Fuzzy multi-attribute security risk assessment model

Gu Yonghao,Liu Yong
2007-01-01
Abstract:Successful practice indicates that security requirements and investments should refer to the result of risk assessment; however, simplistic risk assessment that results in lists of risks do not give sufficient information to rank risks when resources such as time and money are limited. This paper presents a fuzzy multi-attribute evaluation model. In this model, additive value function is used with an integrated weights assessing method in fuzzy environment; moreover, this model shows a new fuzzy distance measure to rank risks. With this model, fuzzy multi-attribute analysis provides a convenient framework to systematically develop risk assessments that the security manager can use to prioritize security requirements and make economical and reasonable security investments.
What problem does this paper attempt to address?