Managing software security knowledge in context: An ontology based approach

被引:0
|
作者
Wen S.-F. [1 ]
Katt B. [1 ]
机构
[1] Faculty of Information Technology and Electrical Engineering, Norwegian University of Science and Technology, Gjøvik
关键词
Context-based; Knowledge management; Security ontology; Software security;
D O I
10.3390/INFO10060216
中图分类号
学科分类号
摘要
Knowledge of software security is highly complex since it is quite context-specific and can be applied in diverse ways. To secure software development, software developers require not only knowledge about general security concepts but also about the context for which the software is being developed. With traditional security-centric knowledge formats, it is difficult for developers or knowledge users to retrieve their required security information based on the requirements of software products and development technologies. In order to effectively regulate the operation of security knowledge and be an essential part of practical software development practices, we argue that security knowledge must first incorporate features that specify what contextual characteristics are to be handled, and represent the security knowledge in a format that is understandable and acceptable to the individuals. This study introduces a novel ontology approach for modeling security knowledge with a context-based approach, by which security knowledge can be retrieved, taking the context of the software application at hand into consideration. In this paper, we present our security ontology with the design concepts and the corresponding evaluation process. © 2019 by the authors.
引用
收藏
相关论文
共 50 条
  • [1] Managing Software Security Knowledge in Context: An Ontology Based Approach
    Wen, Shao-Fang
    Katt, Basel
    INFORMATION, 2019, 10 (06):
  • [2] An Ontology-Based Context Model for Managing Security Knowledge in Software Development
    Wen, Shao-Fang
    Katt, Basel
    PROCEEDINGS OF THE 2018 23RD CONFERENCE OF OPEN INNOVATIONS ASSOCIATION (FRUCT), 2018, : 416 - 424
  • [3] Approach for knowledge sharing based on ontology context immigration
    School of Control and Computer Engineering, North China Electric Power University, Beijing 102206, China
    不详
    J. Southeast Univ. Engl. Ed., 2009, 4 (473-476):
  • [4] An ontology framework for managing security attacks and defences in component based software systems
    Vorobiev, Artem
    Han, Jun
    Bekmamedova, Nargiza
    ASWEC 2008: 19TH AUSTRALIAN SOFTWARE ENGINEERING CONFERENCE, PROCEEDINGS, 2008, : 552 - 561
  • [5] An Ontology-Based Approach For Software Architectural Knowledge Management
    Choobdaran, Narges
    Sharfi, Sayed Mehran
    Khayyambashi, Mohamad Reza
    JOURNAL OF MATHEMATICS AND COMPUTER SCIENCE-JMCS, 2014, 11 (02): : 93 - 104
  • [6] The Semantic Approach to Cyber Security Towards Ontology Based Body of Knowledge
    Aviad, Adiel
    Wecel, Krzysztof
    Abramowicz, Witold
    PROCEEDINGS OF THE 14TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS-2015), 2015, : 328 - 336
  • [7] Toward a Context-Based Approach for Software Security Learning
    Wen, Shao-Fang
    Katt, Basel
    JOURNAL OF APPLIED SECURITY RESEARCH, 2019, 14 (03) : 288 - 307
  • [8] An ontology-based approach to software comprehension - Reasoning about security concerns
    Zhang, Yonggang
    Rilling, Juergen
    Haarslev, Volker
    30TH ANNUAL INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE, VOL 1, REGULAR PAPERS/PANELS, PROCEEDINGS, 2006, : 333 - +
  • [9] Study on customer creativity knowledge acquisition based on context- knowledge ontology interaction for complex software
    Zhang, Q. (zqh_100@163.com), 1600, Advanced Institute of Convergence Information Technology, Myoungbo Bldg 3F,, Bumin-dong 1-ga, Seo-gu, Busan, 602-816, Korea, Republic of (07):
  • [10] Ontology Based Patterns for Software Security Engineering
    Moradian, Esmiralda
    Hakansson, Anne
    Andersson, Jan-Olof
    ADVANCES IN KNOWLEDGE-BASED AND INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS, 2012, 243 : 406 - 419