信息网络安全 ›› 2020, Vol. 20 ›› Issue (2): 1-6.doi: 10.3969/j.issn.1671-1122.2020.02.001

• • 上一篇    下一篇

一种新的等级测评综合得分算法研究

黎水林1(), 祝国邦2, 范春玲2, 陈广勇1   

  1. 1.公安部第三研究所,上海 200031
    2.公安部网络安全保卫局,北京 100741
  • 收稿日期:2019-07-10 出版日期:2020-02-10 发布日期:2020-05-11
  • 作者简介:

    作者简介:黎水林(1981—),男,湖北,助理研究员,硕士,主要研究方向为网络安全、等级保护;祝国邦(1979—)男,吉林,副研究员,硕士,主要研究方向为信息技术、网络安全、等级保护;范春玲(1976—)女,吉林,副研究员,硕士,主要研究方向为信息技术、网络安全、等级保护;陈广勇(1973—),男,天津,副研究员,硕士,主要研究方向为信息技术、网络安全。

  • 基金资助:
    国家重点研发计划[2018YFB0803503]

Research on a New Scoring Algorithm of Testing and Evaluation for Classified Cybersecurity Protection

LI Shuilin1(), ZHU Guobang2, FAN Chunling2, CHEN Guangyong1   

  1. 1. The Third Research Institute of Ministry of Public Security, Shanghai 200031, China
    2. Cyber Security Department of the Ministry of Public Security, Beijing 100741, China
  • Received:2019-07-10 Online:2020-02-10 Published:2020-05-11

摘要:

信息安全等级保护测评报告模版(2015版)给出了信息系统等级测评综合得分算法,但该算法存在计算工作量大、计算结果不影响测评结论的问题。针对2015版等级测评综合得分算法存在的不足,文章提出了一种新的等级测评综合得分算法,该算法缩小了测评项符合程度的得分取值范围,简化了测评项加权得分的计算方法,大幅度降低了等级测评的计算工作量,实现了对信息系统等级测评结论的定量判定。实验结果表明,新的等级测评综合得分算法能够对信息系统进行合理评价,有效提高了等级测评结论的准确性和科学性。

关键词: 网络安全等级保护, 等级测评, 综合得分算法

Abstract:

The report template (2015 edition) gives the scoring algorithm of testing and evaluation for classified cybersecurity protection, however, there are some problems in this algorithm, such as the heavy workload of calculation and the result of calculation does not affect the evaluation conclusion. In this paper, aiming at the problem of scoring algorithm in 2015 edition report template, a new scoring algorithm of classified cybersecurity protection evaluation is proposed. The algorithm reduces the score range of coincidence degree of evaluation items, simplifies the calculation method of weighted score of evaluation items, greatly reduces the computational workload, and realizes the quantitative determination of evaluation conclusion. The experimental results show that the new scoring algorithm achieves a reasonable result in quantitative evaluation of information system, and effectively improves the accuracy and scientificity of evaluation conclusion.

Key words: classified cybersecurity protection, testing and evaluation for classified cybersecurity protection, scoring algorithm

中图分类号: