Abstract:Aiming at the problem of network threat quantitative evaluation of typical power information system, a network threat dynamic analysis method hmm-ids based on network intrusion detection syetem (NIDS) alarm information and hidden Markov model was proposed in this paper. NIDS alarm information was fully used to analyzes alarm threats from four aspects: priority, severity, asset value and reliability. A quantitative description and classification method of alarm threats were given and the observation matrix in hidden Markov model was optimized. The reliability of successful attack based on Bayesian network was analyzed, which avoided the interference of NIDS false alarm information. Based on the improved hidden Markov model, the dynamic risk quantification value of the system was obtained by fusion. DDoS attacks were simulated based on DARPA2000 experimental scenario. Through comparative experiments, the effectiveness and superiority of the proposed method were verified.