%0 Journal Article %A CHEN Tian-ping %A GE Hai-hui %A YANG Yi-xian %A ZHENG Shi-hui %T Fuzzy Risk Assessment of Information Security Threat Scenario %D 2013 %R 10.13190/j.jbupt.2013.06.019 %J Journal of Beijing University of Posts and Telecommunications %P 89-92,107 %V 36 %N 6 %X
A risk assessment approach for threat scenario (TS) was proposed. Firstly, hierarchical index system of venture evaluation was constructed for TS, and a new index called uncontrollability was proposed to describe the uncontrollability of relationship between safety measures and risk formation, meanwhile, integrality of index system was enhanced. Secondly, membership function of indicators based on Gaussian function was defined, thereafter, an improved fuzzy comprehensive evaluation model based on membership matrix constructor method was given to reduce the influence of subjective factors. Finally, a combining method of fuzzy algorithm above and analytic hierarchy process were adopted to calculate the degree of risk quantitatively. The case study shows that this method is beneficial to risk size sort.
%U https://journal.bupt.edu.cn/EN/10.13190/j.jbupt.2013.06.019