论文部分内容阅读
为识别体系(So S)中的薄弱环节、评价威胁风险并提高体系安全性,根据安全系统工程和体系工程理论,提出体系安全性基本概念。基于复杂网络科学和传统安全分析技术,提出一种双层次分析框架,从脆弱性角度和威胁风险角度研究体系安全性。脆弱性分析可从拓扑结构和非拓扑因素2方面识别对体系安全较关键的脆弱点;威胁风险分析能得到脆弱点面临的任意威胁组合,并识别后果较严重的威胁风险。结果表明:体系安全性包括宏观的脆弱性应对能力,和微观的威胁风险控制能力。体系安全性分析需宏观和微观双层次相结合,全面考虑体系安全性诸因素。基于识别结果的威胁评价将提高安全分析的针对性和效率。
To identify the weak links in the system (So S), evaluate the threat risk and improve the security of the system, according to the security system engineering and system engineering theory, the basic concepts of system security are proposed. Based on complex network science and traditional security analysis techniques, a two-level analysis framework is proposed to study system security from the perspective of vulnerability and threat risk. Vulnerability analysis identifies top vulnerabilities that are more critical to system security from both topological and non-topological factors2; threat risk analysis can capture any combination of threats faced by vulnerabilities and identify the more serious threat risks. The results show that the system security includes macro-level vulnerability coping ability and micro-level threat risk control. System security analysis needs macro and micro-level combination of two levels, fully consider the various factors of system security. Threat assessment based on recognition results will improve the relevance and efficiency of security analysis.