计算机应用 ›› 2009, Vol. 29 ›› Issue (05): 1305-1307.

• 信息安全 • 上一篇    下一篇

一种基于实体行为风险评估的信任计算方法

武小年1,张润莲2,周胜源1   

  1. 1. 桂林电子科技大学
    2. 西安交通大学 电子与信息工程学院;桂林电子科技大学 信息与通信学院
  • 收稿日期:2008-11-26 修回日期:2009-01-04 发布日期:2009-06-09 出版日期:2009-05-01
  • 通讯作者: 武小年
  • 基金资助:
    国家级基金;省部级基金

Method for trust computation based on behavior risk evaluation

  • Received:2008-11-26 Revised:2009-01-04 Online:2009-06-09 Published:2009-05-01

摘要: 在分布、动态环境中,风险和信任是影响安全决策的关键因素。基于安全风险评估原理,提出一种基于实体行为风险评估的信任计算方法。该方法通过识别并量化信息资产的重要性和实体行为威胁的严重性,给出了实体行为风险量化和实体信任度的计算方法。应用实例及计算结果表明,该方法能够正确地识别实体的风险变化,并能通过信任度计算为系统正确地控制实体的后续行为提供客观支持。

关键词: 信任, 风险, 安全评估, 风险量化, trust, security evaluation, security evaluation, risk quantification

Abstract: Risk and trust are key factors impacting on the security decision-making in the distributed and dynamic environments. According to information risk evaluation theory, the author proposed a method for trust computation based on behavior risk evaluation. The proposed method described risk quantification method by identifying and quantifying the significance of assets and the criticality of threats from the behaviors of entities, and designed trust computation methods based on the quantified risk. Experimental results show that the proposed method can correctly identify the changing risk implied in the behaviors of entities, and compute trust based on the changing risk. It can provide objective reference for the system to correctly control the follow-up behaviors of entities.