首页|基于知识图谱的网络安全测试方案生成方法

基于知识图谱的网络安全测试方案生成方法

扫码查看
现有安全性测试方案主要依赖于安全专家知识,无法有效使用历史攻击技术,导致安全性测试存在测试不全面、效率低的问题。知识图谱通过关联真实世界中存在的各类实体,为智能检索提供强大支撑。首先,设计了安全测试领域资产模型、脆弱点模型、攻击技术模型等相互关联的本体框架;然后,抽取网络安全历史数据,用图数据库构建网络安全测试知识图谱;接下来,提出了一种基于知识图谱的网络安全测试方案生成算法;最后,通过实验对提出的算法进行了分析验证。
A Method of Cyber Security Test Scheme Generation Based on Knowledge Graph
Existing security testing schemes mainly rely on the knowledge of security experts,and cannot effectively use his-torical attack techniques,resulting in the problems of incomplete testing and low efficiency in security testing.Knowledge graph pro-vides strong support for intelligent retrieval by correlating various entities existing in the real world.Firstly,an ontology framework related to the asset model,vulnerability model,and attack technology model in the field of security testing is designed.Then,histor-ical data of cyber security is extracted,and a graph database is used to build a knowledge graph of cyber security testing.Thirdly,a cyber security test scheme generation algorithm based on knowledge graph is proposed.Finally,the proposed algorithm is analyzed and verified through experiments.

knowledge graphsecurity testcyber security

苗泉强、刘迎龙、吴迪

展开 >

63891部队 洛阳 471000

知识图谱 安全测试 网络安全

2024

计算机与数字工程
中国船舶重工集团公司第七0九研究所

计算机与数字工程

CSTPCD
影响因子:0.355
ISSN:1672-9722
年,卷(期):2024.52(11)