[1]高阳,罗军舟.基于灰色关联决策算法的信息安全风险评估方法[J].东南大学学报(自然科学版),2009,39(2):225-229.[doi:10.3969/j.issn.1001-0505.2009.02.008] 　Gao Yang,Luo Junzhou.Information security risk assessment based on grey relational decision-making algorithm[J].Journal of Southeast University (Natural Science Edition),2009,39(2):225-229.[doi:10.3969/j.issn.1001-0505.2009.02.008] 基于灰色关联决策算法的信息安全风险评估方法()

39

2009年第2期

225-229

2009-03-20

## 文章信息/Info

Title:
Information security risk assessment based on grey relational decision-making algorithm

Author(s):
School of Computer Science and Engineering,Southeast University,Nanjing 210096,China

Keywords:

TP309
DOI:
10.3969/j.issn.1001-0505.2009.02.008

Abstract:
An approach based on grey system theory is put forward to evaluate information system security for solving uncertainty in parameter values.Firstly,uncertainty in parameter values is analyzed and classified to grey parameter values and vacant parameter ones.According to the actual condition and history statistical data,the vacant parameter values may meet three kinds of distributions: uniform distribution,exponential distribution,and normal distribution.The corresponding prior estimates are given to fill them up.Then,the algorithm of grey relational decision-making is applied to estimate information security risk.The study of an example proves the validity of this method.And the results show that the approach can properly deal with uncertainty in parameter values,decrease the subjectivity in evaluation process,and easily rank each information system by security level.It brings a new thought to information security risk assessment approaches.

