在网络风险评估领域中,为了提高评估的准确性,很多研究工作中都引入了网络节点间的连通性,然而,这种性质还不足以表达出各节点间基于物理连通关系之上的某种特殊的逻辑关系,如一方对另一方独有资源的控制关系.为此,文中引入了网络节点关联性(NNC)的概念,通过对实践过程中若干种访问情景的分析,提出了NNC的分类方法,然后讨论了NNC的发现方法,并举例阐明了NNC在网络风险评估中的应用及作用.通过深入地分析和对比可以看出,利用NNC可以将若于孤立的弱点联系起来,有助于分析网络的安全风险;此外,NNC在包含各协议层连通性的基础上丰富了网络节点间独有的特权关系,利用NNC也有助于提高检测网络弱点和网络攻击的准确性.
In the field of network risk assessment, to enhance the accuracy of assessment, the connectivity between network nodes has been introduced to many studies. However, this characteristic is not sufficient for expressing certain special logical relations over physical connective relations between nodes, such as one partyrs control on particular resources of the other party. Therefore, this paper introduces a conception of network node correlation (NNC). Through analyzing several access scenarios in practice, this paper proposes a NNC taxonomy, then discusses NNC detection methods, and an example is given to illustrate the application and effect of NNC in network risk assessment. Deep analysis and comparison show that using NNC can help to correlate some isolated vulnerabilities to analyze the security risk of networks. Moreover, NNC adds privilege relations between network nodes on the basis of the connectivity of protocol layers so that using NNC also helps to improve the accuracy of detecting network vulnerabilities and attacks.