Tongxin xuebao (Jan 2008)

Bayesian-network-approximate-reasoning-based method for network vulnerabilities evaluation

  • JIA Wei1,
  • LIAN Yi-feng2,
  • FENG Deng-guo2,
  • CHEN Si-si3

Abstract

Read online

To evaluate the large-scale computer networks,a Bayesian-network-approximate-reasoning-based method for vulnerabilities evaluation was proposed.First,it models the elements which compose the network and the factors which affect the network security.Second,it builds the attack state graph(ASG) of the computer network to describe the process of vulnerability exploitation.Then,it makes the approximate reasoning to the ASG by stochastic sampling.At last,after the samples analysis and statistic,it achieves the quantitative evaluation result and will provide the theoretical evidence to improve the network security.

Keywords