节点文献

信息系统安全风险评估研究综述疆

Review on Study of Risk Evaluation for IT System Security

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 李鹤田刘云何德全

【Author】 LI He-Tian LIU Yun,Prof. HE De-quan,Academician (College of Electronics & Information Engineering, Beijing Jiaotong University, Beijing 100044,China)

【机构】 北京交通大学电子信息工程学院北京交通大学电子信息工程学院 北京100044北京100044教授北京100044院士

【摘要】 风险评估是信息系统安全保证的关键技术。笔者对国内外现有的信息安全风险评估方法与技术进行归纳和系统的评述。回顾了信息安全风险评估的理论框架与现有的评估标准;在此基础上,比较了包含FTA,FMECA,HAZOP等在内的传统风险评估技术和以CORAS为代表的现代风险评估技术;肯定了现代风险评估技术在利用统一建模语言进行半形式化表述方面的先进性以及根据信息系统生命周期的各个阶段特点选用适宜的风险评估方法的灵活性;同时指出该现代风险评估技术在动态识别、评估安全风险方面的不足;提出了一种改进和完善现代风险评估技术的方法,即利用Markov链形式化描述并分析信息系统,确保了分布式信息系统风险评估的需要。此外,针对信息安全风险的不确定性,提出了通过模糊集理论丰富现代风险评估方法的研究方向。

【Abstract】 Risk assessment as one of the core technologies ensures IT system security. The existing risk evaluation methods and technologies are systematically summarized. The theoretical framework and evaluation criteria for information security are reviewed first. Traditional technologies including FTA, FMECA and Hazop and modern technologies such as CORAS are compared in terms of their rationale and applicability. Modern risk assessment technologies are not efficient in identifying and evaluating dynamic risk in distributed networks whereas modern risk assessment technologies have strengths in semi-formally describing the behavior of IT system and the integrated risk analysis methods covering the whole lifecycle of IT system contrasting traditional technologies. Finally, the approach based on Markov chain to formally describing IT system and its behavior as well as the fuzzy-set based quantitative method is introduced to enhance and enrich modern risk assessment technologies for further research.

【基金】 国家“863”信息安全计划资助(2002AA144030)。
  • 【文献出处】 中国安全科学学报 ,China Safety Science Journal(CSSJ) , 编辑部邮箱 ,2006年01期
  • 【分类号】X913.2
  • 【被引频次】85
  • 【下载频次】1203
节点文献中: