电子科技 ›› 2019, Vol. 32 ›› Issue (10): 75-78.doi: 10.16180/j.cnki.issn1007-7820.2019.10.015

• • 上一篇    下一篇

基于攻击图的渗透测试方法

杨本毅   

  1. 云南南天电子信息产业股份有限公司 信息安全测评中心,云南 昆明 650000
  • 收稿日期:2019-01-09 出版日期:2019-10-15 发布日期:2019-10-29
  • 作者简介:杨本毅(1988-),男,工程师。研究方向:等级测评、渗透测试、网络安全与等级保护。
  • 基金资助:
    云南省科技厅科技项目(2017KJF35762)

Research on Corrosion Detection Technology of Power System Grounding Grid

YANG Benyi   

  1. Information Security Evaluation Center, Yunnan Nantian Electronic Information Industry Co., Ltd. , Kunming 650000, China
  • Received:2019-01-09 Online:2019-10-15 Published:2019-10-29
  • Supported by:
    Science and Technology Project of Yunnan Science and Technology Department(2017KJF35762)

摘要:

传统的病毒检测系统、网络防火墙、入侵检测系统等技术只能够检测出已知的大部分威胁,但却无法检测出网络中存在的潜在的问题。为此,文中提出了一种基于攻击图的渗透测试方法。首先,考虑到攻击持续时间、攻击类型等方面因素,对现有的攻击图方法进行改进,提出一种新的攻击图技术;其次,基于实际应用,从攻击的路径、时间、代价、方式等方面综合考虑,提出攻击图最优攻击路径选择策略;最后,设计基于攻击图的渗透测试模型,并进行了试验测试。测试结果表明,该渗透测试算法能够更好的模拟现实世界中的真实攻击。同时能够对当前设备的安全状态进行评估,可以在实际渗透测试中进行应用。

关键词: 攻击图, 渗透测试, 攻击图最优攻击路径

Abstract:

Traditional virus detection systems, network firewalls, and intrusion detection systems can only detect most of the known threats, but cannot detect potential problems in the network. To this end, the paper proposed a penetration test method based on attack graph. Firstly, considering the factors such as attack duration and attack type, the existing attack graph method was improved, and a new attack graph technique was proposed. Secondly, based on the actual application, the path, time, cost and method of the attack were based on the actual application. Based on the comprehensive considerations, the optimal attack path selection strategy of attack graph was proposed. Finally, the penetration test model based on attack graph was designed and tested. The test results showed that the penetration test algorithm could better simulate real-world attacks in the real world, and could evaluate the current state of the device, which could be applied in the actual penetration test.

Key words: attack graph, penetration test, attack map optimal attack path

中图分类号: 

  • TP91