登录    注册    忘记密码

专利详细信息

基于报警信息的安全评估方法       

文献类型:专利

专利类型:发明专利

是否失效:

是否授权:

申 请 号:CN201110182168.5

申 请 日:20110630

发 明 人:石进 张辰 高为 刘建邦 潘健翔

申 请 人:江苏南大苏富特科技股份有限公司 南京大学

申请人地址:210036 江苏省南京市清江南路89号南大苏富特科技创新

公 开 日:20120215

公 开 号:CN102355361A

代 理 人:陈建和

代理机构:32112 南京天翼专利代理有限责任公司

语  种:中文

摘  要:基于报警信息的安全评估方法,采用关联报警信息重构攻击场景的方法,使用谓词来表示攻击的前提条件和后果;采用无环有向图来表示重构后的攻击场景:1)根据超报警类型的前提集和后果集生成初始攻击场景图集合;2)对于初始攻击场景图集合中的每一个攻击场景图,计算其中各个节点证据支持度,消去可能的误报;攻击场景图G中误报结点的消去;从报警可信度的基础上对报警关联算法进行改进,并从可信性、危险性及对系统造成的风险上,对报警关联后的攻击序列进行了评估;并进行攻击序列的危险性分析和网络系统的损失分析。本发明通过对报警信息与目的地系统的环境匹配度、攻击类型、相关攻击信息以及目的地系统节点安全度的计算得出报警信息。

主 权 项:1.基于报警信息的安全评估方法,其特征是采用关联报警信息重构攻击场景的方法,使用谓词来表示攻击的前提条件和后果;具体步骤如下:(1)采用无环有向图来表示重构后的攻击场景,攻击场景图的生成分为三步;1)根据超报警类型的前提集和后果集生成初始攻击场景图集合;2)对于初始攻击场景图集合中的每一个攻击场景图,计算其中各个节点(攻击步骤)的证据支持度,消去可能的误报;攻击场景图G中误报结点的消去;3)对攻击场景图G中每个节点计算其报警可信度Cr,考虑所有Cr≤ε(ε是管理员设定的一极小值,表示当报警可信度小于等于ε的报警可视为误报,(下同)的节点;4)消去没有前向节点且报警可信度Cr≤ε的节点;5)消去没有后向节点且报警可信度Cr≤ε的节点;6)对于剩下的Cr≤ε的节点,分情况讨论:a)若删去该节点导致攻击场景图分裂,则保留该节点;b)若删去该节点攻击场景图仍然连通,则删去该节点;(2)从报警可信度的基础上对报警关联算法进行改进,并从可信性、危险性及对系统造成的风险上,对报警关联后的攻击序列进行了评估,攻击序列的危险性分析的步骤如下:设攻击序列S={a1,a2,…,an}由n个报警a1,a2,…,an组成,报警ai的自身危险度、节点价值、服务价值分别为ri、ni、si,其定义及取值见?,则攻击序列S的危险度 <math> <mrow> <msub> <mi>r</mi> <mi>S</mi> </msub> <mo>=</mo> <munderover> <mi>&amp;Sigma;</mi> <mrow> <mi>i</mi> <mo>=</mo> <mn>1</mn> </mrow> <mi>n</mi> </munderover> <msub> <mi>r</mi> <mi>i</mi> </msub> <mo>&amp;C</p><p class='subject'><strong>关 键 词:</strong>攻击 &nbsp;<b class='type_ico_id'></b>报警信息 <b class='type_ico_id'></b>场景图 目的地系统 &nbsp;<b class='type_ico_id'></b>报警 误报 &nbsp;重构 &nbsp;<b class='type_ico_id'></b>危险性分析 场景 &nbsp;关联 &nbsp;<b class='type_ico_id'></b>安全评估 报警类型 &nbsp;关联算法 &nbsp;节点安全 &nbsp;前提条件 &nbsp;损失分析 &nbsp;网络系统 &nbsp;相关攻击 &nbsp;可信性 &nbsp;可信度 &nbsp;匹配度 &nbsp;有向图 &nbsp;结点 &nbsp;<b class='type_ico_id'></b>谓词 无环 &nbsp;证据 &nbsp;评估 &nbsp;风险 &nbsp;</p><p class='class'><strong>IPC专利分类号:</strong>H04L12/24(20060101);H04L29/06(20060101)</p> </div> <div class="article_relate_list"> <div> <h2 name="ckwx" id="ckwx"> 参考文献:</h2> <div id="listckwx"> <p class='submit'> <img src='/images_new/loading.gif' width='16' height='16' /> 正在载入数据...</p> </div> </div> <div> <h2 name="2jckwx" id="2jckwx"> 二级参考文献:</h2> <div id="list2jckwx"> <p class='submit'> <img src='/images_new/loading.gif' width='16' height='16' /> 正在载入数据...</p> </div> </div> <div> <h2 name="ohwx" id="ohwx"> 耦合文献:</h2> <div id="listohwx"> <p class='submit'> <img src='/images_new/loading.gif' width='16' height='16' /> 正在载入数据...</p> </div> </div> <div> <h2 name="yzwx" id="yzwx"> 引证文献:</h2> <div id="listyzwx"> <p class='submit'> <img src='/images_new/loading.gif' width='16' height='16' /> 正在载入数据...</p> </div> </div> <div> <h2 name="2jyzwx" id="2jyzwx"> 二级引证文献:</h2> <div id="list2jyzwx"> <p class='submit'> <img src='/images_new/loading.gif' width='16' height='16' /> 正在载入数据...</p> </div> </div> <div> <h2 name="tbywx" id="tbywx"> 同被引文献:</h2> <div id="listtbywx"> <p class='submit'> <img src='/images_new/loading.gif' width='16' height='16' /> 正在载入数据...</p> </div> </div> </div> </div> <div class="r"> </div> <div class="clear"> </div> </div> </div> <div class="vlink_layer" style="display: none"> <div class="vlink"> <img src="/template/t1/images/loading2.gif" width="64" height="64"> <span style="font-size:22px;vertical-align:middle;margin-left:20px;">正在为您导引到下载地址...</span> </div> <div id="vlink" style="display: none"></div> </div> <script type="text/javascript" src="/Template/t5/js/article_relative.min.js"></script> <script type="text/javascript" src="/js/articlevlink.min.js"></script> <div class="foot"> <div class="inner"> <p style="text-align: center;"> 版权所有&copy;重庆科技学院 <script type="text/javascript"> document.write("2001-" + new Date().getFullYear()); </script> 重庆维普资讯有限公司 <a target="_blank" href="https://beian.miit.gov.cn/#/Integrated/recordQuery">渝B2-20050021-7</a><br />  <a target="_blank" href="http://www.beian.gov.cn/portal/registerSystemInfo?recordcode=50019002500408"><img style="position:relative; top:5px; margin-right:3px;" src="/images_new/ghs.png" /><span style="color:inherit;">渝公网安备 50019002500408号</span></a> 违法和不良信息举报中心 <p> </div> </div> <a id="backtop" style="display: none" href="javascript:void(0)" title="返回顶部"></a> <script type="text/javascript"> $(function () { $('#backtop').hover(function () { $(this).css({ opacity: 1 }); }, function () { $(this).css({ opacity: 0.8 }); }); $('#backtop').click(function () { $('html,body').animate({ scrollTop: 0 }, 100); }); $(window).scroll(function () { var scroH = document.documentElement.scrollTop + document.body.scrollTop; if (scroH > $('.head').height()) { $('#backtop').show(); } else { $('#backtop').hide(); } }); }); /**google代码*/ $(function () { // (function (i, s, o, g, r, a, m) { // i['GoogleAnalyticsObject'] = r; i[r] = i[r] || function () { // (i[r].q = i[r].q || []).push(arguments); // }, i[r].l = 1 * new Date(); a = s.createElement(o), //m = s.getElementsByTagName(o)[0]; a.async = 1; a.src = g; // m.parentNode.insertBefore(a, m); // })(window, document, 'script', '//www.google-analytics.com/analytics.js', 'ga'); // ga('create', 'UA-2219013-35', 'cqvip.com'); // ga('send', 'pageview'); }); </script> <!--[if IE 6]> <script type="text/javascript" src="/js/lib/DD_belatedPNG.min.js"></script> <script type="text/javascript"> $(document).ready(function () { /**png图片修正*/ DD_belatedPNG.fix('.logo, .logo a img, .ico_login, .ico_reg, .ico_help, .head_search .search, .head_search .search_guid a, .head_search .search_relative .relative_intro, .head_search .search_relative .relative_op a, .top, .top h1, .user_info .hide tt, li, .search_list .num .t, .search_report h2 em, .search_report, .article_search_list .num .t, .m_op .cl img, .graph_list .sort img, .guid .class .cn1 span, .guid .class .cn2 span, .graph_top h3, .head_nav li a'); }); </script> <![endif]--> <script type="text/javascript"> $(function () { var urlPath = location.href; var request = g_getUrlParms(); //当检索条件不为空时,为检索框赋值 if (!request.q) { $("#artcleSearchCondtion").val(""); } else { var json1 = JSON.parse(request["q"]); if (!request.invokemethod&&json1.ajaxKeys && urlPath && urlPath.indexOf("articles.aspx")!=-1) { $("#artcleSearchCondtion").val(decodeURI(json1.ajaxKeys).replace(/\+/g, " ")); $("#dropSearchFieldName").find("option[showField='"+json1.customShowCondition.split('=')[0]+"']").prop("selected","selected"); } else { $("#artcleSearchCondtion").val(""); } } $("#dropSearchFieldName").easySelectBox(); $("#artcleSearchCondtion").keydown(function (event) { var e = $.event.fix(event); if (e.keyCode == 13) { $("#artcleSearchBtn").click(); return false; } }); $("#artcleSearchBtn").click(function () { var fieldValue = $("#artcleSearchCondtion").val(); if (!fieldValue) { alert("检索内容不能为空!"); } else { var condition = {}; var fieldName= $("#dropSearchFieldName").val(); var tempField = fieldName.split("@"); var tempFieldName = tempField[0].split("|"); if (tempFieldName[0] == "multiple") //期刊题名或关键词检索条件拼接 { condition.customRules = "(" + getSearchRules("title_c", fieldValue) + " OR " + getSearchRules("title_e", fieldValue) + " OR " + getSearchRules("keyword_e", fieldValue) + " OR " + getSearchRules("keyword_c", fieldValue) + " OR " + getSearchRules("subject_text", fieldValue) + ")"; } else { if (tempFieldName.length == 1) { //当检索规则只含有一个字段 condition.customRules = getSearchRules(tempFieldName, fieldValue); } else { var flag = true; var customStr = "("; for (var i = 0; i < tempFieldName.length; i++) { //按检索规则字段个数,循环拼接检索条件,此处各字段间为OR关系 if (flag) { customStr += getSearchRules(tempFieldName[i], fieldValue); } else { customStr += " OR " + getSearchRules(tempFieldName[i], fieldValue); } flag = false; } customStr += ")"; condition.customRules = customStr; } } condition.customShowCondition = tempField[1] + "=" + fieldValue; condition.ajaxKeys = fieldValue; location.href = "/3233/articles.aspx?q=" + encodeURIComponent(JSON.stringify(condition)); if (window.event) window.event.returnValue = false; //ie6fix } }); }); /**返回格式化的搜索规则*/ function getSearchRules(fieldName, fieldValue) { var returnValue = ""; if (fieldName == "worknumber") { $.ajax({ type: "get", url: "/ajax/WriterIdByWorkNumber.ashx", data: { "organid": "" + $('#hidGlobalOrganID').val() + "", "number": "" + fieldValue + "", "_t": new Date }, dataType: 'text', async: false, success: function (msg) { if (!msg) { msg = "0"; } returnValue = "({0}:\"{1}\")".format("writerids_s", msg); } }); } else { returnValue = fieldName == "ALL" ? "({0}:\"{1}\")".format(fieldName, fieldValue.toLowerCase()) : "({0}:\"{1}\")".format(fieldName, fieldValue.toLowerCase()); } return returnValue; } </script> <div class="layer_bg" style="display: none" id="serLayerBg"> </div> <div class="advance_layer" style="display: none; top: 150px;" id="serAdvanceLayer"> <form> <div class="advance"> <h6> <tt class="close" onclick=" g_HideAdvanceSearch(); "> <img alt="x" src="/Template/t5/images/advance-close.gif"></tt> </h6> <div class="cnt" id="cnt1"> <div class="sinput_top"> <div class="sel"> <input type="hidden" id="hfldFieldNameArticles0" name="hfldFieldNameArticles" /> <select name="dropAdvanceSearchFieldName" style="display: none"> </select> </div> <div class="input"> <input type="text" name="txtSearchArticles" id="txtSearchArticles0" maxlength="50"/> </div> </div> <div class="sinput"> <div class="s"> <input type="hidden" value=" AND | 与 " name="hfldRelationArticles" id="hfldRelationArticles1" /> <select name="dropAdvanceSearchLogic"> <option value=" AND | 与 ">与</option> <option value=" OR | 或 ">或</option> <option value="AND NOT | 非 ">非</option> </select> </div> <div class="sel"> <input type="hidden" id="hfldFieldNameArticles1" name="hfldFieldNameArticles" /> <select name="dropAdvanceSearchFieldName" style="display: none"> </select> </div> <div class="input"> <input type="text" name="txtSearchArticles" id="txtSearchArticles1" maxlength="50"/> </div> </div> <div class="sinput" style="display: none"> <div class="s"> <input type="hidden" value=" AND | 与 " name="hfldRelationArticles" id="hfldRelationArticles2" /> <select name="dropAdvanceSearchLogic"> <option value=" AND | 与 ">与</option> <option value=" OR | 或 ">或</option> <option value="AND NOT | 非 ">非</option> </select> </div> <div class="sel"> <input type="hidden" id="hfldFieldNameArticles2" name="hfldFieldNameArticles" /> <select name="dropAdvanceSearchFieldName" style="display: none"> </select> </div> <div class="input"> <input type="text" name="txtSearchArticles" id="txtSearchArticles2" maxlength="50"/> </div> </div> <div class="sinput" style="display: none"> <div class="s"> <input type="hidden" value=" AND | 与 " name="hfldRelationArticles" id="hfldRelationArticles3" /> <select name="dropAdvanceSearchLogic"> <option value=" AND | 与 ">与</option> <option value=" OR | 或 ">或</option> <option value="AND NOT | 非 ">非</option> </select> </div> <div class="sel"> <input type="hidden" id="hfldFieldNameArticles3" name="hfldFieldNameArticles" /> <select name="dropAdvanceSearchFieldName" style="display: none"> </select> </div> <div class="input"> <input type="text" name="txtSearchArticles" id="txtSearchArticles3" maxlength="50"/> </div> </div> <div class="sel_op"> <input type="button" class="add" /><input type="button" class="cut" /> </div> <div class="filter"> <strong>时间:</strong> <div class="t"> <input type="hidden" value="1989" id="hfldAdvanceStartYear" name="hfldAdvanceStartYear" /> <select name="dropAdvanceSearchYears" id="dropAdvanceSearchStartYears"> </select> </div> <span>-</span><div class="t"> <input type="hidden" value="2013" id="hfldAdvanceEndYear" name="hfldAdvanceEndYear" /> <select name="dropAdvanceSearchYears" id="dropAdvanceSearchEndYears"> </select> </div> </div> <div class="filter"> </div> <div class="submit"> <input type="button" onclick="g_AdvanceSearch(1);" value="确定" class="btn-green"> <input type="button" onclick="g_HideAdvanceSearch();" value="关闭" class="btn-gray"> </div> </div> </div> </form> </div> <script type="text/javascript" src="/Template/t5/js/advancesearch.min.js"></script> <script type="text/javascript"> $(function () { var encodestr = $("#hifBaseLog").val().trim(); var BaseGch = ""; var BaseArticleId = ""; var BaseClass = ""; var BaseObjectType = 0; var BaseObjectValue = ""; if (encodestr != "") { var parames = encodestr.split(';'); BaseGch = parames[0]; BaseArticleId = parames[1]; BaseClass = parames[2]; BaseObjectType = parames[3]; BaseObjectValue = parames[4]; } var obj = {}; obj.remark = "机构库站点访问记录-重庆科技学院"; obj.user_id = 0; obj.user_ip_address = "216.73.216.221"; obj.user_group_id = 0; obj.user_organ_id = 3233; obj.site_id = 13; if (BaseGch) { obj.gch = BaseGch; } if (BaseArticleId) { obj.article_id = BaseArticleId; } if (BaseClass) { obj.full_class_ids = BaseClass; } if (BaseObjectType) { obj.object_id = BaseObjectType; } if (BaseObjectValue) { obj.object_value = BaseObjectValue; } loadScript("http://log.cqvip.com/VipCloud/Service/Log/js/analysis.js", function() { vipLog("view", obj,"LIBBEHAVIORANALYSIS"); }); }); </script> </body> </html>