Netinfo Security ›› 2019, Vol. 19 ›› Issue (9): 111-114.doi: 10.3969/j.issn.1671-1122.2019.09.023

• Orginal Article • Previous Articles     Next Articles

Research on Network Security Evaluation System Oriented to Critical Information Infrastructure

Mengru GAO1, Fangjun XIE1, Hongqin DONG1, Xiang LIN2   

  1. 1. Network Security Corps of Shanghai Public Security Bureau, Shanghai 200025, China
    2. School of Cybersecurity, Shanghai Jiaotong University, Shanghai 200240, China
  • Received:2019-07-15 Online:2019-09-10 Published:2020-05-11

Abstract:

With the wide application of Internet and cloud computing, the security problem of critical information infrastructure has become increasingly prominent. At present, the three-tier hierarchical structure of the critical information infrastructure security index system has the problems that lacking of quantify indicators, and lacking of correlation between management indicators and technical indicators. These problems lead to the low degree of informatization and a long period of security risk assessment. In order to solve the above problems, this paper establishes the relationship between management indicators and technical indicators by introducing the knowledge graph, and forms the four-level network security quantitative evaluation system based on knowledge graph by classifying the actual situation data to refine the technical indicators. Through the practical application, the system can assess the security risk of Internet assets of critical information infrastructure in near real-time, and significantly improve the efficiency of supervision.

Key words: network security evaluation system, knowledge graph, indicator quantification

CLC Number: