A Website Security Risk Assessment Method Based on the I-BAG Model

作者:Liu, Lin; Liu, Liang; Huang, Cheng; Zhang, Zhao; Fang, Yong
来源:China Communications, 2016, 13(5): 172-181.
DOI:10.1109/CC.2016.7489985

摘要

In order to protect the website and assess the security risk of website, a novel website security risk assessment method is proposed based on the improved Bayesian attack graph (I-BAG) model. First, the Improved Bayesian attack graph model is established, which takes attack benefits and threat factors into consideration. Compared with the existing attack graph models, it can better describe the website's security risk. Then, the improved Bayesian attack graph is constructed with optimized website attack graph, attack benefit nodes, threat factor nodes and the local conditional probability distribution of each node, which is calculated accordingly. Finally, website's attack probability and risk value are calculated on the level of nodes, hosts and the whole website separately. The experimental results demonstrate that the risk evaluating method based on I-BAG model proposed is a effective way for assessing the website security risk.

  • 出版日期2016-5
  • 单位四川大学; 中国信息安全测评中心

全文