AN INFORMATION SECURITY RISK ASSESSMENT MODEL BASED ON BAYESIAN NETWORK AND FUZZY INFERENCE SYSTEM
Öz
This study proposes a novel information security risk assessment approach based on Bayesian network and Fuzzy Inference System in order to evaluate and calculate both qualitative and / or quantitative risks. The proposed model is developed to analyse test processes for a software services company in order to evaluate the information security risks. Threats, vulnerabilities, risks, and their relations are constructed with a Bayesian network and marginal probabilities are calculated for each risk factor. Several fuzzy membership functions and fuzzy decision rules are designed and constructed for assets’ values, risks’ probabilities, and relative risk values. Finally, the impacts of risk values are calculated after the aggregation and defuzzification process. It is shown that this new model enables the business decision makers and managers to obtain more objective, reliable, and flexible information security risk assessment results.
Anahtar Kelimeler
Kaynakça
- Altuzarra, A., Moreno-Jimnez, J., and Salvador, M. (2007). "A Bayesian prioritization procedure for AHP-group decision making". European Journal of Operation Research, 18(1), pp. 367-382.
- Ariyanti, R., Kusumadewi, S., and Paputungan, I. (2010). "Beck Depression Inventory Test Assessment Using Fuzzy Inference System", Proccedings of IEEE Intelligent Systems. Modelling and Simulation 2010 International Conference, Liverpool, UK, pp. 6-9.
- Award, G., Suitan, E., Ahmad, N., Ithnan, N., and Beg, A. (2011). "Multi-objective model to process security risk assessment based on AHP-PSO". Modern Applied Science, 5(3), pp. 246-250.
- Barber, D. (2011). Bayesian Reasoning and Machine Learning. Cambridge University Press, UK.
- Bayraktarlı, Y., Ulfkjaer, J., Yazgan, U., and Faber, M. (2005). "On the Application of Bayesian Probabilistic Networks for Earthquake Risk Management", Proceedings of 9th International Conference on Structural Safety and Reliability (ICOSSAR 05), Rome, Italy, pp. 20-23.
- Çiçekli, U. G. and Karaçizmeli, A. (2013). "Bulanık Analitik Hiyerarşi Süreci ile Başarılı Öğrenci Seçimi: Ege Üniversitesi İktisadi ve İdari Bilimler Fakültesi Örneği". Ege Stratejik Araştırmalar Dergisi, 4(1), pp.71-94.
- Beken S. and Eminağaoğlu M. (2018). “Information Security Risk Assessment using Bayesian Network and Fuzzy Inference System: A Case Study”, ICATCES2018, Proceedings of International Conference on Advanced Technologies, Computer Engineering and Science, May 11-13, 2018, Safranbolu, Turkey, pp: 1-8.
- Chin, K., Tang, D., Yang, J., Wong, S., and Wang, H. (2009). "Assessing New Product Development Project Risk By Bayesian Network With a Systematic Probability Generation Methodology". Expert Systems with Applications, 36(6), pp. 9879-9890.
Ayrıntılar
Birincil Dil
İngilizce
Konular
-
Bölüm
Araştırma Makalesi
Yazarlar
Sevilay Beken
Bu kişi benim
0000-0003-2456-919X
Türkiye
Yayımlanma Tarihi
25 Ocak 2019
Gönderilme Tarihi
3 Ocak 2019
Kabul Tarihi
21 Ocak 2019
Yayımlandığı Sayı
Yıl 2019 Cilt: 10 Sayı: 1