摘要
对信息系统安全域的划分做了阐述,利用威胁树模型对信息系统进行威胁分析,得到了信息系统可能遭受的威胁源和威胁方式,并将《信息系统安全等级保护测评准则》中的安全测评项利用威胁方式进行分类,得到了威胁型安全域的度量指标,最后结合实例验证表明:该方法在安全域划分上能得到满意的结果,具有较好的实用性.
This paper illustrates the division of an information system security domain, uses threat tree model to analyze the potential threat of an information system and obtains the source and mode of threat that may attack an information system. Also classifies the items in the Hierarchy Protection Standards for an Information System Security based on threat modes, and gets a magnanimity index system of the threat security domain. Finally, tests show that this method is satisfactory with the division of security doamin and possesses good practicality.
出处
《重庆工学院学报》
2007年第23期94-97,共4页
Journal of Chongqing Institute of Technology
关键词
等级保护
安全域
威胁树
hierarchy protection
security domain
threat tree