Application of Multicriteria Methods for Improvement of Information Security Metrics

被引:1
|
作者
Abdiraman, Aliya [1 ]
Goranin, Nikolaj [2 ]
Balevicius, Simas [2 ]
Nurusheva, Assel [1 ]
Tumasoniene, Inga [3 ]
机构
[1] LN Gumilyov Eurasian Natl Univ, Fac Informat Technol, Dept Informat Secur, Astana KZ-010008, Kazakhstan
[2] Vilnius Gediminas Tech Univ, Fac Fundamental Sci, Dept Informat Syst, LT-08412 Vilnius, Lithuania
[3] Vilnius Gediminas Tech Univ, Fac Fundamental Sci, Dept Informat Technol, LT-08412 Vilnius, Lithuania
关键词
MCDM; fuzzy; TOPSIS; WASPAS; AHP; information security metrics; malicious program code; TOPSIS METHOD; FUZZY AHP;
D O I
10.3390/su15108114
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
Metrics are a set of numbers that are used to obtain information about the operation of a process or system. In our case, metrics are used to assess the level of information security of information and communication infrastructure facilities. Metrics in the field of information security are used to quantify the possibility of damage due to unauthorized hacking of an information system, which make it possible to assess the cyber sustainability of the system. The purpose of the paper is to improve information security metrics using multicriteria decision-making methods (MCDM). This is achieved by proposing aggregated information security metrics and evaluating the effectiveness of their application. Classical information security metrics consist of one size or one variable. We obtained the total value by adding at least two different metrics and evaluating the weighting factors that determine their importance. This is what we call aggregated or multicriteria metrics of information security. Consequently, MCDM methods are applied to compile aggregated metrics of information security. These are derived from expert judgement and are proposed for the three management domains of the ISO/IEC 27001 information security standard. The proposed methods for improving cyber sustainability metrics are also relevant to information security metrics. Using AHP, WASPAS and Fuzzy TOPSIS methods to solve the problem, the weights of classical metrics are calculated and three aggregated metrics are proposed. As a result, to confirm the fulfilment of the task of improving information security metrics, a verification experiment is conducted, during which aggregated and classical information security metrics are compared. The experiment shows that the use of aggregated metrics can be a more convenient and faster process and higher intelligibility is also achieved.
引用
收藏
页数:34
相关论文
共 50 条
  • [1] A metrics framework to drive application security improvement
    Nichols, Elizabeth A.
    Peterson, Gunnar
    IEEE SECURITY & PRIVACY, 2007, 5 (02) : 88 - 91
  • [2] A systematic literature review on the application of multicriteria decision making methods for information security risk assessment
    Maček D.
    Magdalenić I.
    Ređep N.B.
    Maček, Davor (davor.macek@foi.hr), 1600, International Information and Engineering Technology Association (10): : 161 - 174
  • [3] Security metrics models and application with SVM in information security management
    Qu, Wei
    Zhang, De-Zheng
    PROCEEDINGS OF 2007 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2007, : 3234 - +
  • [4] Information Visualization Metrics and Methods for Cyber Security Evaluation
    Langton, John T.
    Baker, Alex
    2013 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS: BIG DATA, EMERGENT THREATS, AND DECISION-MAKING IN SECURITY INFORMATICS, 2013, : 292 - 294
  • [5] Information security metrics
    Garcia Rojas, Jesus Leonardo
    CISCI 2007: 6TA CONFERENCIA IBEROAMERICANA EN SISTEMAS, CIBERNETICA E INFORMATICA, MEMORIAS, VOL I, 2007, : 361 - 365
  • [6] Improvement of EIGRP Protocol Routing Algorithm Based on Information Security Metrics
    Snigurov, Arkadiy
    Chakrian, Vadym
    2015 SECOND INTERNATIONAL SCIENTIFIC-PRACTICAL CONFERENCE PROBLEMS OF INFOCOMMUNICATIONS SCIENCE AND TECHNOLOGY (PIC S&T 2015), 2015, : 263 - 265
  • [7] Security Metrics: Principles and Security Assessment Methods
    Arabsorkhi, Abouzar
    Ghaffari, Fariba
    2018 9TH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST), 2018, : 305 - 310
  • [8] Towards a Taxonomy for Information Security Metrics
    Savola, Reijo M.
    QOP'07: PROCEEDINGS OF THE 2007 ACM WORKSHOP ON QUALITY OF PROTECTION, 2007, : 28 - 30
  • [9] Information systems security metrics management
    Kovacich, G
    COMPUTERS & SECURITY, 1997, 16 (07) : 610 - 618
  • [10] Information systems security metrics management
    Kovacich, Gerald
    Computers and Security, 1997, 16 (07): : 610 - 618