...
首页> 外文期刊>Cybersecurity >Social engineering in cybersecurity: a domain ontology and knowledge graph application examples
【24h】

Social engineering in cybersecurity: a domain ontology and knowledge graph application examples

机译:网络安全社会工程:域本体论和知识图应用示例

获取原文
           

摘要

Social engineering has posed a serious threat to cyberspace security. To protect against social engineering attacks, a fundamental work is to know what constitutes social engineering. This paper first develops a domain ontology of social engineering in cybersecurity and conducts ontology evaluation by its knowledge graph application. The domain ontology defines 11 concepts of core entities that significantly constitute or affect social engineering domain, together with 22 kinds of relations describing how these entities related to each other. It provides a formal and explicit knowledge schema to understand, analyze, reuse and share domain knowledge of social engineering. Furthermore, this paper builds a knowledge graph based on 15 social engineering attack incidents and scenarios. 7 knowledge graph application examples (in 6 analysis patterns) demonstrate that the ontology together with knowledge graph is useful to 1) understand and analyze social engineering attack scenario and incident, 2) find the top ranked social engineering threat elements (e.g. the most exploited human vulnerabilities and most used attack mediums), 3) find potential social engineering threats to victims, 4) find potential targets for social engineering attackers, 5) find potential attack paths from specific attacker to specific target, and 6) analyze the same origin attacks.
机译:社会工程对网络空间安全构成了严重的威胁。为了防范社会工程攻击,基本作品是要知道什么构成社会工程。本文首先在网络安全中开发了社会工程的域本体论,并通过其知识图应用进行本体评估。域本体论定义了11个核心实体的概念,这些核心实体显着构成或影响社会工程领域,以及22种关系,描述了这些实体如何彼此相关的关系。它提供了一个正式和明确的知识模式,以了解,分析,重用和分享社会工程的域名知识。此外,本文根据15个社会工程攻击事件和情景建立了知识图形。 7知识图表应用示例(在6种分析模式中)表明本体与知识图表有用于1)了解和分析社会工程攻击情景和事件,2)找到最高排名的社会工程威胁要素(例如最泛滥的人类漏洞和最常用的攻击媒体),3)找到对受害者的潜在社会工程威胁,4)找到社会工程攻击者的潜在目标,5)从特定攻击者到特定目标的潜在攻击路径,6)分析相同的源攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号