<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Comprehensive Approach to Information Security Risk Management</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Tatyana I. Buldakova</string-name>
          <email>buldakova@bmstu.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Dmitrii A. Mikov</string-name>
          <email>mikovda@yandex.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Information Security Department Bauman Moscow State Technical University Moscow</institution>
          ,
          <addr-line>Russian Federation</addr-line>
        </aff>
      </contrib-group>
      <fpage>21</fpage>
      <lpage>26</lpage>
      <abstract>
        <p>-Information security risk management as important process of data protection in automated systems has been presented. Such criteria as estimates consistency and adequacy, adaptability to qualitative data, assessment subjectivity and uncertainty, risk sensitivity, which influence risk management effectiveness, have been identified. A task of integrated methodology development has been formalized in accordance with presented criteria. A structural model of comprehensive methodology, which displays its components and relationships between them, has been designed as a flowchart. A method for drawing up the risk factors list, including information security threats, potentially possible damage, automated system vulnerabilities, based on IDEF0 modeling, has been proposed. An original expert survey method, which provides compliance with the requirements of consistency and adequacy maximization for risk factors assessment, has been suggested. A neuro-fuzzy network based on Takagi-Sugeno-Kang model for information security risk calculation from risk factors assessment has been developed in MATLAB. A countermeasures choice method based on game theory criteria has been illustrated.</p>
      </abstract>
      <kwd-group>
        <kwd>information security risk management</kwd>
        <kwd>estimates consistency</kwd>
        <kwd>estimates adequacy</kwd>
        <kwd>adaptability to qualitative data</kwd>
        <kwd>risk assessment subjectivity</kwd>
        <kwd>risk assessment uncertainty</kwd>
        <kwd>risk sensitivity</kwd>
        <kwd>model IDEF0</kwd>
        <kwd>expert survey</kwd>
        <kwd>neuro-fuzzy network</kwd>
        <kwd>game theory criteria</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>INTRODUCTION</p>
      <p>
        Reliability of functioning of automated systems mostly
depends on ensuring their information security. Therefore,
based on the specifics of automated systems, companies
develop and implement a corresponding set of activities to
manage information security. An important component of this
process is information security risk management (e.g. [
        <xref ref-type="bibr" rid="ref1 ref2 ref3">1-3</xref>
        ]).
      </p>
      <p>Information security risk management consists of:
drawing up the risk factors list (information security
threats, potentially possible damage, automated
system vulnerabilities);
expert survey for risk factors assessment;
risk level calculation, based on risk factors estimates;
choice of the countermeasures for reducing the risk to
acceptable level.</p>
      <p>
        Each stage of information security risk management must
be realized by different methods and tools, which are the most
effective for this particular stage. So, the main research
direction in the field of information security risk management
should be focused on the selection of such methods, which
maximally satisfy the needs of different stages of the process
[
        <xref ref-type="bibr" rid="ref4">4</xref>
        ].
      </p>
      <p>
        Investigation of qualitative, quantitative and
semiqualitative information security risk management methods,
such as hazard and operability study (HAZOP) [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ], layer of
protection analysis (LOPA), preliminary hazard analysis
(PHA), allows to find main disadvantages and formulate a set
of effectiveness criteria for a comprehensive approach:
e(yk) = [0; 1] – uncertainty of risk assessment by
method yk (lack of accurate knowledge about the
status of all risk factors in the system and fuzzy risk
classification in the conditions of the particular system
functioning);
f – risk sensitivity (uneven influence of various risk
factors on the level of risk in certain conditions);
      </p>
      <p>The set of requirements to effectiveness criteria for a
comprehensive information security risk management
methodology is as in (1) and (2)
a(yk) × b(yk) × c(yk) → max
d(yk) × e(yk) → min

</p>
      <p>Practical investigation allows to develop a comprehensive
information security risk management methodology based on
presented set of effectiveness criteria (Fig. 1).</p>
      <p>feedbacks.</p>
      <p>Based on the characteristics of information security risk
management, it is necessary to have risk factors in the
IDEF0model according to a set of principles (Fig. 2).</p>
      <p>
        DRAWING UP THE RISK FACTORS LIST USING IDEF0
The initial stage of information security risk management is
the identification of risk factors (threats, possible damage,
vulnerabilities) [
        <xref ref-type="bibr" rid="ref4 ref6 ref7">4, 6, 7</xref>
        ]. The solution of this problem is
connected with the automated system modeling and the
investigation of the circulating information flows [
        <xref ref-type="bibr" rid="ref8 ref9">8, 9</xref>
        ].
Comparative analysis of the ARIS, IDEF0, IDEF3, UML
methodologies showed that IDEF0 takes into account and
displays all necessary elements:





input documents and data;
output documents and data;
persons, who implements processes;
used tools;
control actions over the processes implementation;
      </p>
      <p>
        When countermeasures are choosing and adding to the
IDEF0 model, it is necessary understand that their list is
preliminary, as the identified risk factors have not been
evaluated yet by the expert group. Therefore, it is impossible to
make an unambiguous conclusion about the degree of their
impact on found threats and vulnerabilities. After risk factors
assessment and subsequently calculating the level of risk, when
all quantities acquire numerical values, the list of
countermeasures can be adjusted [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. Therefore,
corresponding changes in the IDEF0-model are inevitable after
the implementation of further stages of management [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
      </p>
      <p>EXPERT SURVEY FOR RISK FACTORS ASSESSMENT</p>
      <p>To ensure the consistency and adequacy of expert opinions
in assessment of risk factors from the list compiled with the
IDEF0 model, a special method of expert interview has been
developed. Assessment of threats, potentially possible damage
and vulnerabilities must be performed by the expert group in
accordance with (3), (4) and (5):

xij1 = kij1 × pij1 × fij1
xij2 = kij2 × pij2 × fij2
xij3 = kij3 × pij3 × fij3



xij1 – threat estimate;
kij1 ϵ [0; 10] – threat power;
pij1 ϵ [0; 1] – probability of threat realization;
fij1 ϵ [0; 1] – risk sensitivity to threat assessment;
xij2 – potentially possible damage estimate;
kij2 ϵ [0; 10] – asset value;
pij2 ϵ [0; 1] – probability of the highest damage;
fij2 ϵ [0; 1] – risk sensitivity to damage assessment;
xij3 – vulnerability estimate;
kij3 ϵ [0; 10] – vulnerability degree;
pij3 ϵ [0; 1] – probability of vulnerability exploit;
fij3 ϵ [0; 1] – risk sensitivity to vulnerability assessment;
i = {1, 2, ..., m} – experts;
j = {1, 2, ..., n} – risk factors from the list.</p>
      <p>The consistency (a(yk)) of estimates is provided by
calculating the concordance coefficient W using (6), (7), (8),
(9):





</p>
      <p>xj = ∑xij
x = 1/n × ∑xij</p>
      <p>S = ∑(xj - x)2</p>
      <p>W = 12S/(m2(n3 - n))</p>
      <p>Then it is necessary to screen out extreme scores using an
algorithm based on the verbal-numeric Margolin and
Harrington scales (Fig. 1). The adequacy (b(yk)) of overall
threat (x1), potentially possible damage (x2) and vulnerability
(x3) estimates is provided by maximization of the objective
function (10):</p>
      <p>F(x) = x1 + x2 + x3 → max
</p>
      <p>It is necessary to construct a linear constraint system of
inequalities (11) containing the number of remaining estimates
of threats (ai1), potentially possible damage (ai2) and
vulnerabilities (ai3) for each expert, and the sum of each expert
estimates (bi):
ai1 × x1 + ai2 × x2 + ai3 × x3 ≤ bi




</p>
      <p>
        The linear constraint system of inequalities reduces to the
optimization problem of linear programming and can be solved
using the simplex method [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
      </p>
      <p>IV.</p>
      <p>NEURO-FUZZY NETWORK FOR RISK LEVEL ASSESSMENT
It is necessary to use a method that is adaptive to qualitative
data (c(yk)), minimizes subjectivity (d(yk)) and uncertainty
(e(yk)) of estimates and takes into account risk sensitivity to
various factors (f).</p>
      <p>
        A comparative analysis of the approaches, based on
machine learning [
        <xref ref-type="bibr" rid="ref13 ref14 ref15">13-15</xref>
        ], soft calculations [
        <xref ref-type="bibr" rid="ref16 ref17 ref18">16-18</xref>
        ] and hybrid
models [
        <xref ref-type="bibr" rid="ref19 ref20">19, 20</xref>
        ], showed the following results (Table I).
      </p>
      <p>The results of the comparative analysis show that
neurofuzzy networks have the best effectiveness criteria values.</p>
      <p>Therefore, a neuro-fuzzy network is chosen as a risk
assessment tool, which calculates risk level using three input
risk factors values received in the previous stage.</p>
      <p>The realized neuro-fuzzy network is transformed from
Takagi-Sugeno-Kang fuzzy model and contains five layers:
fuzzification, aggregation, activation, accumulation,
defuzzification (Fig. 3).</p>
      <p>Characteristics of the neuro-fuzzy network:










structure – five-layered neuro-fuzzy network:
fuzzy model type – Takagi-Sugeno-Kang;
three input variables – threat, damage, vulnerability;
five fuzzy sets for input variables – very low, low,
medium, high, very high;
trapezoidal membership function for input variables
(Fig. 4);
one output variable – information security risk level;
nine values for output variable – negligibly low (0),
very low (0,125), low (0,25), below average (0,375);
average (0,5), above average (0,625), high (0,75),
very high (0,875), critical (1);
conjunction – algebraic product method;
disjunction – algebraic sum method;
defuzzification – weighted average method.</p>
      <p>A verbal-numerical risk assessment scale, based on nine
initially specified values of the output variable, has been
developed. The scale allows to interpret the risk level obtained
at the output in the form of a numerical index (Table II).</p>
      <p>If the neuro-fuzzy network shows that the risk level is
unacceptable, it is necessary to select the appropriate
countermeasures to reduce it.</p>
      <p>Risk level
Negligibly low (0)
Very low (0,125)</p>
      <p>Low (0,25)
Below average</p>
      <p>(0,375)
Average (0,5)
Above average</p>
      <p>(0,625)</p>
      <p>High (0,75)
Very high (0,875)</p>
      <p>Critical (1)</p>
      <p>Description</p>
      <p>Risk can be neglected
If the information is regarded as a very low risk, it
is necessary to determine whether there is a need
for corrective actions, or there is a possibility to
take this risk
The risk level allows to work, but there are
prerequisites for a malfunction
It is necessary to develop and apply a corrective
action plan within an acceptable period of time
The risk level does not allow to work stably, there
is an urgent need for corrective actions that change
the mode of work towards reducing the risk
The system can continue to work, but the
corrective action plan must be applied as quickly as
possible
The risk level is such that business processes are in
an unstable state
It is necessary to take measures to reduce the risk
immediately
The risk level is very high and unacceptable for the
organization, which requires discontinuing the
system operation and taking radical measures to
reduce the risk</p>
      <p>
        The developed method of the countermeasures choice is
based on the above expert survey method, but uses the game
theory criteria for searching the optimal economic strategy.
There are three possible criteria – Wald’s maximin model,
Hurwicz criteria and Minimax regret [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ].
      </p>
      <p>Wald’s maximin model is aimed at minimizing the loss or
guaranteed minimal result. The minimal impact of each
countermeasure on any risk factor is determined, after that the
countermeasure with the maximal smallest influence is chosen.
It is the lower price of the game.</p>
      <p>Hurwicz criteria is based on the choice of the pessimism
indicator in the range from 0 to 1. If the pessimism indicator is
maximal (equal to 1), Hurwicz criteria corresponds to Wald’s
maximin model, realizing a pessimistic strategy. The minimal
pessimism indicator (equal to 0) should not be chosen, because
the optimistic strategy is focused on maximizing the project's
result, so the risk associated with unfavorable development of
the external environment is not taken into account. Hurwicz
criteria is the most flexible of all methods of the game theory,
because it allows to compare several optimistic and pessimistic
scenarios. The disadvantage is the subjectivity of the
pessimism indicator choice by the researcher or the person
making the decision.</p>
      <p>Minimax regret is based on a matrix of regrets, made up of
a matrix of strategies. Regrets are a lost result with a
suboptimal strategy for each current state of the automated
system. At first the maximal impact on each risk factor among
all countermeasures is determined. Further, lost results of all
countermeasures are calculated, then the regression matrix is
compiled, where the maximal ineffective result of each
countermeasure is determined. The countermeasure with the
smallest maximal lost result is selected.</p>
      <p>Each expert should complete two copies of the matrix of
strategies (Table III) – for active countermeasures impact (cija)
that reduces threats and damage, and for passive
countermeasures impact (cijp) that reduces vulnerabilities and
damage.</p>
      <p>...</p>
      <p>am = vm
There are:
b1
c11
c21
...
cm1
b2
c12
c22
...
cm2
...
...
...
...
...</p>
      <p>bn
c1n
c2n
...
cmn
ai – countermeasures;
bj – risk factors;
cij – impact of countermeasure on risk factor;
vi – cost of countermeasure;</p>
      <p>After choosing a countermeasure in accordance with any of
three criteria, depending on the economic strategy, the
corresponding line is removed from the strategy matrix, after
that it is necessary to conduct a new cycle. Countermeasures
among the remaining are selected until their total value does
not exceed the amount of potential damage (12):

∑v ≤ vd

where: ∑v – total cost of selected countermeasures;
vd – cost of potentially possible damage (budget for the
countermeasures implementation).</p>
      <p>Each expert needs to subtract his estimates of the
countermeasures impact (cija, cijp) on risk factors from his
earlier estimates (xij1, xij2, xij3) as (13), (14) and (15):
x*ij1 = xij1 - cija
x*ij2 = xij2 - cija - cijp
x*ij3 = xij3 - cijp


</p>
      <p>Finally, the neuro-fuzzy network calculates the residual risk
level after the countermeasures implementation.</p>
      <p>VI.</p>
      <p>CONCLUSION</p>
      <p>The developed comprehensive information security risk
management methodology meets the required effectiveness
criteria, has a complex and branched structure and represents a
set of methods and models used to implement various stages of
management. The methodology is based on the joint use and
interaction of IDEF0 model, expert survey, neuro-fuzzy
network, methods of game theory and allows the most effective
implementation of drawing up risk factors list, risk factors
assessment, risk level calculation and countermeasures choice.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Kostogryzov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Krylov</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nistratov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Nistratov</surname>
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Popov</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stepanov</surname>
            <given-names>P</given-names>
          </string-name>
          .
          <article-title>Mathematical models and applicable technologies to forecast, analyze, and optimize quality and risks for complex systems</article-title>
          .
          <source>In Proceedings of the First International Conference on Transportation Information and Safety (ICTIS)</source>
          ,
          <source>ASCE</source>
          ,
          <year>2011</year>
          , pp.
          <fpage>845</fpage>
          -
          <lpage>854</lpage>
          . DOI:
          <volume>10</volume>
          .1061/9780784411773.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Brooks</surname>
            <given-names>D.J. Mapping</given-names>
          </string-name>
          <article-title>the consensual knowledge of security risk management experts</article-title>
          .
          <source>In Proceedings of the 7th Australian Information Warfare and Security Conference</source>
          (Edith Cowan University, Perth, Western Australia,
          <fpage>4</fpage>
          -
          <issue>5</issue>
          <year>December 2006</year>
          ),
          <year>2006</year>
          , 10 p. DOI:
          <volume>10</volume>
          .4225/75/57a823cbaa0d8.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Ruighaver</surname>
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Warren</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ahmad</surname>
            <given-names>A</given-names>
          </string-name>
          .
          <article-title>Ascent of Asymmetric Risk in Information Security: An Initial Evaluation</article-title>
          .
          <source>In Proceedings of the 10th Australian Information Warfare and Security Conference</source>
          (Edith Cowan University, Perth, Western Australia,
          <fpage>1</fpage>
          -
          <issue>3</issue>
          <year>December 2009</year>
          ),
          <year>2009</year>
          , 8 p. DOI:
          <volume>10</volume>
          .4225/75/57a7f620aa0c6.
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Barabanov</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Markov</surname>
            <given-names>A.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tsirlov</surname>
            <given-names>V.L. Methodological</given-names>
          </string-name>
          <article-title>Framework for Analysis and Synthesis of a Set of Secure Software Development Controls</article-title>
          ,
          <source>Journal of Theoretical and Applied Information Technology</source>
          ,
          <year>2016</year>
          , vol.
          <volume>88</volume>
          , No 1, pp.
          <fpage>77</fpage>
          -
          <lpage>88</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Marques</surname>
            <given-names>P.H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jacinto</surname>
            <given-names>C</given-names>
          </string-name>
          .
          <article-title>Human-HAZOP studies in the risk management of major accidents</article-title>
          .
          <source>In Proceedings of the International Symposium on Occupational Safety and Hygiene (SHO'</source>
          <year>2015</year>
          , Guimarães, Portugal,
          <fpage>12</fpage>
          -
          <lpage>13</lpage>
          February
          <year>2015</year>
          ),
          <year>2016</year>
          , pp.
          <fpage>146</fpage>
          -
          <lpage>148</lpage>
          . DOI:
          <volume>10</volume>
          .13140/RG.2.1.4446.1684.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Jakub</surname>
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schindler</surname>
            <given-names>F.</given-names>
          </string-name>
          <string-name>
            <surname>Assets</surname>
          </string-name>
          <article-title>Dependencies Model in Information Security Risk Management</article-title>
          .
          <source>In Proceedings of the Second IFIP International Conference (ICT EurAsia</source>
          , Bali, Indonesia),
          <year>2014</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>10</lpage>
          . DOI:
          <volume>10</volume>
          .13140/RG.2.1.3376.6480.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Alan</surname>
            <given-names>A.R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Arshad</surname>
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ibrahim</surname>
            <given-names>J.</given-names>
          </string-name>
          , et al.
          <source>IT Risk</source>
          , Information Security &amp;
          <article-title>Governance Practices in Malaysia IHLs</article-title>
          .
          <source>In Proceedings of the International Research Invention, Innovation, and Exhibition</source>
          <year>2014</year>
          (
          <article-title>IRIIE 2014, IIUM</article-title>
          ,
          <string-name>
            <surname>Kuala</surname>
            <given-names>Lumpur</given-names>
          </string-name>
          , Malaysia),
          <year>2014</year>
          , pp.
          <fpage>459</fpage>
          -
          <lpage>459</lpage>
          . DOI:
          <volume>10</volume>
          .13140/2.1.2868.5440.
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Pandey</surname>
            <given-names>P</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Shekkens</surname>
            <given-names>E.A.</given-names>
          </string-name>
          <article-title>An Assessment of Market Methods for Information Security Risk Management</article-title>
          .
          <source>In Proceedings of the 16th IEEE International Conference on High Performance and Communications</source>
          <year>2014</year>
          (WiP Track, Paris, France),
          <year>2014</year>
          , 8 p.
          <source>DOI: 10.13140/2</source>
          .1.4348.5445.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Yilmaz</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yalman</surname>
            <given-names>Y.</given-names>
          </string-name>
          <article-title>A Comparative Analysis of University Information Systems within the Scope of the Information Security Risks</article-title>
          .
          <source>TEM Journal</source>
          .
          <year>2016</year>
          . V.
          <article-title>5</article-title>
          . N 2. P.
          <volume>180</volume>
          -
          <fpage>191</fpage>
          . DOI:
          <volume>10</volume>
          .18421/TEM52-10.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Moore</surname>
            <given-names>T.W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Probst</surname>
            <given-names>C.W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ranneberg</surname>
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>van Eeten</surname>
            <given-names>M. Assessing</given-names>
          </string-name>
          <article-title>ICT Security Risks in Socio-Technical Systems</article-title>
          . Dagstuhl Reports.
          <year>2017</year>
          . V.
          <article-title>6</article-title>
          . N 11. P.
          <volume>63</volume>
          -
          <fpage>89</fpage>
          . DOI:
          <volume>10</volume>
          .4230/DagRep.6.11.63.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Aleksandrov</surname>
            <given-names>A.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Neusipin</surname>
            <given-names>K.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Proletarsky</surname>
            <given-names>A.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Fang</surname>
            <given-names>K.</given-names>
          </string-name>
          <article-title>Innovation development trends of modern management systems of educational organizations</article-title>
          .
          <source>In: 2012 International Conference on Information Management</source>
          ,
          <article-title>Innovation Management and Industrial Engineering</article-title>
          . IEEE, Sanya, China,
          <year>2012</year>
          , pp.
          <fpage>187</fpage>
          -
          <lpage>189</lpage>
          . DOI:
          <volume>10</volume>
          .1109/ICIII.
          <year>2012</year>
          .
          <volume>6339951</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Buldakova</surname>
            <given-names>T.I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mikov D</surname>
          </string-name>
          .
          <article-title>A. Ensuring the Concordance and the Adequacy of Information Security Risk Factors Assessment</article-title>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          .
          <source>2017. N</source>
          <volume>3</volume>
          (
          <issue>21</issue>
          ), pp.
          <fpage>8</fpage>
          -
          <lpage>15</lpage>
          . DOI:
          <volume>10</volume>
          .21581/
          <fpage>2311</fpage>
          -3456-2017-2-8-15.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>McNaught</surname>
            <given-names>K.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sutovsky</surname>
            <given-names>P.</given-names>
          </string-name>
          <string-name>
            <surname>Representing</surname>
          </string-name>
          <article-title>Variable Source Credibility in Intelligence Analysis with Bayesian Networks</article-title>
          .
          <source>In Proceedings of the 5th Australian Security and Intelligence Conference (Novotel Langley Hotel, Perth, Western Australia, 3-5 December</source>
          <year>2012</year>
          ),
          <year>2013</year>
          , pp.
          <fpage>44</fpage>
          -
          <lpage>51</lpage>
          . DOI:
          <volume>10</volume>
          .4225/75/57a03050ac5cb.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Grigoras</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mustata</surname>
            <given-names>A.-M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Teodorescu</surname>
            <given-names>C</given-names>
          </string-name>
          .
          <article-title>Predicting the state of security using neural networks</article-title>
          .
          <source>In Proceedings of the 9th International Scientific Conference on eLearning and Software for Education</source>
          (Bucharest, Romania,
          <fpage>25</fpage>
          -
          <lpage>26</lpage>
          April
          <year>2013</year>
          ),
          <year>2013</year>
          , pp.
          <fpage>362</fpage>
          -
          <lpage>367</lpage>
          . DOI:
          <volume>10</volume>
          .12753/2066-026X-
          <fpage>17</fpage>
          -167.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Starodubtsev</surname>
            <given-names>Yu.I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Grechishnikov</surname>
            <given-names>E.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Komolov D</surname>
          </string-name>
          .V.
          <article-title>Use of neural networks to ensure stability of communication networks in conditions of external impacts</article-title>
          .
          <source>Telecommunications and Radio Engineering</source>
          .
          <year>2011</year>
          . V. 70. N 14. P.
          <volume>1263</volume>
          -
          <fpage>1275</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Beheshti</surname>
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Alborzi</surname>
            <given-names>M. Using</given-names>
          </string-name>
          <article-title>Fuzzy Logic to Increase the Accuracy of E-Commerce Risk Assessment Based on an Expert System</article-title>
          . Engineering, Technology &amp; Applied Science Research.
          <year>2017</year>
          . V.
          <article-title>7</article-title>
          . N 6. P 2205-
          <fpage>2209</fpage>
          . DOI:
          <volume>10</volume>
          .5281/zenodo.1118299.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Sasidevi</surname>
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sugumar</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Priya</surname>
            <given-names>P.S.</given-names>
          </string-name>
          <article-title>A Cost-Effective Privacy Preserving Using Anonymization Based Hybrid Bat Algorithm With Simulated Annealing Approach For Intermediate Data Sets Over Cloud Computing</article-title>
          .
          <source>International Journal of Computational Research and Development</source>
          .
          <year>2017</year>
          . V.
          <article-title>2</article-title>
          . N 2. P.
          <volume>173</volume>
          -
          <fpage>181</fpage>
          . DOI:
          <volume>10</volume>
          .5281/zenodo.1069736.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Vorobiev</surname>
            <given-names>E.G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Petrenko</surname>
            <given-names>S.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kovaleva</surname>
            <given-names>I.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Abrosimov</surname>
            <given-names>I.K.</given-names>
          </string-name>
          <article-title>Analysis of computer security incidents using fuzzy logic</article-title>
          .
          <source>In Proceedings of the 20th IEEE International Conference on Soft Computing and Measurements (24-26 May</source>
          <year>2017</year>
          , St. Petersburg, Russia).
          <source>SCM</source>
          <year>2017</year>
          ,
          <year>2017</year>
          , pp.
          <fpage>369</fpage>
          -
          <lpage>371</lpage>
          . DOI:
          <volume>10</volume>
          .1109/SCM.
          <year>2017</year>
          .
          <volume>7970587</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Singh</surname>
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Prasad</surname>
            <given-names>T.V.</given-names>
          </string-name>
          <article-title>Exploration of Hybrid Neuro Fuzzy Systems</article-title>
          .
          <source>In Proceedings of the National Conference on Advances in Knowledge Management (NCAKM</source>
          <year>2010</year>
          , At Lingaya's University, Faridabad, Haryana, India),
          <year>2010</year>
          , 6 p.
          <source>DOI: 10.13140/RG.2.1.3570.0327.</source>
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Derugo</surname>
            <given-names>P.</given-names>
          </string-name>
          <article-title>Application of competitive and transition Petri layers in adaptive neuro-fuzzy controller</article-title>
          .
          <source>Power Electronics and Drives Berlin</source>
          .
          <year>2016</year>
          . V.
          <volume>1</volume>
          (
          <issue>36</issue>
          ). N 1. P.
          <volume>103</volume>
          -
          <fpage>115</fpage>
          . DOI:
          <volume>10</volume>
          .5277/PED160108.
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <surname>Schauer</surname>
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stamer</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bosse</surname>
            <given-names>C.</given-names>
          </string-name>
          , et al.
          <article-title>An adaptive supply chain cyber risk management methodology</article-title>
          .
          <source>In Proceedings of the Hamburg International Conference of Logistics (HICL</source>
          , Hamburg, Germany),
          <year>2017</year>
          , pp.
          <fpage>405</fpage>
          -
          <lpage>425</lpage>
          . DOI:
          <volume>10</volume>
          .15480/882.149.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>