高级检索

    徐萃华, 林家骏, 张雪芹. 基于证据推理及评估用例的信息系统安全评估模型[J]. 华东理工大学学报(自然科学版), 2010, (6): 818-824.
    引用本文: 徐萃华, 林家骏, 张雪芹. 基于证据推理及评估用例的信息系统安全评估模型[J]. 华东理工大学学报(自然科学版), 2010, (6): 818-824.
    XU Cui-hua, LIN Jia-jun, ZHANG Xue-qin. An Information Security Evaluation Model Based on Evidence Reasoning Model and Evaluation Cases[J]. Journal of East China University of Science and Technology, 2010, (6): 818-824.
    Citation: XU Cui-hua, LIN Jia-jun, ZHANG Xue-qin. An Information Security Evaluation Model Based on Evidence Reasoning Model and Evaluation Cases[J]. Journal of East China University of Science and Technology, 2010, (6): 818-824.

    基于证据推理及评估用例的信息系统安全评估模型

    An Information Security Evaluation Model Based on Evidence Reasoning Model and Evaluation Cases

    • 摘要: 为了实现信息系统安全评估的规范准确,根据评估过程的实际需要,在《信息系统安全保障评估框架》标准基础上建立了证据推理模型,把系统的安全等级、评估规约、直接证据融合入模型之中。引入软件测试理论中测试用例的概念构造评估用例,定义了安全指标的3种类型,提出了基于这3种类型的评估规则,最后给出了模型的实现方式。从实例分析可以看出,该评估方法提高了评估工作的规范性,减少了人为因素对评估结果的影响。

       

      Abstract: In order to realize a standard and accurate security evaluation on the information system, this paper establishes an evaluation reasoning model based on information system security assurance evaluation framework. It integrates the security level, evaluation rule and evaluation evidence into the present model. The concept of testing cases in software testing theory is utilized to form the evaluation cases. Security indexes are discriminated into three different types, and evaluation regulations are presented for the three different types, respectively. Finally, the realization of this model is given. The analysis on the actual examples shows that the proposed model may improve the standard level of security evaluation and decrease the subjective affects of experts.

       

    /

    返回文章
    返回