Abstract
The meaning of Information Security is variation at different times, developing
from cryptography to information security assurance system. Accordingly, how to
ensure the security of information system should be considered from complete
technology framework and whole system; at the same time, the assurance system of
information security has changed from technology-only reductionism to systematicism
based on technology, management and process, where systematic assurance framework
of information security compared with information security of production and
technology. With the developing of information security, single technology and product
has become well-developed, and the idea of systematic information security has been
accepted gradually. However, how to give the systematic information security a
quantitative analysis is still a vacancy. The research in this field stays in qualitative level
or quantitative analysis in some aspects. Whereas, what the users of information system
care most and the most important problem is the security level of whole information
system. So we need to design a total measurement of systematic information security,
which is studied in this dissertation: systematic quantitative assessment framework of
information security.
Comparing with static assessment, which is assessment of security level of
information system, dynamic assessment is considering the whole life cycle of
information system. With dynamic assessment, we can find out the sensitivity of
security factor to whole information security quantitative system, the availability of
information security policy, the effect of assurance process to system security, and the
minimal cost of endurable security level. We use the theory of Systematic, Management,
Mathematics and Computer Science in studying the technology, management and
process of information security, to build quantitative assessment system of information
security assurance framework. The main points are listed below:
A complete information security assurance system is dynamic, systematic, and
complete, for information security is developing from single confidentiality to
confidentiality, integrity and availability based on the 3-D system of process,
technology and management. Based on the engineering practice, we conclude a
direction system of “one project, two factor assurance, three dimension vectors, four
tools, and five level” about systematic information quantitative assessment framework.
The representation of this direction system is quantitative model, quantitative tools, and
quantitative process.
We study five basis quantitative models: threat-tree model based on threat analysis,
which is the basis of quantitative information confidentiality, integrity and availability;
AHP model, which has high efficiency and practice with fully consider the effect of
expert group; dynamic weight model, which is fit for multi-target information security
quantitative assurance system; quantitative table model based on assurance framework,
which can simply quantities using database technology; control-feedback model, which
is fit for online assessment to make quantitative assessment more dynamic and
controllable. We often interactively use these models in our assessment practice. Our
research and summarization on the models found the basis of quantitative assessment.
Based on the quantitative model, we develop assessment tools and software
prototype for quantitative assessment. The assessment tools and software’s are