Security Situation Assessment Method Based On States Transition

22 Mar 2018, 14:20
20m
Room 802 (Academia Sinica)

Room 802

Academia Sinica

Oral Presentation Networking, Security, Infrastructure & Operations Networking, Security, Infrastructure & Operation Session

Speaker

Mr Hanji Shen (Computer Network Information Center of Chinese Academy of Sciences)

Description

With the development of demands in the network security operation, how to assess the network security situation becomes a research hotspot. In order to solve the problem that the security situation of current network cannot be reflected by the alarm information from security equipment, the security situation assessment model based on state transition was built with HMM, by re-searching hosts states and analysing events affected states transition. This method is effective in training the parameters of the model, and it can analyse the security situation quantitatively and qualitatively. At last, the result validates the method by the historical security data in CSTNET.

Primary authors

Dr Chun Long (Computer Network Information Center of Chinese Academy of Sciences) Mr Hanji Shen (Computer Network Information Center of Chinese Academy of Sciences) Mrs Jing Zhao (Computer Network Information Center of Chinese Academy of Sciences) Mr Peng Gao (Computer Network Information Center of Chinese Academy of Sciences) Dr Wei Wan (Computer Network Information Center of Chinese Academy of Sciences)

Presentation materials