摘要
作为国内现有的较为成熟的信息系统安全标准,《信息系统安全等级保护基本要求》在我国信息系统安全建设中发挥了巨大作用。描述逻辑作为一种知识表达的逻辑集,具有强大的表达能力和可判定性,可满足安全策略建模的需求。因此,提出了一种信息系统等级保护安全校验方法。该方法以描述逻辑为基础进行面向等级保护的系统安全建模,之后通过使用推理机进行安全规约符合性判定。实验表明,该方法可以在降低安全审计人员工作量的同时,提升其结果的准确度。
As a relatively mature information system security standard, the Classified Security Protection of Information System plays a great role in China's security construction. As a logical set of knowledge expression, description logic has powerful expressive power and decidability, and could meet the technical requirement for modeling security policy. A re.cation method of information system security is thus proposed, and this method, with description logic as the basis, realizes the classified protection-oriented modeling of system security, and then uses the inference engine for statute and satisfactory judgment. Experiment indicates that this method could improve the accuracy of the evaluation while reducing the workload.
出处
《通信技术》
2017年第11期2554-2560,共7页
Communications Technology
基金
科技部国家重点研发计划(No.2016YFB0800100
No.2016YFB0800105)
国家自然科学地区科学基金项目(No.61562004)~~
关键词
等级保护
描述逻辑
推理机
安全校验
classified security protection
description logic
reasoner
security verification