信息系统风险评估是对信息系统的资产存在的弱点、面临的威胁、造成的影响,以及三者总和作用带来风险的可能性的评估。为了对云计算环境下的电力系统的安全性能进行动态评价,在隐马尔可夫模型的基础上,在科学、高效、准确、可参考的基础下,结合实体行为对系统风险的影响,对现有的静态风险评估算法进行了改进。对系统资产,威胁及脆弱性进行了分析,给出了一种改进的风险计算方法。理论分析和实验结果表明改进方法提高了评估结果的可靠性和时效性。
The information system risk assessment is used to assess the asset threat,weakness and impact of informationsystem,and risk possibility of the three items. In order to dynamically evaluate the safety of the electric power system in cloudcomputing environment,and on the basis of hidden Markov model,the available static risk assessment algorithm was improvedby combining the influence of entity behavior on system risk. The threat and vulnerability of system assets are analyzed,and animproved risk calculation method is given. The theoretical analysis and experimental results show that the improved method canenhance the reliability and timeliness of the assessment results.