期刊文献+

一种基于风险传播的信息系统风险评估方法 被引量:1

An Information System Risk Assessment Method Based on Risk Propagation
原文传递
导出
摘要 传统信息系统的风险评估方法未考虑节点的状态变化和风险的传播方向,且评估结果的准确性受专家主观性的影响,对此,提出了一种基于风险传播的信息系统风险评估方法。首先,确定节点的初始状态转移概率矩阵,并根据攻击属性对矩阵进行修正,得到节点状态转移概率;其次,基于系统风险传播网络拓扑图和节点属性值计算节点在各方向的传播概率;然后,利用三参数区间数方法获取节点威胁事件的量化值;最后,根据风险评估方法计算各节点的风险值。实验结果表明,基于风险传播方法的评估流程更客观、合理,可提高信息系统风险评估的整体性和准确性。 Traditional information system risk assessment methods do not consider the state change of nodes and the direction of risk propagation,and the accuracy of the evaluation results is affected by the subjectivity of experts.To solve these problems,an information system risk assessment method based on risk propagation is proposed.First,the initial state transition probability matrix of the node is determined,and the node state transition probability is obtained by modifying the matrix according to the attack attributes.Then,the propagation probability of nodes in all directions is calculated based on the topology network and node attribute value.Next,the three-parameter interval number method is used to obtain the quantitative value of node threat events.Finally,the risk value of each node is calculated according to the risk assessment method.Experimental results show that the proposed methodis more objective and reasonable,and it improves the integrity and accuracy of the risk assessment of information systems.
作者 杨宏宇 张乐 张良 YANG Hong-yu;ZHANG Le;ZHANG Liang(College of Safety Science and Engineering,Civil Aviation Univereity of China,Tianjin 300300,China;College of Computer Science and Technology,Civil Aviation University of China,Tianjin 300300,China;College of Information,University of Arizona,Tucson AZ 85721,USA)
出处 《北京邮电大学学报》 EI CAS CSCD 北大核心 2021年第4期41-48,共8页 Journal of Beijing University of Posts and Telecommunications
基金 国家自然科学基金民航联合研究基金项目(U1833107)。
关键词 风险评估 风险传播 状态转移概率 传播概率 三参数区间数 risk assessment risk propagation state transition probability propagation probability three-parameter interval number
  • 相关文献

参考文献5

二级参考文献52

  • 1冯登国,张阳,张玉清.信息安全风险评估综述[J].通信学报,2004,25(7):10-18. 被引量:307
  • 2龚俭,梅海彬,丁勇,魏德昊.多特征关联的入侵事件冗余消除[J].东南大学学报(自然科学版),2005,35(3):366-371. 被引量:13
  • 3朱建军,刘思峰,王翯华.群决策中两类三端点区间数判断矩阵的集结方法[J].自动化学报,2007,33(3):297-301. 被引量:36
  • 4张方伟,曲淑英,王志强,姚炳学,曾现洋.偏差最小化方法及其在多属性决策中的应用[J].山东大学学报(理学版),2007,42(3):32-35. 被引量:7
  • 5GB/T 20984-2007.信息安全技术信息安全风险评估规范[S].中国国家质量监督检验检疫局,2007.
  • 6XU Zeshui. An automatic approach to reaching consensus in multiple attribute group decision making [ J ]. Computers & Indus- trial Engineering, 2009(05 ) : 1369-1374.
  • 7COOK W D. Distance-based and ad hoc consensus models in ordinal preference ranking[J].European Journal of Operational Research, 2006, 172(2) :369-385.
  • 8JACINTO G P, CARLOS R. Aggregation of partial ordinal rankings: an interval goal programming approach[ J]. Computers & Operations Research, 2001 (7) :827-834.
  • 9FAN ZhiPing, YUE Qi, FENG Bo. An approach to group decision-making with uncertain preference ordinals [ J ]. Computers & Industrial Engineering, 2010, (5) :51-57.
  • 10LO Chichun, CHEN Wanjia. A hybrid information security risk assessment procedure considering interdependenees between controls [J]. Expert Systems with Applications, 2012, 39(2012): 247-257.

共引文献111

同被引文献36

引证文献1

二级引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部