对信息系统进行有效的风险评估,选择有效的防范措施,主动防御信息威胁是解决信息系统安全问题的关键所在。将神经网络和模糊理论应用于信息安全的风险评估。首先针对信息安全风险评估的不确定性和复杂性,将神经网络理论应用到风险评估。其次,针对神经网络适合定量数据,对于定性指标的分析缺乏相应的处理能力,而风险因素的指标值具有很大的不易确定性等问题,采用模糊评价法对信息安全的风险因素的指标进行量化,对神经网络的输入进行模糊预处理,提出了基于模糊神经网络的风险评估方法。仿真结果表明:模糊神经网络经过训练,可以实时地估算风险因素的级别。
Evaluating risk effectively,selecting effective defence measures and defending information threats actively are the key points of resolving security problems of information system.Based on the actual requirements and status of risk assessment of informat/on security,we integrate the neural network and fuzzy logic to apply them in studying risk assessment of information security.Firstly,focused on the uncertainty and complexity of risk assessment of information security,we integrate the neural network to apply them in studying risk assessment.On the other hand,since the neural network is suited for the quantity data processing,and poor to the qualitative analyze,and risk is uncertain ,the risk factors are quantized by fuzzy evaluation method proposed in this dissertation so that the input of neural network are pre-treated, a risk assessment method based on fuzzy neural network is proposed.The simulation results show that the trained neural network can estimate the degree of risk factor real time.