针对网络安全状况量化分析难的现状,运用博弈论开展基于影响模型的网络安全态势定量感知方法研究.该方法将网络服务状态作为基本态势要素,综合考虑网络系统中存在的攻防行为,建立了网络安全态势博弈模型,并对状态空间、策略集和效用函数等模型参数给出了明确定义,经仿真实验找到该模型的Nash均衡解,在均衡局势下攻防双方达到收益平衡,完成了对网络安全态势的定量刻画.研究表明,该方法无需考虑攻击行为细节,具有效率高、实时性较强等特点,全面完成了对网络安全态势的量化分析,为安全管理员正确决策提供支持.
Aiming at the actuality that network security was hard to be quantified, gambling theory.was adopted in research on quantification of network security situational awareness based on impact model. Network service states were regarded as basic situational elements, network offense and defense behaviors were both taken into account, gambling model for network security situation was constructed, in which the model parameters such as state space, strategy set and payoff function were definitely formulated. By simulation experiment, the Nash equilibriums was computed when attackers and defenders got a balance between payoffs, then quantitative depict of network security situation was accomplished. Research shown this method has shielded details about attacks, and it is efficient and realtime, quantitative analysis of comprehensive network security situation can be accomplished which will help security administrator to make correct decisions.