Yüksek LisansAçık Erişim

Bayes ağları ve bulanık çıkarım sistemi tabanlı bir bilgi güvenliği risk değerlendirme modeli

Bu tez size mi ait?

Bu kayıt toplu arşivden geldi. Sizinse profilinize bağlayın.

2019
0 görüntülenme
0 i̇ndirme

Özet (EN)

This study proposes an information security risk assessment model for calculating both qualitative and/or quantitative risk factors by using Bayesian network model and fuzzy inference system. The proposed model is developed for a software services company in order to evaluate the information security risks according to their test processes. First of all, in order to collect data for our risk assessment model, information assets, vulnerabilities, threats, and related risk values are identified and analysed with experts and managers based on the testing process in the company. The relations between identified and selected threats, vulnerabilities and information risks constructed in the Bayesian network. This Bayesian model is used for calculation of marginal probabilities for each risk factor. After completing the construction of Bayesian network, several fuzzy membership functions are designed for assets' values, relative risk values and risks' probabilities. Then, Fuzzy decision rules are constructed and derived for some of the chosen risks by using the assets' values, relevant risk probabilities, and relative risk values. Lastly, aggregation and defuzzification process are completed for calculating the impacts of risk values.

Yazar

Sevilay Beken

Bu Yayına Nasıl Atıf Yapılır

Sevilay Beken (Master Thesis). Bayes ağları ve bulanık çıkarım sistemi tabanlı bir bilgi güvenliği risk değerlendirme modeli, 2019, Dokuz Eylül University.

Anahtar Kelimeler

Lisans

Tüm Hakları Saklıdır

Bu eser belirtilen lisans koşulları altında paylaşılmaktadır.

Dokuz Eylül University tezlerinden daha fazlası