基于贪心策略的多目标攻击图生成方法
收稿日期: 2009-11-15
修回日期: 2010-02-09
网络出版日期: 2010-06-01
基金资助
国家自然科学基金资助项目(60603062,60603015,60970034);湖南省教育厅资助科研项目(07C718);公安部应用创新计划(2007YYCXHNST072)
A Method of Generating the MultiTargets Attack Graphs Based on Greedy Policies
Received date: 2009-11-15
Revised date: 2010-02-09
Online published: 2010-06-01
朱明1,殷建平1,程杰仁1,2,刘强1,林加润1 . 基于贪心策略的多目标攻击图生成方法[J]. 计算机工程与科学, 2010 , 32(6) : 22 -25 . DOI: 10.3969/j.issn.1007130X.2010.
In order to avoid the combination of states occurred in the generation of attack graphs while analyzing network vulnerabilities and to make the attack graphs available for analyzing the multitargets’ vulnerabilities, a new method of generating attack graphs based on greedy policies is proposed. The method introduces the network node correlations, uses greedy policies to reduce the amount of vulnerabilities, chooses the attack routes that allow attackers to gain network node priority with the greatest potential and generate the attack graphs with those attack routes. The algorithm analysis and the experimental results show that the cost of time and space of the method is the polynomial level of the network node number and the network node correlation number, which means it has solved the problem of the great combination of states effectively. The attack graph it generates covers all network nodes that attackers can access, so the method can be used to analyze the multitargets’ vulnerabilities.
/
| 〈 |
|
〉 |