期刊文献+

一种面向敏感信息处理的敏感度度量方法 被引量:4

A Sensitivity Measurement for Sensitive Information Processing
下载PDF
导出
摘要 应用软件一般需要输入和处理敏感信息,如密码,以实现用户和远程服务器之间的可靠认证和安全交互.定量度量敏感信息在敏感信息处理中的安全性是目前研究的难点.根据敏感信息处理的流程和敏感信息出现点的上下文,定义敏感信息处理的固有属性、可变属性和推求属性,设计了从固有属性和可变属性到数据操作的映射规则,提出了基于层次分析法(analytic hierarchy process,AHP)及折中型多属性决策(technique for order preference by similarity to an ideal solution,TOPSIS)的敏感度计算方法,从而实现敏感度的定量计算,展示在敏感信息处理中敏感度的动态变化规律,为敏感信息处理的安全防护提供支持.该方法可以应用于可信软件的安全分析和可信度量,最后,实验分析了3种敏感信息在处理中的敏感度变化,发现了敏感信息处理的潜在危险点,从而证实了该方法的有效性. Application software needs to use sensitive information to build up the authentication between client and server, so how to measure the security or sensitivity of sensitive information during /.. processing is an open issue. According to the procedure of sensmve information processing and context of its occurrence, inherent property, variable property and inferenced property have been defined, the mapping rules from these properties to data operations have been designed, and a method of sensitivity calculation based on AHP (analytic hierarchy process) and TOPSIS (technique for order preference by similarity to an ideal solution) has been proposed. This method can demonstrate dynamic changes of sensitivities among sensitive information processing to support security prevention against information leakage and attacks, and can be applied to security analysis and trust measure of trustworthy software on sensitive information. Finally, experimental results demonstrate that this method can describe sensitivity changes among sensitive information processing, and discover the potentially dangerous points in this processing, so its effectivity has been verified.
出处 《计算机研究与发展》 EI CSCD 北大核心 2014年第5期1050-1060,共11页 Journal of Computer Research and Development
基金 国家科技重大专项基金项目(2010ZX03006-001-01) 国家自然科学基金项目(61202387,90718005,61272451) 高等学校博士学科点专项科研基金项目(20120141110002)
关键词 可信软件 可信度量 敏感信息 敏感度 折中型决策方法 trustworthy software trust measure sensitive information sensitivity technique fororder preference by similarity to an ideal solution (TOPSIS)
  • 相关文献

参考文献27

  • 1Matt W, Sudhir A, Michael C, et al. Testing metrics forpassword creation policies by attacking large sets of revealedpasswords [C]//Proc of the 17thACM Conf on Computerand Communications Security.New York: ACM, 2010 : 162-175. 被引量:1
  • 2Zhang Yinqiang,Fabian M,Michael K,et al. The securityof modern password expiration: An algorithmic frameworkand empirical analysis [C]//Proc of the17th ACM Conf onComputer andCommunications Security. New York: ACM,2010: 176-186. 被引量:1
  • 3Garfinkel T, Pfaff B, Chow J,et al. Data life time is asystems problem [C]//Proc of the 11th Workshop on ACMSIGOPS European Workshop. New York: ACM, 2004 : 64-75. 被引量:1
  • 4Microsoft. MSDN: About keyboard input [EB/OL]. [2013-02-17]. http://msdn. microsoft. com/en-us/library/ms646267CVS. 85). aspx. 被引量:1
  • 5Garfinkel T, Pfaff B, Chow J, et al. Understanding datalifetime via whole system simulation [C]//Proc of the 13thUSENIX Security Symp. New York: ACM, 2004 : 87-96. 被引量:1
  • 6David Z,Jaeyeon J, Dawn S,et al. TaintEraser: Protectingsensitive data leaks using application-level taint tracking [J],ACM SIGOPS OperationSystems Review, 2011,45(1):142-154. 被引量:1
  • 7Zhao Q. Cao T. Collecting sensitive information fromwindows physical memory [J]. Journal of ComputersJanuary, 2009, 4(1) : 3-10. 被引量:1
  • 8Wang Xiaofeng, Li Zhuowei, Li Ninghui, et al. PRECIP:Practical and retrofittable confidential information protectionagainst spyware surveillance [C]//Proc of the 15th NetworkDistributed System Security Symp. New York: ACM,2008: 45-57. 被引量:1
  • 9Shi Weidong, Joshua B,Gu Guofei,et al. InfoShield: Asecurity architecture for protecting information usage inmemory [C]//Proc of the 12th Int SymponHigh-Performance Computer Architecture. Piscataway, NJ:IEEE, 2006: 128-141. 被引量:1
  • 10Jim C,Ben P,Tai G,et al. Shredding your garbage:Reducing data lifetime through secure deallocation [C]//Procof the 14th USENIX Security Symp. New York: ACM,2005: 104-118. 被引量:1

二级参考文献68

共引文献117

同被引文献48

引证文献4

二级引证文献29

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部