摘要
针对复杂信息系统复杂程度高、互影响性与互依赖性强,现有风险评估方法难以适应大规模网络安全风险评估与应用实践的需要的问题,研究了基于GTST-MLD的适合复杂信息系统的风险要素分析方法和整体风险评估方法,包括研究事故互依赖关系模型,进行风险要素建模以及风险传导分析,以提高针对复杂信息系统的风险评估能力和分析水平。结果证明,模型对复杂信息系统安全特性的目标、功能、结构、行为等因素予以综合,实现在更高的系统功能层面上对系统安全性的分析研究,为复杂信息系统的量化风险评估提供了可靠的量化分析手段。
Aiming at the broblems that complex information systems have the high complexity,mutual influence and in- terdependence,and the existing risk assessment methods are difficult to adapt to large-scale network security risk as- sessment and application needs of practice, we researched risk factor analysis method and the overall risk assessment methods of complex information system based on GTST-MLD, including the study of complex systems model of acci- dents interdependencies, risk factors model and risk conduction analysis, which improves risk assessment capabilities and level of analysis for complex information system. The results prove that the model consolidates the security features of complex in^ormation system, such as objectives, functions, structure, behavior and so on, achieves security analysis at a higher level system functions, and provides a reliable means of quantitative analysis for complex information system risk assessment.
出处
《计算机科学》
CSCD
北大核心
2014年第7期194-199,共6页
Computer Science
基金
国家科技支撑计划项目(2012BAH14B02)
国家发改委信息安全专项项目(发改办高技[2012]1424号)资助
关键词
复杂网络
信息安全
风险评估
依赖关系
风险传导
Complex network, Information security, Risk assessment, Interdependencies, Risk conduction