Computer Engineering & Science ›› 2022, Vol. 44 ›› Issue (08): 1372-1381.
• Computer Network and Znformation Security • Previous Articles Next Articles
WANG Ke-ke1,GUO Li-li1,LANG Jing-hong2
Received:
Revised:
Accepted:
Online:
Published:
Abstract: The existing security risk assessment methods and models do not fully consider the impact of the risk assessment behavior itself on the assessment results, which is a big lack of understanding that the behavior of risk assessment may introduce security risk. In response to this problem, this paper first establishes a complete STAMP model of risk assessment behavior. On this basis, the STPA analysis method is used to conduct security analysis on risk assessment behavior, the STAMP theory is used to construct a risk assessment behavior security index system, and the improved AHP method is used to screen important index factors in the security index system. The proposed security index system focuses on the emergence of the system as a whole rather than the reliability of individual components. According to the reasons for the occurrence or danger of system safety accidents, it provides a more effective way of constructing a safety index system.
Key words: information system, risk assessment, security index, system-theoretic accident model and process(STAMP), system theoretic process analysis(STPA), improved AHP algorithm
WANG Ke-ke, GUO Li-li, LANG Jing-hong. A security index system of security risk assessment behavior based on STAMP model[J]. Computer Engineering & Science, 2022, 44(08): 1372-1381.
0 / / Recommend
Add to citation manager EndNote|Ris|BibTeX
URL: http://joces.nudt.edu.cn/EN/
http://joces.nudt.edu.cn/EN/Y2022/V44/I08/1372