Network Security Situation Assessment Approach Based On Attack-Defense Stochastic Game Model

Jianyi Liu,Fangyu Weng,Ru Zhang,Yunbiao Guo
DOI: https://doi.org/10.1007/978-3-030-00012-7_15
2018-01-01
Abstract:To analyze the influence of threat propagation on network system and accurately evaluate system security, this paper proposes an approach to improve the awareness of network security, based on Attack-Defense Stochastic Game Model (ADSGM). The variety of network security elements collected by multi-sensors are fused into a standard dataset such as assets, threats and vulnerabilities. For every threat, it builds a threat propagation network and propagation rule. By using the game theory to analyze the network offensive and defensive process, it establishes the ADSGM. The ADSGM can dynamically evaluate network security situation and provide the best reinforcement schema. Experimental results on a specific network indicate that the approach is more precise and more suitable for a real network environment. The reinforcement schema can effectively prevent the propagation of threats and reduce security risks.
What problem does this paper attempt to address?