作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2007, Vol. 33 ›› Issue (16): 133-135,. doi: 10.3969/j.issn.1000-3428.2007.16.046

• 安全技术 • 上一篇    下一篇

网络安全评估方法的研究与实践

刘宝旭1,王晓箴1,2,池亚平3   

  1. (1. 中国科学院高能物理研究所计算中心,北京 100049;2. 中国科学院研究生院,北京 100049;3. 北京电子科技学院通信工程系,北京 100070)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2007-08-20 发布日期:2007-08-20

Research and Practice on Network Security Evaluation Method

LIU Bao-xu1, WANG Xiao-zhen1,2, CHI Ya-ping3   

  1. (1. Computering Center, Institute of High Energy Physics, Chinese Academy of Sciences, Beijing 100049; 2. Graduate School, Chinese Academy of Sciences, Beijing 100049; 3. Communication Engineering Department, Beijing Electronic Science and Technology Institute, Beijing 100070)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-08-20 Published:2007-08-20

摘要: 网络安全评估技术和方法的研究对网络安全防护体系的建设具有重要意义。该文结合实际工作经验和研究成果,在分析安全评估技术发展现状的基础上,提出了一种定性分析与定量计算相结合的风险评估模型,给出了具体算法及基于该算法的风险评估流程,并加以实际应用。实践结果证明,应用该算法和模型实施的风险评估对被评估单位的网络安全防护和管理工作起到了良好的指导作用。

关键词: 信息安全, 评估, 模型, 算法

Abstract: Network security evaluation technologies and methods are important to the network security protection system. Combined with the actual experience and research results and based on the analysis of the present status about security evaluation technologies, this paper puts forward and describes an efficient model and algorithm with qualitative analysis and the quantify calculate, and gives a risk evaluation flow based on the algorithm. The model is applied in security evaluation work and the practice result proves that the model and algorithm do a good directive function in network security protection and management.

Key words: information security, evaluation, model, algorithm

中图分类号: