网络入侵风险评估所涉及的数据量较大,传统入侵风险评估模块采用静态风险评估的方法,每隔一段时间对网络进行一次风险评估,无法适应网络入侵的实时性,导致风险评估结果不可靠。为此,设计一种基于Android智能手机入侵的风险评估模块,该模块由硬件和软件共同实现,硬件部分主要由漏洞扫描模块、数据包捕获器、ARM处理器和Android智能手机报警模块构成,通过Android智能手机短信报警模块对超过既定阈值的风险进行报警;系统软件结构主要由入侵风险评估模块、一系列网络信息系统专家数据库和服务模块构成,给出入侵风险评估实现的部分代码。实验结果表明,所设计模块不仅风险评估结果可靠性高,而且达到平稳处理的时间较低。
A invasion risk assessment module based on Android smart phone was designed instead of the traditional intru?sion risk assessment module due to its poor real?time performance and unreliable risk assessment result. The detailed structureof the module is introduced in this paper. The module is mainly composed of vulnerability scanning module,data packet acquirer,ARM processor and Android smart phone alarm module,by which an alarm is given according to the defined threshold. The sys?tem software is mainly composed of invasion risk assessment module,network information expert databases and service module.Some codes of realizing the invasion risk assessment are given. The experimental result shows that the risk assessment modulehas high assessment reliability and short processing time to reach stable state.