电子科技 ›› 2019, Vol. 32 ›› Issue (11): 78-82.doi: 10.16180/j.cnki.issn1007-7820.2019.11.016

• • 上一篇    下一篇

基于等级保护的信息安全评估算法研究

查红泽   

  1. 云南南天电子信息产业股份有限公司 信息安全测评中心,云南 昆明 650000
  • 收稿日期:2018-11-09 出版日期:2019-11-15 发布日期:2019-11-15
  • 作者简介:查红泽(1991-),男,工程师。研究方向:网络安全、等级保护。
  • 基金资助:
    云南省科技厅科技项目(2017KJF35762)

Research on Information Security Evaluation Algorithm Based on Hierarchical Protection

ZHA Hongze   

  1. Information Security Evaluation Center,Yunnan NantianElectronic Information Industry Co. Ltd.,Kunming 650000,China
  • Received:2018-11-09 Online:2019-11-15 Published:2019-11-15
  • Supported by:
    Project of Yunnan Science and Technology Department(2017KJF35762)

摘要:

对信息安全系统要进行安全评估,首先要考虑的问题为如何建立模型进行风险评估分析。针对这一问题,文中基于等级保护提出一种信息安全风险评估方法,并建立信息系统安全评估模型。以GBT 20984-2007作为评估依据,针对主机安全与网络安全建立层次结构,并利用权重计算方法RISK-Weight 算法完成对模型的计算与分析。实例测试结果表明,该评估方法降低人为主观因素的影响,实现对信息系统安全科学的量化评估。

关键词: 信息安全, 安全评估, 层次分析法, 等级保护

Abstract:

The key issue for evaluating information security systems is the establishment and analysis of risk assessment indicators. Aiming at this problem, this paper proposed an information security risk assessment method based on hierarchical protection and establishes an information system security assessment model. Based on GBT 20984-2007, a hierarchical structure was established for host security and network security, and the calculation and analysis of the model were completed by using the weight calculation method RISK-Weight algorithm. The example's results showed that the evaluation method reduced the influence of human subjective factors and achieved a quantitative assessment of the security science of information systems.

Key words: information security, security assessment, AHP method, classified protection

中图分类号: 

  • TN918