首页> 外国专利> METHOD AND APPARATUS FOR SECURITY INVESTMENT BASED ON EVALUATING SECURITY RISKS

METHOD AND APPARATUS FOR SECURITY INVESTMENT BASED ON EVALUATING SECURITY RISKS

机译:评估安全风险的安全投资方法和装置

摘要

The present invention relates to a security investment method and an apparatus thereof and, more specifically, to a security investment method based on a security risk evaluation in a cloud computing environment and an apparatus thereof. The security investment method based on a security risk evaluation comprises the steps of: setting a vulnerability for each security threat and at least one security threat which may occur in a cloud service according to the type of the cloud service; hierarchically connecting a vulnerability for each detailed attack step constituting one security threat, simplifying the same vulnerability as one vulnerability node if vulnerabilities included in a first security threat and a second security threat are identical, and generating an attack tree map by connecting the first security threat and the second security threat to a unified vulnerability node; matching a security control item for supplementing a corresponding vulnerability to each vulnerability node of the attack tree map; calculating a weak score of each vulnerability node by using a child node structure and correlation of the vulnerability node; and doing the sum of the weak score for each security control item and quantitatively evaluating a security risk of the cloud service by using the same. According to the present invention, a security risk is evaluated by considering an attack step of a security threat which may occur in a cloud environment, and thus a more accurate security evaluation can be performed by excluding a duplicate evaluation for a duplicated attack.
机译:安全投资方法及其设备技术领域本发明涉及一种安全投资方法及其设备,更具体地,涉及基于云计算环境中的安全风险评估的安全投资方法及其设备。基于安全风险评估的安全投资方法,包括以下步骤:根据云服务的类型,为每种安全威胁以及云服务中可能发生的至少一种安全威胁设置一个漏洞。针对构成一个安全威胁的每个详细攻击步骤,对漏洞进行分层连接;如果第一安全威胁和第二安全威胁中包含的漏洞相同,则简化与一个漏洞节点相同的漏洞,并通过连接第一安全威胁来生成攻击树图对统一漏洞节点的第二个安全威胁;使安全控制项与攻击树图的每个漏洞节点相匹配,以补充相应的漏洞;通过使用子节点结构和该漏洞节点的相关性来计算每个漏洞节点的弱得分;并对每个安全控制项的弱得分进行求和,并通过使用其对云服务的安全风险进行定量评估。根据本发明,通过考虑可能在云环境中发生的安全威胁的攻击步骤来评估安全风险,因此可以通过排除针对重复攻击的重复评估来执行更准确的安全评估。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号