删除或更新信息,请邮件至freekaoyan#163.com(#换成@)

基于权限提升矩阵的攻击图生成方法

本站小编 Free考研考试/2021-12-21

本文二维码信息
二维码(扫一下试试看!)
基于权限提升矩阵的攻击图生成方法
Attack Graph Generation Method Based on Privilege Escalation Matrix
投稿时间:2017-07-30
DOI:10.15918/j.tbit1001-0645.2019.01.017
中文关键词:风险评估攻击图权限提升矩阵攻击模式
English Keywords:risk assessmentattack graphprivilege escalation matrixattack pattern
基金项目:
作者单位
秦虎中国信息安全测评中心, 北京 100085
王建利中国信息安全测评中心, 北京 100085
彭逍遥中国信息安全测评中心, 北京 100085
摘要点击次数:891
全文下载次数:358
中文摘要:
目前的攻击图生成算法的复杂度较高,难以应用于大规模网络环境的攻击图生成.本文对攻击图构建过程进行了研究,在攻击模式库和目标环境描述模型的基础上,提出了基于权限提升矩阵的攻击图生成方法,以矩阵描述攻击过程中攻击者的权限提升过程,能够以较低的算法复杂度生成攻击图.搭建实验网络,验证了本文算法的攻击图生成过程.
English Summary:
Attack graph is a visual display of the attack paths. It can reveal the relation of the vulnerabilities and damage may be caused. Attack graph provides a more intuitive and in-depth analysis method for risk assessment and penetration test. The complexity of current attack graph generation algorithms is too high to apply to large-scale network environments. In this paper, studying the process of constructing attack graph, an attack graph generation method was proposed based on privilege escalation matrix, attack pattern bank and describing target model. With the use of matrixes to describe the process of privilege escalation, the complexity of attack graph generation algorithms was lowered greatly. Finally, an experimental network was built as a case to illustrate the attack graph generation process.
查看全文查看/发表评论下载PDF阅读器
相关话题/北京 过程 环境 网络 中文