首页 | 官方网站   微博 | 高级检索  
     


Multiple behavior information fusion based quantitative threat evaluation
Affiliation:1. AIT Austrian Institute of Technology, Donau-City-Straße 1, 1220 Vienna, Austria;2. SBA Research, Favoritenstraße 16, 1040 Vienna, Austria;1. Department of Computer Science, Information Technology University, Lahore 54000, Pakistan;2. Center for Smart Analytics, Institute of Innovation, Science and Sustainability, Federation University, Brisbane, QLD 4000, Australia
Abstract:How to evaluate network security threat quantitatively is one of key issues in the field of network security, which is vital for administrators to make decision on the security of computer networks. A novel model of security threat evaluation with a series of quantitative indices is proposed on the analysis of prevalent network intrusions. This model is based on multiple behavior information fusion and two indices of privilege validity and service availability that are proposed to evaluate the impact of prevalent network intrusions on system security, so as to provide security evolution over time, i.e., monitor security changes with respect to modification of security factors. The Markov model and the algorithm of D-S evidence reasoning are proposed to measure these two indices, respectively. Compared with other methods, this method mitigates the impact of unsuccessful intrusions on threat evaluation. It evaluates the impact of important intrusions on system security comprehensively and helps administrators to insight into intrusion steps, determine security state and identify dangerous intrusion traces. Testing in a real network environment shows that this method is reasonable and feasible in alleviating the tremendous task of data analysis and facilitating the understanding of the security evolution of the system for its administrators.
Keywords:
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号