• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

Computer Engineering & Science

Previous Articles     Next Articles

A risk assessment framework based on  attack events in dynamic networks

 LI Yan,HUANG Guang-qiu,ZHANG Bin   

  1. (School of Management,Xi’an University of Architecture & Technology,Xi’an 710055,China)
  • Received:2015-07-15 Revised:2015-09-23 Online:2016-09-25 Published:2016-09-25

Abstract:

By applying the evolution theory of dynamic network into the risk assessment of computer network, we propose a new risk assessment framework based on attack events in dynamic networks. We first construct the dynamic access relation network based on static physical links. Then the Timeline algorithm uses its time characteristic effectively to describe the attack evolution trend and find important attacks. The graph approximation algorithm is also adopted to simplify the analysis process as an analysis among approximate graphs and reduce the impact of noise behaviors effectively. In addition, the framework can track the network segment evolution and do correlation analysis. Case study shows that the proposal has good practicability, reveals attackers' attack strategies better, and finds the close ties between important attacks.

Key words: dynamic attack graph, network risk analysis, attack graph, network evolution, risk assessment