AI 中文总结
针对小型企业网络安全资源不足问题,提出轻量型VPID框架,含漏洞优先级排序与入侵检测模块,经实验验证其各项性能指标良好。
AI 中文摘要
小型企业面临日益严峻的内部网络威胁,但往往缺乏部署资源密集型安全平台所需的资金、计算能力和专业人员。本文设计并实现了VPID,这是一个用于漏洞优先级排序和入侵检测的轻量型框架,由两个主要模块组成:受控漏洞验证和智能入侵防御。第一个模块使用OpenVAS进行资产映射和漏洞识别,应用决策树对漏洞进行优先级排序,并采用规则引擎生成针对性的验证有效载荷。第二个模块使用Scapy捕获网络流量,通过结合决策树与多项朴素贝叶斯的检测管道对其进行分析,使用Snort规则验证被评估为高风险的流量,并通过iptables执行拦截和告警。评估使用包含正常和攻击流量的550,000个网络流样本训练检测器,以及15,000个带标签的漏洞记录。在漏洞排名测试集上,决策树的准确率为91.8%,召回率为89.5%,F1分数为90.6%。在包含55,000个流量样本的独立测试集上,组合检测管道的准确率为94.5%,召回率为88.3%,F1分数为91.3%,同时保持误报率低于1.5%。
英文摘要
Small enterprises face increasingly serious threats to their internal networks but often lack the financial resources, computing capacity, and specialist staff required to deploy resource intensive security platforms. This paper designs and implements VPID, a lightweight framework for vulnerability prioritization and intrusion detection that consists of two principal modules: controlled vulnerability validation and intelligent intrusion defense. The first module uses OpenVAS for asset mapping and vulnerability identification, applies a decision tree to prioritize vulnerabilities, and employs a rule engine to generate targeted validation payloads. The second module captures network traffic using Scapy, analyzes it through a detection pipeline that combines a decision tree with multinomial Naive Bayes, verifies traffic assessed as high risk using Snort rules, and performs blocking and alerting through iptables. The evaluation uses 550,000 network flow samples containing normal and attack traffic for detector training, together with 15,000 labeled vulnerability records. On the vulnerability ranking test set, the decision tree achieves a precision of 91.8%, a recall of 89.5%, and an F1 score of 90.6%. On an independent test set containing 55,000 traffic samples, the combined detection pipeline achieves a precision of 94.5%, a recall of 88.3%, and an F1 score of 91.3%, while maintaining a false positive rate below 1.5%.
Comments21 pages, 6 figures, 8 tables