为了评价主机系统的安全风险变化,建立了一个描述主机安全状态的隐马尔可夫模型.利用该模型计算主机处于被攻击状态的概率,分析了影响攻击执行过程的因素,提出了一种计算攻击成功概率的方法,并最终计算主机系统的风险指数.该方法可以动态获取主机系统的风险态势曲线,有利于指导安全管理人员调整安全策略.
The simple Hidden Markov Model(HMM) for describing host security states was established to evaluate the security risk of host system.The probability for host to be attacked was calculated by this model.The basic factors of attack executing process was analyzed,and a calculating method for attack success probability was presented,and the quantitative risk index of host system was computed finally.This method can provide the real-time risk curves of host system for security managers to adjust security policies.