信息网络安全 ›› 2021, Vol. 21 ›› Issue (12): 91-101.doi: 10.3969/j.issn.1671-1122.2021.12.013

• 入选论文 • 上一篇    下一篇

基于贝叶斯网络的视频专网安全风险分析方法

朱容辰1, 李欣1,2(), 林小暖3   

  1. 1.中国人民公安大学信息网络安全学院,北京 100026
    2.公安部安全防范技术与风险评估重点实验室,北京 100026
    3.中国信息通信研究院安全研究所,北京 100191
  • 收稿日期:2021-09-17 出版日期:2021-12-10 发布日期:2022-01-11
  • 通讯作者: 李欣 E-mail:lixin@ppsuc.edu.cn
  • 作者简介:朱容辰(1996—),男,山东,硕士研究生,主要研究方向为网络安全、风险评估|李欣(1977—),男,江西,副教授,博士,主要研究方向为网络安全|林小暖(1996—),女,山东,硕士,主要研究方向为国际ICT产业与政策、网络安全
  • 基金资助:
    国家自然科学基金项目(62076246);公安部科技强警基础工作专项项目(2020GABJC01);中国人民公安大学拔尖创新人才培养经费支持研究生科研创新项目(2021yjsky016)

The Security Risk Analysis Method for Video Private Network Based on Bayesian Network

ZHU Rongchen1, LI Xin1,2(), LIN Xiaonuan3   

  1. 1. School of Information Network Security, People’s Public Security University of China, Beijing 100026, China
    2. Security Prevention Technology and Risk Assessment Key Laboratory of Ministry of Public Security,Beijing 100026, China
    3. Security Research Institute of China Academy of Information and Communications Technology, Beijing 100191
  • Received:2021-09-17 Online:2021-12-10 Published:2022-01-11
  • Contact: LI Xin E-mail:lixin@ppsuc.edu.cn

摘要:

公安视频专网是为视频监控系统联网及应用而建立的专门网络,是提高公安工作效率、辅助侦破案件的利器,有效的安全风险评估可以指导配置安全保护资源并补齐短板。针对公安视频专网的安全风险评估研究不足。文章提出了一种视频专网安全风险评估方法,从视频专网安全态势、安全保护水平、运行安全风险因素、安全事件后果等多维度考虑专网安全风险。借助贝叶斯网络(Bayesian Network,BN)、事件树和模糊集理论细粒度总结风险因素,动态分析并量化风险值。通过情景分析、部分验证与案例研究的方法验证合理性与有效性,验证结果表明,该方法有助于提高公安部门对视频专网的安全风险感知、分析与评估能力。

关键词: 视频专网, 风险分析, 贝叶斯网络, 事件树, 风险评估

Abstract:

The public security video private network is a special network established by the public security department for the networking and application of video surveillance systems, and is a way for improving the efficiency of public security work and assisting in the detection of cases. Effective assessment can guide the allocation of security protection resources and fill in shortcomings. At present, there is insufficient research on the security risk assessment of public security video private network. This paper proposed a method for evaluating the security risk of a video private network, which considered the security risk of the private network from the perspective of the security situation of the private video network, the level of security protection and the consequences of security incidents. With the help of Bayesian network, event tree and fuzzy set theory, the risk factors were summarized in a fine-grained manner, and the risk value was dynamically analyzed and quantified. The methods of scenario analysis, partial verification and case studies were used to verify the rationality and effectiveness of the method. The results show that this method can improve the security risk perception, analysis and assessment capabilities of the public security department on the video private network.

Key words: video private network, risk analysis, Bayesian network, event tree, risk assessment

中图分类号: