面向实网环境的漏洞指标体系构建和应用研究
作者:
作者单位:

作者简介:

通讯作者:

施凡,E-mail:shifan17@nudt.edu.cn

中图分类号:

TP393

基金项目:

国家重点研发计划项目(2021YFB3100500)


Construction and application of the vulnerability metricsystem for the realistic network environment
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    互联网上的网络资产数量庞大,环境复杂多变。然而,现有的评估指标无法全面地评估这些因素对漏洞产生的影响,从而影响评估结果的准确性。为了解决上述问题,构建了一种面向实网环境的漏洞指标体系,并将其应用到实际评估中。采用通用漏洞评分系统的基本指标作为静态指标,并利用预训练模型对漏洞描述文本进行静态分数的自动评估。同时,使用资产和环境因素作为动态指标,基于层次分析法计算各指标的权重,构建评估方程。在基于网络空间资源测绘平台数据计算动态分数的基础上,将其与静态分数结合,计算漏洞危害评分。所提出的面向实网环境的漏洞评估指标体系和基于网络空间资源测绘平台数据的漏洞评估方法,能够对漏洞的真实危害性进行评估,具有较高的评估准确性和较快的评估速度,因而具有良好的应用价值。

    Abstract:

    Currently, there is a vast number of network assets on the Internet, and the environmentis complex and constantly changing. However, the existing evaluation metrics cannotcomprehensively assess the impact of these factors on vulnerabilities, which will affect theaccuracy of assessment results. To solve this problem, a vulnerability metric system was constructedfor realistic network environment and applied to practical assessments. Specifically,the basic metrics of the common vulnerability scoring system were used as static metrics andpre-trained models were applied to automatically evaluate the static scores of vulnerability descriptiontexts. Meanwhile, asset and environmental factors were used as dynamic metricsand the method of analytic hierarchy process was used to calculate the weight of each metricand construct an evaluation equation. Based on the data calculated by the network space resourcemapping platform for dynamic scoring and static scores, the vulnerability hazard score was obtained . The proposed vulnerability assessment metric system for realistic network environmentsand the vulnerability assessment method based on network space resource mappingplatform data can accurately assess the true hazard of vulnerabilities and have high accuracy,high speed and good application value as well.

    参考文献
    相似文献
    引证文献
引用本文

施凡,开少锋,钟瑶. 面向实网环境的漏洞指标体系构建和应用研究[J]. 信息对抗技术,2023, 2(2):39-53. [SHI Fan, KAIShaofeng, ZHONG Yao. Construction and application of the vulnerability metric system for the realistic network environment[J]. Information Countermeasure Technology, 2023, 2(2):39-53.(in Chinese)]

复制
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2022-11-30
  • 最后修改日期:2023-01-13
  • 录用日期:
  • 在线发布日期: 2023-07-07
  • 出版日期: