为对安全漏洞的风险进行量化评估,提出一种基于连通度算子的漏洞风险评估方法。通过构建的漏洞攻击图对漏洞的利用关系进行定量分析,并提出两种连通度算子,对漏洞间的连通度进行计算,实现对漏洞自身风险和传播风险的量化分析;在此基础上提出风险评估算法VREA-CO,对系统漏洞的全局风险进行评估,评估结果能够帮助管理者确定关键漏洞,提高安全管理的效率。实例分析结果表明,该方法是可行有效的。
To quantify the security vulnerability risk, a vulnerabilities risk evaluation algorithm was proposed based on connecti- vity operators. The vulnerability relationship was quantitatively analyzed with the use of vulnerability attack graph. Two kinds of connectivity operators were proposed to calculate the connectivity between vulnerabilities, a quantitative analysis of the vulne- rability's self risk and spread risk then achieved. On this basis, the risk assessment algorithm VREA-CO was raised and the ove- rall risk of the system was assessed. The vulnerability assessment results help managers identify key vulnerabilities, and improve the safety management efficiency. Example analysis shows that the method is feasible and effective.