计算机科学 ›› 2010, Vol. 37 ›› Issue (5): 45-48.

• 计算机网络与信息安全 • 上一篇    下一篇

一种基于信息熵的企业信息系统的安全风险定量评估方法

刘勇,林奇,孟坤   

  1. (东北大学 沈阳110004);(航空工业信息中心 北京100012);(清华大学计算机系 北京100084)
  • 出版日期:2018-12-01 发布日期:2018-12-01
  • 基金资助:
    本文受国家自然科学基金(60803123)资助。

Research on Quantitive Security Risk Assessment Method of an Enterprise Information System Based on Information Entropy

LIU Yong,LIN Qi,MENG Kun   

  • Online:2018-12-01 Published:2018-12-01

摘要: 针对信息系统风险评估中过分依赖主观赋值的现象,提出了基于信息嫡的风险评估方法,该方法通过构建威胁一脆弱性矩阵和威胁一损失矩阵,并对所构建的矩阵用信息嫡方法分别对其行和列进行处理,从而降低了对主观赋值的依赖性,提高了结果的准确性。最后结合中小企业的实际,设计了一套方便可行的评估流程。利用该方法对典型的企业信息系统进行了实例分析,说明了该方法的有效性。

关键词: 信息熵,风险评估,定量方法,企业信息系统

Abstract: For the security risk assessment, the result always relies on the value assigned by some ctueries directly. In order to assess the information system of an enterprise objectively, we proposed an security risk assessment method based on information entropy. By constructing the matrix of Threat-Vulnerability and the matrix of Threat-Loss, we can enhance the result accuracy through dealing with the data of the matrixes by the method of the information entropy.In the end of the paper, we gave an example to explain the efficiency of the proposed method by analyzing an special enterprise information system

Key words: Information entropy, Security risk assessment, Quantitive method, Enterprise information system

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!