摘要
介绍了一种对信息安全风险的数值分析方法,包括对资产价值的评估、对威胁和薄弱点评估以及最终的风险计算和函数拟合方法。通过这种方法,可以在传统方法的基础上,定量地计算出不同信息资产的风险程度,以供安全方案的设计和投资指导之用。
A method based on numerical analysis theory to asset risks of information security was introduced, involving information assessment, threads, vulnerabilities, risk calculation and function approximation. So by this approach, risks to different information assets could be calculated quantificationally on the base of traditional method. And security solution and investigation could be evaluated accurately.
出处
《计算机工程与设计》
CSCD
北大核心
2006年第3期404-406,410,共4页
Computer Engineering and Design
关键词
信息资产
风险评估
威胁
薄弱点
风险值
information assets
risk assessment
thread
vulnerability
vulnerability