论文部分内容阅读
安全评估是贯穿信息系统生命周期的重要管理手段,是制定和调整安全策略的基础和前提。结合服务、主机的重要性和网络信息系统的体系结构,基于入侵检测系统(IDS,Intrusion Detection System)报警信息和流量感知信息,采用自下而上、先局部后整体的方式评估网络系统的整体安全态势。采用网络熵的方法评估节点服务性能的变化情况,根据链路性能下降程度,有效地界定不同强度和不同种类的网络威胁行为对网络信息系统造成的损失程度,进而对网络信息系统安全态势进行准确评估。
Security assessment is an important management tool throughout the life cycle of information systems and is the foundation and precondition for the formulation and adjustment of security policies. Based on the importance of service and host and the architecture of network information system, based on intrusion detection system (IDS, Intrusion Detection System) alarm information and traffic awareness information, the whole network system Security posture. The method of network entropy is used to evaluate the service performance of the nodes. According to the decrease of the link performance, the degree of network information system loss caused by different intensities and different types of network threats is effectively defined, and then the security situation of the network information system is accurately estimated Evaluation.