Information security risk evaluation based on D-S evidence theory

LI Cong-cong · Journal of North China Electric Power University · 2008

Dempster-Shafer(D-S) evidence theory was applied to treat the uncertainty of the information security risk evaluation.A risk evaluation model based on D-S evidence theory was proposed.The improved Demspter's rule of combination of evidence was used to combine the risk factors of information system.It reduced the uncertainty of risk factors.The improved Demspter's rule of combination of evidence,i.e.discount ratio,is used in basic belief assignment to combine kinds of risk factors.By simulation analysis,the correctness of the algorithm was proved.Finally,it was verified that evidence theory had higher accuracy than fuzzy comprehensive evaluation method.

Read the paper · More papers on PaperTik