为提高传统网络风险评估方法的准确性,针对大部分网络风险评估方法未考虑攻击能力值的问题,提出了一种基于项目反应理论的实时网络风险评估方法。该方法利用项目反应理论引入的攻击能力值参数以及服务安全等级参数,对传统攻击成胁值和攻击成功概率计算方法进行改进,并采用三标度层次分析法构建出更准确的服务重要性权重,最终获得符合网络环境的评估态势。仿真结果表明:该方法可以提高评估结果的准确度,并实时地绘制更符合真实网络环境的安全态势图。
In order to improve the accuracy of traditional risk assessment methods and solve the problem that most of risk assessment methods did not consider attack ability,this paper puts forward a risk assess-ment method for network security based on item response theory(IRT). Firstly,the attack ability intro-duced by IRT and the service security level is used to calculate the threat of attack and the success proba-bility of attack. Secondly,the three-scale analytic hierarchy process is adopted to calculate the importance weight of service accurately. Finally,the risk situation graphs are generated by the improved method. The simulation results show that this method can improve the accuracy of evaluation and get a more realistic network risk situation graph in real-time.