在資訊爆發的時代,電腦及網路設備已成為組織中的一項重要資產;而隨著與日俱增的電腦攻擊事件的增加,如何發展適當的評估方法將這些行為突顯出來以幫助管理者做資訊安全上的策略,已成為一項重要的議題。 在過去, 風險評價只基於電腦本身的特性,而不能動態地在連續改變的網路環境裡反映出其應有的風險值。在本篇論文中,我們主張風險評估系統所考量的因素可分為內在因素及外在因素,其中內在因素為被評估機器在組織中的重要性指數及安全性指數,外在因素為網路攻擊行為資訊,包含了攻擊行為本身的攻擊目標、攻擊類別、攻擊等級及攻擊的時間點。在定義好內在及外在因素所包含的資訊有哪些後,我們分析該兩種因素的性質並依其性質自行設計我們的風險評估數學模組。透過我們的風險評估系統,可以突顯的網路攻擊行為模式有:1.攻擊類別與主機所提供的服務相關時,透過我們的系統可在單位時間內突顯出來、2.優先權越高的警報透過我們的系統可被突顯出來、3.若攻擊行為愈密集,更顯示出其正處於危險的狀態,透過我們的系統可在單位時間內突顯出來。而由實驗的結果知,動態的風險評估可以適當地反映機器的危險狀態。
In the era of computing, computers and computer networks have become one of the most critical assets of most organizations. As the number of computer attacks increases everyday, it is important to develop a method to evaluate whether a certain service hosting computer is in critical state such that information security staff may be alerted to follow up the condition. In the past, risk evaluation was only based on the characteristics of a computer, which is not able to reflect the dynamics in the continually changing network environment. In this study, we proposed to evaluate the risk of a computer according to both the intrinsic and static characteristics of the host itself as well as the extrinsic and dynamic characteristics of the attacks aiming at the host. The former includes the vulnerableness and the importance of the host, and the latter consists of the relevance, the seriousness and the continuativeness of the attacks. We devised a set of procedures to quantify the originally qualitative characteristics, some of which are based on industrial practices. We further designed a formula to integrate all quantified characteristics into a risk index. As shown in the experimental result, the dynamically changing index is able to reveal the risk state of a host.