Managing software security knowledge in context: An ontology based approach

被引:0
|
作者
Wen S.-F. [1 ]
Katt B. [1 ]
机构
[1] Faculty of Information Technology and Electrical Engineering, Norwegian University of Science and Technology, Gjøvik
关键词
Context-based; Knowledge management; Security ontology; Software security;
D O I
10.3390/INFO10060216
中图分类号
学科分类号
摘要
Knowledge of software security is highly complex since it is quite context-specific and can be applied in diverse ways. To secure software development, software developers require not only knowledge about general security concepts but also about the context for which the software is being developed. With traditional security-centric knowledge formats, it is difficult for developers or knowledge users to retrieve their required security information based on the requirements of software products and development technologies. In order to effectively regulate the operation of security knowledge and be an essential part of practical software development practices, we argue that security knowledge must first incorporate features that specify what contextual characteristics are to be handled, and represent the security knowledge in a format that is understandable and acceptable to the individuals. This study introduces a novel ontology approach for modeling security knowledge with a context-based approach, by which security knowledge can be retrieved, taking the context of the software application at hand into consideration. In this paper, we present our security ontology with the design concepts and the corresponding evaluation process. © 2019 by the authors.
引用
收藏
相关论文
共 50 条
  • [31] Towards Managing Information Security Knowledge Through Metamodelling Approach
    Baras, Doaa Saleh Abobakr
    Othman, Siti Hajar
    Ahmad, Mohammad Nazir
    Ithnin, Norafida
    2014 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2014, : 310 - 315
  • [32] An Ontology-based Approach for Automatic Specification, Verification, and Validation of Software Security Requirements: Preliminary Results
    Tsoukalas, Dimitrios
    Siavvas, Miltiadis
    Mathioudaki, Maria
    Kehagias, Dionysios
    2021 21ST INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY COMPANION (QRS-C 2021), 2021, : 83 - 91
  • [33] Ontology based Approach in Knowledge Sharing Measurement
    ZadJabbari, Behrang
    Wongthongtham, Pornpit
    Hussain, Farookh Khadeer
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2010, 16 (06) : 956 - 982
  • [34] A Security Ontology with MDA for Software Development
    Kang, Wentao
    Liang, Ying
    2013 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY (CYBERC), 2013, : 67 - 74
  • [35] Managing Security Knowledge through Case based Reasoning
    Visaggio, Corrado Aaron
    De Rosa, Francesca
    SECURITY IN INFORMATION SYSTEMS, PROCEEDINGS, 2009, : 127 - 136
  • [36] An Ontology-based Knowledge Sharing Portal for Software Testing
    Vasanthapriyan, Shanmuganathan
    Tian, Jing
    Zhao, Dongdong
    Xiong, Shengwu
    Xiang, Jianwen
    2017 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY COMPANION (QRS-C), 2017, : 472 - 479
  • [37] Research on Knowledge Model for Grid Security Incident Based on Ontology
    Huang, Feng
    Du, Ke
    Liang, Yun
    Huang, Li
    Yao, Ji-ming
    INTERNATIONAL CONFERENCE ON COMPUTER, NETWORK SECURITY AND COMMUNICATION ENGINEERING (CNSCE 2014), 2014, : 431 - 436
  • [38] Research on Ontology-based Network Security Knowledge Map
    Chen, Biqiong
    Liu, Yanhua
    Zheng, YaNing
    2018 INTERNATIONAL CONFERENCE ON CLOUD COMPUTING, BIG DATA AND BLOCKCHAIN (ICCBB 2018), 2018, : 36 - 42
  • [39] Knowledge for software security
    Barnum, S
    McGraw, G
    IEEE SECURITY & PRIVACY, 2005, 3 (02) : 74 - 78
  • [40] Mapping the Knowledge of Dante Commentaries in the Digital Context: A Web Ontology Approach
    Meghini, Carlo
    Tavoni, Mirko
    Zaccarello, Michelangelo
    ROMANIC REVIEW, 2021, 112 (01): : 138 - 157