An Ontology of Information Security
Almut Herzog,
Nahid Shahmehri and
Claudiu Duma
Additional contact information
Almut Herzog: Linkopings Universitet, Sweden
Nahid Shahmehri: Linkopings Universitet, Sweden
Claudiu Duma: Linkopings Universitet, Sweden
International Journal of Information Security and Privacy (IJISP), 2007, vol. 1, issue 4, 1-23
Abstract:
We present a publicly available, OWL-based ontology of information security which models assets, threats, vulnerabilities, countermeasures and their relations. The ontology can be used as a general vocabulary, roadmap, and extensible dictionary of the domain of information security. With its help, users can agree on a common language and definition of terms and relationships. In addition to browsing for information, the ontology is also useful for reasoning about relationships between its entities, for example, threats and countermeasures. The ontology helps answer questions like: Which countermeasures detect or prevent the violation of integrity of data? Which assets are protected by SSH? Which countermeasures thwart buffer overflow attacks? At the moment, the ontology comprises 88 threat classes, 79 asset classes, 133 countermeasure classes and 34 relations between those classes. We provide the means for extending the ontology, and provide examples of the extendibility with the countermeasure classes ‘memory protection’ and ‘source code analysis’. This article describes the content of the ontology as well as its usages, potential for extension, technical implementation and tools for working with it.
Date: 2007
References: Add references at CitEc
Citations: View citations in EconPapers (2)
Downloads: (external link)
http://services.igi-global.com/resolvedoi/resolve. ... 4018/jisp.2007100101 (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:igg:jisp00:v:1:y:2007:i:4:p:1-23
Access Statistics for this article
International Journal of Information Security and Privacy (IJISP) is currently edited by Yassine Maleh
More articles in International Journal of Information Security and Privacy (IJISP) from IGI Global
Bibliographic data for series maintained by Journal Editor ().