计算机科学与探索 ›› 2016, Vol. 10 ›› Issue (10): 1387-1397.DOI: 10.3778/j.issn.1673-9418.1509088

• 网络与信息安全 • 上一篇    下一篇

基于企业环境的网络安全风险评估

杨云雪1+,鲁  骁2,董  军3   

  1. 1. 中国科学院 计算技术研究所 网络数据科学与技术重点实验室,北京 100190
    2. 国家计算机网络与信息安全管理中心,北京 100029
    3. 中国石油天然气管道局,河北 廊坊 065000
  • 出版日期:2016-10-01 发布日期:2016-09-29

Network Security Risk Assessment Based on Enterprise Environment

YANG Yunxue1+, LU Xiao2, DONG Jun3   

  1. 1. Key Laboratory of Network Data Science and Technology, Institute of Computing Technology, Chinese Academy of Sciences, Beijing 100190, China
    2. National Computer Network and Information Security Management Center, Beijing 100029, China
    3. China Petroleum Pipeline Bureau, Langfang, Hebei 065000, China
  • Online:2016-10-01 Published:2016-09-29

摘要: 针对网络安全风险评估问题,提出了一种依据企业环境特征评估网络安全风险的方法。在企业内部基于企业环境特征进行安全漏洞危险性评估,提出了一种基于企业经济损失的漏洞危险性评估方法。使用贝叶斯攻击图模型,并结合企业网络系统环境变化进行动态安全风险评估。最后,通过案例研究说明了提出的动态安全风险评估方法的具体计算过程,并且使用仿真实验说明了提出的方法更加切合被评估网络或信息系统遭受攻击的真实情况,评估结果更加客观准确。

关键词: 网络管理, 网络安全风险评估, 漏洞评估, 贝叶斯攻击图, 层次分析法

Abstract: This paper studies the issue of network security risk assessment and proposes a method for the network security risk assessment based on enterprise environment. First of all, this paper proposes a vulnerability severity risk assessment method based on economic losses of an enterprise to evaluate the vulnerability severity for the enterprise. Next, this paper proposes a dynamic security risk assessment method by using the Bayesian attack graph model and combining the changes of network environment. Last, the case study interprets the detailed calculation processes of the proposed dynamic security risk assessment method, and the simulation experiment shows that the proposed method conforms to the real threat level of the network or information system evaluated, therefore, the evaluation results are more accurate and objective.

Key words: network management, network security risk assessment, vulnerability assessment, Bayesian attack graph, analytic hierarchy process