安全指数作为反映和测度网络安全态势的一种核心方法,具有重要的研究意义.为度量网络信息系统在运行过程中的安全态势,文中给出了网络运行安全指标和指数的定义,提出了10个关键分类属性以及指数分类的通用概念模型ICM,该模型为具体指数分类模型的构建和不同分类模型的比较提供了统一的模型方法.基于ICM模型和10维分类属性,文中同时提出了一个多维属性指数分类模型ICM M10,并通过4个典型指数的应用实例阐明了M10模型的应用过程和应用意义.应用实例分析表明,M10模型能够刻画出安全指数在10个关键属性上的本质特性,对深入研究指数特性、关系及其内在含义具有指导意义,同时,也为建构多层次安全指数体系提供了理论和技术基础.
As a core method, security indices are greatly significant for reflecting and measuring network security situation. To measure the security situation of network information systems in runtime, this paper defines two concepts of network operation security indicator and index, proposes ten key classification attributes and a common conceptual model for index classification (ICM) which provides a uniform formal methodology for establishment of a model example and comparison of different models. Based on ICM and the attributes, this paper also presents an index classification model with multidimensional attributes M10. Four representative indices are given to illustrate the process and senses of applying M10. The analysis of the application example indicates that because of ability to depict the natures of security indices on ten key attributes, M10 has guiding significances for deep study on the natures, correlations and meanings of indices, and also provides a theory and technology base for establishing a hierarchical system of security indices.