Journal of Beijing University of Posts and Telecommunications

  • EI核心期刊

JOURNAL OF BEIJING UNIVERSITY OF POSTS AND TELECOM ›› 2006, Vol. 29 ›› Issue (2): 59-61.doi: 10.13190/jbupt.200602.59.pengjh

• Papers • Previous Articles     Next Articles

Measure Model of Security Risk Based on Utility

PENG Jun-hao,XU Guo-ai,YANG Yi-xian,TANG Yong-li   

  1. Information Security Center, Beijing University of Posts and Telecommunications
  • Online:2006-04-28 Published:2006-04-28

Abstract: Utility function was introduced into security risk area, and its inverse function is used to define absolute loss effect and relative loss effect as measure of risk. They are used to build criteria of risk rank. Absolute loss effect can measure the difference of risk between security incidents with high loss,low probability and security incidents with low loss,high probability. Relative loss effect can measure the difference of risk tolerance among organizations with different scale, but the average loss used very often can't measure these differences.

Key words: information security, risk evaluation, utility theory, loss effect