网络攻击效果评估的目的是对网络攻击行为所能达到的攻击效果进行综合评判,从而发现网络中的薄弱点。文中提出了一个网络攻击与效果评估系统:首先恶意代码控制系统框架制定攻击策略对目标系统进行攻击;接着对网络攻击进行破坏能力预估,采用层次分析法定义指标,利用Delphi法确定指标权重,最后通过加权法综合效果评估值。三次攻击实验的实测结果表明该系统可以量化实际的网络攻击效果,从而准确评价网络攻击所达到的破坏程度。
The aim of network attack effect evaluation is to evaluate the attack effect which network attacks achieve. As a result, network weak points can be found. A network attack and effect evaluation system is proposed. Firstly ,the system control framework of malicious code works out and implies an attack strategy to the target computer. Secondly, destructive capacity pre-evaluation, indicator selection with analytic hierarchy process, index weight coefficient definition with Delphi method, and integrative evaluation value calculation with weighting method are executed. The results of there experiments indicate that the system can quantify the practical network attack effect. Thereby, the damage that network attacks do could be accurately evaluated.