Managing software security knowledge in context: An ontology based approach

被引:0
|
作者
Wen S.-F. [1 ]
Katt B. [1 ]
机构
[1] Faculty of Information Technology and Electrical Engineering, Norwegian University of Science and Technology, Gjøvik
关键词
Context-based; Knowledge management; Security ontology; Software security;
D O I
10.3390/INFO10060216
中图分类号
学科分类号
摘要
Knowledge of software security is highly complex since it is quite context-specific and can be applied in diverse ways. To secure software development, software developers require not only knowledge about general security concepts but also about the context for which the software is being developed. With traditional security-centric knowledge formats, it is difficult for developers or knowledge users to retrieve their required security information based on the requirements of software products and development technologies. In order to effectively regulate the operation of security knowledge and be an essential part of practical software development practices, we argue that security knowledge must first incorporate features that specify what contextual characteristics are to be handled, and represent the security knowledge in a format that is understandable and acceptable to the individuals. This study introduces a novel ontology approach for modeling security knowledge with a context-based approach, by which security knowledge can be retrieved, taking the context of the software application at hand into consideration. In this paper, we present our security ontology with the design concepts and the corresponding evaluation process. © 2019 by the authors.
引用
收藏
相关论文
共 50 条
  • [21] Distributed knowledge management based on software agents and ontology
    Laclavik, M
    Balogh, Z
    Hluchy, L
    Slota, R
    Krawczyk, K
    Dziewierz, M
    PARALLEL PROCESSING AND APPLIED MATHEMATICS, 2004, 3019 : 694 - 699
  • [22] Embedding and Predicting Software Security Entity Relationships: A Knowledge Graph Based Approach
    Xiao, Hongbo
    Xing, Zhenchang
    Li, Xiaohong
    Guo, Hao
    NEURAL INFORMATION PROCESSING (ICONIP 2019), PT III, 2019, 11955 : 50 - 63
  • [23] OntCAAC: An Ontology-Based Approach to Context-Aware Access Control for Software Services
    Kayes, A. S. M.
    Han, Jun
    Colman, Alan
    COMPUTER JOURNAL, 2015, 58 (11): : 3000 - 3034
  • [24] The approach of software component description based on ontology
    Zhou, Xiaofeng
    DCABES 2007 PROCEEDINGS, VOLS I AND II, 2007, : 416 - 420
  • [25] Managing knowledge security
    Ryan, Julie J.C.H.
    VINE, 2006, 36 (02): : 143 - 145
  • [26] An Ontology Based Approach for Context Based Collaborative Browsing
    AlAgha, Iyad
    Burd, Liz
    ICALT: 2009 IEEE INTERNATIONAL CONFERENCE ON ADVANCED LEARNING TECHNOLOGIES, 2009, : 131 - 135
  • [27] Towards an Ontology for IoT Context-Based Security Evaluation
    Gonzalez-Gil, Pedro
    Skarmeta, Antonio F.
    Antonio Martinez, Juan
    2019 GLOBAL IOT SUMMIT (GIOTS), 2019,
  • [28] Context in Ontology for Knowledge Representation
    Chebba, Asmaa
    Bouabana-Tebibel, Thouraya
    Rubin, Stuart H.
    ADVANCED COMPUTATIONAL METHODS FOR KNOWLEDGE ENGINEERING, 2015, 358 : 311 - 320
  • [29] Managing software security risks
    McGraw, G
    COMPUTER, 2002, 35 (04) : 99 - 101
  • [30] Developing and managing software components in an ontology-based application server
    Oberle, D
    Eberhart, A
    Staab, S
    Volz, R
    MIDDLEWARE 2004, PROCEEDINGS, 2004, 3231 : 459 - 477