提出面向网络系统的脆弱性利用成本估算模型,从安全角度分析网络系统的参数,定位由于网络系统互联所引入的关联脆弱性,基于行为规则关联方法,构建系统状态图,用于表示网络系统的脆弱性状况.在此基础上计算脆弱性利用成本的期望值,即成功利用系统脆弱性达到安全破坏目标所需消耗的成本,以此衡量网络系统的脆弱性程度.
The exploitation of a network system's vulnerabilities will result in security breach, whose possibility reflected by the exploitation cost of vulnerabilities. This paper proposes an Evaluation Model of Vulnerability Exploitation Cost (EMVEC) for network system. It analyzes attributes of a network system and locates the correlative vulnerabilities due to inter-connections among hosts. Based on the correlating method of action rules, it constructs a transferring graph of system states, to represent the vulnerable conditions of the network system. Thereon, it computes the Expectation of Exploitation Cost of vulnerabilities, i. e. , the cost of successfully exploiting vulnerabilities of the system to make security breach, with the intention of evaluating the vulnerable extent of the network system.