摘要
在全面分析第三方支付安全事件的基础上,基于威胁树理论构建了第三方支付威胁树风险评估模型,并给出了威胁树的权值计算算法以及最小威胁树修剪算法,最后运用此模型和算法选取典型的第三方支付系统进行了实例评估,对评估结果深入分析的基础上提出了第三方支付系统的安全防范对策建议。结果表明,该评估模型能有效地找到第三方支付系统的威胁路径和风险点,能为第三方支付系统安全的改进和用户选择提供参考。
Based on the analysis of security events occurring to the third-party payment system, this paper proposed a third- party payment attack tree model by using attack tree theory, as well as algorithms about attack tree weights calculation and attack tree pruning. By using the model,it implemend security assessment on typical third-party payment system, also gave secu- rity countermeasures on the basis of analysis of the evaluation results. The conclusion shows that the model can effectively find out the threat route and risk point of the third-party payment system, and give a support to the security improvements and users' choosing.
出处
《计算机应用研究》
CSCD
北大核心
2014年第4期1204-1207,1211,共5页
Application Research of Computers
基金
国家自然科学基金资助项目(71272234)
河南省教育厅人文社会科学青年项目(2012-QN-063)
关键词
第三方支付系统
支付流程
风险评估
威胁树
third-party payment system
payment process
risk assessment
attack tree