针对系统漏洞的严重性评估问题,提出基于灰色评估方法和层次分析法的量化评估模型。首先根据漏洞严重性的影响因素,建立漏洞严重性评估指标体系。通过层次分析法建立递阶层次模型并计算漏洞各因素的权重,采用基于中心点三角白化权函数的灰色评估方法对漏洞各层次指标进行评估和分析,得到漏洞的综合评估结果即漏洞严重性的等级和综合量化值。实验结果表明该模型能有效、准确地评估系统漏洞的严重性。
A vulnerability quantitative evaluation model based on grey evaluation method and analytic hierarchy process(AHP) is proposed.Evaluating indexes are created according to influencing factors of vulnerability severity.AHP is utilized to establish a hierarchical model and get the weight of vulnerability factors.Grey evaluation method with a central point triangular whiten weight function is used to compute and assess each level index of vulnerabilities.Then the quantitative result of certain vulnerability is achieved.The experimental results show that this model can evaluate the vulnerabilities severity of computer systems effectively and accurately.