Software Security Risk Analysis Using Fuzzy Expert System
Main Article Content
Abstract
Today, there is wide concern on the security of software systems because many organizations depend largely on them for their day-to-day operations. Since we have not seen a software system that is completely secure, there is need to analyze and determine the security risk of emerging software systems. This work presents a technique for analyzing software security using fuzzy expert system. The inputs to the system are suitable fuzzy sets representing linguistic values for software security goals of confidentiality, integrity and availability. The expert rules were constructed using the Mamdani fuzzy reasoning in order to adequately analyse the inputs. The defuzzification technique was done using Centroid technique. The implementation of the design is done usingMATLAB fuzzy logic tool because of its ability to implement fuzzy based systems. Using newly develop software products from three software development organizations as test cases, the results show a system that can be used to effectively analyze software security risk
Article Details
How to Cite
S., S. A., D., L. H. O., & M., F. O. (2008). Software Security Risk Analysis Using Fuzzy Expert System. INFOCOMP Journal of Computer Science, 7(3), 70–77. Retrieved from https://infocomp.dcc.ufla.br/index.php/infocomp/article/view/231
Section
Articles
Upon receipt of accepted manuscripts, authors will be invited to complete a copyright license to publish the paper. At least the corresponding author must send the copyright form signed for publication. It is a condition of publication that authors grant an exclusive licence to the the INFOCOMP Journal of Computer Science. This ensures that requests from third parties to reproduce articles are handled efficiently and consistently and will also allow the article to be as widely disseminated as possible. In assigning the copyright license, authors may use their own material in other publications and ensure that the INFOCOMP Journal of Computer Science is acknowledged as the original publication place.