安全资源的优化配置对于实现复杂网络信息系统安全风险管理具有非常重要的作用.建立了基于攻击传播性及分层防护的复杂网络信息系统安全资源分配模型.以该模型为基础,实现了单层防护以及双层防护方式下的安全资源分配过程.通过仿真实验的验证,在安全风险评估过程中考虑攻击传播性,有助于更加准确地评估整个组织中的安全风险.同时,采用分层防护方式能够在固有投资条件下更加有效地降低复杂网络信息系统的安全风险.
Optimal allocations of security resources have important effects on achieving security risk management in complex network information systems. The allocation model of security resource is established based on attack propagation and layered protection in this paper. Based on it, the paper realizes the process of security resource allocation in the single tier protection and the two tiers protection. Via the validation of simulation experiment, taking attack propagation into account is helpful to evaluating security risks more accurately. In additions, the adoption of layered protection can effectively reduce the security risks in complex network information systems.