攻击源威胁行为评估是骨干网安全监测条件下海量报警信息处理的迫切需要.传统的安全评估方法研究侧重于信息系统的安全性评测,无法有效利用骨干网视窗优势评估攻击源威胁能力差异.本文在分析网络攻击源的行为特点的基础上,分类并量化多维度评估指标,并借助AHP层次分析法建立了基于"目标—准则—指标"三层评估体系的动态评估模型.实验结果表明,该方法能动态有效的评估网络攻击源在其所处监测环境下的威胁能力.
The network attacker behavior assessment is the urgent need for massive alarm information processing in the backbone net- work security monitoring. Traditional security assessment methods focus on the evaluation of the security on information systems, which can not effectively utilize the large eyeshot of the backbone network to assess the threat capability of network attackers. Base on the characteristics analysis of the attacker behavior, this paper classifies and quantifies multi-dimensional assessment indexes, and es- tablishes Three-tier evaluation system dynamic evaluation model based on the "goal-criteria- index" evaluation system. The experiment proves that this method can dynamically and effectively evaluate the threat capability of the network attacker.