节点文献

网络安全评估模型研究

【作者】 张强

【导师】 王华; 王英龙;

【作者基本信息】 山东大学 , 计算机技术, 2006, 硕士

【摘要】 网络安全评估模型研究是本着以实现系统安全为目的,按照科学的程序和方法,对系统中危险要素进行充分的定性、定量分析,并做出综合评价。安全需求正经历着从信息安全到信息保障的转变。传统的被动防护已不能适应当前的安全形势,主动性网络安全检测评估理论应运而生。 本文论述了计算机网络安全现状、评价现状,以及网络信息安全评估标准,包括美国可信计算机安全评价标准(TCSEC),欧洲的安全评价标准(TSEC)国际通用准则(CC),我国计算机信息系统安全保护等级划分准则(GB 17859-1999)。结合网络评价定性的、不确定性的因素较多的特征,本课题着重介绍了模糊综合建模的方法,应用系统工程的理论和方法识别、分析和评价网络信息安全固有或潜在风险发生的可能性和危险因素,论述了网络模糊综合安全风险的评价步骤与过程,建立基于硬件、软件及外部环境的计算机网络信息安全综合评价指标体系。建立了实体与环境安全,组织管理与安全制度,安全技术措施,网络通信安全,软件与信息安全五个一级指标,对应每个一级指标建立了二级指标。分析了指标。体系权重的建立原则以及权重的归一化处理方法。通过单因素模糊评价,给出了多级模糊综合评价模型。结合工程实例给出了使用评价模型进行网络安全评价的步骤,评价结果与实际基本相符。

【Abstract】 The paper, which aims at systematic security in the real world。 According to scientific procedure and method, it carries on abundant qualitative analysis and quantitative analysis to the dangerous key element in the system, and makes effective safety measure。 Requirement for Security is changing from information security to information assurance。 Traditional passive protection can’t adapt to this new situation, then enhanced defense and proactive defense are proposed。This paper described the current situation of network security, the current situation of network evaluation and the evaluation standard of the security of network information。 Including TCSEC (Trusted Computer System Evaluation Criteria; commonly called the "Orange Book"), which is a standard for computer security issued by the US government; ITSEC (the Information Technology Security Evaluation Criteria), which is a standard for computer security that was issued by the Europe, CC (Common Criterion), which is a world standard for computer security; GB 17859-1999 , which classified criteria for security protection of Computer information system in China。 Many qualitative and uncertain factors of network evaluation considered , this paper introduces emphatically about Fuzzy Synthesis Evaluation Modeling Method of network。 How to discern, analyze and appraise by using of theory and method of system engineering the possibility happening about inherent or potential risk of network information security and the dangerous factor。 The evaluation step about network synthesis security risk has been described。 Based on hardware and software and external environment condition, synthesis Evaluation Index system can be established。 Set up five first level indexes, such as the entity and environment security of the network, the organization and management system , safe practice measure , communication security of the network。 Corresponding to each first level

  • 【网络出版投稿人】 山东大学
  • 【网络出版年期】2006年 12期
  • 【分类号】TP393.08
  • 【被引频次】8
  • 【下载频次】1045
节点文献中: 

本文链接的文献网络图示:

本文的引文网络