期刊文献+

信息系统安全风险评估模型及其在铁路客票系统中的应用 被引量:7

A Security Risk Evaluation Model for IT System and Its Application on Railway Passenger Ticket System
在线阅读 下载PDF
导出
摘要 提出一种基于模糊综合评判理论的信息系统安全风险综合评估模型与方法,实现量化信息系统安全风险的目标。通过确定信息系统的安全风险因素集、指标集以及因素的权重系数集,建立安全风险模糊综合评估矩阵,并应用于铁路客票预定与发售系统的安全风险评估。铁路客票预定与发售系统包括信息资产和物理资产,受到来自系统本身、外部环境以及人为和自然界的安全威胁。应用建立的信息系统安全风险评估模型,定量计算铁路客票预定与发售系统Web组件的安全风险值。根据计算值确定信息系统中的高风险组件,为系统管理与使用部门采取相应的防护技术和管理措施提供理论依据,增强系统安全性。 A security risk evaluation method based on fuzzy-set comprehensive evaluation theory is demonstrated in this paper to obtain the aim of quantitatively assessing security risk. The security risk is evaluated by making the fuzzy matrix for security risk and addressing risk factor set, security risk indicator sets and the weigh coefficient of security risk factors and applied to the railway passenger ticket system. The security targets provided by the railway passenger ticket system consist of system security, availability, identification authenticity and transaction reliability in order to protect the physical assets and information assets in face of the threats which come from system itself, personnel, environmental and natural disasters. The proposed model for security risk evaluation is used to calculate the security severity of Web server for the system. The numeric results for security risk also provide a method to decide the most critical component of the system which should arouse the system administrator enough attention to take the appropriate technical or administrative security measure or controls to enhance the security of the system.
出处 《中国铁道科学》 EI CAS CSCD 北大核心 2007年第1期127-130,共4页 China Railway Science
基金 国家'八六三'计划项目(2002AA142150)
关键词 信息系统安全 风险评估 铁路客票系统 模糊数学 Information system securityt Risk assessment Railway passenger ticket system Fuzzy mathematics
  • 相关文献

参考文献4

二级参考文献10

  • 1章少强,电力企业管理信息系统,1998年
  • 2周慧玲,风险管理学,1996年
  • 3汪培庄,模糊系统理论与模糊计算机,1996年
  • 4李洪兴,工程模糊数学方法及应用,1993年
  • 5韩立岩,应用模糊数学,1989年
  • 6Yacoub S, Ammar H. A Methodology for ArchitecturalLevel Reliability Risk Analysis[J ]. IEEE Trans. Software Eng, 2002, 28(6) :529 - 547.
  • 7Goseva-Popstojanova Katerina, Ahmed Hassan, Architectural-Level Risk Analysis Using UML [ J ]. IEEE Trans.Software Eng, 2003,29(10) :946 - 959.
  • 8Munson J, Khoshgoftaar T. Sotware Metrics for Reliability Assessment[J]. Handbook of Software Reliability Eng.,1996,33: 493 - 529.
  • 9Molak. Fundamentals of Risk Analysis and Risk Maragement[M]. Boca Raton: CRC Press, 1996.
  • 10Vlasta Molak. Fundamentals of Risk Analysis and Risk Management[ M]. Boca Raton: Lewis Publishers, 1997.

共引文献42

同被引文献50

引证文献7

二级引证文献57

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部