• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2013, Vol. 35 ›› Issue (7): 53-59.

• 论文 • Previous Articles     Next Articles

An enhanced LAMBDA description language
oriented to combined attack effectiveness evaluation               

PENG Zimei1,ZHAO Wentao2,ZOU Rongnian1   

  1. (1.Troop 91669,Haikou 571100;
    2.School of Computer Science,National University of Defense Technology,Changsha 410073,China)
  • Received:2011-07-29 Revised:2011-09-28 Online:2013-07-25 Published:2013-07-25

Abstract:

Modeling attack actions with description language can depict the details of the attack more effectively. By evaluating the effectiveness of network attacks, the qualitative and quantitative evaluation of the effect of network attacks is concluded, and it can test the effectiveness of attack actions and help to establish effective security policy of network. Based on the LAMBDA description language, this paper expands its expressiveness on time constraints and effectiveness constraints, proposes an enhanced attack description language, the enhanced LAMBDA, and then gives an application example of the enhanced LAMBDA. In the end, this paper uses DARPA data set, the LLDOS1.0, to construct a test scenario of combined attack of network and evaluates its effectiveness based on the enhanced LAMBDA. The experimental results indicate that Enhanced LAMBDA can effectively support the evaluation of effectiveness of combined attacks.

Key words: attack modeling;LAMBDA;description language;effectiveness evaluation