作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2011, Vol. 37 ›› Issue (9): 57-58,61. doi: 10.3969/j.issn.1000-3428.2011.09.019

所属专题: “核高基”专题

• “核高基”专题 • 上一篇    下一篇

一种安全操作系统风险评估模型

邓 平1,范科峰2,张素兵2,莫 玮2   

  1. (1. 桂林电子科技大学电子工程与自动化学院,广西 桂林 541004;2. 中国电子技术标准化研究所,北京 100007)
  • 出版日期:2011-05-05 发布日期:2011-05-12
  • 作者简介:邓 平(1984-),男,硕士,主研方向:嵌入式操作系统;范科峰、张素兵,博士;莫 玮,教授、博士生导师
  • 基金资助:
    “核高基”重大专项(2009ZX01039-003-001-04);国家自然科学基金资助项目(61001178);中国博士后科学基金资助项目(20080440333, 200902073);北京自然科学基金资助项目(4102012);广西壮族自治区研究生创新基金资助项目

Risk Assessment Model of Security Operating System

DENG Ping  1, FAN Ke-feng  2, ZHANG Su-bing  2, MO Wei  2   

  1. (1. School of Electronic Engineering and Automation, Guilin University of Electronic Technology, Guilin 541004, China; 2. China Electronics Standardization Institute, Beijing 100007, China)
  • Online:2011-05-05 Published:2011-05-12

摘要: 针对安全操作系统风险管理难以进行定量评判的问题,提出一种适用于安全操作系统风险等级定量评估的模型。通过引入风险矩阵法,将信息安全风险评估归纳为以专家矩阵、Borda法则和层次分析法为评估流程的风险等级评估模型,实现安全操作系统风险等级的定量评估,增强评估操作系统风险等级的客观性。通过实例应用对评估模型进行验证,结果表明该模型能有效评估出安全操作系统的风险等级。

关键词: 安全操作系统, 风险评估, Borda法则, 层次分析法

Abstract: Aiming at the problem of security operating system risk management is difficult to evaluate quantitatively, this paper puts forward a suitable operating system security risk grade quantitatively evaluation model. Through introducing the risk matrix method, putting the information safety risk assessment as the risk evaluation model by experts matrix, Borda rule and Analytic Hierarchy Process(AHP) assess the risk assessment process, and achieve safe operation system risk management quantitative evaluation, enhance the objectivity of the operating system risk rank quantitative evaluation. In conclusion, the application evaluation model is validated through the examples, and the results show that the model can effectively assess the operating system security risk levels.

Key words: security operating system, risk assessment, Borda rule, Analytic Hierarchy Process(AHP)

中图分类号: