摘要
提出了基于资产关联拓扑结构的信息系统安全评估模型。以资产关联拓扑结构图为原型表示资产间的关联,量化计算判定各资产间关联以及关联性对整个信息系统风险的影响。该信息系统安全评估模型改进了传统的信息系统风险评估方法,添加资产关联性作为评估过程中的重要信息,实现了量化的信息安全评估。最后给出实例验证了模型对传统评估方法的改进。
This paper presents a new risk assessment model for measuring the security risk level of information systems. This model uses the topology structure of the correlations among system assets. It quantitatively computes the correlation extents and decides the influence of these correlations on the evaluated system. This risk assessment model improves the traditional security risk assessment model. By adding assets correlation as an important element to the process of risk assessment. It has achieved the quantitative risk assessment. Finally, an example of this risk assessment model is presented to show that this new model is better than the traditional ones.
出处
《华东理工大学学报(自然科学版)》
CAS
CSCD
北大核心
2009年第3期447-451,共5页
Journal of East China University of Science and Technology
关键词
风险评估
资产关联
拓扑结构
定量评估
攻击路线
risk assessment
assets' connections
topology structure
quantitative computation
attacking route