期刊文献+

基于信息熵的信息安全风险分析模型 被引量:32

Information Security Risk Analysis Model Using Information Entropy
下载PDF
导出
摘要 为解决信息系统风险分析过程中不确定信息难以量化分析的问题,用信息熵度量信息系统风险.引入信息熵风险分析算法,采用定性分析与定量计算相结合,构建一种信息系统风险分析模型,并以实例分析与验证基于此模型的风险分析方法.仿真结果表明,该方法是一种有效的风险分析算法,较准确地反映了信息系统的风险状况,为信息系统风险分析提供了一种新的思路. According to the characteristic of uncertainty information in the information system risk analysis process, and information system risk measurement using entropy theory, a risk analysis algorithm using entropy-weight coefficient is presented. When combining qualitative analysis and quantitative calculation, a model of information system risk analysis is constructed. Finally, an instance of the risk analysis approach based on the model is analyzed and validated, which demonstrates the rationality and feasibility of the model. So it provides a new method for information system risk analysis.
出处 《北京邮电大学学报》 EI CAS CSCD 北大核心 2008年第2期50-53,共4页 Journal of Beijing University of Posts and Telecommunications
基金 国家“973计划”项目(2007CB310704) 北京市自然科学基金项目(4062025)
关键词 信息安全 风险分析 熵权系数 故障树分析 information security risk analysis entropy-weight coefficient fault tree analysis
  • 相关文献

参考文献7

二级参考文献17

  • 1王玉峰,王文东,程时端.基于效用的资源适配机制公平性研究[J].北京邮电大学学报,2004,27(3):38-42. 被引量:8
  • 2王艳春,张晨霞.无线网络安全研究[J].齐齐哈尔大学学报(自然科学版),2005,21(2):76-78. 被引量:15
  • 3谢宗晓,刘振华,张文卿.VaR法在信息安全风险评估中的应用探讨[J].微计算机信息,2006,22(06X):76-77. 被引量:9
  • 4United States General Accounting Office, Accounting and Information Management Division. Information Security Risk Assessment[Z]. Augest 1999.
  • 5National Institute of Standards and Technology. Special Publications 800-30, Risk Management Guide(DRAFT)[Z]. June 2001.
  • 6BUTLER S A, FISCHBECK P. Multi-Attribute Risk Assessment, Technical Report CMD-CS-01-169[R]. December 2001.
  • 7BUTLER S A. Security Attribute Evaluation Method: A Cost-Benefit Approach[Z]. Computer Science. Department, 2001.
  • 8PELTIER T R. Information Security Risk Analysis[Z]. Rothstein Associates Inc, 2001.
  • 9贺仲雄.模糊数学及其应用[M].天津:天津科学出版社,1985..
  • 10Kevin J,Soo H.How much is enough? a risk-management approach to computer security[D].School of Engineering,Stanford University,2000.

共引文献381

同被引文献232

引证文献32

二级引证文献192

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部