Fuzzy Risk Analysis for Safeguards and Network Security

Year
1992
Author(s)
Andrew Zardecki - Los Alamos National Laboratory
Laura A. Stoltz - Los Alamos National Laboratory
Abstract
Analyzing the risk of a safeguards system, in particular the security of a computer network based on the notion of fuzzy sets and linguistic variables, addresses concerns such as complexity and inherent imprecision in estimating the possibility of loss or compromise. Automated risk analysis allows the risk to be determined for an entire system based on estimates for lowest level components and the component weight. In addition, for each component (asset) we select the most effective combination of protection mechanisms against a given set of threats.