首页> 外文会议>Information Security and Cryptology >A Simple, Smart and Extensible Framework for Network Security Measurement
【24h】

A Simple, Smart and Extensible Framework for Network Security Measurement

机译:一个简单,智能和可扩展的网络安全度量框架

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Several efficient tools have emerged to aim at auditing and measuring the security of a computer system or an internal network. Along with the increasing complexity of network attacks, these tools become more and more complicated. Even so, most of them can only do simple snapshot analysis of the current system and are incapable of identifying possible attacks whose preconditions are not fulfilled at the beginning but may be possible during the further attack progression. This paper proposes a new framework for the security measurement that commits complex attack sequences and does stateful inspection of the target environment. The framework consists of five core components: Information Gatherer, Knowledge Base, Interaction Agent, Evaluation Engine and User Interface. An easy-to-use tool, called SNAPP, is realized based on the proposed framework. The dependencies among each attack step in an attack sequence revealed by SNAPP can be easily expressed using Attack Graphs which assist to make security evaluations of the testing environment. Several experiments that actually simulate and perform some well known penetration attacks using SNAPP are presented and analyzed for comparison and measurement of current security methods, such as the conventional filtering-based firewalls and our patented Lock-Keeper technology, which is an implementation of the high-level security concept "Physical Separation".
机译:已经出现了几种有效的工具,旨在审核和衡量计算机系统或内部网络的安全性。随着网络攻击的复杂性越来越高,这些工具也变得越来越复杂。即使这样,它们中的大多数也只能对当前系统进行简单的快照分析,并且无法识别可能的攻击,这些攻击的先决条件在开始时并未满足,但在进一步的攻击进行中可能是可能的。本文提出了一种用于安全度量的新框架,该框架可提交复杂的攻击序列并对目标环境进行状态检查。该框架由五个核心组件组成:信息收集器,知识库,交互代理,评估引擎和用户界面。基于所提出的框架,实现了一种易于使用的工具,称为SNAPP。 SNAPP揭示的攻击序列中每个攻击步骤之间的依赖关系都可以使用“攻击图”轻松表达,该图有助于对测试环境进行安全评估。提出并分析了一些实际使用SNAPP模拟并执行一些众所周知的渗透攻击的实验,以比较和衡量当前的安全性方法,例如常规的基于过滤的防火墙和我们的专利Lock-Keeper技术,这是高安全性的一种实现。级安全概念“物理隔离”。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号