攻击图是网络安全分析人员常用的分析工具之一,文章重点研究了基于攻击图模型的系统安全分析架构,并结合攻击难度提出了应用蚁群算法,在攻击图中获取最小关键攻击集的优化解。同时,文章将实验结果与贪婪算法进行了比较,证明了蚁群算法在该应用上是一种高效的优化算法。
Attack graph is a common tool for analyzing network security. This paper focuses on analyzing attack graph model in system security evaluation, and in combination of attack difficulty, proposes the ant algorithm to obtain minimal critical attack set in specific attack graph. Furthermore, the results of ant algorithm are compared with those of greed algorithm, and the experiment proves that the ant algorithm is an optimal and effective algorithm in this application.