中国科学技术大学学报 ›› 2012, Vol. 42 ›› Issue (1): 67-76.DOI: 10.3969/j.issn.0253-2778.2012.01.011

• 原创论文 • 上一篇    下一篇

一个多维信息安全指标体系及等级保护量化模型

周焕盛   

  1. 1.同济大学计算机科学与技术系,上海 201804;2.同济大学软件学院,上海 201804
  • 收稿日期:2011-04-28 修回日期:2011-07-01 出版日期:2012-01-31 发布日期:2012-01-31
  • 通讯作者: 江建慧
  • 作者简介:周焕盛,男,1985年生,硕士. 研究方向:信息安全. E-mail: zhoudaxia@gmail.com
  • 基金资助:
    上海申通地铁集团公司科研项目“轨道交通网络信息化规划与应用研究”资助.

A multidimensional security index system and quantitative level protection model

ZHOU Huansheng   

  1. 1.Department of Computer Science and Technology, Tongji University, Shanghai 201804, China; 2.School of Software Engineering, Tongji University, Shanghai 201804, China
  • Received:2011-04-28 Revised:2011-07-01 Online:2012-01-31 Published:2012-01-31

摘要: 把信息安全性能度量和信息安全等级分配结合起来,建立了一个多维信息安全指标体系,提出了一个基于安全指数的信息安全等级保护量化模型.用层次化的基于评分的方法来对系统的信息安全性进行评估,安全等级分配问题则被抽象成一类线性规划问题.与使用传统方法的模型相比,该模型具有易于量化、可操作性强等特性.通过举例说明了模型的实际应用.

关键词: 信息安全指标体系, 信息安全等级保护, 安全等级分配, 安全指数, 代价函数

Abstract: A multidimensional security index system was established by integrating information security measurements and allocation of information security levels. A quantitative level protection model based on security index was proposed. The security index of a system was evaluated by using a hierarchical method based on grading. The problem of security level allocation was abstracted as a kind of linear programming problem. Compared to models using conventional methods, the proposed model is more quantifiable and operable. The application of the model was illustrated with an example of a real information system.

Key words: information security index system, information security level protection, allocation of security level, security index, cost function