1. 中南大学信息科学与工程学院, 长沙 410083;
2. 湖南工业大学计算机与通信学院, 株洲 412007

Constructing general cube to be aware of network security situation
WEN Zhicheng1,2, Chen Zhigang1
1. School of Information Science and Engineering, Central South University, Changsha 410083, China;
2. College of Computer and Communication, Hunan University of Technology, Zhuzhou 412007, China
Abstract: Concerning the problems of limited current network security situation assessment scope, single information source, higher time and space complexity and larger deviation of the accuracy, a method was put forward to construct general cube, which can be aware of the network security situation. The continuous situation factor data monitored can be pretreated by discretizing by "3σ rule" and aggregated in the general built cube, that fused into component security situation vertically and merged into the network security situation from component security situation using statistical methods horizontally. It can provide reliable reference to enhance network security. Finally, making full use of network data, the network security situation awareness model and algorithm proposed are verified and the experimental results show correctness of this method.
Key words: network security     situation awareness     network manager     information fusion     general cube

1 安全态势感知模型 1.1 整体感知模型

 图 1 整体网络安全态势感知模型 Fig. 1 Overall network security situational awareness model
1.2 多源多层次信息融合分层感知框架

 图 2 多源多层次信息融合分层感知框架 Fig. 2 Multi-source and multi-level information fusion layered awareness framework

2 安全态势感知前提与基础

2.1 态势因子的遴选

2.2 态势因子值离散化

1) 采集xin个大样本历史数据,计算其平均值xi,代替总体xi的数学期望E(xi)=μ=xi.

2) 同理,计算xi的方差Si2,代替总体xi的方差D(xi)=σ2=S2i.

3) 按照上述方法把xi划分为5个区间SSi.

4) 当获得xi的一个具体值时,根据落在哪个区间SSi来取相应的离散值i.

2.3 数据库的构建

2.4 信息融合方法

3 安全态势感知方法 3.1 构建广义立方体

 图 3 三维广义立方体格 Fig. 3 3D generalized cubic physique

3.2 组件安全态势感知

3.3 网络安全态势感知

3.4 查找异常组件

3.5 安全态势感知算法

1) for every situation factor xi do

2)

3)

4) constructing five sections SSi for this factor

5) end do

6) constructing general cube (A,H) according to the definition 1 and definition 2

1) discretizing the monitored n×m data

2) the discretization n×m data are aggregated into the general cube (A,H)

3) for i=0 to 4 do

4) in j1, j2，···， or jm

5)

6)

7) gaining a part of the component’s situation SAc,that the value is Lc

8) end do

9) for the three category situation factors,repeating from 3) to 8)

10) gaining the situation of this component SAc=(runnabilityc,vulnerabilityc,threatc)

1) for j=1 to 3

2) for i=0 to 4 do

3)

4) end do

5)

6) gaining a part of the network’s situation SAn,that the value is Ln.

7) end do

8) gaining the situation of network SAn=(runnability,vulnerability,threat).

4 仿真实验

 图 4 组件异常情况采样 Fig. 4 Component anomalies sample

 图 5 广义立方体中样本聚集 Fig. 5 Generalized cube samples gathered

 图 6 组件安全态势对比 Fig. 6 Components security situation contrast

 图 7 组件和网络安全态势感知 Fig. 7 Components and network security situational awareness

5 结 束 语

