首页> 外文会议>2015 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery >A Hierarchical Framework of Security Situation Assessment for Information System
【24h】

A Hierarchical Framework of Security Situation Assessment for Information System

机译:信息系统安全态势评估的层次框架

获取原文

摘要

Security situation assessment is an effective way to analyze the situation of an information system, which helps administrator understand the current system risk status and make policy to response in time. However, the existing researches for security situation assessment mostly focus on network. The proposed methods for network are not so suitable for information systems. This paper proposes a hierarchical security situation analysis framework for information system, based on a classical NSSA [1] (network security situation analysis) model. The framework provides a standard flow for analyzing the security situation of information system. It consists a security situation analysis model of information system, an index system used in the model proposed, and a quantitative index fusion method to calculate a security situational value. We divided information system into 3 levels: sub-system level, composition level and index level. The collected information from the index level can be combined with grey model to determine the correlation degree between each major index and secondary index. Finally we calculate the whole system security situational value level by level. We use data from Tsinghua University information system to verify the proposed model and method. The result shows that this model can reflect the current security situation of information system comprehensively.
机译:安全状况评估是分析信息系统状况的有效方法,可帮助管理员了解当前系统的风险状况并制定及时响应的策略。但是,现有的安全态势评估研究主要集中在网络上。所提出的网络方法不太适合信息系统。本文提出了一种基于经典NSSA [1](网络安全状况分析)模型的信息系统分层安全状况分析框架。该框架提供了用于分析信息系统安全状况的标准流程。它由信息系统的安全态势分析模型,模型中使用的索引系统和计算安全态势值的定量索引融合方法组成。我们将信息系统分为3个级别:子系统级别,组合级别和索引级别。从索引级别收集的信息可以与灰色模型组合,以确定每个主要指标和二级指标之间的相关程度。最后,我们逐级计算出整个系统的安全态势值。我们使用来自清华大学信息系统的数据来验证所提出的模型和方法。结果表明,该模型可以全面反映当前信息系统的安全状况。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号