【24h】

Decentralized Semantic Threat Graphs

机译:分散的语义威胁图

获取原文

摘要

Threat knowledge-bases such as those maintained by MITRE and NIST provide a basis with which to mitigate known threats to an enterprise. These centralised knowledge-bases assume a global and uniform level of trust for all threat and countermeasure knowledge. However, in practice these knowledge-bases are composed of threats and countermeasures that originate from a number of threat providers, for example Bugtraq. As a consequence, threat knowledge consumers may only wish to trust knowledge about threats and countermeasures that have been provided by a particular provider or set of providers. In this paper, a trust management approach is taken with respect to threat knowledge-bases. This provides a basis with which to decentralize and delegate trust for knowledge about threats and their mitigation to one or more providers. Threat knowledge-bases are encoded as Semantic Threat Graphs. An ontology-based delegation scheme is proposed to manage trust across a model of distributed Semantic Threat Graph knowledge-bases.
机译:威胁知识库(例如由斜切和NIST维护的基础提供了一种基础,用于减轻对企业的已知威胁。这些集中知识库对所有威胁和对策知识都承担了全球和统一的信任程度。但是,在实践中,这些知识库由源自许多威胁提供者的威胁和对策组成,例如Bugtraq。因此,威胁知识消费者可能只希望信任对特定提供者或一套提供者提供的威胁和对策的知识。在本文中,对威胁知识库进行了信任管理方法。这提供了分散和委托对威胁知识及其对一个或多个提供者的缓解的基础。威胁知识库被编码为语义威胁图。提出了一种基于本体的委派计划,以管理分布式语义威胁图知识库模型的信任。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号