Semantic Risk Assessment for Cybersecurity

被引:0
作者
Aviad, Adiel [1 ]
Wecel, Krzysztof [1 ]
Abramowicz, Witold [1 ]
机构
[1] Poznan Univ Econ, Poznan, Poland
来源
PROCEEDINGS OF THE 13TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2018) | 2018年
关键词
cyber security; semantic web technology; risk management; risk assessment; WEB;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity is in essence a function of risk reduction for the organization. Due to the rapid evolvement and wide diversity of technologies, it is important that risks will be managed in a way that is capable of handling much wider and diversified knowledge while reducing the increasing costs of such effort. There is a variety of methods for risk assessment but it is common for them to consider threats and improve security by taking countermeasures. Due to constraints of budget and time together with the rapid evolvement of risks (threats), knowledgeable prioritization is important. In this paper we present a semantic approach to the handling of a "fabric of knowledge" in the form of a model and ontology of the cybersecurity body of knowledge. Such a model may serve as a cybersecurity framework, managing the knowledge in a way that enables sharing of the knowledge while bridging terminology gaps and automatic processing of the data. It makes use of machine understanding and automatic reasoning. Several aspects of the cybersecurity body of knowledge are examined, presenting a semantic way of handling them, together with the benefits of handling them semantically. These aspects cover the cybersecurity body of knowledge extensively, culminating to risk assessment based on knowledge that is wider and more up to date while also enable automatic reasoning. The automatic reasoning may assist in better processing of the vast amount of new knowledge that is constantly added to this body of knowledge. Such reasoning may also be part of the knowledge, and also shared the rest of the knowledge. This paper proposes semantic approach for risk management. The CORAS risk assessment and the CVSS risk scoring methods are used to exemplify semantic representation of the risk assessment and scoring sub domains, respectively. A model is presented, advantages and limitations are discussed.
引用
收藏
页码:513 / 520
页数:8
相关论文
共 35 条
[1]  
[Anonymous], 2006, CORAS MODEL BASED ME
[2]  
[Anonymous], 2010, The National Security Systems Instruction, V4009, P103
[3]  
Barnum S., 2014, STIX WHITEPAPER
[4]  
Behnia A., 2012, The Smart Computing Review, V2, P79, DOI DOI 10.6029/SMARTCR.2012.01.007
[5]   The Semantic Web - A new form of Web content that is meaningful to computers will unleash a revolution of new possibilities [J].
Berners-Lee, T ;
Hendler, J ;
Lassila, O .
SCIENTIFIC AMERICAN, 2001, 284 (05) :34-+
[6]  
Bornman W., 2004, INFORM SECURITY S AF
[7]  
Brown S., 2015, P 2 ACM WORKSH INF S, P43, DOI [10.1145/2808128.2808133, DOI 10.1145/2808128.2808133]
[8]  
Dahl H.E.I., 2007, P 2 INT WORKSH INT S, P79
[9]  
Davidson M., 2014, TAXII WHITEPAPER TAX
[10]  
Ekelhart A., 2009, Proceedings of the 42nd Hawaii International Conference on System Sciences (HICSS'09), P1, DOI DOI 10.1109/HICSS.2009.82