(1. 空軍工程大學 導彈學院,陜西 三原 713800)
(2. 中國人民解放軍93942部隊,陜西 咸陽 712000)
(3. 寶雞石油機械有限責任公司,陜西 寶雞 721002)
摘 要:防空信息網絡安全態勢評估方法,是掌握網絡安全態勢調整安全策略的依據。在分析防空信息網絡結構基礎上,提出了“從下至上,先局部后整體”的評估思想,建立了計算服務安全態勢、防御強度、主機安全態勢、局域網安全態勢和廣域網安全態勢模型;根據網絡安全態勢量化評估模型,分別研究了威脅程度、安全屬性受安全措施影響程度、服務重要性權重、主機重要性權重和局域網重要性權重的確定方法。通過仿真實驗表明,層次化網絡安全態勢量化評估方法,可以科學準確地反映防空信息網絡安全態勢,對調整網絡安全策略以及保障信息網絡安全具有一定的理論價值和現實意義。
關鍵詞:防空信息網絡;網絡攻擊;網絡安全態勢
中圖分類號:TP824 文獻標識碼:A 文章編號:
The Hierarchical Quantitative Security Evaluation Model of
the Air Defense Information Network
Huang Ren-quan1,2, Li Wei-min1, Dong Wen3, Duan Nan-nan2
(1. The Missile Institute of AFEU, Shanxi Sanyuan 713800, China)
(2. PLA, No. 93942 Troop, Shanxi Xianyang, 712000, China)
(3. Baoji Oilfield Machinery Co. , LTD, Shanxi Baoji 721002, China)
Abstract: According to the security evaluation model of air defense information network, the network security situation could be obtained, and the defense strategy would be adjusted. Based on the analysis of the air defense information network structure, the thought of “from down to up, and local to integer” was proposed, and the model of service, defense, host, LAN and WAN were set up. According to the quantitative security evaluation model, the threat degree, the affect of security measures to security attribute and the weight of service, host LAN were conformed. Then, it showed reasonable of the hierarchical quantitative security evaluation model for the air defense information network by the simulation, and it was meaningful to adjust the security measures and secure the information network from theory and reality.
Keywords: Air Defense Information Network; Cyber Attack; Network Security Situation
參考文獻
[1] 呂登明. 信息化戰爭與信息化軍隊[M]. 北京:解放軍出版社,2004.
[2] 姚紅星,溫柏華. 美軍網絡戰研究[M]. 北京:國防大學出版社,2010:184-185.
[3] 郭慶豐. 透過美國空軍“舒特”計劃探析戰場網絡戰[J]. 空軍裝備研究,2010,4(2):58-61.
[4] 程啟月. 作戰指揮決策運籌分析[M]. 北京:軍事科學出版社,2004.
[5] 陳秀真,鄭慶華等. 層次化網絡安全威脅態勢量化評估方法[J]. 軟件學報,2006,17(4): 885-897.
[6] Vickie R Westmark. A Definition for Information System Survivability [J]. Proceeding of the 37th Hawaii International Conference on System Science, Hawaii, USA, 2004, 428-437.
[7] 賴積保. 基于異構傳感器的網絡安全態勢感知若干關鍵技術研究[D]. 哈爾濱:哈爾濱工程大學,2009.
[8] 孫 敏. 網絡安全宏觀態勢評估與預測技術研究[D]. 哈爾濱:哈爾濱工程大學,2009.
[10] Projec H. Know your enemy: Statistics. 2002. http://www.Honeynet.org/papers/stars/.
作者簡介:
黃仁全(1983-),男,湖南郴州人,空軍工程大學導彈學院軍事運籌學博士研究生,研究方向:防空作戰建模與仿真。