首页> 外文会议>Communications Conference-MILCOM 2008, 2008 IEEE Military >Enabling cyber situation awareness, impact assessment, and situation projection
【24h】

Enabling cyber situation awareness, impact assessment, and situation projection

机译:增强网络态势感知,影响评估和态势预测

获取原文

摘要

In the paper we focus on (i) an assessment of impact on missions or business processes resulting from cyber attacks and (ii) the subsequent projection of further possible attacks and corresponding impact assessments. A reference model for impact assessment and situation projection (IASP) is provided, based on which we propose a constraint satisfaction (CS) algorithmic approach for performing IASP. The nodes of a constraint network contain variables with accompanying certainty factors characterizing aspects of missions, services, IT assets, network connections, known vulnerabilities, safeguards, cyber alerts, attack categories, and partial models of complex stepping-stone or island-hopping attacks. Given constraints among these variables, e.g. mission X depends on services Y and Z, the CS algorithm calculates IASP with degree of certainty. We demonstrate the approach on dataset containing audit trails, IDS alerts, and TCP traffic.
机译:在本文中,我们重点关注(i)网络攻击对任务或业务流程的影响评估,以及(ii)随后可能发生的进一步攻击的预测以及相应的影响评估。提供了影响评估和情况预测(IASP)的参考模型,在此模型的基础上,我们提出了执行IASP的约束满足(CS)算法方法。约束网络的节点包含带有伴随确定性因素的变量,这些确定性因素表征了任务,服务,IT资产,网络连接,已知漏洞,安全措施,网络警报,攻击类别以及复杂的踏脚石或跳岛攻击的部分模型。在这些变量中给定约束,例如任务X取决于服务Y和Z,CS算法将确定性地计算IASP。我们演示了对包含审计跟踪,IDS警报和TCP流量的数据集的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号