The invention relates to the technical field of the
information security, in particular to a security evaluating and detecting method used for a cloud infrastructure. The method is completed by a device formed by a dispatching module, a
testing software library, a testing mirror, a testing configuration
library, a testing result
library, an analysis module, a testing requirement docment, a testing report and other modules. Configuration operating is carried out on the
testing software library by a user in advance before testing;
security testing software which exists in the market and aims at the cloud infrastructure and independently programmed
testing software programs are uploaded to the testing
software library; classification is carried out on the
software according to the usual classification, namely the
system security, the
network security, the
data security, the behavior security and the like, and the software is partitioned to different 'testing software lists'; the testing software library can be continuously updated, and the advancement and the maturity of the testing software are guaranteed. The problem of compatibility of the
information security testing method and the cloud calculation is solved, and the method can be used for security evaluating and testing of the cloud infrastructure.