计算机科学 ›› 2009, Vol. 36 ›› Issue (9): 122-126.

• 软件工程与数据库技术 • 上一篇    下一篇

面向对比评估的软件系统安全度量研究

张鑫,顾庆,陈道蓄   

  1. (南京大学计算机软件新技术国家重点实验室 南京 210093)
  • 出版日期:2018-11-16 发布日期:2018-11-16
  • 基金资助:
    本文受国家863项目(2006AA01Z177),江苏省自然科学基金基础研究项目(BK2006115) ,国家自然科学基金项目(NSFC60873027)资助。

Study of Security Metrics of Software System for Comparative Evaluation

ZHANG Xin, GU Qing, CHEN Dao-xu   

  • Online:2018-11-16 Published:2018-11-16

摘要: 保护质量是指安全模块在进行安全处理时需要达到的安全目标。它是以一定的量化标准来衡量的。如何客观有效地评估现有软件系统是否满足保护质量的要求已成为研究热点之一。目前,大多数安全领域的从业者使用的是具有较高主观性的定性评估方法,使得评估结果依赖于个人经验而并不可靠,从而需要独立、客观、定量的安全度量方法。针对安全度量的复杂性和实施困难的情况,提出了基于对比评估的安全度量模型,分别从攻击面、拒绝服务和攻击图的角度讨论了两个或多个软件系统之间的相对安全性,并对评估的过程和结果进行了综合分析与研究。

关键词: 保护质量,安全度量,攻击面,拒绝服务,漏洞,攻击图

Abstract: Quality of protection can be seen as the security target of security modules when doing their security treatments,which can be judged by ctuantitative criteria. The question of how to evaluate whether the current software system has fulfills the quality of protection target objectively and effectively has become one of the hotspots of research.Currently, however, most security professionals use the ctualitative method for security evaluation, which is highly sub- jective and makes the evaluation result dependent on the individual experience and thus unreliable. So what needed are substantive and quantitative security metrics. Because of the complexity and the difficulty of implementing the security metrics, a novel security evaluation model was presented in this paper, which analyzed the relative security level of given systems from the views of attack surface, denial of service and attack graph. At last, a general discussion for the process and the result of the evaluation were given.

Key words: Quality of protection, Security metrics, Attack surface, Denial of service, Vulnerability, Attack graph

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!