JOURNAL ARTICLE

Network Security Situation Awareness Framework based on Threat Intelligence

Hongbin ZhangYuzi YiJunshe WangNing CaoQiang Duan

Year: 2018 Journal:   Cmc-computers Materials & Continua Vol: 56 (3)Pages: 381-399   Publisher: Tech Science Press

Abstract

Network security situation awareness is an important foundation for network security management, which presents the target system security status by analyzing existing or potential cyber threats in the target system. In network offense and defense, the network security state of the target system will be affected by both offensive and defensive strategies. According to this feature, this paper proposes a network security situation awareness method using stochastic game in cloud computing environment, uses the utility of both sides of the game to quantify the network security situation value. This method analyzes the nodes based on the network security state of the target virtual machine and uses the virtual machine introspection mechanism to obtain the impact of network attacks on the target virtual machine, then dynamically evaluates the network security situation of the cloud environment based on the game process of both attack and defense. In attack prediction, cyber threat intelligence is used as an important basis for potential threat analysis. Cyber threat intelligence that is applicable to the current security state is screened through the system hierarchy fuzzy optimization method, and the potential threat of the target system is analyzed using the cyber threat intelligence obtained through screening. If there is no applicable cyber threat intelligence, using the Nash equilibrium to make predictions for the attack behavior. The experimental results show that the network security situation awareness method proposed in this paper can accurately reflect the changes in the network security situation and make predictions on the attack behavior.

Keywords:
Computer security Computer science Network security Offensive Cloud computing security Computer security model Situation awareness Cloud computing Engineering Operations research

Metrics

33
Cited By
4.67
FWCI (Field Weighted Citation Impact)
0
Refs
0.95
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Network Security and Intrusion Detection
Physical Sciences →  Computer Science →  Computer Networks and Communications
Advanced Malware Detection Techniques
Physical Sciences →  Computer Science →  Signal Processing

Related Documents

JOURNAL ARTICLE

Threat intelligence technology in network security situation awareness

Yan YinHongbin ZHANGBin LiuDongmei Zhao

Journal:   DOAJ (DOAJ: Directory of Open Access Journals) Year: 2021
BOOK-CHAPTER

Network Security Situational Awareness Model Based on Threat Intelligence

Hongbin ZhangYan YinDongmei ZhaoBin LiuHongbin Gao

Lecture notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering Year: 2021 Pages: 526-536
© 2026 ScienceGate Book Chapters — All rights reserved.