首页> 外文会议>IEEE Global Conference on Consumer Electronics >Ontology-based Dynamic and Context-aware Security Assessment Automation for Critical Applications
【24h】

Ontology-based Dynamic and Context-aware Security Assessment Automation for Critical Applications

机译:用于关键应用程序的基于本体的动态和上下文感知的安全评估自动化

获取原文

摘要

Several assessment techniques and methodologies exist to analyze the security of an application dynamically. However, they either are focused on a particular product or are mainly concerned about the assessment process rather than the product's security confidence. Most crucially, they tend to assess the security of a target application as a standalone artifact without assessing its host infrastructure. Such attempts can undervalue the overall security posture since the infrastructure becomes crucial when it hosts a critical application. We present an ontology-based security model that aims to provide the necessary knowledge, including network settings, application configurations, testing techniques and tools, and security metrics to evaluate the security aptitude of a critical application in the context of its hosting infrastructure. The objective is to integrate the current good practices and standards in security testing and virtualization to furnish an on-demand and test-ready virtual target infrastructure to execute the critical application and to initiate a context-aware and quantifiable security assessment process in an automated manner. Furthermore, we present a security assessment architecture to reflect on how the ontology can be integrated into a standard process.
机译:存在几种评估技术和方法来动态分析应用程序的安全性。但是,它们要么专注于特定产品,要么主要关注评估过程,而不是产品的安全性。最关键的是,他们倾向于将目标应用程序的安全性评估为独立的工件,而不评估其宿主基础结构。这样的尝试可能会低估总体安全状况,因为当基础结构承载关键应用程序时,基础结构就变得至关重要。我们提出了一种基于本体的安全模型,旨在提供必要的知识,包括网络设置,应用程序配置,测试技术和工具以及安全性指标,以评估关键应用程序在其宿主基础结构中的安全性。目的是将当前的良好实践和标准集成到安全测试和虚拟化中,以提供按需且可测试的虚拟目标基础结构,以执行关键应用程序并以自动化方式启动上下文感知和可量化的安全评估过程。此外,我们提出了一种安全评估体系结构,以反映如何将本体集成到标准流程中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号