Network Security Situation Awareness Framework based on Threat Intelligence

被引:18
|
作者
Zhang, Hongbin [1 ,2 ]
Yi, Yuzi [1 ]
Wang, Junshe [1 ]
Cao, Ning [3 ]
Duan, Qiang [4 ]
机构
[1] Hebei Univ Sci & Technol, Sch Informat Sci & Engn, Shijiazhuang 050000, Hebei, Peoples R China
[2] Hebei Normal Univ, Hebei Key Lab Network & Informat Secur, Shijiazhuang 050024, Hebei, Peoples R China
[3] Qingdao Binhai Univ, Coll Informat Engn, Qingdao 266000, Peoples R China
[4] Penn State Univ, Dept Informat Sci & Technol, 1600 Woodland Rd, Abington, PA 19001 USA
来源
CMC-COMPUTERS MATERIALS & CONTINUA | 2018年 / 56卷 / 03期
基金
中国国家自然科学基金;
关键词
Situation awareness; stochastic game; cloud computing; virtual machine introspection; cyber threat intelligence; Nash equilibrium;
D O I
10.3970/cmc.2018.03787
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network security situation awareness is an important foundation for network security management, which presents the target system security status by analyzing existing or potential cyber threats in the target system. In network offense and defense, the network security state of the target system will be affected by both offensive and defensive strategies. According to this feature, this paper proposes a network security situation awareness method using stochastic game in cloud computing environment, uses the utility of both sides of the game to quantify the network security situation value. This method analyzes the nodes based on the network security state of the target virtual machine and uses the virtual machine introspection mechanism to obtain the impact of network attacks on the target virtual machine, then dynamically evaluates the network security situation of the cloud environment based on the game process of both attack and defense. In attack prediction, cyber threat intelligence is used as an important basis for potential threat analysis. Cyber threat intelligence that is applicable to the current security state is screened through the system hierarchy fuzzy optimization method, and the potential threat of the target system is analyzed using the cyber threat intelligence obtained through screening. If there is no applicable cyber threat intelligence, using the Nash equilibrium to make predictions for the attack behavior. The experimental results show that the network security situation awareness method proposed in this paper can accurately reflect the changes in the network security situation and make predictions on the attack behavior.
引用
收藏
页码:381 / 399
页数:19
相关论文
共 50 条
  • [41] Study on network security situation awareness based on particle swarm optimization algorithm
    Zhao Dongmei
    Liu Jinxing
    [J]. COMPUTERS & INDUSTRIAL ENGINEERING, 2018, 125 : 764 - 775
  • [42] Network virus propagation and security situation awareness based on Hidden Markov Model
    Tang, Wei
    Yang, Hui
    Pi, Jinxiu
    Wang, Chun
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2023, 35 (10)
  • [43] A Network Security Situation Awareness Method Based on GRU in Big Data Environment
    Wen, Zhicheng
    Zhang, Longxin
    Wu, Qinlan
    Deng, Wengui
    [J]. INTERNATIONAL JOURNAL OF PATTERN RECOGNITION AND ARTIFICIAL INTELLIGENCE, 2023, 37 (01)
  • [44] Network Security Risk Assessment Model and Method Based on Situation Awareness and CORAS
    Qi, Yong
    Wang, Yan
    Li, Qianmu
    [J]. INSTRUMENTATION, MEASUREMENT, CIRCUITS AND SYSTEMS, 2012, 127 : 191 - 204
  • [45] CNSSA: A Comprehensive Network Security Situation Awareness System
    Xi, Rongrong
    Jin, Shuyuan
    Yun, Xiaochun
    Zhang, Yongzheng
    [J]. TRUSTCOM 2011: 2011 INTERNATIONAL JOINT CONFERENCE OF IEEE TRUSTCOM-11/IEEE ICESS-11/FCST-11, 2011, : 482 - 487
  • [46] A novel situation awareness model for network systems' security
    Zhao, Guosheng
    Wang, Huiqiang
    Wang, Jian
    Shen, Linshan
    [J]. COMPUTATIONAL SCIENCE - ICCS 2007, PT 3, PROCEEDINGS, 2007, 4489 : 1077 - +
  • [47] Network Security Situation Awareness Model Based on Multi-period Assessment
    Li Chun
    Shen Xiaoliu
    [J]. INFORMATION TECHNOLOGY APPLICATIONS IN INDUSTRY II, PTS 1-4, 2013, 411-414 : 613 - 618
  • [48] Network security situation awareness forecasting based on statistical approach and neural networks
    Sokol, Pavol
    Stana, Richard
    Gajdos, Andrej
    Pekarcik, Patrik
    [J]. LOGIC JOURNAL OF THE IGPL, 2023, 31 (02) : 352 - 374
  • [49] Research on Network Security Situation Awareness Based on the LSTM-DT Model
    Zhang, Haofang
    Kang, Chunying
    Xiao, Yao
    [J]. SENSORS, 2021, 21 (14)
  • [50] Research on Network Security Situation Awareness and Dynamic Game Based on Deep Q Learning Network
    Guo, Xian
    Yang, Jianing
    Gang, Zhanhui
    Yang, An
    [J]. JOURNAL OF INTERNET TECHNOLOGY, 2023, 24 (02): : 549 - 563