Selecting Best Software Vulnerability Scanner Using Intuitionistic Fuzzy Set TOPSIS

被引:2
|
作者
Bhatt, Navneet [1 ]
Kaur, Jasmine [2 ]
Anand, Adarsh [2 ]
Alhazmi, Omar H. [3 ]
机构
[1] Deemed Univ, Anil Surendra Modi Sch Commerce, Narsee Monjee Inst Management Studies, Mumbai 400056, Maharashtra, India
[2] Univ Delhi, Fac Math Sci, Dept Operat Res, Delhi 110007, India
[3] Taibah Univ, Dept Comp Sci, Medina 30001, Saudi Arabia
来源
CMC-COMPUTERS MATERIALS & CONTINUA | 2022年 / 72卷 / 02期
关键词
Intuitionistic fuzzy set; group decision making; multi-criteria deci-sion making (MCDM); ranking algorithm; software security; TOPSIS; vul-nerability; vulnerability scanners; GROUP DECISION-MAKING;
D O I
10.32604/cmc.2022.026554
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Software developers endeavor to build their products with the least number of bugs. Despite this, many vulnerabilities are detected in software that threatens its integrity. Various automated software i.e., vulnerability scanners, are available in the market which helps detect and manage vulnerabilities in a computer, application, or a network. Hence, the choice of an appropriate vulnerability scanner is crucial to ensure efficient vulnerability management. The current work serves a dual purpose, first, to identify the key factors which affect the vulnerability discovery process in a network. The second, is to rank the popular vulnerability scanners based on the identified attributes. This will aid the firm in determining the best scanner for them considering multiple aspects. The multi-criterion decision making based ranking approach has been discussed using the Intuitionistic Fuzzy set (IFS) and Technique for Order of Preference by Similarity to Ideal Solution (TOPSIS) to rank the various scanners. Using IFS TOPSIS, the opinion of a whole group could be simultaneously considered in the vulnerability scanner selection. In this study, five popular vulnerability scanners, namely, Nessus, Fsecure Radar, Greenbone, Qualys, and Nexpose have been considered. The inputs of industry specialists i.e., people who deal in software security and vulnerability management process have been taken for the ranking process. Using the proposed methodology, a hierarchical classification of the various vulnerability scanners could be achieved. The clear enumeration of the steps allows for easy adaptability of the model to varied situations. This study will help product developers become aware of the needs of the market and design better scanners. And from the user's point of view, it will help the system administrators in deciding which scanner to deploy depending on selection.
引用
收藏
页码:3613 / 3629
页数:17
相关论文
共 50 条
  • [1] Selecting appropriate ERP software using integrated fuzzy linguistic preference relations fuzzy TOPSIS method
    Cakir, Suleyman
    [J]. INTERNATIONAL JOURNAL OF COMPUTATIONAL INTELLIGENCE SYSTEMS, 2016, 9 (03) : 433 - 449
  • [2] Selecting appropriate ERP software using integrated fuzzy linguistic preference relations — fuzzy TOPSIS method
    Süleyman Çakır
    [J]. International Journal of Computational Intelligence Systems, 2016, 9 : 433 - 449
  • [3] TOPSIS based Renewable-Energy-Source-Selection using Moderator Intuitionistic Fuzzy Set
    Joshi, Bhagawati Prasad
    Joshi, Navneet
    Gegov, Alexander
    [J]. INTERNATIONAL JOURNAL OF MATHEMATICAL ENGINEERING AND MANAGEMENT SCIENCES, 2023, 8 (05) : 979 - 990
  • [4] Dynamic Agent Evaluation Using Intuitionistic Fuzzy TOPSIS
    Zhang, Libo
    Liu, Jiubing
    Huang, Bing
    Li, Huaxiong
    Zhou, Xianzhong
    [J]. PROCEEDINGS OF THE 2018 IEEE 22ND INTERNATIONAL CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK IN DESIGN ((CSCWD)), 2018, : 773 - 778
  • [5] SELECTING TARGET MARKET BY SIMILAR MEASURES IN INTERVAL INTUITIONISTIC FUZZY SET
    Nguyen Xuan Thao
    Truong Thi Thuy Duong
    [J]. TECHNOLOGICAL AND ECONOMIC DEVELOPMENT OF ECONOMY, 2019, 25 (05) : 934 - 950
  • [6] Selecting Start-up Businesses in a Public Venture Capital with Intuitionistic Fuzzy TOPSIS
    Afful-Dadzie, Eric
    Oplatkova, Zuzana Kominkova
    Nabareseh, Stephen
    Senkerik, Roman
    [J]. WORLD CONGRESS ON ENGINEERING AND COMPUTER SCIENCE, WCECS 2015, VOL I, 2015, : 471 - 476
  • [7] Research on risk evaluation for venture capital based on intuitionistic fuzzy set and TOPSIS
    Liu, Peide
    [J]. PROCEEDINGS OF THE FIRST INTERNATIONAL SYMPOSIUM ON DATA, PRIVACY, AND E-COMMERCE, 2007, : 415 - 417
  • [8] Performance Evaluation of Online Recruitment Enterprises Based on Intuitionistic Fuzzy Set and TOPSIS
    Chen, Xiaoyun
    Xue, Zhe
    [J]. MATHEMATICAL PROBLEMS IN ENGINEERING, 2022, 2022
  • [9] Performance Evaluation of Online Recruitment Enterprises Based on Intuitionistic Fuzzy Set and TOPSIS
    Chen, Xiaoyun
    Xue, Zhe
    [J]. Mathematical Problems in Engineering, 2022, 2022
  • [10] EVALUATION OF GOVERNMENT WEBSITES USING INTUITIONISTIC FUZZY AHP AND TOPSIS
    Buyukozkan, Gulcin
    Gocer, Fethullah
    [J]. UNCERTAINTY MODELLING IN KNOWLEDGE ENGINEERING AND DECISION MAKING, 2016, 10 : 930 - 935