作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (17): 197-199. doi: 10.3969/j.issn.1000-3428.2006.17.069

• 安全技术 • 上一篇    下一篇

融入木桶原理的综合评估

周 毅;张 竞;周 宁;陈晓桦   

  1. 上海交通大学信息安全工程学院,上海 200030
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2006-09-05 发布日期:2006-09-05

Synthetic Assessment with Cask Theory

ZHOU Yi;ZHANG Jing;ZHOU Ning;CHEN Xiaohua   

  1. School of Information Security Engineering, Shanghai Jiaotong University, Shanghai 200030
  • Received:1900-01-01 Revised:1900-01-01 Online:2006-09-05 Published:2006-09-05

摘要: 随着人们对信息系统安全的关注,各种评估方法开始逐渐应用于安全评估领域,其中也包括了“加权平均评估法”这一常见的综合评估算法。文章对该算法在信息安全评估领域的应用情况进行了深入研究,发现它难以体现信息安全领域普遍适用的“木桶原理”。因此,文章随后对该算法作了适当的改进,使之融入了木桶原理,从而使其更适用于对信息系统安全的评估。

关键词: 层次分析法(AHP), 安全评估, 加权平均, 木桶原理

Abstract: Along with the increasing attention to the security of information systems, various methods of assessment and evaluation, including the “weighted average assessment”, which is a common method of synthetic assessment, start to play role in the field of information security. This paper studies the application of the “weighted average assessment” within the field of information security assessment and finds out that it is not compatible with the “cask theory” which is universally obeyed in the field of information security. Therefore, this paper improves the “weighted average assessment” with cask theory, so as to make it agree more with the matter of fact and to fit better for the application.

Key words: Analytic hierarchy process(AHP), Security assessment, Weighted average, Cask theory