信息网络安全 ›› 2016, Vol. 16 ›› Issue (6): 41-47.doi: 10.3969/j.issn.1671-1122.2016.06.007

• • 上一篇    下一篇

网络蠕虫危害性的量化评估模型研究

段彬(), 韩伟红, 李爱平   

  1. 国防科技大学计算机学院,湖南长沙410073
  • 收稿日期:2016-04-28 出版日期:2016-06-20 发布日期:2020-05-13
  • 作者简介:

    作者简介: 段彬(1991—),女,湖北,硕士研究生,主要研究方向为病毒评估、信息安全等;韩伟红(1976—),女,湖南,研究员,博士,主要研究方向为海量数据处理、信息安全;李爱平(1974—),男,山东,研究员 ,博士,主要研究方向为大数据分析、网络安全等。

  • 基金资助:
    国家自然科学基金[61402511,61502510]

Research on Quantitative Assessment Model for Internet Worm Threat

Bin DUAN(), Weihong HAN, Aiping LI   

  1. School of Computer Science, National University of Defense Technology, Changsha Hunan 410073, China
  • Received:2016-04-28 Online:2016-06-20 Published:2020-05-13

摘要:

现有的网络蠕虫危害性评估方法,有些在评估粒度上不够细致;有些虽然粒度够细,但只讨论网络蠕虫某一方面的特性,不能从整体性能上进行评估。基于这种情况,针对网络蠕虫的危害性,文章提出了层次化的量化评估模型。首先,根据蠕虫病毒的特征,提出了几种评估蠕虫病毒危害性的指标,并利用数据归一化、融合等方法对指标进行量化。然后,建立一个层次化的树形评估模型,将量化后的指标数据作为树的叶子节点输入。最后,利用模糊综合评估和加权平均等方法,从叶子节点向上聚集计算得到根节点值,即对蠕虫病毒危害性的评估结果。此评估结果预测与国家互联网应急中心病毒评价呈线性相关,具体验证将在下一阶段研究中进行。

关键词: 网络蠕虫, 量化评估, 指标

Abstract:

Some existing Internet worm threat assessment methods are not fine-grained on the assessment granularity. Some are too fine-grained to have overall assessments on the threats of the worms, which only focus on one respect of the worms. Under the circumstance, this paper proposes a quantitative assessment model to assess the threat of Internet worm. First, based on characteristics of the worm, the paper proposes several indicators to assess the threat of the worm and quantify the indicators by data normalization and data fusion. Then, the paper proposes a hierarchical tree assessment model, whose leaves are the quantified indicators. Finally, the value of the root node that is the assessment result of the threat of the worm is computed from the leaves nodes by the fuzzy comprehensive assessment method and weighted average method. The assessment result is predicted in line with the virus evaluation of the National Internet Emergency Response Center, and the specific verification will be carried out in the next research stage.

Key words: Internet worm, quantitative assessment, indicator

中图分类号: