Information System Security Risk Assessment Based on Entropy Weight Method - Bayesian Network

Xinjian Lv,Nan Song,Jing Wei,Ye Tian,Jie Li,Jian Li
DOI: https://doi.org/10.1007/978-981-19-0523-0_10
2022-01-01
Abstract:Traditional information security risk assessment models usually rely on expert analysis to obtain prior knowledge, which leads to a greater impact on the results of security risk assessment by subjective bias. To solve this problem, we added the entropy weight method to the traditional Bayesian network-based information security risk assessment model. Entropy weight method is used to compute the weight coefficients of each risk factor involved in a risk event. Compared with traditional evaluation models, weighting risk factors during risk evaluation can effectively reduce the impact of excessive reliance on expert information, that is, excessive subjective factors, and theoretically improve the accuracy of the evaluation results. Finally, an instance of the risk assessment approach on the model is analyzed, which demonstrates the rationality and feasibility of this method.
What problem does this paper attempt to address?