论文部分内容阅读
为弥补目前网络脆弱性评估系统比较简单、评估结果不全面不准确的不足,提出一种基于脆弱点依赖图的网络脆弱性评估方法,并在该评估方法基础上开发出相应的评估系统.该方法吸收了通用弱点评价体系(CVSS)的优势,同时与目标网络的脆弱点依赖图很好地结合起来,可对网络脆弱性做出一个客观评价.在计算过程中,该方法将脆弱性可利用性和脆弱性影响分开计算,并与实际目标网络中的脆弱点依赖图相结合,从而使得计算值更有参考和实用价值.
In order to make up for the current network vulnerability assessment system is relatively simple and the assessment results are not comprehensive inaccurate, a vulnerability assessment method based on vulnerability point dependency graph is proposed, and a corresponding assessment system is developed based on the assessment method. The method absorbs the advantages of the CVSS and combines it well with the vulnerability-dependent graph of the target network to make an objective evaluation of the vulnerability of the network.In the process of calculation, Utilization and vulnerability impact separately calculated, and with the actual target network vulnerability point dependency graph combination, making the calculated value more reference and practical value.