基于可拓集的信息安全风险评估  被引量:2

Information security risk assessment method based on extensible set

在线阅读下载全文

作  者:肖敏[1] 范士喜[2] 柴蓉[3] 杨富平[1] 

机构地区:[1]重庆邮电大学计算机科学与技术学院,重庆400065 [2]北京印刷学院计算机科学系,北京102600 [3]重庆邮电大学通信与信息工程学院,重庆400065

出  处:《计算机应用》2009年第12期3178-3181,共4页journal of Computer Applications

基  金:国家自然科学基金资助项目(40801214)

摘  要:针对信息安全风险评估中风险要素关系复杂、评价因素难以准确度量的问题,以威胁为中心组织风险要素、建立风险评估模型并实现基于可拓集的风险评价方法。此模型应用资产、弱点和控制措施对威胁发生可能性和后果进行评估,并呈现系统风险的层次结构。基于此模型,可拓集方法将评价因素的定性表达区间化并利用区间关联函数实现定性向定量的转化,然后根据定量的风险关联度向量对系统风险做出定性的判决,从而实现系统风险的定性与定量相结合的评估。具体的实例分析表明了此方法的可行性和有效性。In the process of information security risk assessment, there are complex relationships between risk elements and it is also difficult to accurately measure risk evaluation factors. The paper proposed a risk assessment model which took threat as a center to organize risk elements and a risk evaluation method based on extensible set. The model displayed a hierarchical structure for system risk, in which the possibility and consequences of threat were evaluated by three risk factors -asset, vulnerability and control measure. Based on this model, the extensible set method translated qualitative determination into quantitative result by mapping qualitative expression to interval and using interval dependent function and made a qualitative judgment according to a quantitative risk-correlation vector, and therefore, could combine quantitative and qualitative methods to evaluate system risk. A specific example illustrates that the method is feasible and effective.

关 键 词:信息安全 风险评估 可拓集 关联函数 

分 类 号:TP393[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象