详细信息

基于证据推理及评估用例的信息系统安全评估模型    

An Information Security Evaluation Model Based on Evidence Reasoning Model and Evaluation Cases

文献类型:期刊文献

中文题名:基于证据推理及评估用例的信息系统安全评估模型

英文题名:An Information Security Evaluation Model Based on Evidence Reasoning Model and Evaluation Cases

作者:徐萃华[1];林家骏[1];张雪芹[1]

机构:[1]华东理工大学信息科学与工程学院,上海200237

年份:2010

卷号:36

期号:6

起止页码:818

中文期刊名:华东理工大学学报(自然科学版)

外文期刊名:Journal of East China University of Science and Technology

收录:CSTPCD;;Scopus;北大核心:【北大核心2008】;CSCD:【CSCD2011_2012】;

语种:中文

中文关键词:证据推理;安全等级;评估规约;评估用例;安全指标

外文关键词:evidence reasoning; security level; evaluation rule; evaluation case; security index

摘要:为了实现信息系统安全评估的规范准确,根据评估过程的实际需要,在《信息系统安全保障评估框架》标准基础上建立了证据推理模型,把系统的安全等级、评估规约、直接证据融合入模型之中。引入软件测试理论中测试用例的概念构造评估用例,定义了安全指标的3种类型,提出了基于这3种类型的评估规则,最后给出了模型的实现方式。从实例分析可以看出,该评估方法提高了评估工作的规范性,减少了人为因素对评估结果的影响。
In order to realize a standard and accurate security evaluation on the information system,this paper establishes an evaluation reasoning model based on information system security assurance evaluation framework.It integrates the security level,evaluation rule and evaluation evidence into the present model.The concept of testing cases in software testing theory is utilized to form the evaluation cases.Security indexes are discriminated into three different types,and evaluation regulations are presented for the three different types,respectively.Finally,the realization of this model is given.The analysis on the actual examples shows that the proposed model may improve the standard level of security evaluation and decrease the subjective affects of experts.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心