The invention belongs to technical fields characterized by protocols and discloses an
attack occurrence confidence-based
network security situation assessment method and
system. According to the
attack occurrence confidence-based
network security situation assessment method and
system, a
machine learning technology is adopted to analyze network
stream data and calculate a probability that networkstreams belong to
attack streams; a D-S evidence theory is used to fuse the information of multi-step attacks to obtain the confidence of attack occurrence; and a
network security situation is calculated by means of situational factor integration on the basis of security
vulnerability information,
network service information and host protection strategies; and therefore, the accuracy of assessmentis effectively improved. Since the confidence information of detection equipment is added to the assessment
system, the influence of false negatives and false positives can be effectively reduced. Anensemble learning method is adopted, so that the accuracy of confidence calculation can be improved. A
network attack is regarded as a dynamic process, and merging
processing is performed on the information of the multi-step attacks.
Information fusion technology is adopted, so that network environment characteristics such as vulnerabilities,
service information and protection strategies are comprehensively considered.