作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (1): 40-42.

• 博士论文 • 上一篇    下一篇

基于 PRA 的网络安全风险评估模型

王英梅 1,刘增良2   

  1. 1. 北京科技大学信息工程学院信息安全实验室,北京 100083;2. 国防大学信息安全实验室,北京 100011
  • 出版日期:2006-01-05 发布日期:2006-01-05

A Risk Assessment Model for Network Security Based on PRA

WANG Yingmei1, LIU Zengliang 2   

  1. 1. Lab of Information Security, College of Information Engineering, Beijing University of Science and Technology, Beijing 100083;2. Information Security Laboratory of National Defense Academy, Beijing 100011
  • Online:2006-01-05 Published:2006-01-05

摘要: 概率风险分析被广泛应用于社会各领域,如交通、能源、化工处理、航天、军事等。文章采用概率风险分析的方法,对网络的逻辑构成、网络攻击和攻击结果进行分析,通过故障树描述了网络系统被攻击的原因与途径,并建立了风险评估模型。

关键词: 概率风险分析;网络安全;风险评估;漏洞;威胁

Abstract: Probabilistic risk analysis (PRA) is currently being widely applied to many sectors, including transport, energy, chemical processing, aerospace, and military. A method of PRA is used to analyze the fundamental reasons why network systems are vulnerable to attacks. After making a study on network composition and different types of system vulnerabilities, a model of information security risk assessment is proposed.

Key words: Probabilistic risk analysis (PRA); Network security; Risk assessment; Vulnerability; Threat