首页> 外国专利> A NETWORK SECURITY PLANNING ARCHITECTURE

A NETWORK SECURITY PLANNING ARCHITECTURE

机译:网络安全规划架构

摘要

Described are techniques used for assessing the security of a network. Pruned attack trees are generated using a forward chaining, breadth-first technique representing the attack paths of a possible attacker in the network. A vulnerability score is determined for each network and attacker starting point using attack loss values assigned to each host and information extracted from the attack tree(s) concerning compromised hosts. Different hypothetical alternatives may be evaluated to improve security of the network and each alternative may be evaluated by recomputing the network vulnerability score and comparing the recomputed score to the original network vulnerability score. Also disclosed is a method for determining end-to-end connectivity of a network. The resulting end-to-end connectivity information is used in generating the pruned attack tree.
机译:描述了用于评估网络安全性的技术。修剪的攻击树是使用表示网络中可能的攻击者的攻击路径的广度优先的前向链接技术生成的。使用分配给每个主机的攻击损失值以及从攻击树中提取的有关受感染主机的信息,为每个网络和攻击者起点确定漏洞评分。可以评估不同的假设替代方案以提高网络的安全性,并且可以通过重新计算网络漏洞评分并将重新计算的评分与原始网络漏洞评分进行比较来评估每个替代方案。还公开了一种用于确定网络的端到端连接性的方法。生成的端到端连接性信息将用于生成修剪的攻击树。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号