计算机与现代化

• 信息安全 • 上一篇    

基于不完全信息博弈模型的信息系统安全风险评估方法

  

  1. (1.信息工程大学三院,河南郑州450001;2.郑州市公安局,河南郑州450001)
  • 收稿日期:2018-09-27 出版日期:2019-04-26 发布日期:2019-04-30
  • 作者简介:弭乾坤(1990-),男,甘肃兰州人,硕士研究生,研究方向:项目风险管理,E-mail: 411503725@qq.com; 吴斌(1977-),男,河南焦作人,工程师,硕士,研究方向:通信系统安全; 杜宁(1987-),男,山东青岛人,硕士研究生,研究方向:SDN网络管理,项目风险管理; 秦晰(1978-),女,河南焦作人,副教授,博士,研究方向:SDN安全,可信计算。

Information System Security Risk Assessment Based on Incomplete Information Game Model

  1. (1. 3rd School, PLA Information Engineering University, Zhengzhou 450001, China;
    2. Zhengzhou Public Security Bureau, Zhengzhou 450001, China) 
  • Received:2018-09-27 Online:2019-04-26 Published:2019-04-30

摘要: 博弈理论具有的目标对立性、关系非合作性和策略依存性等特征与网络攻防对抗过程保持一致,将博弈理论应用于网络信息安全已经成为研究热点,但目前已有的研究成果大都采用完全信息博弈模型,与网络攻防实际不符。基于此,为提高信息系统风险评估的准确性,本文构建不完全信息条件下的静态贝叶斯攻防博弈模型,将其应用于网络信息系统安全风险评估,构建相应的信息系统安全风险评估算法。通过仿真实验验证了本文模型和方法的有效性,能够对信息系统安全威胁进行科学、有效的评估。

关键词: 博弈理论, 完全信息博弈, 静态贝叶斯博弈, 风险评估

Abstract: Game theory has the characteristics of opposition target, non-cooperation relationship and dependence policy. It is consistent with the network attack and defense process. Applying game theory to network information security has become a research hotspot, but most of the existing research results have adopted complete information. The game model does not match the actual network attack and defense. Based on this, in order to improve the accuracy of information system risk assessment, this paper constructs a static Bayesian offensive and defensive game model under incomplete information conditions, and applies it to network information system security risk assessment to construct a corresponding information system security risk assessment algorithm. The effectiveness of the model and method is verified by experiments, which can provide a scientific and effective evaluation of information system security threats.

Key words: game theory, complete information game, static Bayesian game, risk assessment

中图分类号: