A Network Security Risk Assessment Framework Based on Game Theory

作者:He Wei*; Xia Chunhe; Zhang Cheng; Ji Yi; Ma Xinyi
来源:2nd International Conference on Future Generation Communications and Networking, Hainan Island, China, 2008-12-13 To 2008-12-15.
DOI:10.1109/FGCN.2008.166

摘要

Network security risk assessment depends on the prediction of attacker's behavioral decision. In computer network attack and defense area, this kind of decision is the optimal judgment for attackers and defenders themselves in consideration of the opponents' strategy spaces. Thus, The attack and defend behavior can be seen as a game process. In this paper, we studied how to bring Game Theory into the research area of network security risk assessment. First, we analyze the concept and the process of risk assessment to find the combining point where game theory can be used in network security risk assessment. Then we present a risk assessment framework based on game theory, and set up a risk assessment system using this framework. We emphatically introduce GTADM (Game Theoretical Attack-Defense Model) and HRCM (Hierarchical Risk Computing Model) in the system, and provide detailed analysis and specification by a scenario.

全文