Approach of Linkage Policy Decision Based on Security Vulnerability Situation and Multi Factors Fusion

Weijian Li,Qianqian Jin,Bo Zhang,Qiang Liu,Yuanyi Xia
DOI: https://doi.org/10.1109/iaeac.2018.8577470
2018-01-01
Abstract:With the rapid development of Internet, the occurrence of information security events is having been more and more frequent, and the impact of the events is becoming more and more serious. The linkage policy decision facing the alert of security events is widely concerned, and it's also a difficult problem. In this paper, a multi factor linkage policy decision model is proposed. First, base on the given network configuration, system setting, and vulnerability information, the network attack graph is generated by MulVAL multi-stage and multi-step security analyzer. Then, the combination of attack graph and alert information to generate candidate linkage policy is further integrated. The attack chain after the enforcement of the assumed linkage policy is given, and the security risk of the system is calculated based on the popularity, ease and influence of the vulnerability. Finally, a reasonable security linkage policy is given in combination with the enforcement of the linkage policy and the impact on the security risk of the system. The experimental test results show that the method can analyze the influence of security policy from the overall system, and provide a feasible and effective security linkage policy for security administrators, which makes the administrator get rid of the problem of the decision of the linkage response policy of security events.
What problem does this paper attempt to address?