
软件学报 ISSN 1000-9825, CODEN RUXUEW E-mail: jos@iscas.ac.cn
Journal of Software,2017,28(4):1010−1026 [doi: 10.13328/j.cnki.jos.005142] http://www.jos.org.cn
©中国科学院软件研究所版权所有. Tel: +86-10-62562563
网络安全态势感知综述
∗
龚
俭
1,2,3
,
臧小东
1,2,3
,
苏
琪
1,2,3
,
胡晓艳
1,2,3
,
徐
杰
1,2,3
1
(东南大学 计算机科学与工程学院,江苏 南京 211189)
2
(江苏省计算机网络重点实验室,江苏 南京 211189)
3
(计算机网络和信息集成教育部重点实验室,江苏 南京 211189)
通讯作者: 龚俭, E-mail: jgong@njnet.edu.cn; 臧小东, E-mail: xdzang@njnet.edu.cn
摘 要: 随着网络空间安全重要性的不断提高,网络安全态势感知(network security situation awareness,简称
NSSA)的研究与应用正在得到更多的关注.NSSA 实现对网络中各种活动的行为辨识、意图理解和影响评估,以支持
合理的安全响应决策.它是对网络的安全性进行定量分析的一种手段,网络安全管理系统可以借助其宏观把握整个
网络的安全状况,分析攻击者的意图,为管理决策提供重要的依据.讨论了 NSSA 的任务范围,并据此对网络安全态势
感知的概念进行了重新定义.然后,分别从网络安全态势觉察、网络安全态势理解、网络安全态势投射这 3 个层面
综述了网络安全态势感知的研究现状和存在的问题.
关键词: 网络安全态势感知;数据融合;模型;关联性分析;综述
中图法分类号: TP309
中文引用格式: 龚俭,臧小东,苏琪,胡晓艳,徐杰.网络安全态势感知综述.软件学报,2017,28(4):1010−1026. http://www.jos.org.
cn/1000-9825/5142.htm
英文引用格式: Gong J, Zang XD, Su Q, Hu XY, Xu J. Survey of network security situation awareness. Ruan Jian Xue Bao/
Journal of Software, 2017,28(4):1010−1026 (in Chinese). http://www.jos.org.cn/1000-9825/5142.htm
Survey of Network Security Situation Awareness
GONG Jian
1,2,3
, ZANG Xiao-Dong
1,2,3
, SU Qi
1,2,3
, HU Xiao-Yan
1,2,3
, XU Jie
1,2,3
1
(School of Computer Science and Technology, Southeast University, Nanjing 211189, China)
2
(Jiangsu Provincial Key Laboratory of Compmer Network Technology, Nanjing 211189, China)
3
(Key Laboratory of Computer Network and Information Integration Ministry of Education, Nanjing 211189, China)
Abstract: As the priority of cyber-security arises world-wide, network security situation awareness (NSSA) and its application help to
draw more attentions of researchers. NSSA is able to identify network activities, understand their intentions and evaluate the impact of
these activities on the managed network, as well as to support an optimal security response to the security threats. It is a means of
quantitative analysis for network security, with which network security management system can have a global view of security states of
the managed network, find the intention of attackers, and make a management decision based on these findings. In the paper, the coverage
of NSSA is discussed to redefine the concept of NSSA. Then a survey is given on the state-of-art of NSSA’s research in the aspects of
network security situation perception, comprehension and projection. Finally the features and challenges of network security situation
awareness are summarized.
Key words: network security situation awareness; data fusion; model; correlation analysis; survey
互联网基础设施的不断发展和新应用的不断涌现使得网络规模逐渐扩大,拓扑结构日益复杂,网络安全管
∗ 基金项目: 国家自然科学基金(61602114)
Foundation item: National Natural Science Foundation of China (61602114)
收稿时间: 2016-05-11; 修改时间: 2016-08-09, 2016-10-26; 采用时间: 2016-11-11; jos 在线出版时间: 2016-11-24
CNKI 网络优先出版: 2016-11-24 13:41:13, http://www.cnki.net/kcms/detail/11.2560.TP.20161124.1341.003.html
相关文档
评论