期刊文献+

一种新的系统等级测评不确定性演化推理模型 被引量:7

A New Uncertainty Evolution Inference Model for Classified Evaluation of Information System
下载PDF
导出
摘要 为了更加合理地判定系统综合保护能力是否达到相应的等级要求,将测评标准GB/T 22239—2008中的安全要素与信息安全事件进行关联分析,利用故障树对安全事件进行分解,并将故障树的最小割集转化成推理规则;利用不确定推理技术推导系统脆弱性可能引发的安全事件,计算损失大小和风险值,将它作为系统保护能力评价的参考依据.以某网站为例进行实验,结果表明该模型能够根据系统的脆弱性进行合理的风险计算,提高了等级测评结论的合理性,为等级保护与风险分析进行有机结合提供了可能. To evaluate reasonably the ability of protection system,the requirements of evaluation standard GB/T 22239-2008 and information security events have to be considered and analyzed comprehensively.The fault tree is applied to decomposition of security incidents and the minimal cut set of fault tree can be translated into inference rules.Then,the uncertain reasoning technique is used to derive security incidents caused probably by system vulnerability.The loss and risk are taken into account,which could be regarded as the basis to assess the capacity of protection system.Experimental results show that the performance of proposed model is corresponding to the system vulnerability and the judgment of classified assessment is reasonable.Above work provides a possible route to synthesize the search of classified protection and risk analysis.
出处 《北京理工大学学报》 EI CAS CSCD 北大核心 2010年第5期537-542,共6页 Transactions of Beijing Institute of Technology
基金 国家"八六三"计划项目(2006AA01Z450)
关键词 等级测评 保护能力 风险分析 故障树 不确定性演化推理 classified assessment protection ability risk analysis fault tree uncertainty evolution inference
  • 相关文献

参考文献6

二级参考文献25

共引文献52

同被引文献35

引证文献7

二级引证文献11

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部