Study of SDN intrusion intent identification algorithm based on Bayesian attack graph

Since the existing software defined network (SDN) security prediction methods do not consider the attack cost and the impact of controller vulnerabilities on SDN security, a Bayesian attack graph-based algorithm to assessing SDN intrusion intent was proposed.The PageRank algorithm was used to obtain...

Full description

Saved in:
Bibliographic Details
Main Authors: Zhiyong LUO, Yu ZHANG, Qing WANG, Weiwei SONG
Format: Article
Language:zho
Published: Editorial Department of Journal on Communications 2023-04-01
Series:Tongxin xuebao
Subjects:
Online Access:http://www.joconline.com.cn/zh/article/doi/10.11959/j.issn.1000-436x.2023073/
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:Since the existing software defined network (SDN) security prediction methods do not consider the attack cost and the impact of controller vulnerabilities on SDN security, a Bayesian attack graph-based algorithm to assessing SDN intrusion intent was proposed.The PageRank algorithm was used to obtain the criticality of the device, and combining with the vulnerability value, attack cost, attack benefit and attack preference, an attack graph was constructed, and a risk assessment model was established to predict the intrusion path.Through experimental comparison, it is obvious that the proposed model can more accurately predict the intrusion path, effectively ensure the accuracy of security prediction, and provide a basis for SDN defense.
ISSN:1000-436X