论文部分内容阅读
针对攻击行为预警的发展要求,特别是对未知攻击行为的预警,提出了基于状态的预警模型。模型根据攻击工具的分类详细定义了状态项,并以网络熵为基础,建立了状态、系统状态和系统状态集以及状态之间的转移关系。应用该模型,实现了存在攻击情形下的预警:状态项预警、系统状态预警、网络系统预警和受损度预警。
Aiming at the development requirements of early warning of attack behavior, especially for the early warning of unknown attack behavior, a state-based early warning model is proposed. The model defines the state items in detail according to the classification of attack tools. Based on the network entropy, the model establishes the state, the system state, the system state set, and the state transition relations. The model is applied to realize the early warning in the presence of attacks: early warning of state items, early warning of system status, early warning of network system and early warning of damage degree.