为解决当前缺乏有效的信息系统动态风险评估技术的问题,研究了信息系统风险评估空间动态应力关系计算方法。通过对信息系统资产的安全属性进行空间转化,构造出信息资产安全属性空间,基于空间应力函数建立了资产属性相互关系动态应力模型。根据描述的资产所在安全属性空间曲面中的曲率变化,表现出资产安全属性之间的相互影响关系,并随时调整和计算资产安全属性值,实现了动态的风险防范措施决策,最后用实例证明了模型的有效性。
To address the problem of current lack of effective information system dynamic risk assessment technology, the spatial calculating the dynamic stress method of information system risk assessment is studied. The information asset safety attribute space is established through a space conversion on the information asset attributes, and the dynamic space stress calculation model of the assets of the relationship between attributes is based on space stress function. The correlation of the asset safety attributes is shown from the curvature of the asset-relating surface, the asset safety attribute value is adjusted and calculated dynamically, and the dynamics of decisionmaking of risk prevention measures is achieved. Finally, a case study is presented to verify the feasibility of the model.