Tongxin xuebao (Apr 2023)

Study of SDN intrusion intent identification algorithm based on Bayesian attack graph

  • Zhiyong LUO,
  • Yu ZHANG,
  • Qing WANG,
  • Weiwei SONG

Journal volume & issue
Vol. 44
pp. 216 – 225

Abstract

Read online

Since the existing software defined network (SDN) security prediction methods do not consider the attack cost and the impact of controller vulnerabilities on SDN security, a Bayesian attack graph-based algorithm to assessing SDN intrusion intent was proposed.The PageRank algorithm was used to obtain the criticality of the device, and combining with the vulnerability value, attack cost, attack benefit and attack preference, an attack graph was constructed, and a risk assessment model was established to predict the intrusion path.Through experimental comparison, it is obvious that the proposed model can more accurately predict the intrusion path, effectively ensure the accuracy of security prediction, and provide a basis for SDN defense.

Keywords