Information security risk assessment is a new technology in China, there are so many difficulties in its application. In this paper, we introduced Bayesian network into information security risk assessment system based on risk analysis studies. Firstly, we create a risk assessment model based on Bayesian network, which used probabilistic reasoning to seek value at risk and combined with expert knowledge. And then we give a risk assessment model system architecture network based on Bayesian analysis and the corresponding security knowledge base in detail. Finally, we present an implementation of risk analysis module based on Bayesian network, and used it to analyze an example. We believe that the model of information security risk assessment based on Bayesian analysis is an effective model of risk assessment system.
Zijie DengGuocong FengQingshui HuangHong ZouJiafa Zhang
Pavel YermalovichMohamed Mejri