在网络攻击图的基础上引入防御因素,以网络脆弱性关联分析为基础,控制权限提升为目的,构建了网络攻防策略图。首先,基于网络主机信息、主机连接关系、脆弱性信息、攻击者信息和防御者信息等五个要素描述了网络攻防状态变迁,并给出了网络攻防策略图定义;然后,在三点假设的基础上,提出了攻防策略图生成算法,分析了算法复杂度,并给出了算法优化;最后,通过仿真实验验证了该方法的有效性与适用性。
For the sake of promoting authority control, a network attack-defense strategy graph is proposed based on the network vulnerability correlation analysis with the introduction of protective factors on the basis of network attack graph. Firstly, the state transition of network attack-defense is described based on five factors, such as the network host information, host connectivity relations, vulnerability information, information of attackers and defenders, and the definition of network attack-defense strategy graph is given. Secondly, a generation algorithm for network attack-defense strategy graph is proposed based on three assumptions. Complexity of the algorithm is analyzed and optimal process of algorithm is given. Finally, validity and applicability of the method is verified through simulation experiments.