首页> 外文会议>Practical Aspects of Knowledge Management; Lecture Notes in Artificial Intelligence; 4333 >Ontology-Based Business Knowledge for Simulating Threats to Corporate Assets
【24h】

Ontology-Based Business Knowledge for Simulating Threats to Corporate Assets

机译:基于本体的业务知识,用于模拟对公司资产的威胁

获取原文
获取原文并翻译 | 示例

摘要

We propose a security ontology, to provide a solid base for an applicable and holistic IT-Security approach for SMEs, enabling low-cost threat analysis. Based on the taxonomy of computer security and dependability by Landwehr [ALRL04] and the threat classification according to Peltier [Pel01], a heavy-weight ontology can be used to organize and systematically structure knowledge on threats, safeguards, and assets. The ontology is used in an organization to capture business knowledge required for and created during a security risk analysis where instances of concepts are added to the ontology to allow the simulation of different attack and disaster scenarios. Each scenario can be replayed with a different protection profile as to evaluate the effectiveness and the cost/benefit ratio of individual safeguards.
机译:我们提出了一种安全本体,以为适用于中小企业的整体IT安全方法提供坚实的基础,从而实现低成本威胁分析。基于Landwehr [ALRL04]的计算机安全性和可靠性分类标准,以及根据Peltier [Pel01]进行的威胁分类,可以使用重量级的本体来组织和系统地构造有关威胁,防护和资产的知识。在组织中使用该本体来捕获在安全风险分析过程中所需和创建的业务知识,在该过程中,将概念实例添加到本体中以允许模拟不同的攻击和灾难情况。可以用不同的保护配置文件重播每种情况,以评估各个保障措施的有效性和成本/收益比。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号