首页|基于攻击路径的国产计算机威胁模型

基于攻击路径的国产计算机威胁模型

扫码查看
针对信息技术应用创新产业(信创)广泛使用的国产计算机面临的安全威胁,提出一种基于攻击路径的威胁模型。在威胁发现阶段,根据国产计算机的脆弱性及面临的安全风险,建立了威胁模型并进行逐级分解,形成了具体的攻击路径。在威胁量化阶段,采用模糊层次分析法(FAHP)计算出了攻击路径的概率。在威胁消减阶段,通过部署具体测试环境,利用安全测试方法对模型进行验证,最后给出了威胁消减措施。结果表明,该模型能够识别国产计算机的主要安全威胁,通过安全设计减轻威胁有助于提升信创计算机产品和应用的安全性。
Threat Model of Domestic Computer Based on Attack Path
Concerning the threats faced by computers widely used in the information technology application innovation industry,a threat model based on attack path is proposed.In the stage of threat discovery,considering the vulnerability and risks faced by domestic computers,the model was established and decomposed step by step to form specific attack paths.In the quantification phase,the attack probability was calculated using fuzzy analytic hierarchy process(FAHP).In the mitigation phase,security testing methods were used to validate the model.Finally,the threat response measures were provided.The results show that the model can identify the main threats of domestic computers,and mitigating threats through design can help improve the security of products and applications.

information technology application innovation industrydomestic computerthreat modelattack pathfuzzy analytic hierarchy process

苏振宇

展开 >

浪潮电子信息产业股份有限公司,山东 济南 250101

信创 国产计算机 威胁模型 攻击路径 模糊层次分析法

2024

山东工业技术

山东工业技术

ISSN:
年,卷(期):2024.(6)