Netinfo Security ›› 2021, Vol. 21 ›› Issue (11): 17-27.doi: 10.3969/j.issn.1671-1122.2021.11.003

Previous Articles     Next Articles

Research on Network Security Measurement Method Based on Attack Identification

ZHAO Xiaolin(), ZHAO Bin, ZHAO Jingjing, XUE Jingfeng   

  1. School of Computer Science and Technology, Beijing Institute of Technology, Beijing 100081
  • Received:2021-07-08 Online:2021-11-10 Published:2021-11-24
  • Contact: ZHAO Xiaolin E-mail:zhaoxl@bit.edu.cn

Abstract:

At present, most of the traditional system security state assessment criteria are qualitative assessment, The disadvantage of this method is that it can not quantify the risk, and there are many kinds of quantitative assessment methods, most of which have the problems of incomplete assessment and low accuracy of attack identification. Attack-based identification plays an important role in network security measurement, this paper proposed a network security measurement model of asset threat vulnerability management, which combined static assessment with dynamic assessment. Static evaluation used AHP analytic hierarchy process, combined with common vulnerability scoring system vulnerability evaluation system to rate asset vulnerability and management. In the aspect of dynamic evaluation, the combination of DW-K-means++ algorithm and XGBoost method were used to improve the effect of attack recognition. The overall evaluation results of the network system are given by combining static and dynamic evaluation. This paper uses public dataset CICIDS2017 to prove the clustering advantage of DW-K-means++ algorithm on large dataset. At the same time, the validity of the network security measurement model proposed in this paper is verified by the data based on simulation experiments.

Key words: network security, risk assessment, AHP, Dw-K-means++, Dw-cluster-XGBoost

CLC Number: