论文部分内容阅读
为有效地对Web应用威胁进行评估,分析了Web应用威胁现状,定义了Web应用威胁模型,提出了一种利用攻击图对Web应用进行威胁建模和定量评估的方法。描述了攻击图建模过程,并给出其生成算法。研究了利用攻击图对Web威胁进行量化评估的分析方法。通过一个典型的Web应用网络环境,对攻击图生成算法和Web威胁评估方法进行了验证。对Web应用进行量化威胁评估的结果,有效揭示了web应用面临的各种可能的威胁隐患和攻击路径,对有效抵御风险具有重要的意义。
In order to evaluate the threat of web application effectively, the status quo of web application threat is analyzed, the threat model of web application is defined, and a method of threat modeling and quantitative evaluation of web application using attack graph is proposed. Describes the attack graph modeling process and gives its generation algorithm. The method of analyzing the threat of Web using the attack graph is studied. Through a typical Web application network environment, the attack graph generation algorithm and Web threat assessment method were verified. The result of quantitative threat assessment of Web application has effectively revealed all potential threat threats and attack paths faced by web applications and is of great significance to effectively resist risks.