构建了一个基于贝叶斯网络的信息安全风险概率计算模型,并保证其可扩展性、精确性和客观性.模型的网络结构以规划渗透图表现,模型网络参数由专家知识确定并利用贝叶斯学习对其进行更新.实例分析表明构建的模型可以正确量化评估信息安全风险概率.
A planning exploitation graph-bayesian networks model that can be applied in measurement of information security risk frequency is proposed, and the model's scalability, accuracy and objectivity are achieved. The model graph structure is deter- mined by Planning Exploitation Graph, the local conditional probability distributions are computed by combination of expertise knowledge and the maximum entropy prior probability distribution method,and the model parameters are updated with training data by Bayesian networks learning. The analysis of the example shows the model could evaluate the information security risk frequency successfully.