计算机工程与应用 ›› 2012, Vol. 48 ›› Issue (30): 128-131.

• 网络、通信、安全 • 上一篇    下一篇

多因素分层模糊综合风险评估方法的应用研究

陈雪刚1,程杰仁2   

  1. 1.湘南学院 计算机科学系,湖南 郴州 423000
    2.杭州电子科技大学,杭州 310018
  • 出版日期:2012-10-21 发布日期:2012-10-22

Research on application of risk assessment approach for multi-factor hierarchical fuzzy comprehensive evaluation

CHEN Xuegang1, CHENG Jieren2   

  1. 1.Department of Computer Science, Xiangnan University, Chenzhou, Hunan 423000, China
    2.Hangzhou Dianzi University, Hangzhou 310018, China
  • Online:2012-10-21 Published:2012-10-22

摘要: 针对电子档案信息安全指标体系中的指标属性冗余的问题,提出了基于相关分析的指标属性检测方法。该方法采用量化指标属性的原则,根据指标属性的平均值和标准差,度量指标属性间的相关性;针对信息安全风险评估准确度不高的问题,提出了多因素分层模糊综合评估模型,该算法采用了层次分析法和模糊数学理论。某单位的电子档案信息系统的实际应用结果表明,该方法能直观、有效地评估系统,评估结果与实际吻合程度较高,为信息安全风险决策提供可靠的依据。

关键词: 电子档案, 相关性分析, 风险评估, 层次分析法, 模糊综合评价

Abstract: According to the problem of redundant attributes for indicator system of information security based on electronic archive, an attributes detection method based on correlation analysis is presented. The proposed algorithm exploits the principles of the quantified indicators properties, and the correlation between the indicators properties according to mean and standard deviation of indicators properties is measured; aiming at the problem of the low accuracy on risk assessment of information security , multi-factor hierarchical fuzzy comprehensive evaluation model based on AHP and fuzzy mathematics is proposed. The practical application on a certain information system proves that it can assess the system directly and effectively, and the assessment result is to actual with higher degree ,and it can provide reliable basis for decision making of risk about information security.

Key words: electronic archive, eorrelation analysis;risk assessment, Analytic Hierarchy Process(AHP), fuzzy comprehensive evaluation