A qualitative and quantitative risk assessment method in software security

A qualitative and quantitative risk assessment method in software security
复制标题

DOI:
10.1109/icacte.2010.5578960
复制
发表时间:
2010-09
期刊:
2010 3rd International Conference on Advanced Computer Theory and Engineering(ICACTE)
影响因子:
--
通讯作者:
Yi-kun Zhang;Su-yang Jiang;Ying-an Cui;Bao-wei Zhang;Hui Xia
Yi-kun Zhang;Su-yang Jiang;Ying-an Cui;Bao-wei Zhang;Hui Xia
中科院分区:
其他
文献类型:
--
作者:
Yi-kun Zhang;Su-yang Jiang;Ying-an Cui;Bao-wei Zhang;Hui Xia

文献摘要

被引文献

相似文献

本文聚焦于软件安全风险评估,采用攻击树模型分析与贝叶斯网络分析相结合的方法,利用定性分析和定量分析两者的优势来评估软件安全风险。通过构建和修剪攻击树模型,该方法首先缩小软件系统所产生的威胁范围。在初步控制风险概率的基础上,借助先验概率值、条件概率表和贝叶斯公式,该方法能够准确评估软件系统的风险概率。最终,这种风险评估方法弥补了单一风险评估方法的不足,获得了更准确的评估结果。它能够更准确地获取软件项目的风险等级,并对存在风险的部分模块进行防御和恢复。
Focusing on the software security risk assessment, this paper adopts the combination of the attack tree model analysis and the Bayesian Network analysis, which takes the advantage of both qualitative analysis and quantitative analysis to assess risks of software security. By the construction and pruning of the attack tree model, this method narrow down the scope of threats that are generated by software system at first. With a preliminary control of risk probability, and through the prior probability value, the conditional probability table and the Bayesian formula, this method can assess the risk probability of the software system accurately. Finally the risk assessment method makes up the deficiency of single risk assessment method, won more accurate evaluation results. It can obtain the software project risk rank more accurate and carries on the defense and the recovery to the risk partial modules.