Applying Fuzzy Multiple Criteria Decision Making to Evaluate Network Access Control System

碩士 === 華梵大學 === 資訊管理學系碩士班 === 98 === In the internal network, the defense demand gradually increased, the Network Access Control (NAC) is able to perform the user’s identity authentication and test the security such as anti-virus software enable and update virus patterns, install the operation syste...

Full description

Bibliographic Details
Main Authors: Min-Shu Liao, 廖敏書
Other Authors: Tsung-Ynan Tseng
Format: Others
Language:zh-TW
Published: 2010
Online Access:http://ndltd.ncl.edu.tw/handle/58557995926327105526
Description
Summary:碩士 === 華梵大學 === 資訊管理學系碩士班 === 98 === In the internal network, the defense demand gradually increased, the Network Access Control (NAC) is able to perform the user’s identity authentication and test the security such as anti-virus software enable and update virus patterns, install the operation system patch(es) and so on before user access internal network. The NAC is able to isolated user until his information equipment repaired to prevent virus or worm if user’s equipment does not meet security policy. For an organization, the pre-deployment assessment of NAC system might includes: the extent of changes to the existing network infrastructure, difficulty of deployment, functional requirements, the user's access control and cost aspects. These assessments is more involved in network management, the user's computer management, access control and many other units. Therefore, the NAC solution evaluation becomes more difficult and complex because of a number of assessment criteria of choice . This study proposes the NAC solution decision-making model which utilize the NAC standards and information technology security products selecting guides to develop evaluation criteria of NAC for criteria evaluation questionnaires. The questionnaires were conducted on experts. We utilized the Analytic Hierarchy Process (AHP) to determine the weighted values of various principles and to find out the important principles of the evaluation criteria and utilized Fuzzy Synthetic Decision method to determine the NAC solution selection priority as an organization select NAC solution reference basis. The results show that the system integrity and the cost of attention are most import to decision-makers. Therefore, the most in need of consideration of issues for the NAC implement are risk reducing and implement cost to an organization.