• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2012, Vol. 34 ›› Issue (11): 38-45.

• 论文 • 上一篇    下一篇

基于攻击的局域网安全性度量方法

黎筱彦1,2,王清贤1,杨林2,朱云3   

  1. (1.信息工程大学信息工程学院,河南 郑州 450002;2.中国电子系统工程研究所,北京 100141;
    3.总参数据管理中心,北京 100100)
  • 收稿日期:2011-09-21 修回日期:2011-12-10 出版日期:2012-11-25 发布日期:2012-11-25
  • 基金资助:

    国家自然科学基金资助项目(60902102,60970141)

Security Measurement Method of LAN Based on Attack

LI Xiaoyan1,2,WANG Qingxian1,YANG Lin2,ZHU Yun3   

  1. (1.School of Information Science and Technology,Information Science and Technology,Zhengzhou 450002;
    2.Institute of China Electronic System Engineering,Beijing 100141;
    3.General Staff Data Management Center,Beijing 100100,China)
  • Received:2011-09-21 Revised:2011-12-10 Online:2012-11-25 Published:2012-11-25

摘要:

为了对局域网的安全性进行更为科学、全面的度量,本文提出了以攻击效果度量防御效能的思路,设计了恶意程序攻击、网络攻击、信息破坏攻击、信息内容安全攻击等多种攻击场景,提出了以攻击时长、控制时长、干扰时长、感染率为核心的攻击指标集,基于该指标集,采用层次分析法设计了网络防御效能度量模型。仿真实验表明,基于本文给出的度量模型和度量方法,能够较好地度量整个网络的安全性。

关键词: 安全度量, 局域网, 指标体系, 量化计算

Abstract:

For making more scientific and comprehensive quantitative measure on the security of the LAN, the idea of measuring the defense performance byusing attack effect is proposed. The malicious code, network attacks, information sabotage attack, information attack, and other content security attack scenarios are designed. Attack target set containing attack duration, control duration, interference duration, infection rates are proposed.  Based on the attack target set, a network defense performance model using AHP analysis method is presented. Simulation results show that the proposed measurement method and model can better measure the security of network protection systems.

Key words: security measurement;LAN;index system;quantitative calculation