期刊文献+

基于VAR的电子商务系统安全风险量化方法研究 被引量:3

VAR-Based Method of E-Commerce System Security Risk Quantification
在线阅读 下载PDF
导出
摘要 信息安全是制约电子商务发展的重要因素之一,安全风险的评估和量化是进行风险控制、保证交易安全的基础。该文分析了金融领域广泛使用的风险计算方法--VAR方法,在分析威胁、脆弱点及资产价值等风险因素的基础上,给出了风险因素的形式化表示及信息安全风险量化的VAR方法。通过仿真实验说明了VAR与安全投资之间的关系及利用VAR进行风险评估的意义。电子商务企业可以根据VAR值选择适当的控制措施,从而达到安全投资和风险的平衡。 Information security is a critical factor that restrain the development of E-commerce, security risk assessment and quantification is the foundation of risk control and trade security. In this paper, the value at risk (VAR) method used in the fields of financial risk assessment is introduced, the risk factors, threat, vulnerability, and assets are analized, and a risk quantification model and the method of calculating VAR are proposed. Simulation experiment shows the relationship between VAR and security investment as well as the significance of using VAR in risk assessment. E-commerce enterprises can select proper security control measures according to VAR and get a well trade-off between security investment and risk.
出处 《电子科技大学学报》 EI CAS CSCD 北大核心 2009年第S1期61-64,共4页 Journal of University of Electronic Science and Technology of China
基金 山东省教育厅科技计划(J07YJ14)
关键词 资产 风险量化 威胁 在险价值 脆弱点 assets risk quantification threat value at risk vulnerability
  • 相关文献

参考文献7

  • 1张一娆,杨世平.基于PRA的电子商务安全风险评估模型[J].计算机工程与设计,2008,29(17):4420-4422. 被引量:5
  • 2谢宗晓,刘振华,张文卿.VaR法在信息安全风险评估中的应用探讨[J].微计算机信息,2006,22(06X):76-77. 被引量:9
  • 3GORDON L A,LOEB M P,LUCYSHYN W,et al.CSI/FBI computer crime and security survey. http://duecare.biz/cgi-bin/mt/mt-tb.cgi/64 . 2009
  • 4MUKHOPADHYAY A,CHAKRABARTI B B,SAHA D,et al.E-risk management through self insurance:An option model. Proceedings of the40th Hawaii International Conference on System Sciences . 2007
  • 5Mercuri R T.Analyzing Security Costs. Communications of the ACM . 2003
  • 6T. A. Longstaff,C. Chittister,R. Pethia,Y. Y. Haimes.Are we forgettingthe risks of information technology?. IEEE Computer . 2000
  • 7Jorion P Value at Risk.The New Benchmark for Controlling Market Risk. . 1997

二级参考文献13

共引文献12

同被引文献19

引证文献3

二级引证文献31

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部