Author:
Välja Margus,Heiding Fredrik,Franke Ulrik,Lagerström Robert
Abstract
AbstractThreat modeling is of increasing importance to IT security, and it is a complex and resource demanding task. The aim of automating threat modeling is to simplify model creation by using data that are already available. However, the collected data often lack context; this can make the automated models less precise in terms of domain knowledge than those created by an expert human modeler. The lack of domain knowledge in modeling automation can be addressed with ontologies. In this paper, we introduce an ontology framework to improve automatic threat modeling. The framework is developed with conceptual modeling and validated using three different datasets: a small scale utility lab, water utility control network, and university IT environment. The framework produced successful results such as standardizing input sources, removing duplicate name entries, and grouping application software more logically.
Publisher
Springer Science and Business Media LLC
Subject
Artificial Intelligence,Computer Networks and Communications,Information Systems,Software
Reference63 articles.
1. Aier, S, Buckl S, Franke U, Gleichauf B, Johnson P, Närman P, Schweda CM, Ullberg J (2009) A survival analysis of application life spans based on enterprise architecture models. In: Mendling J, Rinderle-Ma S, Esswein W (eds)Enterprise modelling and information systems architectures : Proceedings of the 3rd international workshop on enterprise modelling and information systems architectures. vol. LNI P-152, 141–154.. Gesellschaft für Informatik, Bonn.
2. Aier, S, Gleichauf B, Saat J, Winter R (2009) Complexity levels of representing dynamics in ea planning. In: Albani A, Barjis J, Dietz JLG (eds)Advances in Enterprise Engineering III, 55–69.. Springer, Berlin.
3. Akhawe, D, Barth A, Lam PE, Mitchell J, Song D (2010) Towards a formal foundation of web security In: 23rd IEEE Computer Security Foundations Symposium, 290–304.. IEEE, Edinburgh.
4. Antunes, G, Bakhshandeh M, Mayer R, Borbinha J, Caetano A (2014) Using ontologies for enterprise architecture integration and analysis. Compl Syst Informa Model Q 1(1):1–23. https://doi.org/10.7250/csimq.2014-1.01 https://www.ingentaconnect.com/content/doaj/22559922/2014/00000001/00000001/art00001.
5. Antunes, G, Borbinha J, Caetano A (2016) An application of semantic techniques to the analysis of enterprise architecture models In: 49th Hawaii International Conference on System Sciences (HICSS), 4536–4545.. IEEE, Honolulu. https://doi.org/10.1109/HICSS.2016.564.
Cited by
18 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献