Evaluating Performance of Web Application Security Through a Fuzzy Based Hybrid Multi-Criteria Decision-Making Approach: Design Tactics Perspective

被引:27
作者
Alenezi, Mamdouh [1 ]
Agrawal, Alka [2 ]
Kumar, Rajeev [2 ]
Khan, Raees Ahmad [2 ]
机构
[1] Prince Sultan Univ, Coll Comp & Informat Sci, Riyadh 11586, Saudi Arabia
[2] BBA Univ, Dept Informat Technol, Lucknow 226025, Uttar Pradesh, India
关键词
Web application; security assessment; security design; security tactics; Fuzzy-AHP; Fuzzy-TOPSIS; AHP;
D O I
10.1109/ACCESS.2020.2970784
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Design of software can have a major impact on the overall security of the software. Developing a secure website design is a challenge for architectures. It depends on different and tough decisions which determine the security of website. Increasing number of vulnerabilities increase the level of security requirements. Hence, security design tactics are to be adopted to satisfy these security requirements. Security design tactics are the mechanisms to define, detect and mitigate vulnerabilities and attacks. Therefore, faults in the application of security tactics or their weakening during website maintenance could be one of the key reasons behind the emergence of new and severe vulnerabilities that can be targeted by the hackers. There is a need for in-depth analysis of security tactics and its prioritization for the sake of determining the most prioritized factor. This will further help in gaining a more secure system. In this research study, the authors have used the hybrid method of Fuzzy AHP-TOPSIS (Analytic Hierarchy Process-Technique for Order Preference by Similarity Ideal Solution) for the evaluation of security design tactics and its attributes. The efficiency of this approach has been tested on a real time web application of Babasaheb Bhimrao Ambedkar University, Lucknow, India. Further, different web applications of the University have been used to validate the obtained results. This study's evaluation of the most impactful web application design for improving security will help the architects to secure systems by using security tactics.
引用
收藏
页码:25543 / 25556
页数:14
相关论文
共 27 条
[1]   Measuring the Sustainable-Security of Web Applications Through a Fuzzy-Based Integrated Approach of AHP and TOPSIS [J].
Agrawal, Alka ;
Alenezi, Mamdouh ;
Kumar, Rajeev ;
Khan, Raees Ahmad .
IEEE ACCESS, 2019, 7 :153936-153951
[2]   A Framework for Selecting Architectural Tactics Using Fuzzy Measures [J].
Alashqar, Abdelkareem M. ;
El-Bakry, Hazem M. ;
Elfetouh, Ahmad Abo .
INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2017, 27 (03) :475-498
[3]  
[Anonymous], [No title captured]
[4]  
[Anonymous], [No title captured]
[5]  
[Anonymous], [No title captured]
[6]  
[Anonymous], [No title captured]
[7]  
[Anonymous], [No title captured]
[8]  
[Anonymous], [No title captured]
[9]  
[Anonymous], 2010, 2014 47 HAW INT C SY, DOI DOI 10.1109/HICSS.2010.18
[10]  
[Anonymous], [No title captured]