Netinfo Security ›› 2019, Vol. 19 ›› Issue (9): 11-15.doi: 10.3969/j.issn.1671-1122.2019.09.003

• Orginal Article • Previous Articles     Next Articles

Information System Security Risk Analysis Based on Evidence Distance Theory

Jinhua LINGHU, Ping PAN, Yaoyao DU   

  1. School of Computer Science and Technology, Guizhou University, Guiyang Guizhou 550025, China
  • Received:2019-07-15 Online:2019-09-10 Published:2020-05-11

Abstract:

Aiming at the diversity of expert evaluation opinions in the process of information security risk assessment and the difficulty in quantifying uncertain information, this paper proposes a risk assessment method based on evidence distance theory. Firstly, according to the level protection requirements and on-site inspection data, the matrix norm is used to solve the vulnerability evidence distance of the system assets. Secondly, the D-S evidence theory synthesis rules are applied to solve the evidence distance that threat may act on system assets. Finally, The result of the fusion of the vulnerability evidence distance and the evidence distance that threat may act on system asset is taken as the risk value of the system. Practice has proved that this method can effectively reduce the subjectivity and randomness of multi-source risk assessment, make the assessment results more scientific and reasonable, and provide a scientific and effective way for information security risk assessment.

Key words: matrix norm, D-S evidence theory, evidence distance, risk

CLC Number: