Theoretical Model for the Security Risk Quantitative Analysis of Large Software R & D Projects

WANG Changfeng,WANG Hualan
DOI: https://doi.org/10.3321/j.issn:1000-0054.2009.z2.005
2009-01-01
Abstract:The security risk probability of large software R & D projects is analyzed based on the documentation quality risk factor in the software coding phase as an actual case and the risk characteristics of complex systems.The "Fuzzy-FAT"quantitative analysis method combines fuzzy mathematics and fuzzy set theory.The method first calculates the top event probability and the probability importance of the end event, then the importance of the top event is used to determine the top event having the weakest links to reduce the top event probability.A case study shows that the system effectively uses the risk assessment of the top events to evaluate the event probability and the importance to identify security risks that influence the software development process safety and reliability.Therefore, the method effectively controls large software development project security issues in an efficient, controlled manner.
What problem does this paper attempt to address?