首页 | 本学科首页   官方微博 | 高级检索  
     

一种基于风险传播的信息系统风险评估方法
引用本文:杨宏宇,张乐,张良.一种基于风险传播的信息系统风险评估方法[J].北京邮电大学学报,2021,44(4):41-48.
作者姓名:杨宏宇  张乐  张良
作者单位:1. 中国民航大学 安全科学与工程学院, 天津 300300;2. 中国民航大学 计算机科学与技术学院, 天津 300300;3. 亚利桑那大学 信息学院, 图森 AZ 85721
基金项目:国家自然科学基金民航联合研究基金项目(U1833107)
摘    要:传统信息系统的风险评估方法未考虑节点的状态变化和风险的传播方向,且评估结果的准确性受专家主观性的影响,对此,提出了一种基于风险传播的信息系统风险评估方法.首先,确定节点的初始状态转移概率矩阵,并根据攻击属性对矩阵进行修正,得到节点状态转移概率;其次,基于系统风险传播网络拓扑图和节点属性值计算节点在各方向的传播概率;然后,利用三参数区间数方法获取节点威胁事件的量化值;最后,根据风险评估方法计算各节点的风险值.实验结果表明,基于风险传播方法的评估流程更客观、合理,可提高信息系统风险评估的整体性和准确性.

关 键 词:风险评估  风险传播  状态转移概率  传播概率  三参数区间数  
收稿时间:2021-02-02

An Information System Risk Assessment Method Based on Risk Propagation
YANG Hong-yu,ZHANG Le,ZHANG Liang.An Information System Risk Assessment Method Based on Risk Propagation[J].Journal of Beijing University of Posts and Telecommunications,2021,44(4):41-48.
Authors:YANG Hong-yu  ZHANG Le  ZHANG Liang
Affiliation:1. College of Safety Science and Engineering, Civil Aviation University of China, Tianjin 300300, China;2. College of Computer Science and Technology, Civil Aviation University of China, Tianjin 300300, China;3. College of Information, University of Arizona, Tucson AZ 85721, USA
Abstract:Traditional information system risk assessment methods do not consider the state change of nodes and the direction of risk propagation, and the accuracy of the evaluation results is affected by the subjectivity of experts. To solve these problems, an information system risk assessment method based on risk propagation is proposed. First, the initial state transition probability matrix of the node is determined, and the node state transition probability is obtained by modifying the matrix according to the attack attributes. Then, the propagation probability of nodes in all directions is calculated based on the topology network and node attribute value.Next, the three-parameter interval number method is used to obtain the quantitative value of node threat events. Finally, the risk value of each node is calculated according to the risk assessment method. Experimental results show that the proposed methodis more objective and reasonable, and it improves the integrity and accuracy of the risk assessment of information systems.
Keywords:risk assessment  risk propagation  state transition probability  propagation probability  three-parameter interval number  
本文献已被 万方数据 等数据库收录!
点击此处可从《北京邮电大学学报》浏览原始摘要信息
点击此处可从《北京邮电大学学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号