信任是人们在各种交易活动中的一个基本要素,其与风险密切相关,并成为系统安全决策的两个关键因素.现有的信任研究大多将风险看作信任的一种补充,甚至忽略了风险的影响,这将导致系统安全决策的片面性和主观性.针对该问题,文中提出了一种基于实体行为风险评估的信任模型.该模型通过对系统的资产识别、脆弱性识别和威胁识别,建立了用于实体行为特征匹配的规则,提出一种加权复合函数计算实体行为中潜在的风险,并给出一种基于风险的实体信任计算方法.应用实例及测试结果表明该模型能够有效地识别实体行为中潜在的风险,并随着实体行为的变化正确地计算出实体风险与信任的变化,为系统安全决策提供了客观、可靠的信息支持.
Trust is an essential ingredient of the transaction process. And trust and risk are two closely related factors to make security decisions during transaction process in an uncertain environment that hidden risks. The existing trust models mostly regard risk as a supplement to trust, or neglect risk. This will result in that the security decision is unilateral and subjective. To address the problem, this paper proposes a trust model based on behaviors risk evaluation. In this model, a set of feature matching rules was established based on asset identification, vulnerability identification and threat identification for the system, a complex weighting function was constructed to compute the potential risk implied in behaviors of the entities, and a trust computation method based on risk was designed. The application of the proposed model and the experimental results show that the proposed model can efficiently identify the potential risk implied in behaviors of the entities, and correctly compute the changing risk and trust according to the changing behaviors of the entities, which provide objective and reliable information to correctly make security decision for the system.