信息网络安全 ›› 2014, Vol. 14 ›› Issue (12): 37-42.doi: 10.3969/j.issn.1671-1122.2014.12.008

• 技术研究 • 上一篇    下一篇

基于蚁群智能的网络安全态势研究与应用

李林1, 2, 许家乐1, 2, 张晓1, 2, 刘念3   

  1. 1.北京邮电大学信息安全中心,北京 100876;
    2.灾备技术国家工程实验室,北京 100876;
    3.北京电子科技学院信息安全系,北京 100080
  • 收稿日期:2014-08-30 出版日期:2014-12-15
  • 通讯作者: 李林 lilin270245@163.com
  • 作者简介:李林(1990-),男,河南,硕士研究生,主要研究方向:信息安全;许家乐(1988-),男,黑龙江,硕士研究生,主要研究方向:信息安全;张晓(1991-),男,山东,硕士研究生,主要研究方向:信息安全;刘念(1981-),男,山东,博士,讲师,主要研究方向:信息安全。
  • 基金资助:
    国家信息安全专项[发改办高技[2013]1309号,京发改[2013]1236号]

Study and Application of Network Security Situation Based on Ant Intelligence

LI Lin1, 2, XU Jia-le1, 2, ZHANG Xiao1, 2, LIU Nian3   

  1. 1. Information Security Center, Beijing University of Posts and Telecommunications, Beijing 100876, China;
    2. National Engineering Laboratory for Disaster Backup and Recovery, Beijing 100876, China;
    3. Information Security Department, Beijing Institute of Electronic Science and Technology, Beijing 100080, China
  • Received:2014-08-30 Online:2014-12-15

摘要: 随着网络技术的发展,网络安全问题也越来越严峻。网络安全的研究由传统的网络安全技术研究发展到了整个网络的安全态势研究。传统网络安全技术有脆弱性检测机制、恶意代码检测技术、防火墙技术、入侵检测技术、信息安全风险管理技术,这些技术由于实时性较差,可能存在误报和漏报,可能引入新的脆弱性,无法定量反应系统当前的安全形势。同时,随着网络结构的日益复杂,也给网络安全管理带来了新的挑战,系统管理员无法及时有效地解决网络安全问题,如何实现网络安全态势分析与防御技术的有效结合是当前研究的一个热点。为了解决这个问题,文章提出一种基于蚁群智能的网络安全态势框架(ant intelligence situation awareness,AISA)及关键技术实现。在管理员和主机之间插入Agent,通过Agent进行信息采集、态势分析、态势评估及自主防御。在网络安全态势感知过程中,借助蚁群智能算法,通过信息素指导Agent的移动,实现网络安全态势分析及自主防御技术有效的结合。实验表明,该框架实现了对网络安全态势的实时和定量感知,减少了管理员的参与,提高了网络安全管理效率。

关键词: 蚁群智能, 网络安全态势, 防御

Abstract: With the rapid development of network technology, the network security problem has become increasingly serious, the traditional network security technologies-vulnerability detection mechanisms, malicious code detection technology, firewall technology, intrusion detection technology, information security risk management technologies-which has the poor real-time and false positives and false negatives. They may introduce new vulnerabilities and cannot react the quantitatively of the current security situation. At the same time, the increasing complexity of network structure also brings new challenges for network security management. System administrator cannot solve network security problem timely and effectively. Therefore, how to achieve effective combination of situation analyses and defense technology for network security becomes a hot issue recently. In order to solve this question, this paper proposes a framework based on ant colony of intelligent network security situation awareness (ant intelligence situation awareness, AISA) and the key technology needed to achieve that. An agent inserted between the administrator and the host can be used for information collection, situation analysis, situation assessment and self-defense. In the process of network security situation awareness, ant colony algorithm can be resorted to and the pheromone guides the movement of the Agent to achieve an effective integration of network security situation analysis and self-defense techniques. Experiments show that the framework realizes a real-time network security awareness and quantitative perception, which can reduce the labor of administrators and improve management efficiency of the network security.

Key words: ant intelligence, network security situation, defense

中图分类号: