A Semantic Approach for Automating Knowledge in Policies of Cyber Insurance Services

被引:7
|
作者
Joshi, Ketki [1 ]
Joshi, Karuna Pande [1 ]
Mittal, Sudip [2 ]
机构
[1] Univ Maryland, Dept Informat Syst, Baltimore, MD 21250 USA
[2] Univ Maryland, CSEE Dept, Baltimore, MD 21250 USA
关键词
Cyber Insurance; Ontology; Knowledge Representation; Policies;
D O I
10.1109/ICWS.2019.00018
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
With the rapid adoption of web services, the need to protect against various threats has become imperative for organizations operating in cyberspace. Organizations are increasingly opting to get financial cover in the event of losses due to a security incident. This helps them safeguard against the threat posed to third-party services that the organization uses. It is in the organization's interest to understand the insurance requirements and procure all necessary direct and liability coverages. This helps transfer some risks to the insurance providers. However, cyber insurance policies often list details about coverages and exclusions using legalese that can be difficult to comprehend. Currently, it takes a significant manual effort to parse and extract knowledgeable rules from these lengthy and complicated policy documents. We have developed a semantically rich machine processable framework to automatically analyze cyber insurance policy and populate a knowledge graph that efficiently captures various inclusion and exclusion terms and rules embedded in the policy. In this paper, we describe this framework that has been built using technologies from AI, including Semantic Web, Modal/ Deontic Logic, and Natural Language Processing. We have validated our approach using industry standards proposed by the United States Federal Trade Commission (FTC) and applying it against publicly available policies of 7 cyber insurance vendors. Our system will enable cyber insurance seekers to automatically analyze various policy documents and make a well-informed decision by identifying its inclusions and exclusions.
引用
收藏
页码:33 / 40
页数:8
相关论文
共 50 条
  • [1] Automating integration of manufacturing systems and services: A Semantic Web Services approach
    Yang, ZH
    Gay, R
    Miao, CY
    Zhang, JB
    Shen, ZQ
    Zhuang, LQ
    Lee, HM
    IECON 2005: THIRTY-FIRST ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, VOLS 1-3, 2005, : 2255 - 2260
  • [2] Semantic Approach to Automating Management of Big Data Privacy Policies
    Joshi, Karuna P.
    Gupta, Aditi
    Mittal, Sudip
    Pearce, Claudia
    Joshi, Anupam
    Finin, Tim
    2016 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2016, : 482 - 491
  • [3] An approach to automating the integration of the Access Control Policies for Web Services
    Alodib, Mohammed
    2013 14TH ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING (SNPD 2013), 2013, : 181 - 187
  • [4] Facing Uncertainty in Cyber Insurance Policies
    Meland, Per Hakon
    Tondel, Inger Anne
    Moe, Marie
    Seehusen, Fredrik
    SECURITY AND TRUST MANAGEMENT (STM 2017), 2017, 10547 : 89 - 100
  • [5] The Semantic Approach to Cyber Security Towards Ontology Based Body of Knowledge
    Aviad, Adiel
    Wecel, Krzysztof
    Abramowicz, Witold
    PROCEEDINGS OF THE 14TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS-2015), 2015, : 328 - 336
  • [6] A New Approach to Automating Services
    Lacity, Mary C.
    Willcocks, Leslie P.
    MIT SLOAN MANAGEMENT REVIEW, 2016, 58 (01) : 41 - 49
  • [7] Analyzing Coverages of Cyber Insurance Policies Using Ontology
    Charalambous, Markos
    Farao, Aristeidis
    Kalantzantonakis, George
    Kanakakis, Panagiotis
    Salamanos, Nikos
    Froudakis, Evangelos
    Kotsifakos, Evangelos
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022, 2022,
  • [8] Steps Toward a Principled Approach to Automating Cyber Responses
    Musman, Scott
    Booker, Lashon
    Applebaum, Andrew
    Edmonds, Brian
    ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING FOR MULTI-DOMAIN OPERATIONS APPLICATIONS, 2019, 11006
  • [9] Semantic Usage Policies for Web Services
    Speiser, Sebastian
    SEMANTIC WEB - ISWC 2009, PROCEEDINGS, 2009, 5823 : 982 - 989
  • [10] Knowledge services on the semantic web
    Mentzas, Gregoris
    Kafentzis, Kostas
    Georgolios, Panos
    COMMUNICATIONS OF THE ACM, 2007, 50 (10) : 53 - 58