首页 | 本学科首页   官方微博 | 高级检索  
     

基于标准化安全指标体系的云服务安全等级评估模型
引用本文:李想,杨瑞,陈兴蜀,刘垚磊,王启旭.基于标准化安全指标体系的云服务安全等级评估模型[J].四川大学学报(工程科学版),2020,52(3):159-167.
作者姓名:李想  杨瑞  陈兴蜀  刘垚磊  王启旭
作者单位:四川大学,四川大学,四川大学,四川大学,四川大学
基金项目:国家自然科学基金:61802270面向大数据平台的服务认证协议的可证明安全及效率优化研究;,国家自然科学基金;,高校基金:SCU2018D018;,高校基金:SCU2018D022
摘    要:针对传统云服务安全评估方法中存在的评估指标粒度粗且难以量化以及评估方法主观依赖度高且效率低等问题,提出了一种基于标准化安全指标体系的云服务安全等级评估模型。首先,依据评估指标体系设计原则,以我国云计算服务安全能力要求标准为基础,借鉴国外机构有关云服务的安全控制框架及服务水平协议标准,提出了一种细粒度及可量化的标准化安全指标体系构建方法;然后,基于此指标体系提出了云服务安全等级评估模型,该模型在评估云服务的安全等级时,考虑到安全指标体系中指标类型的差异化及其属性对云服务安全性的影响,设计了一种基于客观指标权重分配的安全等级评估方法,对评估对象的安全等级进行量化评估;最后,分别通过应用案例和性能分析实验,验证了本文所提出的评估模型的有效性以及评估方法的效率。实验结果表明,本文提出的基于标准化安全指标体系的云服务安全等级评估模型不仅能有效、准确地评估不同云服务商的安全能力,而且其安全等级评估方法在性能方面优于传统的基于层次分析法的云服务安全评估方法。

关 键 词:云服务  安全指标体系  安全等级评估  客观权重分配  逼近理想解排序法
收稿时间:2019/5/8 0:00:00
修稿时间:2020/4/13 0:00:00

Assessment Model of Cloud Service Security Level Based on Standardized Security Metric Hierarchy
LI Xiang,YANG Rui,CHEN Xingshu,LIU Yaolei,WANG Qixu.Assessment Model of Cloud Service Security Level Based on Standardized Security Metric Hierarchy[J].Journal of Sichuan University (Engineering Science Edition),2020,52(3):159-167.
Authors:LI Xiang  YANG Rui  CHEN Xingshu  LIU Yaolei  WANG Qixu
Affiliation:College of Computer Sci., Sichuan Univ., Chengdu 610065, China;Cybersecurity Research Inst., Sichuan Univ., Chengdu 610065, China;College of Cybersecurity, Sichuan Univ., Chengdu 610065, China
Abstract:In order to cope with the issues existing in the traditional literature that assessment metrics were coarse-grained and nonquantitative as well as assessment methods were subjective and low efficiency, a could service security level assessment model based on the standardized security metric hierarchy was proposed. First, a fine-grained, quantifiable and standardized cloud service security metric hierarchy was structured according to the principle of evaluation metric system. The content of cloud service security metric hierarchy was composed of both domestic and foreign standards related to the cloud service security. Second, a cloud service security level evaluation model is proposed based on the metric hierarchy. considering the difference of metrics'' type and attributes impacting on the security features of cloud services, the proposed model designs a security level assessment method based on objective weights assignment of the metrics for evaluating the security level of cloud services. Finally, a case study and a performance comparison experiment were respectively conducted to validate effectiveness of the proposed assessment model and efficiency of its evaluation method. Experimental results show that the proposed assessment method was not only efficient and accurate in the cloud service security level assessment, but its evaluation method outperformed the traditional cloud service security assessment methods.
Keywords:cloud service  security metric hierarchy  security level assessment  objective weight assignment  TOPSIS
点击此处可从《四川大学学报(工程科学版)》浏览原始摘要信息
点击此处可从《四川大学学报(工程科学版)》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号