A Reference Model for Security Level Evaluation: Policy and Fuzzy Techniques
نویسندگان
چکیده
In a world made of interconnected systems which manage huge amounts of confidential and shared data, security plays a significant role. Policies are the means by which security rules are defined and enforced. The ability to evaluate policies is becoming more and more relevant, especially when referred to the cooperation of services belonging to un-trusted domains. We have focused our attention on Public Key Infrastructures (PKIs); at the state of the art security policies evaluation is manually performed by technical and organizational people coming from the domains that need to interoperate. However, policy evaluation must face uncertainties derived from different perspectives, verbal judgments and lack of information. Fuzzy techniques and uncertainty reasoning can provide a meaningful way for dealing with these issues. In this paper we propose a fuzzy technique to characterize a policy and to define a Reference Evaluation Model representing different security levels against which we are able to evaluate and compare policies. The comparison takes into account not only minimal system needs but evaluator’s severity, too; furthermore it gives clear information regarding policy weakness that could be used to help security administrators to better enforce rules. Finally we present a case study which evaluates the security level of a ”legally recognized” policy.
منابع مشابه
Designing a Combined-fuzzy Methodology to Improve Organizational Diagnosis Process Effectiveness through Identification and Assessment of Effective Parameters
Organizational diagnosis is a systematic and scientific method to identify, categorize and single out the obstacles and their impact on organizational performance through interaction between internal and external views and preparation and setting up operational plans to solve them in the organization. Providing standard products and emphasizing on the financial measures do not guarantee the sur...
متن کاملAnalysis of Speed Control in DC Motor Drive Based on Model Reference Adaptive Control
This paper presents fuzzy and conventional performance of model reference adaptive control(MRAC) to control a DC drive. The aims of this work are achieving better match of motor speed with reference speed, decrease of noises under load changes and disturbances, and increase of system stability. The operation of nonadaptive control and the model reference of fuzzy and conventional adaptive contr...
متن کاملUsing multi-criteria evaluation techniques of fuzzy analytic hierarchy process and fuzzy TOPSIS in locating waste sanitary landfill sites
Considering non-normative extension and too much development of cities, the lack of accurate model of consumption, increasing waste production, the most logical and most economical method for disposal of municipal waste is sanitary landfill. Given that, to identify areas prone to waste landfilling requires application of comprehensive techniques. The main objective for the present research is t...
متن کاملOutcome Evaluation of Therapeutic Community Model in Iran
Background Evaluation of treatment programs in addiction field is a prerequisite to improve the quality of care. This study aimed to investigate the effectiveness of Therapeutic Community (TC) program in Iran. Methods Individuals who had voluntarily enrolled in the TC center within a period of seven years, from early 2005 to late 2011, entered the study. Those who successfully completed the 1...
متن کاملAN INTEGRATED FIS-QFD MODEL FOR EVALUATION OF INTERNET SERVICE PROVIDER
<span style="color: #000000; font-family: Tahoma, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: -webkit-left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ba...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- J. UCS
دوره 11 شماره
صفحات -
تاریخ انتشار 2005