Netinfo Security ›› 2017, Vol. 17 ›› Issue (5): 69-73.doi: 10.3969/j.issn.1671-1122.2017.05.011

• Orginal Article • Previous Articles     Next Articles

Research on Information Systems Security Risk Assessment Based on Fuzzy Theory of Evidence

Xiaoning DONG1, Huarong ZHAO1(), Dianwei LI1, Jiasheng WANG2   

  1. 1. Naval Staff, Beijing 100841, China
    2. Department of Information Security, Naval University of Engineering, Wuhan Hubei 430033, China
  • Received:2017-02-21 Online:2017-05-20 Published:2020-05-12

Abstract:

Considering that there are many uncertainty factors in the process of information systems security risk assessment, such as lack of evaluation data, incomplete knowledge and system modeling, inadequate risk identification, method based on fuzzy theory of evidence was presented. Concepts of related risk assessment were introduced firstly, and calculation model for the information systems risk assessment was established after that. And then fuzzy sets were introduced into theory of evidence. The basic probability assignments which are core to theory of evidence were constructed using the membership function of fuzzy sets. When the fuzzy relations between risk indexes set and evaluation standard, the problem that the basic probability assignments were difficult to determine was solved. Moreover, the result is more reasonable. An illustration example dedicates that the method was feasible and effective, and provides reasonable data for constituting the risk control strategy of the information systems security.

Key words: DS theory of evidence, fuzzy sets, information systems, risk assessment

CLC Number: