Summary of the invention
In view of the deficiencies of the prior art, the electric power mobile terminal based on analytic hierarchy process (AHP) that the object of the present invention is to provide a kind of
Safety evaluation method and device obtain electric power mobile terminal by the threat index of the security threat using electric power mobile terminal
Safety index carries out security evaluation to electric power mobile terminal using the safety index of the electric power mobile terminal, reduces electric power and move
The security threat bring negative effect of dynamic terminal, reduces a possibility that potential problems occur, ensure that electric power mobile terminal
Safe and stable operation.
The purpose of the present invention is adopt the following technical solutions realization:
A kind of electric power mobile terminal security appraisal procedure, it is improved in that the described method includes:
The safety index of electric power mobile terminal is obtained using the threat index of the security threat of electric power mobile terminal;
Security evaluation is carried out to electric power mobile terminal using the safety index of the electric power mobile terminal.
Preferably, the threat index of the security threat using electric power mobile terminal obtains the safety of electric power mobile terminal
Before index, comprising:
Determine that i-th kind of security threat of electric power mobile terminal causes at the loss amount nondimensionalization of jth kind consequence as the following formula
Reason value vi,j*:
In above formula, i ∈ [1, N], N are total type of the security threat of electric power mobile terminal, j ∈ [1, M], k ∈ [1, M], M
Total type of consequence caused by security threat for electric power mobile terminal;vi,jIt is made for i-th kind of security threat of electric power mobile terminal
At the loss amount of jth kind consequence,The loss amount of consequence caused by i-th kind of security threat for electric power mobile terminal
Maximum value;
The threat index T of i-th kind of security threat of electric power mobile terminal is determined as the following formulai:
In above formula, WjThe weight of jth kind consequence, P caused by security threat for electric power mobile terminaliFor electric power mobile end
The probability that i-th kind of security threat at end occurs.
Preferably, the threat index of the security threat using electric power mobile terminal obtains the safety of electric power mobile terminal
Index, comprising:
S1. selection is more than or equal to the security threat of the corresponding electric power mobile terminal of threat index of secure threshold;
S2. the safety of the electric power mobile terminal is obtained using the threat index of the security threat of the electric power mobile terminal
Threaten the weight coefficient of influenced index of security assessment generic;
S3. the weight system of the index of security assessment generic influenced using the security threat of the electric power mobile terminal
Number obtains the safety index of electric power mobile terminal.
Further, the step S2, comprising:
S2-1. determine the index of security assessment generic a's that the security threat of electric power mobile terminal is influenced as the following formula
Threat index Za:
In above formula, index of security assessment generic that a ∈ [1, A], A are influenced by the security threat of electric power mobile terminal
Total type;b∈[1,Ba], BaIt is electric in the index of security assessment generic a influenced by the security threat of electric power mobile terminal
The total quantity for the index of security assessment that the security threat of power mobile terminal is influenced;Ta,bFor the security threat of electric power mobile terminal
The security evaluation that the security threat of b-th of electric power mobile terminal is influenced in the index of security assessment generic a influenced refers to
Mark the threat index of the security threat of corresponding electric power mobile terminal;
S2-2. the threat of the index of security assessment generic influenced according to the security threat of the electric power mobile terminal
The affiliated class of index of security assessment that index influences the security threat of the electric power mobile terminal according to sequence from big to small
It is not ranked up, obtains the index of security assessment generic sequence that the security threat of electric power mobile terminal is influenced;
S2-3. the index of security assessment generic sequence that the security threat of electric power mobile terminal is influenced is determined as the following formula
The weight coefficient Y for the index of security assessment generic d that the security threat of middle electric power mobile terminal is influencedd:
In above formula, rdIt is electric in the index of security assessment generic sequence influenced by the security threat of electric power mobile terminal
The different degree for the index of security assessment generic d that the security threat of power mobile terminal is influenced,D ∈ [1, D], D
The safety of electric power mobile terminal in the index of security assessment generic sequence influenced by the security threat of electric power mobile terminal
Threaten the serial number maximum value of influenced index of security assessment generic.
Specifically, the step S3, comprising:
Matrix G is set as the following formula:
G=[Y1,Y2, Yd,···,YD]
The safety index S of electric power mobile terminal is determined as the following formula:
S=G β
In above formula, β is fragility coefficient matrix, whereinβdFor the security threat institute shadow of electric power mobile terminal
The fragile property coefficient of loud index of security assessment generic d.
Preferably, the safety index of the electric power mobile terminal is directly proportional to the safety of the electric power mobile terminal.
A kind of electric power mobile terminal security assessment device, it is improved in that described device includes:
Acquiring unit obtains the peace of electric power mobile terminal for the threat index of the security threat using electric power mobile terminal
Total index number;
Assessment unit carries out safety to electric power mobile terminal for the safety index using the electric power mobile terminal and comments
Estimate.
Preferably, described device, further includes:
First determination unit, for determining that i-th kind of security threat of electric power mobile terminal causes jth kind consequence as the following formula
Loss amount nondimensionalization processing costs vi,j*:
In above formula, i ∈ [1, N], N are total type of the security threat of electric power mobile terminal, j ∈ [1, M], k ∈ [1, M], M
Total type of consequence caused by security threat for electric power mobile terminal;vi,jIt is made for i-th kind of security threat of electric power mobile terminal
At the loss amount of jth kind consequence,The loss amount of consequence caused by i-th kind of security threat for electric power mobile terminal
Maximum value;
Second determination unit, the threat index T of i-th kind of security threat for determining electric power mobile terminal as the following formulai:
In above formula, WjThe weight of jth kind consequence, P caused by security threat for electric power mobile terminaliFor electric power mobile end
The probability that i-th kind of security threat at end occurs.
Preferably, the acquiring unit, comprising:
Selecting module, for selecting the safe prestige of the corresponding electric power mobile terminal of threat index more than or equal to secure threshold
The side of body;
First obtains module, and the threat index for the security threat using the electric power mobile terminal obtains the electric power
The weight coefficient for the index of security assessment generic that the security threat of mobile terminal is influenced;
Second obtains module, the index of security assessment institute for being influenced using the security threat of the electric power mobile terminal
The weight coefficient for belonging to classification obtains the safety index of electric power mobile terminal.
Further, described first module is obtained, comprising:
First determines submodule, and the security evaluation for determining that the security threat of electric power mobile terminal is influenced as the following formula refers to
Mark the threat index Z of generic aa:
In above formula, index of security assessment generic that a ∈ [1, A], A are influenced by the security threat of electric power mobile terminal
Total type;b∈[1,Ba], BaIt is electric in the index of security assessment generic a influenced by the security threat of electric power mobile terminal
The total quantity for the index of security assessment that the security threat of power mobile terminal is influenced;Ta,bFor the security threat of electric power mobile terminal
The security evaluation that the security threat of b-th of electric power mobile terminal is influenced in the index of security assessment generic a influenced refers to
Mark the threat index of the security threat of corresponding electric power mobile terminal;
First acquisition submodule, the index of security assessment for being influenced according to the security threat of the electric power mobile terminal
The safety that the threat index of generic influences the security threat of the electric power mobile terminal according to sequence from big to small
Evaluation index generic is ranked up, and obtains the affiliated class of index of security assessment that the security threat of electric power mobile terminal is influenced
Other sequence;
Second determines submodule, and the security evaluation for determining that the security threat of electric power mobile terminal is influenced as the following formula refers to
The weight coefficient for the index of security assessment generic d that the security threat of electric power mobile terminal is influenced in mark generic sequence
Yd:
In above formula, rdIt is electric in the index of security assessment generic sequence influenced by the security threat of electric power mobile terminal
The different degree for the index of security assessment generic d that the security threat of power mobile terminal is influenced,D ∈ [1, D], D
The safety of electric power mobile terminal in the index of security assessment generic sequence influenced by the security threat of electric power mobile terminal
Threaten the serial number maximum value of influenced index of security assessment generic.
Specifically, described second obtains module, comprising:
Submodule is set, for matrix G to be arranged as the following formula:
G=[Y1,Y2, Yd,···,YD]
Third determines submodule, for determining the safety index S of electric power mobile terminal as the following formula:
S=G β
In above formula, β is fragility coefficient matrix, whereinβdFor the security threat institute shadow of electric power mobile terminal
The fragile property coefficient of loud index of security assessment generic d.
Preferably, the safety index of the electric power mobile terminal is directly proportional to the safety of the electric power mobile terminal.
Compared with the immediate prior art, the invention has the benefit that
Technical solution provided by the invention obtains electric power by the threat index of the security threat using electric power mobile terminal
The safety index of mobile terminal carries out security evaluation to electric power mobile terminal using the safety index of the electric power mobile terminal,
Corresponding safety measure can be taken according to assessment result, and is targetedly disposed, and the peace of electric power mobile terminal is reduced
It is complete to threaten bring negative effect, a possibility that potential problems occur is reduced, ensure that the safety and stability fortune of electric power mobile terminal
Row.
Specific embodiment
Specific embodiments of the present invention will be described in further detail with reference to the accompanying drawing.
In order to make the object, technical scheme and advantages of the embodiment of the invention clearer, below in conjunction with the embodiment of the present invention
In attached drawing, technical scheme in the embodiment of the invention is clearly and completely described, it is clear that described embodiment is
A part of the embodiment of the present invention, instead of all the embodiments.Based on the embodiments of the present invention, those of ordinary skill in the art
All other embodiment obtained without making creative work, shall fall within the protection scope of the present invention.
The present invention provides a kind of electric power mobile terminal security appraisal procedures, as shown in Figure 1, which comprises
The safety index of electric power mobile terminal is obtained using the threat index of the security threat of electric power mobile terminal;
Security evaluation is carried out to electric power mobile terminal using the safety index of the electric power mobile terminal.
Further, the threat index of the security threat using electric power mobile terminal obtains the peace of electric power mobile terminal
Before total index number, comprising:
Determine that i-th kind of security threat of electric power mobile terminal causes at the loss amount nondimensionalization of jth kind consequence as the following formula
Reason value vi,j*:
In above formula, i ∈ [1, N], N are total type of the security threat of electric power mobile terminal, j ∈ [1, M], k ∈ [1, M], M
Total type of consequence caused by security threat for electric power mobile terminal;vi,jIt is made for i-th kind of security threat of electric power mobile terminal
At the loss amount of jth kind consequence,The loss amount of consequence caused by i-th kind of security threat for electric power mobile terminal
Maximum value;
The threat index T of i-th kind of security threat of electric power mobile terminal is determined as the following formulai:
In above formula, WjThe weight of jth kind consequence, P caused by security threat for electric power mobile terminaliFor electric power mobile end
The probability that i-th kind of security threat at end occurs.
For example, consequence caused by the security threat of electric power mobile terminal can be with are as follows: not can be carried out key operation, loss production
Power, damages public reputation and endangers public security loss income.
Further, the threat index of the security threat using electric power mobile terminal obtains the peace of electric power mobile terminal
Total index number, comprising:
S1. selection is more than or equal to the security threat of the corresponding electric power mobile terminal of threat index of secure threshold;
S2. the safety of the electric power mobile terminal is obtained using the threat index of the security threat of the electric power mobile terminal
Threaten the weight coefficient of influenced index of security assessment generic;
S3. the weight system of the index of security assessment generic influenced using the security threat of the electric power mobile terminal
Number obtains the safety index of electric power mobile terminal.
Specifically, the step S2, comprising:
S2-1. determine the index of security assessment generic a's that the security threat of electric power mobile terminal is influenced as the following formula
Threat index Za:
In above formula, index of security assessment generic that a ∈ [1, A], A are influenced by the security threat of electric power mobile terminal
Total type;b∈[1,Ba], BaIt is electric in the index of security assessment generic a influenced by the security threat of electric power mobile terminal
The total quantity for the index of security assessment that the security threat of power mobile terminal is influenced;Ta,bFor the security threat of electric power mobile terminal
The security evaluation that the security threat of b-th of electric power mobile terminal is influenced in the index of security assessment generic a influenced refers to
Mark the threat index of the security threat of corresponding electric power mobile terminal;
For example, the security evaluation analytical table of electric power mobile terminal as shown in Table 1, lists some electrical power mobile terminal
Security threat, the security threat index of security assessment influenced of electric power mobile terminal and the security threat institute of electric power mobile terminal
The index of security assessment generic of influence utilizes the threat index of the security threat of the electric power mobile terminal of above method acquisition
The threat index of the index of security assessment generic influenced with the security threat of electric power mobile terminal.
The security evaluation analytical table of 1 electric power mobile terminal of table
S2-2. the threat of the index of security assessment generic influenced according to the security threat of the electric power mobile terminal
The affiliated class of index of security assessment that index influences the security threat of the electric power mobile terminal according to sequence from big to small
It is not ranked up, obtains the index of security assessment generic sequence that the security threat of electric power mobile terminal is influenced;
S2-3. the index of security assessment generic sequence that the security threat of electric power mobile terminal is influenced is determined as the following formula
The weight coefficient Y for the index of security assessment generic d that the security threat of middle electric power mobile terminal is influencedd:
In above formula, rdIt is electric in the index of security assessment generic sequence influenced by the security threat of electric power mobile terminal
The different degree for the index of security assessment generic d that the security threat of power mobile terminal is influenced,D ∈ [1, D], D
The safety of electric power mobile terminal in the index of security assessment generic sequence influenced by the security threat of electric power mobile terminal
Threaten the serial number maximum value of influenced index of security assessment generic.
Further, the safety index of the electric power mobile terminal is directly proportional to the safety of the electric power mobile terminal.
For example, can be obtained using the above method: the security evaluation that the security threat of the electric power mobile terminal in table 1 is influenced refers to
Mark generic hardware classes, network class, system class, using class, data class, perception class and manage class weight coefficient be respectively
0.1097,0.1975,0.1975,0.1975,0.1097,0.1097 and 0.0784;
Specifically, the step S3, comprising:
Matrix G is set as the following formula:
G=[Y1,Y2, Yd,···,YD]
For example, G=[0.1097,0.1975,0.1975,0.1975,0.1097,0.1097,0.0784]
The safety index S of electric power mobile terminal is determined as the following formula:
S=G β
In above formula, β is fragility coefficient matrix, whereinβdFor the security threat institute shadow of electric power mobile terminal
The fragile property coefficient of loud index of security assessment generic d.
For example, the index of security assessment influenced using the security threat that Field Using Fuzzy Comprehensive Assessment obtains electric power mobile terminal
Generic hardware classes, network class, system class, using class, data class, perception class and manage the fragile property coefficient of class be respectively 2,
6,4,2,7,5 and 1, then
The final safety index S=3.9842 for obtaining electric power mobile terminal;
If the safety index of electric power mobile terminal belongs to first threshold range, the security evaluation of the electric power mobile terminal
It as a result is very poor;
If the safety index of electric power mobile terminal belongs to second threshold range, the security evaluation of the electric power mobile terminal
It as a result is poor;
If the safety index of electric power mobile terminal belongs to third threshold range, the security evaluation of the electric power mobile terminal
It as a result is general;
If the safety index of electric power mobile terminal belongs to the 4th threshold range, the security evaluation of the electric power mobile terminal
It as a result is good;
If the safety index of electric power mobile terminal belongs to the 5th threshold range, the security evaluation of the electric power mobile terminal
It as a result is outstanding.
Such as: if the safety index of electric power mobile terminal belong to [0,3), then the security evaluation knot of the electric power mobile terminal
Fruit is very poor;
If the safety index of electric power mobile terminal belong to [3,6), then the security assessment result of the electric power mobile terminal is
Difference;
If the safety index of electric power mobile terminal belong to [6,7), then the security assessment result of the electric power mobile terminal is
Generally;
If the safety index of electric power mobile terminal belong to [7,9), then the security assessment result of the electric power mobile terminal is
Well;
If the safety index of electric power mobile terminal belong to [9,10), then the security assessment result of the electric power mobile terminal is
It is outstanding.
Due to the safety index S=3.9842 of electric power mobile terminal, then the security assessment result of the electric power mobile terminal
For difference.
Electric power mobile terminal security index is divided into hardware classes, network class, system class, application by embodiment provided by the invention
Class, data class, perception class and management class cover two aspect of electric power mobile terminal inherently safe and security management and control, and can be directed to
The features such as electric power mobile terminal data is sensitive, business is crucial.
The present invention also provides a kind of electric power mobile terminal securities to assess device, as shown in Fig. 2, described device includes:
Acquiring unit obtains the peace of electric power mobile terminal for the threat index of the security threat using electric power mobile terminal
Total index number;
Assessment unit carries out safety to electric power mobile terminal for the safety index using the electric power mobile terminal and comments
Estimate.
Further, described device, further includes:
First determination unit, for determining that i-th kind of security threat of electric power mobile terminal causes jth kind consequence as the following formula
Loss amount nondimensionalization processing costs vi,j*:
In above formula, i ∈ [1, N], N are total type of the security threat of electric power mobile terminal, j ∈ [1, M], k ∈ [1, M], M
Total type of consequence caused by security threat for electric power mobile terminal;vi,jIt is made for i-th kind of security threat of electric power mobile terminal
At the loss amount of jth kind consequence,The loss amount of consequence caused by i-th kind of security threat for electric power mobile terminal
Maximum value;
Second determination unit, the threat index T of i-th kind of security threat for determining electric power mobile terminal as the following formulai:
In above formula, WjThe weight of jth kind consequence, P caused by security threat for electric power mobile terminaliFor electric power mobile end
The probability that i-th kind of security threat at end occurs.
Further, the acquiring unit, comprising:
Selecting module, for selecting the safe prestige of the corresponding electric power mobile terminal of threat index more than or equal to secure threshold
The side of body;
First obtains module, and the threat index for the security threat using the electric power mobile terminal obtains the electric power
The weight coefficient for the index of security assessment generic that the security threat of mobile terminal is influenced;
Second obtains module, the index of security assessment institute for being influenced using the security threat of the electric power mobile terminal
The weight coefficient for belonging to classification obtains the safety index of electric power mobile terminal.
Specifically, described first obtains module, comprising:
First determines submodule, and the security evaluation for determining that the security threat of electric power mobile terminal is influenced as the following formula refers to
Mark the threat index Z of generic aa:
In above formula, index of security assessment generic that a ∈ [1, A], A are influenced by the security threat of electric power mobile terminal
Total type;b∈[1,Ba], BaIt is electric in the index of security assessment generic a influenced by the security threat of electric power mobile terminal
The total quantity for the index of security assessment that the security threat of power mobile terminal is influenced;Ta,bFor the security threat of electric power mobile terminal
The security evaluation that the security threat of b-th of electric power mobile terminal is influenced in the index of security assessment generic a influenced refers to
Mark the threat index of the security threat of corresponding electric power mobile terminal;
First acquisition submodule, the index of security assessment for being influenced according to the security threat of the electric power mobile terminal
The safety that the threat index of generic influences the security threat of the electric power mobile terminal according to sequence from big to small
Evaluation index generic is ranked up, and obtains the affiliated class of index of security assessment that the security threat of electric power mobile terminal is influenced
Other sequence;
Second determines submodule, and the security evaluation for determining that the security threat of electric power mobile terminal is influenced as the following formula refers to
The weight coefficient for the index of security assessment generic d that the security threat of electric power mobile terminal is influenced in mark generic sequence
Yd:
In above formula, rdIt is electric in the index of security assessment generic sequence influenced by the security threat of electric power mobile terminal
The different degree for the index of security assessment generic d that the security threat of power mobile terminal is influenced,D ∈ [1, D], D
The safety of electric power mobile terminal in the index of security assessment generic sequence influenced by the security threat of electric power mobile terminal
Threaten the serial number maximum value of influenced index of security assessment generic.
Specifically, described second obtains module, comprising:
Submodule is set, for matrix G to be arranged as the following formula:
G=[Y1,Y2, Yd,···,YD]
Third determines submodule, for determining the safety index S of electric power mobile terminal as the following formula:
S=G β
In above formula, β is fragility coefficient matrix, whereinβdFor the security threat institute shadow of electric power mobile terminal
The fragile property coefficient of loud index of security assessment generic d.
Further, the safety index of the electric power mobile terminal is directly proportional to the safety of the electric power mobile terminal.
It should be understood by those skilled in the art that, embodiments herein can provide as method, system or computer program
Product.Therefore, complete hardware embodiment, complete software embodiment or reality combining software and hardware aspects can be used in the application
Apply the form of example.Moreover, it wherein includes the computer of computer usable program code that the application, which can be used in one or more,
The computer program implemented in usable storage medium (including but not limited to magnetic disk storage, CD-ROM, optical memory etc.) produces
The form of product.
The application is referring to method, the process of equipment (system) and computer program product according to the embodiment of the present application
Figure and/or block diagram describe.It should be understood that every one stream in flowchart and/or the block diagram can be realized by computer program instructions
The combination of process and/or box in journey and/or box and flowchart and/or the block diagram.It can provide these computer programs
Instruct the processor of general purpose computer, special purpose computer, Embedded Processor or other programmable data processing devices to produce
A raw machine, so that being generated by the instruction that computer or the processor of other programmable data processing devices execute for real
The device for the function of being specified in present one or more flows of the flowchart and/or one or more blocks of the block diagram.
These computer program instructions, which may also be stored in, is able to guide computer or other programmable data processing devices with spy
Determine in the computer-readable memory that mode works, so that it includes referring to that instruction stored in the computer readable memory, which generates,
Enable the manufacture of device, the command device realize in one box of one or more flows of the flowchart and/or block diagram or
The function of being specified in multiple boxes.
These computer program instructions also can be loaded onto a computer or other programmable data processing device, so that counting
Series of operation steps are executed on calculation machine or other programmable devices to generate computer implemented processing, thus in computer or
The instruction executed on other programmable devices is provided for realizing in one or more flows of the flowchart and/or block diagram one
The step of function of being specified in a box or multiple boxes.
Finally it should be noted that: the above embodiments are merely illustrative of the technical scheme of the present invention and are not intended to be limiting thereof, to the greatest extent
Invention is explained in detail referring to above-described embodiment for pipe, it should be understood by those ordinary skilled in the art that: still
It can be with modifications or equivalent substitutions are made to specific embodiments of the invention, and without departing from any of spirit and scope of the invention
Modification or equivalent replacement, should all cover within the scope of the claims of the present invention.