首页 | 本学科首页   官方微博 | 高级检索  
     检索      

基于安全熵的间接非授权行为分析理论
引用本文:车天伟,;王超,;李娜,;陈嘉勇.基于安全熵的间接非授权行为分析理论[J].信息安全与通信保密,2014(7):63-65.
作者姓名:车天伟  ;王超  ;李娜  ;陈嘉勇
作者单位:[1]西安电子科技大学计算机学院,陕西西安710071; [2]解放军信息工程大学,河南郑州450001; [3]西北工业大学计算机学院,陕西西安710129; [4]北京中投科信科技发展有限公司,北京100055
摘    要:针对系统中存在间接非授权访问可能性的量化分析和证明问题,提出了一种基于安全熵的量化分析理论.首先,结合信息论有关知识引入安全熵概念,提出系统对间接非授权访问行为响应的不确定性计算方法;然后,基于安全熵提出了系统的间接安全性定理,作为判断系统是否可能存在间接非授权访问的依据;最后,应用该方法对经典安全模型进行了量化分析,验证了该方法的实用性.结果证明该方法适用于系统或访问控制模型对间接非授权访问的防护能力评估和证明.

关 键 词:信息熵  安全熵  访问控制模型  间接非授权访问

Analysis Technique for Classificatory Access Control Model Security based on Security Entropy
Institution:CHE Tian-wei , WANG Chao, LI Na, CHEN Jia- yong ( l School of Computer Science and Technology, Xidian University, Xi'an Shanxi 710071, China ; 2PLA Information Engineering University, Zhengzhou Henan 450001, China; 3 School of Computer Science and Technology, Northwestern Polytechnical University, Xi' an Shaanxi 710129, China; 4Beijing Jianyin Investment Technology Development Co. , Ltd. Beijing 100055, China)
Abstract:To resolve the problems of quantitative analysis and proof on the probability of indirectly unauthorized access existing in the system, a quantitative analysis method based on security entropy is proposed. Firstly,the concept of security entropy is introduced in accordance with information theory, and the calculation method for uncertainty of the system' s response to the irregular access be- haviors is given. Then the security theorem based on security entropy is proposed ,which serves as a basis to determine if there are in- directly unauthorized accesses. Finally, the typical access control model is quantitively analyzed by the method, and through this, the practicability of this method is validated. The experiment result indicates that this methods is suitable for security quantitative analysis and proof on indirectly unauthorized access control capability in information system and access control model.
Keywords:information entropy  security entropy  access control model  indirectly unauthorized access
本文献已被 维普 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号