首页> 外国专利> METHOD AND APPARATUS FOR SECURITY INVESTMENT BASED ON EVALUATING SECURITY RISKS

METHOD AND APPARATUS FOR SECURITY INVESTMENT BASED ON EVALUATING SECURITY RISKS

机译:评估安全风险的安全投资方法和装置

摘要

The present invention relates to a security investment method and apparatus, and more particularly, to a security investment method and apparatus based on security risk assessment in a cloud computing environment. According to the present invention, there is provided a security investment method based on security risk assessment, comprising the steps of: establishing one or more security threats that may occur in the cloud service and a vulnerability of each security threat according to a type of cloud service; Wherein the first and second security threats are hierarchically connected to the vulnerability points of the attack step, and when the vulnerabilities included in the first and second security threats are the same, the same vulnerability is unified into one vulnerability node, Generating an attack tree map by connecting a second security threat, matching a security control item for supplementing the vulnerability node with each of the vulnerability nodes of the attack tree map, using the child node structure and the correlation degree of the vulnerability node Calculating a vulnerability score of each of the vulnerability nodes, Summing the vulnerable score for each item, and by using this, and an aspect in that it comprises the step of quantitatively evaluating the security risk of the cloud service. According to the present invention, it is possible to perform a more accurate security evaluation by excluding a double evaluation of an overlapping attack by evaluating a security risk in consideration of an attack step of a security threat that may occur in a cloud environment.
机译:安全投资方法和装置技术领域本发明涉及一种安全投资方法和装置,尤其涉及一种基于云计算环境中的安全风险评估的安全投资方法和装置。根据本发明,提供了一种基于安全风险评估的安全投资方法,包括以下步骤:根据云的类型,确定可能在云服务中发生的一个或多个安全威胁以及每个安全威胁的脆弱性。服务;其中,第一安全威胁和第二安全威胁与攻击步骤的漏洞点层次连接,并且当第一安全威胁和第二安全威胁中包含的漏洞相同时,将同一漏洞统一到一个漏洞节点中,生成攻击树图通过连接第二个安全威胁,使用子节点结构和漏洞节点的相关程度,将用于对漏洞节点进行补充的安全控制项与攻击树图的每个漏洞节点进行匹配,计算每个漏洞的漏洞评分漏洞节点,总结每个项目的漏洞评分,并使用此方法,以及一方面,它包括定量评估云服务安全风险的步骤。根据本发明,通过考虑云环境中可能发生的安全威胁的攻击步骤,通过评估安全风险来排除重叠攻击的双重评估,从而可以执行更准确的安全评估。

著录项

  • 公开/公告号KR101985421B1

    专利类型

  • 公开/公告日2019-06-03

    原文格式PDF

  • 申请/专利权人 경희대학교 산학협력단;

    申请/专利号KR20180131734

  • 发明设计人 허의남;나상호;박준영;

    申请日2018-10-31

  • 分类号G06Q10/06;G06F21/57;G06Q10/04;

  • 国家 KR

  • 入库时间 2022-08-21 11:48:26

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号