网络熵在计算机防攻击中的安全化实践应用
2016-05-14马小雨刘乃迪
马小雨 刘乃迪


摘 要: 分析了网络熵在计算机防护攻击中的应用。在网络安全指标选取基础要求的前提下,分析基于网络熵效果评估,量化指标,得到安全性度量,构建定量评估模型,系统设置子模块包括基本参数、攻击目的以及服务类型。采用灰色关联度表示评价指标,利用Libpcap库函数进行数据采集,设计系统实现框架图。搭建安全评估系统,发动模拟攻击,验证效果评估模型有效性,计算机防护攻击评估模型能够反应网络攻击效果。计算机防护攻击模型能够定量评估网络攻击效果,可操作性强。
关键词: 计算机防攻击; 安全性; 网络熵; 效果评估
中图分类号: TN915?34 文献标识码: A 文章编号: 1004?373X(2016)08?0048?03
Security practice application of network entropy in computer anti?attack
MA Xiaoyu1, LIU Naidi2
(1. School of Computer Science, Henan Institute of Engineering, Zhengzhou 451191, China; 2. Hebei North University, Zhangjiakou 075000, China)
Abstract: The application of network entropy in computer anti?attack is analyzed. On the premise of the basic requirement of network security indicator selection, the effect evaluation based on network entropy and quantitative index are analyzed to obtain the security metric. The quantitative evaluation model was constructed, in which the submodule of system setup is composed of basic parameters, attack purpose and service types. The framework diagram of the design system was implemented by taking gray correlation degree to express the evaluation index and using Libpcap library function to acquire the data. The security assessment system was built, and a simulation attack was launched to verify the validity of the effect evaluation model. The computer anti?attack evaluation model can react and quantitatively evaluate the network attack effect. The model has strong operability.
Keywords: computer anti?attack; security; network entropy; effect evaluation
随着计算机技术在实际应用中的不断发展进步,计算机网络安全要求逐渐提高,信息安全内涵理解不断延伸[1],已经由原来的信息安全完整性和可靠性拓展为信息的完整性和不可否认性,在信息安全防护中,开始出现防范、检测以及评估等安全理论和技术[2]。对于计算机网络系统评估中,没有特定标准[3]。本文主要结合网络熵概念,提出计算机网络攻击效果评估模型,并验证可行性。
1 网络安全指标的选取
网络攻击目的是破坏对方网络的安全性,因此可以采用特定安全指标进行定量描述。网络安全性指标有很多,如何确定还需要进一步分析。这里采用系统化分析方法,从网络研究的安全机制入手,得到初步有效性能指标集。每一个安全机制划分为不同安全子准则,对应着一定的安全指标。……
