Ontology of Metrics for Cyber Security Assessment

Ontology of Metrics for Cyber Security Assessment
复制标题

DOI:
10.1145/3339252.3341496
复制
发表时间:
2019-08
期刊:
Proceedings of the 14th International Conference on Availability, Reliability and Security
影响因子:
--
通讯作者:
E. Doynikova;A. Fedorchenko;Igor Kotenko
E. Doynikova;A. Fedorchenko;Igor Kotenko
中科院分区:
其他
文献类型:
--
作者:
E. Doynikova;A. Fedorchenko;Igor Kotenko

文献摘要

被引文献

相似文献

开发对评估安全和决策有价值的指标是有效应对网络威胁的重要因素。本文提出了一个本体的度量网络安全评估。所开发的本体是基于确定的概念和初始安全数据的主要特征之间的关系,并形成一组分层互联的安全度量。本文描述了所提出的本体的主要类,揭示的关系,所涉及的安全度量,以及使用的数据源。分析公开可用的安全数据源以获得主要安全度量。该方法的应用上的案例研究。所提出的本体的主要特点是表示作为单独的本体实例的安全度量。它允许使用本体概念之间的关系来计算反映安全状态的整体度量。
Development of metrics that are valuable for assessing security and decision making is an important element of efficient counteraction to cyber threats. The paper proposes an ontology of metrics for cyber security assessment. The developed ontology is based on determining the concepts and relations between primary features of initial security data and forming a set of hierarchically interconnected security metrics. The paper describes the main classes of the proposed ontology, the revealed relations, the involved security metrics, and the used data sources. The publicly available sources of security data are analyzed to get primary security metrics. Application of the approach is shown on a case study. The main feature of the proposed ontology is representation of security metrics as separate instances of ontology. It allows using the relations between the concepts of ontology for calculating integral metrics reflecting the security state.