基于攻击流量和漏洞驱动的态势感知评估方法
作者:
作者单位:

国网江苏省电力有限公司电力科学研究院,南京 211103

作者简介:

通讯作者:

基金项目:

国网江苏省电力有限公司科技项目(J2023180)。


Situation Awareness Assessment Approach Based on Attack Traffic and System Vulnerabilities
Author:
Affiliation:

Electric Power Research Institute, State Grid Jiangsu Electric Power Co., Ltd., Nanjing 211103, China

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
    摘要:

    网络安全态势评估在网络防御策略实施环节扮演重要角色。现有的态势评估方法汇聚攻防双方信息构建评估模型,对于攻击检测的准确性和攻击和漏洞利用关系极为敏感。为了应对上述挑战进而提升评估准确性,本文提出了融合攻击和漏洞的态势评估方法。该方法利用多样的攻击数据集训练攻击检测模型,借助于集成学习的思路实现不同模型攻击检测结果的融合。借助于开源的安全大模型提取不同攻击类型与安全漏洞之间的利用关系知识,计算攻击成功利用漏洞的概率,综合攻击危害程度和攻击成功率获得安全态势评估结果。在基准数据集上进行验证,结果表明提出的攻击检测方法提升了攻击检测性能,平均F1-score达到96.24%,进一步地结合攻击检测结果给出了态势评估应用案例,验证了本文方法的有效性。

    Abstract:

    Network security situation assessment plays an important role in the design and implementation of network defense strategies. The existing situation assessment methods gather the information of both attack and defense to construct an assessment model, which is extremely sensitive to the accuracy of attack detection and the relationship between attack and vulnerability exploitation. To deal with the above challenges and improve the accuracy of assessment, this paper proposes a situation assessment method combining attack and vulnerability. Firstly, various attack data sets are used to train attack detection models, and the attack detection results of different models are fused by the idea of ensemble learning. Secondly, with the help of the open source security model, the exploitation knowledge between different attack types and security vulnerabilities is extracted. Finally, the security situation assessment results are obtained by integrating the degree of attack damage and the probability of vulnerability exploitation calculated using the extracted exploitation knowledge. The results show that the proposed method improves the performance of attack detection, and the average F1-score reaches 96.24. Furthermore, combined with the attack detection results, a situation assessment application case is given to show the effectiveness of the proposed method.

    参考文献
    相似文献
    引证文献
引用本文

李岩,王梓莹,冒佳明,顾智敏,姜海涛.基于攻击流量和漏洞驱动的态势感知评估方法[J].数据采集与处理,2025,40(3):832-844

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
历史
  • 收稿日期:2024-06-24
  • 最后修改日期:2024-08-31
  • 录用日期:
  • 在线发布日期: 2025-06-13