Semantic Risk Assessment for Cybersecurity

被引:0
|
作者
Aviad, Adiel [1 ]
Wecel, Krzysztof [1 ]
Abramowicz, Witold [1 ]
机构
[1] Poznan Univ Econ, Poznan, Poland
关键词
cyber security; semantic web technology; risk management; risk assessment; WEB;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity is in essence a function of risk reduction for the organization. Due to the rapid evolvement and wide diversity of technologies, it is important that risks will be managed in a way that is capable of handling much wider and diversified knowledge while reducing the increasing costs of such effort. There is a variety of methods for risk assessment but it is common for them to consider threats and improve security by taking countermeasures. Due to constraints of budget and time together with the rapid evolvement of risks (threats), knowledgeable prioritization is important. In this paper we present a semantic approach to the handling of a "fabric of knowledge" in the form of a model and ontology of the cybersecurity body of knowledge. Such a model may serve as a cybersecurity framework, managing the knowledge in a way that enables sharing of the knowledge while bridging terminology gaps and automatic processing of the data. It makes use of machine understanding and automatic reasoning. Several aspects of the cybersecurity body of knowledge are examined, presenting a semantic way of handling them, together with the benefits of handling them semantically. These aspects cover the cybersecurity body of knowledge extensively, culminating to risk assessment based on knowledge that is wider and more up to date while also enable automatic reasoning. The automatic reasoning may assist in better processing of the vast amount of new knowledge that is constantly added to this body of knowledge. Such reasoning may also be part of the knowledge, and also shared the rest of the knowledge. This paper proposes semantic approach for risk management. The CORAS risk assessment and the CVSS risk scoring methods are used to exemplify semantic representation of the risk assessment and scoring sub domains, respectively. A model is presented, advantages and limitations are discussed.
引用
收藏
页码:513 / 520
页数:8
相关论文
共 50 条
  • [1] Cybersecurity risk assessment of VDR
    Soner, Omer
    Kayisoglu, Gizem
    Bolat, Pelin
    Tam, Kimberly
    [J]. JOURNAL OF NAVIGATION, 2023, 76 (01): : 20 - 37
  • [2] Cybersecurity Risk Assessment for Space Systems
    Vessels, Ly
    Heffner, Kenneth
    Johnson, Daniel
    [J]. 2019 IEEE SPACE COMPUTING CONFERENCE (SCC), 2019, : 11 - 19
  • [3] A Systems Approach for Cybersecurity Risk Assessment
    Meshkat, Leila
    Miller, Robert L.
    [J]. 2022 68TH ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM (RAMS 2022), 2022,
  • [4] Digital Human in Cybersecurity Risk Assessment
    Jureviciene, Aiste
    Brilingaite, Agne
    Bukauskas, Linas
    [J]. AUGMENTED COGNITION, AC 2021, 2021, 12776 : 418 - 432
  • [5] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Wang, Yunpeng
    Wang, Yinghui
    Qin, Hongmao
    Ji, Haojie
    Zhang, Yanan
    Wang, Jian
    [J]. AUTOMOTIVE INNOVATION, 2021, 4 (03) : 253 - 261
  • [6] A simulation framework for automotive cybersecurity risk assessment
    Jayaratne, Don Nalin Dharshana
    Kamtam, Suraj Harsha
    Shaikh, Siraj Ahmed
    Ramli, Muhamad Azfar
    Lu, Qian
    Mepparambath, Rakhi Manohar
    Nguyen, Hoang Nga
    Rakib, Abdur
    [J]. SIMULATION MODELLING PRACTICE AND THEORY, 2024, 136
  • [7] Cybersecurity Risk Assessment in Smart City Infrastructures
    Kalinin, Maxim
    Krundyshev, Vasiliy
    Zegzhda, Peter
    [J]. MACHINES, 2021, 9 (04)
  • [8] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Yunpeng Wang
    Yinghui Wang
    Hongmao Qin
    Haojie Ji
    Yanan Zhang
    Jian Wang
    [J]. Automotive Innovation, 2021, 4 : 253 - 261
  • [9] Yet another cybersecurity risk assessment framework
    Ekstedt, Mathias
    Afzal, Zeeshan
    Mukherjee, Preetam
    Hacks, Simon
    Lagerstrom, Robert
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (06) : 1713 - 1729
  • [10] A Methodology for Cybersecurity Risk Assessment in Supply Chains
    Gokkaya, Betul
    Aniello, Leonardo
    Karafili, Erisa
    Halak, Basel
    [J]. COMPUTER SECURITY. ESORICS 2023 INTERNATIONAL WORKSHOPS, CPS4CIP, PT II, 2024, 14399 : 26 - 41