摘要
在计算机信息安全领域,针对计算机信息系统的脆弱性量化探讨是目前的研究热点。本文通过对信息系统脆弱性的研究和信息安全风险计算分析与比较,提出了一种基于安全管理平台的脆弱性量化算法,并采用该量化算法在安全管理平台上进行应用实践。结合安全管理平台的脆弱性管理功能和白名单机制,对安全对象进行脆弱性识别后,通过脆弱性量化计算取得目标资产的漏洞和基线的度量值,并由漏洞和基线的度量值综合确定最终的资产脆弱性值。
In the field of computer information security,the quantification probe of the vulnerability of computer information system is the current research hotspot.Based on the analysis of information system vulnerability and the analysis and comparison of information security risk,this paper proposes a quantitative algorithm based on security management platform,and uses this quantization algorithm to apply practice on security management platform.Based on the vulnerability management function and the white list mechanism of the security management platform,the vulnerabilities and baseline measures of the target assets are obtained by the quantitative calculation of the vulnerability,and the vulnerability and the baseline metrics are used to determine the final asset vulnerability.
出处
《电信网技术》
2017年第7期62-69,共8页
Telecommunications Network Technology
关键词
安全管理平台
资产
漏洞
脆弱性
风险评估
量化
security management platform
assets
bug
vulnerability
risk assessment
quantify