首页> 外国专利> METHOD AND APPARATUS FOR SECURITY INVESTMENT BASED ON EVALUATING SECURITY RISKS

METHOD AND APPARATUS FOR SECURITY INVESTMENT BASED ON EVALUATING SECURITY RISKS

机译:评估安全风险的安全投资方法和装置

摘要

The present invention relates to a security investment method and apparatus and, more specifically, to a security investment method and apparatus based on a security risk evaluation in a cloud computing environment. The security investment method based on security risk evaluation comprises the steps of: setting a vulnerability for each security threat and at least one security threat which can be generated in the cloud service according to a cloud service type; generating an attack tree map by singulating a vulnerability overlapping one or more entire security threats into one node; matching a security control item for supplementing a relevant vulnerability to each vulnerability node of the attack tree map; calculating a vulnerability score of each vulnerability node by using the child node structure and correlation of the vulnerability node; and adding the vulnerability score for each security control item and quantitatively evaluating the security risk of the cloud service by using the same. According to the present invention, a security risk can be evaluated by considering an attack step of a security threat which may occur in a cloud environment, and thus a more accurate security assessment can be performed by excluding a duplicate evaluation for a duplicated attack.
机译:安全投资方法和装置技术领域本发明涉及安全投资方法和装置,更具体地,涉及基于云计算环境中的安全风险评估的安全投资方法和装置。基于安全风险评估的安全投资方法,包括以下步骤:为每个安全威胁设置漏洞,并根据云服务类型为云服务中可以生成的至少一个安全威胁设置漏洞;通过将一个或多个整个安全威胁重叠在一个节点中的漏洞来生成攻击树图;使安全控制项与攻击树图的每个漏洞节点相匹配,以补充相关漏洞;通过使用子节点结构和漏洞节点的相关性,计算每个漏洞节点的漏洞分数;并为每个安全控制项添加漏洞评分,并通过使用该漏洞分数来定量评估云服务的安全风险。根据本发明,可以通过考虑可能在云环境中发生的安全威胁的攻击步骤来评估安全风险,因此可以通过排除针对重复攻击的重复评估来执行更准确的安全评估。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号