基于灰色模糊综合理论的信息系统定级

    Classification of Information System Based on Gray-fuzzy Comprehensive Theory

    • 摘要: 针对信息安全等级保护系统定级时存在大量人为主观性的问题,提出了运用灰色模糊理论与信息熵相结合来辅助确定信息系统安全保护等级的方法.首先,构造关于定级指标的灰色样本矩阵,采用灰色模糊理论确定灰色评价矩阵;然后,通过信息熵确定指标权重,计算得到客体被侵害程度;最后,依据传统定级方法(矩阵法)确定系统安全等级.以一个企业信息系统的子系统为例,使用该方法得到子系统客体被侵害程度为2.379,并最终确定该信息系统的安全保护等级为三级.实例结果表明:该定级方法采用定量与定性结合的方式能够有效确定信息系统安全保护等级,使得定级更为客观,是对传统方法的有效补充.

       

      Abstract: To solve the problem of human subjectivity in the process of classification of system, an approach of information system grading based on gray-fuzzy comprehensive theory and information entropy was proposed. Firstly, a gray-sample matrix of grading indexes was constructed and a gray-evaluation matrix was obtained by gray-fuzzy theory. Then, the weights of grading indexes were calculated by information entropy and the severity of object damage was determined. Finally, the grading of information system by combing the matrix method was obtained. An illustrative instance of the subsystem of the enterprise information system was given to demonstrate the general process of information system grading. Results show that the damage degree of subsystem object is 2.379 and the protection classification is determined as the grade-Ⅲ. The experimental analysis proves that the proposed grading method can determine effectively the level of information system. Meanwhile, it acts as a subsidiary of traditional qualitative method.

       

    /

    返回文章
    返回