Multi-Objective Network Security Evaluation Based on Attack Graph Model

Cheng Yexia,Jiang Wen,Xue Zhi,Cheng Yejian
2012-01-01
Journal of Computer Research and Development
Abstract:In order to improve network security and take evaluation to give security solution, a novel method of network security evaluation based on attack graph model is proposed. Using attack graph model and combining with characteristics of Markov Chain and Bayesian Network, we propose four security evaluation metrics and the method to compute them, including attack probability parameter, attack realization parameter, vulnerability level parameter and criticality parameter of vulnerability. Based on this, we research on a model of multi-objective security evaluation method, which can help security administrators control the global network more effectively with security enhancement suggestions. Simulation results show that the method is well in expansibility and practicality.
What problem does this paper attempt to address?