Incident prioritisation using analytic hierarchy process (AHP): Risk Index Model (RIM)

被引:17
|
作者
Anuar, Nor Badrul [1 ,2 ]
Papadaki, Maria [2 ]
Furnell, Steven [2 ]
Clarke, Nathan [2 ]
机构
[1] Univ Malaya, Fac Comp Sci & Informat Technol, Kuala Lumpur, Malaysia
[2] Univ Plymouth, Ctr Secur Commun & Network Res, Plymouth PL4 8AA, Devon, England
关键词
incident prioritisation; risk assessment; analytic hierarchy process; Risk Index Model; ALERT PRIORITIZATION; INTRUSION; VULNERABILITY;
D O I
10.1002/sec.673
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The landscape of security threats continues to evolve, with attacks becoming more serious and the number of vulnerabilities rising. For these threats to be managed, many security studies have been undertaken in recent years, mainly focusing on improving detection, prevention and response efficiency. This paper proposes an incident prioritisation model, the Risk Index Model (RIM), which is based on risk assessment and the analytic hierarchy process. For incidents to be prioritised, the model uses indicators, such as criticality, as decision factors to calculate incidents' risk index. The model also adopts different strategies to enhance the prioritisation process. To evaluate the model, two stages of evaluation study were conducted. The first stage aims to validate the model by comparing its results with the Common Vulnerability Scoring System and Snort. The second stage aims to enhance RIM by analysing the effect of using different strategies in the model. The experimental results in the first stage have shown that 100% of incidents could be rated with RIM, compared with only 17.23% with the Common Vulnerability Scoring System. The experiments in the second stage have shown significant changes in the resultant risk index as well as some of the top-priority incidents. Copyright (c) 2012 John Wiley & Sons, Ltd.
引用
收藏
页码:1087 / 1116
页数:30
相关论文
共 50 条
  • [1] Risk Prioritisation Using The Analytic Hierarchy Process
    Sum, Rabihah Md
    INNOVATION AND ANALYTICS CONFERENCE AND EXHIBITION (IACE 2015), 2015, 1691
  • [2] PIPELINE RISK ASSESSMENT USING ANALYTIC HIERARCHY PROCESS (AHP)
    Yasseri, Sirous F.
    Mahani, R. B.
    OMAE2011: PROCEEDINGS OF THE ASME 30TH INTERNATIONAL CONFERENCE ON OCEAN, OFFSHORE AND ARCTIC ENGINEERING, VOL 4: PIPELINE AND RISER TECHNOLOGY, 2011, : 1 - +
  • [3] Fuzzy prioritisation in the Analytic Hierarchy Process
    Mikhailov, L
    Yan, CM
    Harrison, C
    PROCEEDINGS OF THE FIFTH JOINT CONFERENCE ON INFORMATION SCIENCES, VOLS 1 AND 2, 2000, : 104 - 107
  • [4] Construction of a credit evaluation model using Analytic Hierarchy Process (AHP)
    Analitik Hiyerars¸i Süreci
    Iç, Y.T. (tanselic@yahoo.com), 2000, Gazi Universitesi Muhendislik-Mimarlik (15): : 1 - 2
  • [5] ON THE MEAN RANDOM INCONSISTENCY INDEX OF ANALYTIC HIERARCHY PROCESS (AHP)
    TUMMALA, VMR
    WAN, Y
    COMPUTERS & INDUSTRIAL ENGINEERING, 1994, 27 (1-4) : 401 - 404
  • [6] Sampling distribution of the random consistency index of the Analytic Hierarchy Process (AHP)
    Tummala, VMR
    Ling, H
    JOURNAL OF STATISTICAL COMPUTATION AND SIMULATION, 1996, 55 (1-2) : 121 - 131
  • [7] A Customer Satisfaction Model by Applying Analytic Hierarchy Process (AHP)
    Yang, Chih-Neng
    Lee, Amy H. I.
    EBM 2010: INTERNATIONAL CONFERENCE ON ENGINEERING AND BUSINESS MANAGEMENT, VOLS 1-8, 2010, : 1278 - 1281
  • [8] Analytic hierarchy process (AHP) and attribute hierarchical model(AHM)
    Cheng, Qiansheng
    Xitong Gongcheng Lilun yu Shijian/System Engineering Theory and Practice, 17 (11): : 25 - 28
  • [9] Approaching IT Automation Decisions using Analytic Hierarchy Process (AHP)
    Iskin, Ibrahim
    Daim, Tugrul U.
    Noble, Stephen
    Baltz, Angie
    INTERNATIONAL JOURNAL OF INFORMATION TECHNOLOGY PROJECT MANAGEMENT, 2014, 5 (01) : 77 - 89
  • [10] Prioritizing HAZOP analysis using analytic hierarchy process (AHP)
    Mohamad Rizza Othman
    Rosshila Idris
    Mimi Haryani Hassim
    Wan Hanisah Wan Ibrahim
    Clean Technologies and Environmental Policy, 2016, 18 : 1345 - 1360