节点文献
安全漏洞等级划分关键技术研究
Research on key technology of vulnerability threat classification
【摘要】 针对安全漏洞管理过程中涉及到的威胁等级划分问题,选取了访问途径、利用复杂度和影响程度3组安全漏洞评估要素,采用层次分析法建立安全漏洞等级划分模型,将安全漏洞等级评定为超危、高危、中危和低危4个级别。最终为安全漏洞国家标准制定、安全漏洞管理、安全漏洞处理、风险评估、风险减缓等方面的工作提供参考。
【Abstract】 In order to solve the vulnerability assessment problem of vulnerability management,three attribute groups were selected to qualitatively evaluate vulnerability threat.After the selection of vulnerability attributes,analytic hierarchy process method was used to establish vulnerability classification model,which can divide vulnerabilities into four risk levels: critical,high,moderate and low.The method provides a reference for national standard,vulnerability management,vulnerability handling,risk assessment,risk mitigation,etc.
【关键词】 信息安全;
安全漏洞;
安全漏洞评估;
安全漏洞管理;
【Key words】 information security; vulnerability; vulnerability evaluation; vulnerability management;
【Key words】 information security; vulnerability; vulnerability evaluation; vulnerability management;
【基金】 中国博士后科学基金资助项目(2011M500416,2012T50152);中国科学院研究生院院长基金资助项目(Y25102HN00);国家自然科学基金资助项目(60970140)~~
- 【文献出处】 通信学报 ,Journal on Communications , 编辑部邮箱 ,2012年S1期
- 【分类号】TP393.08
- 【被引频次】62
- 【下载频次】774