在攻击树模型的基础上,对该模型进行扩展,提出了一种新的定量的风险评估方法。在对叶子节点(原子攻击)风险值的量化中,采用了多属性效用理论,使得评估更加客观;对该方法的每一步骤均给出了具体的算法,为实现自动化的评估工具建立了基础。
This paper extended the attack tree model, and proposed a new quantitative risk evaluation method. While the risk value of the leaf node ( atomic attack) was quantified, the multi-attribute utility theory was adopted, which could make the result more reasonable. Presented all algorithms for each steps of this new evaluation method that offered a good foundation for the implementation of the automatic evaluation tool.