A network security situation assessment method based on attack intention perception
Guang Kou, Tang Guangming, Ding Xia, Shuo Wang, Wang Kun · 2016
Through the analysis on the existing network security situation evaluation methods, this paper discovered that they can't accurately reflect the features of large-scale, synergetic, multi-stage gradually shown by network attack behaviors. For this purpose, the association between attack intention and network configuration information was deeply analyzed. Then a network security situation evaluation method based on attack intention recognition was proposed from the angle of attacker. Firstly, this paper conducted casual analysis on attack event, discovered the intrusion path; and simplified the intrusion path, recognized each stage implementing attack; then, taking the attack stage as element, conducted evaluation to network security situation; finally, based on the intrusion stage realized by attacker, combining with connectivity information, recognized the attack intention, and predicted the next attack stage. Through network example verification, it showed that the network security situation value could reflect the actual situation of attack more accurately; and it didn't need training on the historical sequence, so the method is more effective on situation prediction.