一種信息系統(tǒng)生存性的量化分析框架
A Framework of Quantitative Analysis for Information System Survivability
-
摘要: 生存性是信息系統(tǒng)在安全性之上必需考慮的問(wèn)題,對(duì)其量化分析可對(duì)系統(tǒng)生存性做出更為準(zhǔn)確的評(píng)價(jià)以改進(jìn)系統(tǒng)?;谟邢逘顟B(tài)機(jī)描述信息系統(tǒng),利用系統(tǒng)狀態(tài)轉(zhuǎn)移圖來(lái)定義生存性分析過(guò)程,而系統(tǒng)狀態(tài)的層次化結(jié)構(gòu)避免了Markov鏈模型中的列舉系統(tǒng)狀態(tài)問(wèn)題。在SNA方法的基礎(chǔ)上,提出一種便于計(jì)算機(jī)實(shí)現(xiàn)的生存性量化分析框架:通過(guò)系統(tǒng)定義、系統(tǒng)生存性測(cè)試和生存性計(jì)算,最后給出分析報(bào)告。其中基于事件分類(lèi)分級(jí)建立的事件庫(kù)使得測(cè)試方案的生成自動(dòng)化和客觀化,系統(tǒng)的生存性通過(guò)層次化的方式從可抵抗性、可識(shí)別性和可恢復(fù)性3個(gè)方面進(jìn)行了量化計(jì)算。
-
關(guān)鍵詞:
- 生存性; 信息系統(tǒng); 量化分析; 分析框架
Abstract: Survivability should be considered beyond security for information system, and quantitative analysis can assess system survivability accurately for improvement. Information system is presented by finite state machine and its state transition map is used to describe analysis process, where the hierarchical structure of system state avoids the problem of enumerating states in Markov chain model. Based on SNA method, a framework of quantitative analysis is introduced: defining system, testing systems survivability, computing survivability, and giving analysis report finally, which is easily implemented by computer. In the framework, the event database which is based on event classification and grade makes creating test project automatically and objectively, and survivability is computed through resistance, recognition and recovery in a hierarchical process. -
計(jì)量
- 文章訪問(wèn)數(shù): 2737
- HTML全文瀏覽量: 112
- PDF下載量: 958
- 被引次數(shù): 0