Skip to main navigation Skip to search Skip to main content

The cybersecurity risk estimation engine: A tool for possibility based risk analysis

  • University of Massachusetts Boston

Research output: Contribution to journalArticlepeer-review

Abstract

Despite dramatic changes in the constellation of cybersecurity risks, the basic approach to risk calculation has been anchored to probability theory. The probability approach is widely known and conceptually simple. But it is disadvantageous in its grounding on expert estimates of frequency data which is often publicly unavailable. This study proposes the use of possibility theory as a complementary grounding for cybersecurity risk calculations. Using a design science research approach, we use possibility theory as the kernel theory in developing and evaluating a practical possibility-based risk estimation prototype. The results offer an expanded grounding to improve cybersecurity risk analysis.

Original languageEnglish
Article number102752
JournalComputers and Security
Volume120
DOIs
StatePublished - Sep 2022

ASJC Scopus Subject Areas

  • General Computer Science
  • Law

Keywords

  • Information security
  • Possibility theory
  • PRAE
  • Risk estimation
  • Risk management

Fingerprint

Dive into the research topics of 'The cybersecurity risk estimation engine: A tool for possibility based risk analysis'. Together they form a unique fingerprint.

Cite this