首页 | 本学科首页   官方微博 | 高级检索  
     检索      

基于安全熵的多级访问控制模型量化分析方法
引用本文:车天伟,马建峰,王超,李娜.基于安全熵的多级访问控制模型量化分析方法[J].华东师范大学学报(自然科学版),2015,2015(1):172-177.
作者姓名:车天伟  马建峰  王超  李娜
作者单位:1. 西安电子科技大学 计算机学院, 西安 710071;
2. 解放军信息工程大学 郑州 450001; 3.西北工业大学 计算机学院, 西安 710129
基金项目:国家自然科学基金资助项目,中央高校基本科研业务费专项资金资助项目
摘    要:针对访问控制模型的安全性分析与证明问题,提出了基于安全熵的量化分析方法.首先,结合信息论有关知识引入安全熵的概念,提出了系统对违规访问行为响应的不确定性计算方法;然后,基于安全熵提出了不同等级信息系统的安全性定理;最后,应用该方法对经典安全模型进行了量化分析,验证了该方法的实用性,并比较了这些访问控制模型安全性以及在等级化信息系统中的适用性.结果证明该方法可适用于访问控制模型的安全性度量以及系统的访问控制能力评估.

关 键 词:信息熵  安全熵  等级化访问控制模型  直接违规访问  流向违规访问
收稿时间:2014-08-01

A quantitative analysis technique for multi-classes access control model based on security entropy
CHE Tian-wei,MA Jian-feng,WANG Chao,LI Na.A quantitative analysis technique for multi-classes access control model based on security entropy[J].Journal of East China Normal University(Natural Science),2015,2015(1):172-177.
Authors:CHE Tian-wei  MA Jian-feng  WANG Chao  LI Na
Institution:CHE Tian-wei;MA Jian-feng;WANG Chao;LI Na;School of Computer Science and Technology,Xidian University;PLA Information Engineering University;School of Computer Science and Technology,Northwestern Polytechnical University;
Abstract:To resolve the problem of quantitative analysis on classificatory information systems, a quantitative analysis technique is proposed based on security entropy. Firstly, the security entropy is put forward according to the information theory, to calculate the uncertainty of the system''s determinations on the
irregular access behaviors. Then the security theorems of classificatory information systems are defined based on security entropy. Finally, the typical access control models are analyzed by the technique, the technique''s practicability is validated, and security and applicability of these models are compared. The result proves that the technique is suit for security quantitative analysis on access control model and evaluation to access control capability in information system
Keywords:information entropy  security entropy  classificatory access control model  directly unauthorized access  right about access
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《华东师范大学学报(自然科学版)》浏览原始摘要信息
点击此处可从《华东师范大学学报(自然科学版)》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号