CSIHO: An Ontology for Computer Security Incident Handling

Guilherme Baesso Moreira, Vanusa Menditi Calegario, Júlio César Duarte, Anderson Fernandes Pereira dos Santos · 2018

The information technology advancements in the last decades led the society to a growing process of dependency on computer systems and Internet-based services. This complex and dynamic scenario implies more challenging cyberdefense initiatives, but, although the industry is applying countless efforts to ensure the Information Security, considerable growth in frequency and severity of incidents is still observed. The primary objective of this work is to present a new model for incident handling, described as an ontology, which is easily extensible and integrable with other models, besides allowing logical inferences and simplifying the knowledge transfer within a collaborative cyber defense context. Among its contributions, the creation of the Computer Security Incident Handling Ontology (CSIHO), in OWL format, can be highlighted. In order to demonstrate the applicability of the ontology, SPARQL queries were created based on competency questions derived from CSIHO, which, as far as we know, is the first cyber security ontology that focuses on incident handling and defines and implements the fundamental concepts of security events while also supporting the recording of temporal aspects of an incident.

Read the paper · More papers on PaperTik