网络安全态势感知为管理者提供一种宏观角度的安全管理,但该领域研究始终缺乏统一的认知和规范。该文基于Endsley的研究成果,提出一种可扩展的网络安全态势感知模型,将态势提取的概念引入网络安全领域。在态势数据处理中,该模型引入时空知识库来规范态势提取过程,并将态势作为实体对象进行建模。所提出的模型中包含了攻击频率、攻击时间和空间信息,简化了态势提取过程,探讨了态势模型的规范化。并利用真实数据评估态势模型,证明了该模型的实用性和效率。
Although network security situation (NSS) becomes a hot topic, the investigation on situation awareness (SA) still lacks an approbatory standard. Based on Endsley's research, the paper presents a scalable NSS model, and improves situation extraction (SE) to fit the network environment. The proposed model utilizes knowledge bases to standardize the situation acquisition and model the situation as an entity. The incident frequency, incident time, and space information are contained in the model, and the situation acquisition is simplified. Finally, the simulation results prove the model's feasibilitv and efficiency.