首页> 外文会议>IEEE/WIC/ACM International Conference on Web Intelligence >Extending the VERIS Framework to an Incident Handling Ontology
【24h】

Extending the VERIS Framework to an Incident Handling Ontology

机译:将VERIS框架扩展到事件处理本体

获取原文
获取外文期刊封面目录资料

摘要

Statistics show that while large amounts of money are being invested in cybersecurity, the number of incidents continues to grow, with cyber attacks motivated by political and financial issues, many times funded by States as part of cyberwarfare. Although the general perception is that the occurrence of incidents is almost inevitable, the literature demonstrates that cybersecurity initiatives are often focused on prevention of incidents rather than its response, with many organizations often poorly prepared and ignoring key incident handling processes. Some initiatives were proposed in order to fill this gap, one of them being the VERIS framework, a "vocabulary for event recording and incident sharing." VERIS goal is to provide a basis for incident documentation, at the same time allowing the sharing of anonymized data to a community database, hence providing metrics for use within organizations or among external parties. As VERIS is a framework focused on information gathering and sharing, this work proposes the extension of the model from its original JSON representation to an OWL ontology, one of the main tools of the Semantic Web initiative, used for knowledge representation and strongly tied to the idea of information sharing. This work focus on the advantages of using such representation for incident handling.
机译:统计数据表明,尽管人们在网络安全上投入了大量资金,但事件的数量仍在继续增长,由于政治和金融问题而引发的网络攻击,许多次是由国家资助的,作为网络战的一部分。尽管人们普遍认为事件的发生几乎是不可避免的,但文献表明,网络安全举措通常侧重于事件的预防而不是其响应,许多组织通常准备不足,并且忽略了关键的事件处理流程。为了弥补这一空白,提出了一些倡议,其中之一就是VERIS框架,即“事件记录和事件共享的词汇”。 VERIS的目标是为事件文档提供基础,同时允许将匿名数据共享到社区数据库,从而提供在组织内部或外部各方之间使用的度量。由于VERIS是一个专注于信息收集和共享的框架,因此该工作提出了将该模型从其原始JSON表示扩展到OWL本体的一种方式,该本体是语义Web计划的主要工具之一,用于知识表示,并且与信息共享的想法。这项工作集中在使用此类表示进行事件处理的优点上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号