信息安全研究 ›› 2018, Vol. 4 ›› Issue (10): 914-921.

• 风险评估专题 • 上一篇    下一篇

基于博弈模型的物联网系统漏洞风险评估

韦早裕1,吴鸣旦2,马楠3,雷敏3,毕伟4   

  1. 1. 北京邮电大学
    2. 杭州安恒信息技术有限公司
    3. 北京邮电大学网络空间安全学院
    4. 中思博安科技有限公司
  • 收稿日期:2018-10-11 出版日期:2018-10-15 发布日期:2018-10-11
  • 通讯作者: 韦早裕
  • 作者简介:韦早裕 硕士研究生,主要研究方向为网络安全. 吴鸣旦 杭州安恒信息技术有限公司网络空间安全学院副院长,主要研究方向为网络安全、安全风险控制、人才培养. 马楠 硕士研究生,主要研究方向为网络安全. 雷敏 北京邮电大学网络空间安全学院副教授,主要研究方向为网络安全. 毕伟 牛津大学计算机科学硕士,伦敦大学光学与视觉科学博士,中思博安科技有限公司首席科学家,元一科技首席科学家,区块链技术创新与应用联盟副秘书长.

Vulnerability Risk Assessment of IoT System Based on Game Model

  • Received:2018-10-11 Online:2018-10-15 Published:2018-10-11

摘要: 随着区块链热度的提高,分布广且数量多的物联网终端设备更易于被攻击而形成挖矿的僵尸网络,物联网系统的安全性愈加受到人们的重视.准确的风险评估和针对性的安全防护是确保物联网系统安全的关键.结合物联网系统的多个攻击层,针对基于多种漏洞组合的攻击策略,构建物联网系统攻防博弈模型,提出攻防收益与成本的量化方法.并运用博弈模型综合分析攻防双方的收益期望,以较低复杂度定量计算物联网系统中的漏洞危害,从而能准确地评估物联网系统特定攻击层的安全风险.最后,通过实例分析证明该漏洞风险量化分析算法的可行性.

关键词: 区块链, 风险评估, 攻击层, 物联网系统, 博弈模型

Abstract: As the heat of the blockchain increases, the IoT terminal devices that hold wide distribution and large quantity are more likely to be attacked to form a mining botnet, so the security of the IoT system has been increasing valued. Accurate risk assessment and targeted defense are the key to ensure the security of the IoT system. To analyze attack strategies with vulnerability combinations, an attack-defense game model of IoT system was built in this paper according to the attack layers of IoT system, and it presented an method for attack-defense benefit and expenditure quantification. With the use of game model, the revenue expectation of both attacker and defender was comprehensive analyzed, and the paper quantitatively evaluated those vulnerabilities with low complexity, so that it could accurately assess the risk of specific attack layer of IoT system. Finally, an example was given to prove the feasibility of this vulnerability risk assessment algorithm.

Key words: blockchain, risk assessment, attack layers, IoT system, game model