信息网络安全 ›› 2022, Vol. 22 ›› Issue (10): 39-44.doi: 10.3969/j.issn.1671-1122.2022.10.006

• 入选论文 • 上一篇    下一篇

基于通用攻击树的脆弱性评估与风险概率研究

黄波1, 秦玉海2, 刘旸1(), 季铎2   

  1. 1.辽宁警察学院公安信息系,大连 116036
    2.中国刑事警察学院公安信息技术与情报学院,沈阳 110035
  • 收稿日期:2022-07-21 出版日期:2022-10-10 发布日期:2022-11-15
  • 通讯作者: 刘旸 E-mail:y.liu_young@aliyun.com
  • 作者简介:黄波(1973—),女,黑龙江,副教授,硕士,主要研究方向为网络安全|秦玉海(1964—),男,辽宁,教授,本科,主要研究方向为网络安全|刘旸(1984—),男,黑龙江,副教授,博士,主要研究方向为网络安全|季铎(1981—),男,辽宁,副教授,硕士,主要研究方向为文本挖掘、机器翻译
  • 基金资助:
    国家重点研发计划(2017YFC0821700)

Research of Vulnerability Assessment and Risk Probability Base on General Attack Tree

HUANG Bo1, QIN Yuhai2, LIU Yang1(), JI Duo2   

  1. 1. Public Security Information Department, Liaoning Police College, Dalian 116036, China
    2. College of Public Security Information Technology and Information, Criminal Investigation Police University of China, Shenyang 110035, China
  • Received:2022-07-21 Online:2022-10-10 Published:2022-11-15
  • Contact: LIU Yang E-mail:y.liu_young@aliyun.com

摘要:

通用攻击树模型以各分支节点为单位对网络安全脆弱性进行层次分析并计算其风险概率。文章采用通用攻击树模型描述网络攻击各节点,分析各节点的脆弱性评估要素,计算各节点的风险概率,并结合实例分析模型在网络攻击事件中的脆弱性评估与风险概率的应用过程。

关键词: 攻击树, 脆弱性评估, 风险评估, 风险概率

Abstract:

The proposed general network attack tree model takes each branch node as a unit to perform hierarchical analysis on network security vulnerability and calculate the risk probability. The identification information of vulnerability assessment and elements of each attack node are discussed with a proposed attack tree model. A novel calculation method for the analysis of risk probability is introduced. Combined with a practical case, the vulnerability assessment and risk probability of this model in network attack events are illustrated and analyzed.

Key words: attack tree, vulnerability assessment, risk assessment, risk probability

中图分类号: