Incident prioritisation using analytic hierarchy process (AHP): Risk Index Model (RIM)

被引:17
|
作者
Anuar, Nor Badrul [1 ,2 ]
Papadaki, Maria [2 ]
Furnell, Steven [2 ]
Clarke, Nathan [2 ]
机构
[1] Univ Malaya, Fac Comp Sci & Informat Technol, Kuala Lumpur, Malaysia
[2] Univ Plymouth, Ctr Secur Commun & Network Res, Plymouth PL4 8AA, Devon, England
关键词
incident prioritisation; risk assessment; analytic hierarchy process; Risk Index Model; ALERT PRIORITIZATION; INTRUSION; VULNERABILITY;
D O I
10.1002/sec.673
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The landscape of security threats continues to evolve, with attacks becoming more serious and the number of vulnerabilities rising. For these threats to be managed, many security studies have been undertaken in recent years, mainly focusing on improving detection, prevention and response efficiency. This paper proposes an incident prioritisation model, the Risk Index Model (RIM), which is based on risk assessment and the analytic hierarchy process. For incidents to be prioritised, the model uses indicators, such as criticality, as decision factors to calculate incidents' risk index. The model also adopts different strategies to enhance the prioritisation process. To evaluate the model, two stages of evaluation study were conducted. The first stage aims to validate the model by comparing its results with the Common Vulnerability Scoring System and Snort. The second stage aims to enhance RIM by analysing the effect of using different strategies in the model. The experimental results in the first stage have shown that 100% of incidents could be rated with RIM, compared with only 17.23% with the Common Vulnerability Scoring System. The experiments in the second stage have shown significant changes in the resultant risk index as well as some of the top-priority incidents. Copyright (c) 2012 John Wiley & Sons, Ltd.
引用
收藏
页码:1087 / 1116
页数:30
相关论文
共 50 条