摘要
提出一种基于渗透图的网络弱点评估模型(EG_NVM),从网络弱点采集、弱点关联分析出发,参考网络环境配置与拓扑结构、模拟渗透状态改变的过程,构建渗透图,通过对关键渗透序列的量化分析进行网络弱点评估。利用EG_NVM能够有效解决生成图"状态爆炸"的问题并直观显示各弱点相互潜在的关联关系。通过一个典型仿真环境,验证了该方法的可行性和有效性。
This paper presents the Network Vulnerability Model based on the Exploit Graph(EG NVM). The model collects the network vulnerability, analyzes the vulnerability relation, references network configuration and topology, simulates the produce of the exploitation state change, builds exploit graph, analyzes the key exploit queue and constructs assessment of network vulnerability, which provides a useful evidence and guidance for making risk decision. The EG_NVM can effectively resolve the "state explosion" of the others', and visually display the vulnerability of each relationship. Typical simulation verifies its feasibility and effectiveness.
出处
《计算机工程》
CAS
CSCD
北大核心
2009年第23期155-157,160,共4页
Computer Engineering
关键词
网络安全
渗透图
网络弱点
关联关系
network security
exploit graph
network vulnerability
association relation