The invention relates to the technical field of network
risk assessment, in particular to a dynamic
risk assessment method for
network security based on a DDS (
Direct Digital Synthesizer)
system. Comprising the steps of S1, building a DDS
system network model, S2, building an equipment layer Bayesian
attack graph to perform static and dynamic
risk quantification, S3, building a business layer SIR model to perform dynamic risk propagation analysis, and S4, integrating multi-dimensional risks to perform
dynamic assessment. According to the method, the Bayesian
attack graph of the equipment layer and the SIR model of the
service layer are organically fused, unified quantification and
dynamic prediction of risks of the physical equipment and the service logic layer are achieved, the prior art is mostly limited to single-level analysis, and through the SIR propagation model and
time sequence analysis, the risk of the physical equipment and the risk of the service logic layer can be predicted. According to the method, the propagation trend of attacks in the network and future node
risk distribution can be predicted, the response speed and accuracy of
risk assessment are remarkably improved, the
online security protection requirement in a
complex network environment is met, and the risk prediction accuracy and timeliness are remarkably improved.