A Hybrid Information Security Risk Assessment Model Based on DEMATEL-ANP and D-S Evidential Theory
WU Tianshui
ZHAO Gang
Abstract:To address the issue of the deficiency in aspects of association and objectivity in current available researches , considering the association influence among risk assessment elements and the uncertainty produced in the process of evalua -tion ,a hybrid information security risk assessment model based on the combination methods of DEMATE-ANP(referred as decision making trial and evaluation laboratory combine analytic network process ) and D-S evidential theory is proposed .Ac-cording to practical running conditions of the system being assessed ,by the proposed approach ,first the network model is constructed ,and DEMATEL-ANP quantization is used to analyze the relevance in the model .Then ,D-S evidential theory is used to dispose data those are subjective and uncertainty .Finally ,we use the model to compute risk level credibility ,and find necessary improved controls ,which will reduce risk in controllable range .Contrastive analyses with other risk assessment examples demonstrate effective of the proposed method for evaluation .The method not only weighs up the association influ-ence between the various evaluation factors in practical evaluation system ,reduces the subjective evaluation ,but also effec-tively reduces the uncertainty of expert evaluation .
Keywords:risk assessmentDEMATELANPD-S evidential theoryinformation security
Publication Date:2014-01-01
Online Publishing Date:2025-08-15(First online date of this platform, not the publication date of the document)
Pages:8( 1801-1807,1862 )
