电子科技 ›› 2024, Vol. 37 ›› Issue (3): 10-17.doi: 10.16180/j.cnki.issn1007-7820.2024.03.002

• • 上一篇    下一篇

网络安全风险评估方法研究综述

吴嘉诚1, 余晓2   

  1. 1.东南大学 网络空间安全学院,江苏 南京 210096
    2.东南大学 继续教育学院,江苏 南京 210096
  • 收稿日期:2022-10-09 出版日期:2024-03-15 发布日期:2024-03-11
  • 作者简介:吴嘉诚(1998-),男,硕士研究生。研究方向:计算机网络安全。
    余晓(1973-),女,讲师。研究方向:网络管理、云计算、网络安全。
  • 基金资助:
    中国高校产学研创新基金(2020ITA07007)

A Review of Research on Cybersecurity Risk Assessment Methods

WU Jiacheng1, YU Xiao2   

  1. 1. School of Cyber Science and Engineering,Southeast University,Nanjing 210096,China
    2. School of Continuing Education,Southeast University,Nanjing 210096,China
  • Received:2022-10-09 Online:2024-03-15 Published:2024-03-11
  • Supported by:
    China University Industry-University-Research Innovation Fund(2020ITA07007)

摘要:

网络安全风险评估是构建网络空间安全体系的重要环节,可以有效保护个人和组织机构避免受到网络安全攻击。文中简要概述了网络安全风险评估理论,重点介绍了目前主流的网络安全风险评估方法,并根据不同的方法性质对现有方法进行分类和对比,分析了各方法的优缺点以及适用范围。在此基础上,文中归纳提取出对网络安全评估结果产生影响的因素并对网络安全评估领域未来的研究重点进行提议。分析结果表明,关联性和评估指标的不确定性以及评估过程的实时性这3个因素是影响风险评估效果的主要因素,并给未来的风险评估方法研究提供了参考依据。

关键词: 风险评估, 定性分析, 定量分析, 指标体系, 评估模型, 关联性, 实时性, 不确定性

Abstract:

Cybersecurity risk assessment is an important part of building a cyberspace security system, which can effectively protect individuals and organizations from the risk of cybersecurity attacks.This study briefly outlines the theory of cybersecurity risk assessment, emphatically introduces the current mainstream cybersecurity risk assessment methods, and classifies and compares the existing methods according to their different nature, analyzes the advantages, disadvantages and application scope of each method.On this basis, this study summarizes and extracts the factors that have an impact on the cybersecurity assessment results and proposes future research priorities in the field of cybersecurity assessment. The analysis results show that the three factors of correlation, uncertainty of assessment indexes and real-time of assessment process are the main factors affecting the effect of risk assessment, and it provides a reference for the research of risk assessment methods in the future.

Key words: risk assessment, qualitative analysis, quantitative analysis, index system, evaluation models, correlation, real-time, uncertainty

中图分类号: 

  • TP393