| With the prevalence of internet and the complexity of network structure, the traditional methods, which are used to resolve single security question, are difficult to fill the demands of security. Assessing and forecasting the entire network security status has became one of hotspots in the field of network security. Network security situation prediction, as an important part of network security situation assessing, made it possible for administrator to protect the security of the network system actively. The traditional methods of network security situation prediction use the value of network security situation in the present and the past. These methods only use single data and don’t combine with a variety of environmental factors. To solve the above problems, the main innovations of the dissertation are as follows:(1) The factors which influence the value of network security situation were studied. The factors were too much for prediction. Considering both the accuracy and efficiency of the prediction, the key factors were selected by using grey relation entropy method. A complete model of network security situation assessing based on grey relation entropy and Kalman was given.(2) GRE-Kalman algorithm was proposed. Combined with the key factors, the GRE-Kalman(Grey Relation Entropy Kalman) algorithm was proposed in this paper. GRE-Kalman prediction model is applicable to any number of factors and the number of factors can be determined according to need. By combining with the key factors, the accuracy of prediction was higher, the adaptability of algorithm was better.(3) AP-Kalman algorithm was proposed. According to the selected best key factor, Attack Packets, the State Equation and Observation Equation required by the Kalman filter were respectively constructed by using the attack packets of the last period of time, the attack packets of the last two period of time, the attack packets of the last three period of time, the attack packets and network security situation of the last period of time. Experimental results show that the model constructed by the attack packets of the last two period of time is the best one. The best one was named as AP-Kalman(Attack Packets Kalman) algorithm. The accuracy of AP-Kalman was higher than GRE-Kalman. The results show that AP-Kalman algorithm was feasible. |