北京邮电大学学报

  • EI核心期刊

北京邮电大学学报 ›› 2016, Vol. 39 ›› Issue (s1): 87-93.doi: 10.13190/j.jbupt.2016.s.020

• 论文 • 上一篇    下一篇

面向Web信息系统安全威胁和风险评估分析

雷敏1,2, 刘晓明3, 张鸿3, 王勉1,2, 杨榆1,2   

  1. 1. 北京邮电大学 信息安全中心, 北京 100876;
    2. 灾备技术国家工程实验室, 北京 100876;
    3. 国家计算机网络应急技术处理协调中心, 北京 100029
  • 收稿日期:2015-08-20 出版日期:2016-06-28 发布日期:2016-06-28
  • 作者简介:雷敏(1979-),男,博士,讲师,E-mail:zymcliu@foxmail.com.
  • 基金资助:

    国家科技支撑计划课题(2015BAH08F02)

Research on Security Threats and Risk Assessment of Web Information System

LEI Min1,2, LIU Xiao-ming3, ZHANG Hong3, WANG Mian1,2, YANG Yu1,2   

  1. 1. Information Security Center, Beijing University of Posts and Telecommunications, Beijing 100876, China;
    2. National Engineering Laboratory for Disaster Backup and Recovery, Beijing 100876, China;
    3. National Computer Network Emergency Response Technical Team/Coordination Center of China, Beijing 100029, China
  • Received:2015-08-20 Online:2016-06-28 Published:2016-06-28

摘要:

将Web信息系统所面临的安全威胁按照威胁所属的类型进行分类,并根据每种威胁的危害程度、发生的概率以及威胁发生后采取措施进行补救的概率等方面对这些威胁进行分级,用模糊综合评价法,构建了一个安全分析的模型,并提出一个通用的Web信息系统安全的分析框架,对Web信息系统进行安全评估分析.

关键词: Web信息系统, 安全评估, 风险评估, 模糊综合评价法

Abstract:

An increasing numbers of web information systems are deployed on the Internet to provide service, however, the web information system is facing various security threats, from physical security on bottom layer to communications and operations management, system security, application security and data security. The article gave out classifications of security threats faced by type of threats in web applications and set up grade for each threat according to its extent of danger, probability of occurrence and remediation. The article also uses fuzzy comprehensive evaluation to build a security analysis model aiming at constructing common analysis framework for web information system security assessment.

Key words: web information system, security assessment, risk assessment, fuzzy comprehensive evaluation

中图分类号: