A New Uncertainty Evolution Inference Model for Classified Evaluation of Information System
-
-
Abstract
To evaluate reasonably the ability of protection system, the requirements of evaluation standard GB/T 22239-2008 and information security events have to be considered and analyzed comprehensively. The fault tree is applied to decomposition of security incidents and the minimal cut set of fault tree can be translated into inference rules. Then, the uncertain reasoning technique is used to derive security incidents caused probably by system vulnerability. The loss and risk are taken into account, which could be regarded as the basis to assess the capacity of protection system. Experimental results show that the performance of proposed model is corresponding to the system vulnerability and the judgment of classified assessment is reasonable. Above work provides a possible route to synthesize the search of classified protection and risk analysis.
-
-