Using Fuzzy Logic and Entropy Theory to Risk Assessment of the Information Security

DongMei Zhao,Jinghong Wang,W. U. Jing,Jianfeng Ma
DOI: https://doi.org/10.1109/ICMLC.2005.1527355
2005-01-01
Abstract:In the previous research of the risk assessment, AHP method and Fuzzy logical method used are obvious subjectivity and limitation. In this paper, AHP method and Fuzzy logical method are improved, the formula of risk degree and entropy-weight coefficient are put forward to the estimation of the information security. Firstly, the hierarchy structure of the risk assessment is constructed and the method of fuzzy comprehensive judgment is improved according to the actual condition of the information security. Secondly, the risk degree put forward is likelihood estimation of the risk probability, the risk impact severity and risk uncontrollability. Finally, for the determination of the weight vector of the risk factor, a method of entropy-weight coefficient is applied to objective computation, and subjective judgment is overcome. The study of the case shows that the method can be easily used to the risk assessment of the information security and its results conform to the actual situation.
What problem does this paper attempt to address?