The invention belongs to the technical field of
network security and particularly relates to an
attack-oriented
network security situation prediction method, device and
system. The method comprises the following steps: detecting and collecting alarm data and network environment operation and maintenance information in a network
countermeasure environment, obtaining an element set required by
network security situation prediction, wherein the element set comprises three types of information of an attacker, a defense party and a network environment; evaluating the attacker capability and the level of the defense party, establishing a dynamic Bayesian
attack graph, and calculating an
attack phase number and an attack state
occurrence probability vector; and combining a
vulnerability scoring standard and network asset information, and performing time-space dimension quantification on the network security situation value. According to the method, dynamic association of the situation elements of the defense party, the attacker, the environment information and the like is achieved, the actual environment of the network is better conformed to, the future situation and the attack occurrencetime can be accurately predicted, higher prediction efficiency is achieved, and storage scale and timeliness of
network security situation awareness are optimized, so as to provide more effective guidance for network protection.