To access information system security risk assessment is very important even in presence of uncertainty of the system. In this paper, we propose a method of AHP/D-S evidence theory to handle the uncertainty of the system. Compared with other methods, the analysis of hierarchy process (AHP) method has been widely used in security risk assessment, for this method can change from the qualitative index into quantitative index. Realistic risk assessment involves many uncertainty factors, some of which are even unknown. Considering the Dempster-Shafer theory of evidence (D-S) which is able to treat those uncertainties very well, this paper proposed a risk assessment model which is generated by combining AHP method with D-S method to solve these problems. Not only does the AHP/D-S method combine the advantages of both, but also can solve uncertain problems more scientifically. Finally, a sample of how to use AHP/D-S method in security risk assessment is given to prove our method.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.