A network security situation evaluation method based on D-S evidence theory
Zhaoyang Qu, Yaying Li, Peng-Li · 2010
Considering the multi-source information lack of automation management, analysis and evaluation in network security field, a new network security situational evaluation model based on D-S evidence theory is proposed. This method fuses multi-source alarm information through D-S evidence theory, associates with nodes vulnerability information, integrates with the severity of threats, computes the value of network security situational assessment, and draws the security-situation-graph of network. Results of case analysis show that the novel algorithm can provide more objective and detailed extract situation information so that the security administrator may form a clearer picture for the whole network security situation.