Incident prioritisation using analytic hierarchy process (AHP): Risk Index Model (RIM)

نویسندگان

  • Nor Badrul Anuar
  • Maria Papadaki
  • Steven Furnell
  • Nathan L. Clarke
چکیده

The landscape of security threats continues to evolve, with attacks becoming more serious and the number of vulnerabilities rising. For these threats to be managed, many security studies have been undertaken in recent years, mainly focusing on improving detection, prevention and response efficiency. This paper proposes an incident prioritisation model, the Risk Index Model (RIM), which is based on risk assessment and the analytic hierarchy process. For incidents to be prioritised, the model uses indicators, such as criticality, as decision factors to calculate incidents’ risk index. The model also adopts different strategies to enhance the prioritisation process. To evaluate the model, two stages of evaluation study were conducted. The first stage aims to validate the model by comparing its results with the Common Vulnerability Scoring System and Snort. The second stage aims to enhance RIM by analysing the effect of using different strategies in the model. The experimental results in the first stage have shown that 100% of incidents could be rated with RIM, compared with only 17.23%with the Common Vulnerability Scoring System. The experiments in the second stage have shown significant changes in the resultant risk index as well as some of the top-priority incidents. Copyright © 2012 John Wiley & Sons, Ltd.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Risk Index Model for Security Incident Prioritisation

With thousands of incidents identified by security appliances every day, the process of distinguishing which incidents are important and which are trivial is complicated. This paper proposes an incident prioritisation model, the Risk Index Model (RIM), which is based on risk assessment and the Analytic Hierarchy Process (AHP). The model uses indicators, such as criticality, maintainability, rep...

متن کامل

Ranking of Financial and Electronic Debts Using Analytic Hierarchy Process (AHP)

Abstract Financial and electronic debts are one of the important issues in Iran's financial scope that are considered by economists due to their role in creating financial instabilities. Therefore, a model was represented in this survey to evaluate and rank financial and electronic debts in Iran including foreign debts, governmental debts, non-governmental debts and banking debts during the pe...

متن کامل

Interactive management control via analytic hierarchy process: an empirical study in a public university hospital

This paper describes an application of analytic hierarchy process (AHP) to enhance interactive budgeting in one of the biggest public university hospitals in Italy. AHP improved budget allocation facilitating elicitation and formalisation of units' needs. Furthermore, AHP facilitated vertical communication among managers and stakeholders, as it allowed multilevel hierarchical representation of ...

متن کامل

Investment Risks Assessment on High-tech Projects Based on Analytic Hierarchy Process and BP Neural Network

In view of the existing problems of investment risks assessment on high-tech industry projects such as a lack of systematic, with too much subjectivity and from the point to improve assessment efficiency and effectiveness, the paper combined Analytic Hierarchy Process (AHP) with BP Neural Network to establish a new and suitable risk assessment model of high-tech projects. Firstly, we applied AH...

متن کامل

Risk Assessment on Storage Security of Hazardous Chemicals Based on AHP-fuzzy Comprehensive Evaluation Approach

To solve the uncertainty and complexity problems in hazardous chemical storage risk assessment, this paper constructs the evaluation index system and proposed the risk assessment model based on AHP-fuzzy comprehensive evaluation approach, which organically integrate the quantitative and the objectively of the analytic hierarchy process (AHP) and the inclusive advantage of fuzzy comprehensive ev...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Security and Communication Networks

دوره 6  شماره 

صفحات  -

تاریخ انتشار 2013