Dissertation > Excellent graduate degree dissertation topics show

The Key Techniques of Attack Graph Generating for Large-scale Network

Author: ZhaoKai
Tutor: ZhangZuo
School: National University of Defense Science and Technology
Course: Computer Science and Technology
Keywords: Network vulnerability analysis Attack Graph Attack graph generation algorithm Parallel Host reachable relationship
CLC: TP393.08
Type: Master's thesis
Year: 2011
Downloads: 32
Quote: 0
Read: Download Dissertation

Abstract


The attack graph is a model-based network vulnerability assessment. The attack graph technology to the host network vulnerability associated with an in-depth analysis of the threat to network security attack path graph shows. The safety managers take advantage of the attack graph can be visually observed the relationship between the various vulnerability in the network, select a minimum price to compensate for network vulnerability. The Attack Figure technology mainly two aspects: the attack graph generation techniques and attack graph analysis techniques. Attack graph generation technology refers to the target network information and attack pattern generation method of attack graphs, the basis of the attack graph technology. Attack graph analysis techniques to the attack graph refers to the analysis of key node and path to quantify vulnerability. Existing attack graph generation technology mainly there are two problems: First, scalability issues. Due to the expansion of the network and the increased vulnerability of the existing attack graph generation algorithm complexity is high, it is difficult to adapt to the large-scale network, so the need to improve the scalability of the attack graph, making it suitable for large-scale network vulnerability analysis ; up to the relational model. The the reachable relationship between the host is a necessary condition of the formation of a single point of vulnerability in the network attack path, but also an important prerequisite for generating attack graphs existing attack graph generation technology, the relationship between the presence of up to is not comprehensive and does not automatically calculate such as inadequate, and therefore need to establish a comprehensive, moderate abstract, computable host up to the relational model, the host reachable relationship in this study on the basis of the calculation method. Address the problem of attack graph generated key technology research work: First, from the perspective of the TCP / IP protocol layering model, in-depth analysis of typical network attacks on network connectivity needs, on this basis, hierarchical host-based TCP / IP protocol stack up to the relational model, and designed to host up to relationship derivation algorithm. Algorithm to ACL rules and routing rules as all of the input and output target network the reachable relationship between the host relationship, as the attack graph generation algorithm necessary input conditions. Secondly, in order to improve the attack graph generation algorithm scalability, making it suitable for large-scale network, designed and implemented an attack graph generation algorithm in parallel. The main idea of ??the algorithm is: the first step in the process of the attack graph generation decomposed into multiple subtasks second step all sub-tasks are processed in parallel on multiple processors, each sub-task to generate a sub-attack graph, the third step is the use of data dependencies merge all the sub-attack graph, to build the final attack. Through theoretical analysis and experimental verification, to prove the attack graph generation algorithm is superior to existing algorithm in the time complexity. Finally, through experiments on attack graphs generated in parallel algorithms and a host of up relationship derivation algorithm for functional verification and performance analysis and experimental results show the validity and correctness of the algorithm, and the complexity of the algorithm and the theoretical analysis of complexity.

Related Dissertations

  1. Research on Parallel Frequent Graph Pattern Mining,TP311.13
  2. Task Partition of Network Simulation under Large-Scale Computing,TP393.01
  3. Analysis and Control of 6-DOF Electrical Driven Parallel Manipulator,TP242.2
  4. Designs and Applications of Fuzzy Synthetic Evaluation Models Based on Parallel Algorithms,TP18
  5. Study on Small Bank-based Constructed Wetland for Remediation of Polluted Water in City Stream,X703
  6. Research on the Online Parallel Connection Examination and Approbation System,D630
  7. Visual Feedback and Memory Behavior Based GPU Parallel Ant Colony Algorithm,TP301.6
  8. The Designing of HD Vehicle Detection System Based on Fpga,TP391.41
  9. The Kinematics and Dynamics on the Cross-rod Parallel Machine Tools,TH113
  10. Study on a Hybrid Mechanism Based on Tripod Universal Wrist & Biglide Parallel Mechanism,TH112
  11. Administrative proceedings associated with civil litigation cases mode,D925
  12. Research on Approximate String Matching and Its Application on URL Detection,TP393.08
  13. Research and Design of a High-Performance Scalable Public Key Cryptographic Coprocessor,TN918.1
  14. The Research of Parallel Video Transcoding in H.264,TN919.81
  15. Research on Video Compression Algorithm Based on Multi-core Computing Platform,TN919.81
  16. Visual Servoing Approaches Based on Parallel Mechanism,TP391.41
  17. Research on Monitoring System of High-Load Parallel Robot,TP242
  18. Research of Finite Element Method on GPU,O241.82
  19. Experiment of Spatial Evolution Established in the Wake of Circular Cylinder under Interference,O353.4
  20. Numerical Simulation of Radiofrequency Waves in Magnetized Plasma,TL612
  21. Design and Implementation of Remote Sensing Image Classification Algorithms for Parallel Computing System,TP751

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile