Incident prioritisation using analytic hierarchy process (AHP): Risk Index Model (RIM)

被引:17
|
作者
Anuar, Nor Badrul [1 ,2 ]
Papadaki, Maria [2 ]
Furnell, Steven [2 ]
Clarke, Nathan [2 ]
机构
[1] Univ Malaya, Fac Comp Sci & Informat Technol, Kuala Lumpur, Malaysia
[2] Univ Plymouth, Ctr Secur Commun & Network Res, Plymouth PL4 8AA, Devon, England
关键词
incident prioritisation; risk assessment; analytic hierarchy process; Risk Index Model; ALERT PRIORITIZATION; INTRUSION; VULNERABILITY;
D O I
10.1002/sec.673
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The landscape of security threats continues to evolve, with attacks becoming more serious and the number of vulnerabilities rising. For these threats to be managed, many security studies have been undertaken in recent years, mainly focusing on improving detection, prevention and response efficiency. This paper proposes an incident prioritisation model, the Risk Index Model (RIM), which is based on risk assessment and the analytic hierarchy process. For incidents to be prioritised, the model uses indicators, such as criticality, as decision factors to calculate incidents' risk index. The model also adopts different strategies to enhance the prioritisation process. To evaluate the model, two stages of evaluation study were conducted. The first stage aims to validate the model by comparing its results with the Common Vulnerability Scoring System and Snort. The second stage aims to enhance RIM by analysing the effect of using different strategies in the model. The experimental results in the first stage have shown that 100% of incidents could be rated with RIM, compared with only 17.23% with the Common Vulnerability Scoring System. The experiments in the second stage have shown significant changes in the resultant risk index as well as some of the top-priority incidents. Copyright (c) 2012 John Wiley & Sons, Ltd.
引用
收藏
页码:1087 / 1116
页数:30
相关论文
共 50 条
  • [31] Prioritisation in the analytic hierarchy process for real and generated comparison matrices
    Srdjevic, Bojan
    Srdjevic, Zorica
    EXPERT SYSTEMS WITH APPLICATIONS, 2023, 225
  • [32] Evaluating Software Quality Attributes using Analytic Hierarchy Process (AHP)
    Belinda, Botchway Ivy
    Emmanuel, Akinwonmi Akintoba
    Solomon, Nunoo
    Kayode, Alese Boniface
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (03) : 165 - 173
  • [33] Ranking of Financial and Electronic Debts Using Analytic Hierarchy Process (AHP)
    Torki, Leila
    Rezai, Ahmadali
    Isfahani, Rahim Dalali
    2013 7TH INTERNATIONAL CONFERENCE ON E-COMMERCE IN DEVELOPING COUNTRIES: WITH FOCUS ON E-SECURITY (ECDC), 2013,
  • [34] CATEGORIZATION AND OFFER IN TOURISM USING ANALYTIC HIERARCHY PROCESS - AHP METHOD
    Cingula, Domagoj
    Primorac, Dinko
    Borovic, Franjo
    ECONOMIC AND SOCIAL DEVELOPMENT: 2ND INTERNATIONAL SCIENTIFIC CONFERENCE BOOK OF PROCEEDINGS, 2013, : 122 - 129
  • [35] COTS evaluation using DESMET methodology & analytic hierarchy process (AHP)
    Morera, D
    PRODUCT FOCUSED SOFTWARE PROCESS IMPROVEMENT, PROCEEDINGS, 2002, 2559 : 485 - 493
  • [36] Probabilistic Assessment of Generator Failure Using the Analytic Hierarchy Process (AHP)
    Amyot, N.
    Hudon, C.
    Belec, M.
    Lamarre, L.
    Nguyen, N. D.
    2008 10TH INTERNATIONAL CONFERENCE ON PROBABILISTIC METHODS APPLIED TO POWER SYSTEMS, 2008, : 339 - +
  • [37] Using analytic hierarchy process (ahp) to assess diabetes quality.
    Long, MD
    Centor, RM
    Allison, JJ
    JOURNAL OF INVESTIGATIVE MEDICINE, 2004, 52 (01) : S279 - S280
  • [38] Research on Building Fire Risk Assessment Based on Analytic Hierarchy Process (AHP)
    Chen, Juan-juan
    Fang, Zheng
    Wang, Jun-heng
    Guo, Xiu-ji
    2014 7TH INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTATION TECHNOLOGY AND AUTOMATION (ICICTA), 2014, : 505 - 508
  • [39] Assessing risk factors in collaborative supply chain with the analytic hierarchy process (AHP)
    Badea, Andra
    Prostean, Gabriela
    Goncalves, Gilles
    Allaoui, Hamid
    CHALLENGES AND INNOVATIONS IN MANAGEMENT AND LEADERSHIP 12TH INTERNATIONAL SYMPOSIUM IN MANAGEMENT, 2014, 124 : 114 - 123
  • [40] Safety risk assessment using analytic hierarchy process (AHP) during planning and budgeting of construction projects
    Aminbakhsh, Saman
    Gunduz, Murat
    Sonmez, Rifat
    JOURNAL OF SAFETY RESEARCH, 2013, 46 : 99 - 105