攻击模型能够对攻击过程进行结构化描述和有效分析,攻击图可以清楚地分析攻击者可能采取的攻击路径,两者对网络安全策略的制定具有重要的指导意义。设计了一种基于状态转移的网络攻击模型,并基于该模型设计了攻击图生成系统的架构和相应的攻击图生成算法,在攻击图生成算法中引入了代价分析机制和规模控制机制。仿真实验结果表明,利用所设计的模型和算法不仅能有效地预测攻击者可能采用的各种攻击路径和最佳攻击路径,而且能有效地控制攻击图的规模。
Attack model can help structurally describing and effectively analyzing the course of attack,and attack graph can clearly analyze the attack paths the attacker may take.Both of them play the guiding role for the establishment of network security policy.A network attack model based on state transition is designed,and a framework of the attack graph generation system as well as the algorithm of generating the attack graph is also designed.In the algorithm,attack costs are analyzed,and the method of controlling the graph size is adopted.The experiment result shows that the possible attack paths as well as the best attack path can be effectively doped out by the model and algorithm, and the graph size can also be controlled by them.