首页 | 本学科首页   官方微博 | 高级检索  
     

铁路客票发售与预订系统风险评估研究
引用本文:赵英明,张德栋,徐东平,李聚宝. 铁路客票发售与预订系统风险评估研究[J]. 铁道运输与经济, 2020, 0(1): 72-76,83
作者姓名:赵英明  张德栋  徐东平  李聚宝
作者单位:中国铁道科学研究院研究生部;中国铁道科学研究院集团有限公司电子计算技术研究所
基金项目:中国铁路总公司科研计划系统重大课题(P2018X002)
摘    要:随着科学技术的发展,我国铁路互联网售票日益重要,随之而来的安全风险问题日益突出。信息安全风险评估的3个要素包括:资产、威胁和脆弱性。我国铁路客票发售与预订系统主要面临的安全威胁包括:基础环境的风险、外部威胁的风险、业务系统的风险、管理和人员问题的风险因素集合。基于铁路客票发售与预订系统的架构和业务特性,提出了一种适用于铁路客票发售与预订系统的风险评估模型,通过对某铁路局集团公司铁路客票发售与预订系统子系统实际测试,表明该模型具有良好的可操作性。

关 键 词:铁路客票  发售与预订系统  风险评估  网络安全  威胁分析

A Study on the Risk Assessment of Railway Ticket Selling and Reservation System
ZHAO Yingming,ZHANG Dedong,XU Dongping,LI Jubao. A Study on the Risk Assessment of Railway Ticket Selling and Reservation System[J]. Rail Way Transport and Economy, 2020, 0(1): 72-76,83
Authors:ZHAO Yingming  ZHANG Dedong  XU Dongping  LI Jubao
Affiliation:(Graduate Department,China Academy of Railway Sciences,Beijing 100081,China;Institute of Computing Technology,China Academy of Railway Sciences Corporation Limited,Beijing 100081,China)
Abstract:With the development of science and technology, the application of internet ticketing in China’s railway is becoming more important. The following security risk problems are also increasingly prominent. The three elements of information risk assessment include assets, threats and vulnerabilities. The main security risk of China’s railway ticket selling and reservation system include the following collection of risk factors: the risk of basic environment, the risk of external threats, the risk of business system, the risk of management and personnel issues. Based on the structure and business characteristics of railway ticket selling and reservation system, this paper puts forward a risk assessment model suitable for the system of ticket sales and reservation. Through the actual test of the subsystem of the railway ticket selling and reservation system of a railway bureau group company, the resuct shows that the model has good operability.
Keywords:Railway Passenger Ticket  Ticket Selling and Reservation System  Risk Assessment  Network Security  Threat Analysis
本文献已被 CNKI 维普 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号