摘要
以防火墙和IDS技术组合为例,利用博弈论研究了信息系统安全等级对该安全技术组合与配置策略的影响,发现安全等级越高对黑客威慑越大,从而可降低黑客入侵率.单一地提高其中一种技术配置并不一定能提高安全等级,只有在两种技术配置相协调时才能提高安全等级,说明安全等级越高对安全技术组合与配置的要求越高.研究还对比了未考虑安全等级和考虑安全等级的均衡策略,认为未考虑安全等级的均衡策略只是考虑安全等级时的一个边界,且这个边界特例在现实中通常无法或无需达到.
The influence of security rank on the technology portfolio and configurations of firewall and IDS was researched through game theory by this paper. It shows that the higher the security rank the bigger deterrence to hackers whose intrusion probability would be decreased. The security rank is not always improved when only one of the technology configurations is improved, and it is improved when both of the two technology configurations are coordinated with each other, which illustrates that the higher the security rank the higher requirement of security technology portfolio and configuration. The equilibrium strategy is also compared to the one without considering security rank, and the latter is an extremity of the former, which could not be reached or with no need to get.
出处
《系统工程理论与实践》
EI
CSSCI
CSCD
北大核心
2016年第5期1231-1238,共8页
Systems Engineering-Theory & Practice
基金
国家自然科学基金(71071033)~~
关键词
信息系统安全
安全等级
技术组合
技术配置
博弈
information system security
security rank
technology portfolio
technology configuration
game theory