-time planning system in dynamic nondeterministic environments[J]. Chinese Journal of Computers, 2005, 7(28): 1163-1170.
安喜锋, 李伟华, 刘尊, 等. 网络安全协同防卫系统研究与实现[J]. 西安交通大学学报, 2008, 42(12):1495-1499.
AN Xifeng, LI Weihua, LIU Zun, et al. Research and implementation of network security cooperative defense system [J]. Journal of Xi'an Jiaotong University, 2008, 42(12): 1495-1499.
韩宗芬, 陶智飞, 杨思睿, 等. 一种基于自治域的协同入侵检测与防御机制[J]. 华中科技大学学报:自然科学版, 2006,12(34):53-55.
HAN Zongfen, TAO Zhifei, YANG Sirui, et al. Cooperative intrusion protection based on security zone [J]. Journal of Huazhong University of Science and Technology:Nature Science Edition, 2006, 12(34): 53-55.
LEE W, FAN W, MILLER M, et al. Toward cost-sensitive modeling for intrusion detection and response [J]. Journal of Computer Security, 2002, 10(1/2): 5-22.
WANG L, ISLAM T, LONG T, et al. An attack graph-based probabilistic security metric [J]. Lecture Notes in Computer Science, 2008(5094): 283-296.
0
浏览量
4
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621