作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2009, Vol. 35 ›› Issue (15): 156-158. doi: 10.3969/j.issn.1000-3428.2009.15.054

• 安全技术 • 上一篇    下一篇

基于FAHP的信息安全风险评估方法

秦大力1,3,张 利2,李吉慧2   

  1. (1. 湖南大学机械与汽车工程学院,长沙 410082;2. 中国信息安全产品测评认证中心系统隐患研究实验室,北京 100089; 3. 湖南农业大学信息科学技术学院,长沙 410128)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2009-08-05 发布日期:2009-08-05

Risk Assessment Approach for Information Security Based on FAHP

QIN Da-li1,3, ZHANG Li2, LI Ji-hui2   

  1. (1. College of Mechanical and Auto Engineering, Hunan University, Changsha 410082; 2. Research Office of System Hidden Fault, China Information Technology Security Evaluation Center, Beijing 100089; 3. College of Information Science and Technology, Hunan Agricultural University, Changsha 410128)
  • Received:1900-01-01 Revised:1900-01-01 Online:2009-08-05 Published:2009-08-05

摘要: 提出基于模糊层次分析法的信息安全风险综合评估模型,从主观评测和工具检测两方面对各个风险因素分别评价其重要程度。利用模糊偏好法求出各个风险因素在系统风险评估中的优先级排序,给出目标系统在不同安全侧面上的量化风险,增强评估准确性。实例分析表明,该模型可方便地应用于信息安全风险评估,具有实用性。

关键词: 风险评估, 模糊层次分析法, 信息安全

Abstract: A model of risk assessment based on Fuzzy-AHP(FAHP) is introduced to the estimation of the information security. The important degree of each risk factor is judged in the aspects of the subjective assessment and tools inspection. By utilizing fuzzy preference programming method, the risk value of each factor is calculated. Next the quantitative risk degree of the target system is calculated, and the veracity of risk assessment is improved. The study case of the assets value shows that the model can be easily used to the risk assessment of the information security, and the results are in accord with the reality.

Key words: risk assessment, Fuzzy-AHP(FAHP), information security

中图分类号: